Back to radar

Production AI Radar

Shadow MCP integrations

Unapproved MCP servers connecting agents to production data and external APIs.

CautionGovernanceNew
Why this ring
Bypasses org security policy, audit logging, and access controls. Same risk profile as shadow SaaS.
Production risk if ignored
Agents with broad tool access exfiltrate data via prompt injection or misconfiguration.
EU AI Act relevance
Undermines risk management and human oversight requirements.
Typical effort
days
Low FinOps impact

Use cases

  • Dev agent tool access
  • IDE MCP plugins
  • Agent swarms

Adoption steps

  1. Inventory MCP servers
  2. Allowlist policy
  3. Runlayer or approved gateway
  4. Audit logging on all tools

In your assessment

MCP inventory + allowlist policy recommendation