The Attack Surface Used to Be Code. Now Part of It Is a Conversation.
I came across a tool today called Proximity. At first it was just another link throwing you at GitHub, but after a few minutes of reading I felt it was opening a small window onto something much bigger than it looks at first glance.
Proximity is a scanner for MCP servers. It collects tools, prompts and resources, then analyses them with a system called NOVA – a system that tries to understand intent, not just words. It combines keyword detection, semantic similarity, and evaluation based on LLMs. The goal is to identify attempts to bypass restrictions, to jailbreak, or to perform prompt injection.
What caught me was not the technical side
It was the moment I understood that systems we are used to seeing as classic application servers have, over the last few months, become something else entirely. Not just code that runs, but a system in constant conversation with tools, models, resources and contexts.
And here is the real story. In the worlds I come from – information security and application security – we were used to the attack surface being code, configuration, operating systems, permissions. Today, part of the attack is text. Context. Conversation. Intent.
That feels strange at first. Almost unnatural. But think about it for a second: a developer who does not know AppSec, and has no awareness at all that a prompt can be an attack vector, will write code that works perfectly from a logical point of view – while everything around it is wide open.
This is not a matter of human error. It is dealing with a lack of awareness of something new that entered our systems before we were ready for it.
Where the limits of AI belong in this
It is also the place to be clear about what AI is not. It is not magic. It does not replace security thinking. It does not understand deep context the way we would like to believe. And it is certainly not meant to execute code blindly, without a framework and without control.
The more I think about it, the more I see how relevant this is for a CISO moving into AI worlds, a CTO leading a new product, or a VP R&D introducing models into an existing stack. Not in the sense of being alarmed – in the sense of stopping for a moment and asking what the system actually does, rather than what we think it does.
Proximity simply reminded me that systems built around models are becoming more organic. Less predictable. Less linear. More dependent on context. And when that is the situation, the defence has to change with it.
I first shared a version of this as a LinkedIn post on 2025-12-07. It is republished here, lightly edited, so it is easier to find and reference. — Erez Metula
