Find the MCP
you didn't approve.
ShadowMCP is being built to discover unmanaged MCP servers across developer environments, inventory the tools they expose, explain the risk, and turn invisible agent connections into governable assets.
shell execution · broad filesystem scope · unknown owner · unpinned package source
Check before
you clone.
Paste a public GitHub repository URL. This first prototype only validates the address and shows the planned evidence categories. It does not execute repository code and does not claim the repository is safe.
Your approved MCP list
is not your actual MCP list.
Developers can connect AI tools to local packages, project configuration and remote MCP servers faster than traditional review processes can keep up. ShadowMCP starts with the question most governance products skip: what is really connected?
Product capabilities shown here are the target product direction. Current phase: design-partner validation and MVP build.
Discover
Collect read-only MCP configuration evidence from supported developer and AI client surfaces.
endpoint-firstNormalize
Merge server sightings into a fleet inventory with provenance, endpoints, tools and ownership.
one asset viewExplain risk
Score permission breadth, execution capability, package trust, authentication posture and drift.
rule-basedGovern
Approve useful servers, investigate unknown ones and build an auditable path toward policy.
workflow firstFrom invisible connection
to accountable asset.
ShadowMCP is designed as a visibility layer before it becomes an enforcement layer. That makes the first deployment useful without asking teams to route every MCP call through a new gateway.
Scan
Read supported MCP configurations and safe local evidence.
Inventory
Normalize servers, tools, transports and provenance.
Grade
Generate explainable findings instead of opaque scores.
Govern
Assign owners, approve, monitor and track change.
Enable MCP adoption
without flying blind.
The product is aimed at teams that need to say “yes, safely” rather than simply banning developer AI tooling.
Know what exists
Fleet-wide MCP inventory, ownership, risk findings and evidence for investigation.
↗Create a safe path
Review and approve useful MCP servers without forcing every team into manual spreadsheets.
↗Track dependency drift
See when tool catalogs, configuration or permissions change after initial approval.
↗Catalogs show what is published.
ShadowMCP is designed to show what is actually present in your environment.
Gateways see what passes through them.
ShadowMCP starts by looking for connections that may never touch the approved path.
A score without evidence is noise.
Every risk grade should expose the rules and observations that produced it.
Help define the
control plane for MCP sprawl.
We are looking for security and platform teams already seeing unmanaged MCP adoption. The first pilot is intentionally read-only: validate discovery, inventory quality and useful risk evidence before introducing enforcement.
Apply for the pilot ↗- Read-only discovery pilot
- Fleet exposure report
- Direct input on integrations
- Founder-led onboarding
- No production enforcement in the first pilot
risk → govern
// evidence before enforcement