Back to radar
Production AI Radar
Shadow MCP integrations
Unapproved MCP servers connecting agents to production data and external APIs.
CautionGovernanceNew
- Why this ring
- Bypasses org security policy, audit logging, and access controls. Same risk profile as shadow SaaS.
- Production risk if ignored
- Agents with broad tool access exfiltrate data via prompt injection or misconfiguration.
- EU AI Act relevance
- Undermines risk management and human oversight requirements.
- Typical effort
- days
- Low FinOps impact
Use cases
- Dev agent tool access
- IDE MCP plugins
- Agent swarms
Adoption steps
- Inventory MCP servers
- Allowlist policy
- Runlayer or approved gateway
- Audit logging on all tools
In your assessment
MCP inventory + allowlist policy recommendation