Unregistered MCP servers on vulnerable versions. Coding agents nobody approved. Secrets pasted into ChatGPT. One lightweight sensor discovers all of it, scores the risk, proves it to your auditors — then blocks the leak and quarantines the endpoint.
*Directional market figures, illustrative of the category — replace with cited sources before publishing.
Network traffic is only one of them. The sensor sweeps every endpoint — because the coding agent installed from a website, or the API key sitting in a shell profile, never shows up in a firewall log.
Outbound calls to LLM APIs and agent web apps — matched by hostname (DNS/SNI), not shared CDN IPs.
real-time · eBPFEvery MCP server and downloaded skill — with its package, version, and the actual source repo.
provenanceProvider keys in env, .env files, and shell profiles — the strongest proof of use. Masked, never exfiltrated.
highest signalDesktop LLM runtimes, coding-agent CLIs, and import openai-style SDK use in running code.
on-deviceEvery extension enumerated by stable ID — AI assistants flagged, nothing quietly filtered out.
by IDTen stages, one platform — from seeing an asset to stopping a leak. Built like an EDR, not a scanner script.
Risks are scored, explained, and ranked — vulnerable MCP versions, typosquats, secrets, unverified provenance — each with the machine, the person, and the fix attached.
| Severity | Class | Risk | Machine | Owner | Status |
|---|---|---|---|---|---|
| critical | Typosquat | @modelcontextprotocol/server-filesysem | WIN-4471 | j.smith | open |
| high | Vulnerable | server-filesystem@0.3.1 · SHAI-2026-001 | MAC-0192 | r.patel | open |
| high | Secret | Plaintext Anthropic API key | MAC-0192 | r.patel | open |
| medium | Provenance | Skill from github.com/randomuser/pdf-skills | LNX-0088 | k.chen | open |
| info | Sanctioned | Claude Code (approved) | MAC-0192 | r.patel | sanctioned |
Illustrative preview — example risks, not live data.
Detection is table stakes. Shadow AI is an enforcement point — it blocks the leak in the browser and can kill a compromised agent across the fleet in one click.
A browser/proxy inspects each prompt and blocks secrets and source code — redacts PII — before it reaches ChatGPT, Claude, or Gemini.
Quarantine an endpoint from the console; the command lands on the agent's next heartbeat and halts collection — with a tamper-evident audit trail of who did it.
Every risk auto-maps to the frameworks your board reports against — the evidence pack that otherwise takes analysts weeks. Export an AI Bill of Materials per host, and hand the assessor a live inventory.
One static binary per OS with a real-time eBPF tracer, feeding a central engine that scores, correlates, and enforces — designed to fail visibly, never silently.
Beyond the platform, we run fixed-fee engagements that turn AI risk into audit-ready evidence: EU AI Act readiness, adversarial red teams, shadow-AI discovery, and continuous testing — delivered with the same tooling, published openly.
Article 9 & 55 evidence, populated — not a template.
2–3 WEEKS · FLAGSHIPAdversarial testing of one LLM app or agent.
2 WEEKS · + RE-TESTApp, RAG and agent layers — including chained paths.
4 WEEKS · DEEPWhat unapproved AI is running right now.
1–2 WEEKSKeep the harness running as models change.
ROLLINGOwn your AI risk programme without a hire.
ONGOINGAgents got hands — MCP and tool-calling turned chatbots into systems that read files, run code, and hold credentials. Regulation entering enforcement now requires organisations to document where AI-processed data flows and prove control over it.
Most teams still can't answer the first question an auditor asks: which AI agents and MCP tools are running in your network right now, unapproved? This answers it in minutes, not quarters.
We're onboarding a small number of design partners for a free Shadow AI Assessment — run the sensor, get a risk report and an AIBOM.