MCP exposure management · design-partner phase

Find the MCP
you didn't approve.

ShadowMCP is being built to discover unmanaged MCP servers across developer environments, inventory the tools they expose, explain the risk, and turn invisible agent connections into governable assets.

01 discover02 inventory03 risk-grade04 govern
EXPOSURE / SAMPLE TENANT
SYNTHETIC DATA
DISCOVERED42MCP servers
SHADOW07unreviewed
CRITICAL03needs review
SERVERSOURCERISK
filesystem-opsproject config84 · CRITICAL
customer-dbremote67 · HIGH
github-localuser config43 · MEDIUM
docs-searchapproved18 · LOW
WHY 84?

shell execution · broad filesystem scope · unknown owner · unpinned package source

DISCOVERYMCP INVENTORYEXPLAINABLE RISKCONFIG DRIFTAPPROVAL WORKFLOWDISCOVERY
EXPERIMENTAL / REPO SCAN

Check before
you clone.

Paste a public GitHub repository URL. This first prototype only validates the address and shows the planned evidence categories. It does not execute repository code and does not claim the repository is safe.

Prototype only · read-only · no repository code is executed.

01 / THE BLIND SPOT

Your approved MCP list
is not your actual MCP list.

Developers can connect AI tools to local packages, project configuration and remote MCP servers faster than traditional review processes can keep up. ShadowMCP starts with the question most governance products skip: what is really connected?

Product capabilities shown here are the target product direction. Current phase: design-partner validation and MVP build.

01

Discover

Collect read-only MCP configuration evidence from supported developer and AI client surfaces.

endpoint-first
02

Normalize

Merge server sightings into a fleet inventory with provenance, endpoints, tools and ownership.

one asset view
03

Explain risk

Score permission breadth, execution capability, package trust, authentication posture and drift.

rule-based
04

Govern

Approve useful servers, investigate unknown ones and build an auditable path toward policy.

workflow first
02 / THE WORKFLOW

From invisible connection
to accountable asset.

ShadowMCP is designed as a visibility layer before it becomes an enforcement layer. That makes the first deployment useful without asking teams to route every MCP call through a new gateway.

01

Scan

Read supported MCP configurations and safe local evidence.

02

Inventory

Normalize servers, tools, transports and provenance.

03

Grade

Generate explainable findings instead of opaque scores.

04

Govern

Assign owners, approve, monitor and track change.

03 / BUILT FOR THE TEAMS IN THE MIDDLE

Enable MCP adoption
without flying blind.

The product is aimed at teams that need to say “yes, safely” rather than simply banning developer AI tooling.

A / SECURITY

Know what exists

Fleet-wide MCP inventory, ownership, risk findings and evidence for investigation.

B / PLATFORM

Create a safe path

Review and approve useful MCP servers without forcing every team into manual spreadsheets.

C / AI ENGINEERING

Track dependency drift

See when tool catalogs, configuration or permissions change after initial approval.

04 / WHY SHADOWMCP
NOT A REGISTRY

Catalogs show what is published.

ShadowMCP is designed to show what is actually present in your environment.

NOT ONLY A GATEWAY

Gateways see what passes through them.

ShadowMCP starts by looking for connections that may never touch the approved path.

NOT A BLACK BOX

A score without evidence is noise.

Every risk grade should expose the rules and observations that produced it.

05 / DESIGN PARTNER PROGRAM

Help define the
control plane for MCP sprawl.

We are looking for security and platform teams already seeing unmanaged MCP adoption. The first pilot is intentionally read-only: validate discovery, inventory quality and useful risk evidence before introducing enforcement.

Apply for the pilot
DESIGN PARTNER / 01
  • Read-only discovery pilot
  • Fleet exposure report
  • Direct input on integrations
  • Founder-led onboarding
  • No production enforcement in the first pilot
COMMUNITY SCANNERPlanned free
TEAM CONTROL PLANEDesign partner
ENTERPRISERoadmap
ShadowMCP · design-partner phase

Make shadow MCP
visible.

Talk to ShadowMCP
discover → inventory
risk → govern
// evidence before enforcement