Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    shadow agent inventory audit

    1

    Discover unsanctioned AI agents, MCP servers, and LLM scaffolds committed across your git organization.

    $11

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned
    shadow agent inventory audit

    shadow agent inventory audit

    Example session with this skill installed

    Run an inventory sweep across the 'acme-co' GitHub org. We need to find any LangGraph or MCP configs committed in the last 6 months and see which ones are actually tied to active CI jobs.

    • Read your context and instructions
    • Compiled the shadow agent inventory
    • Generated the document

    I have completed the inventory sweep for the

    acme-co GitHub organization. I scanned 42 repositories, identifying 7 unique agent configurations across 12 locations.

    Shadow Agent Inventory Report

    FindingRepositoryCategoryConfidence TierLast Modified
    claude_desktop_config.jsonacme-internal-toolsMCP ClientHigh (Active CI)2024-05-12
    agents.yamlmarketing-automationCrewAI ScaffoldHigh (Active CI)2024-06-01
    .mcp.jsondev-sandbox-alphaMCP ClientLow (Config Only)2024-02-15
    langgraph.jsoncustomer-support-botLangGraphHigh (Active CI)2024-05-28
    OAI_CONFIG_LISTresearch-scriptsAutoGenLow (Config Only)2024-03-10

    Coverage Statement
    Scanned 42 of 45 known repos in acme-co's primary GitHub namespace as of 2024-06-07.
    Excluded from this sweep: 3 private repos without access.
    Out of scope by construction: workstation-local or gitignored configs never committed to any repo; agents wired up in interactive sessions; secrets referenced by name (e.g. ${AGENT_ENDPOINT}) where the destination is masked.

    Next steps

    1. Review the High confidence findings in acme-internal-tools and marketing-automation to identify owners.
    2. Run agent-skill-security-scanner on the discovered MCP configs to verify server safety.
    3. Add the verified configurations to your central approved-agent registry.

    shadow-agent-inventory-audit.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Identify shadow AI agents committed to production repositories.Detect unapproved MCP server configurations in developer dotfiles.Audit CI/CD workflows for unauthorized LLM API invocations.Baseline your organization's AI surface area for security reviews.

    About this skill

    Engineering teams are losing visibility into the AI agents, MCP servers, and LLM-framework scaffolds their developers are committing to source control. This skill provides a static, file-based inventory sweep to identify unsanctioned AI tooling across an entire GitHub or GitLab organization. It solves the "shadow AI" problem by scanning repositories for specific configurations like .mcp.json, LangGraph scaffolds, and agent-invoking CI jobs that bypass traditional governance.

    What it does

    • Multi-repo scanning identifies agent configurations and framework scaffolds across all accessible organization repositories.
    • Signal verification reads file contents to filter out false positives from documentation examples, test fixtures, or vendored dependencies.
    • Confidence tiering distinguishes between abandoned experimental configs and actively invoked agents corroborated by CI/cron signals.
    • Coverage reporting generates a mandatory audit statement detailing scanned versus total repos and specific blind spots like gitignored local configs.
    • Allowlist cross-referencing marks findings as either matching existing approvals or requiring immediate owner review.

    How it works

    1. Define the sweep scope by enumerating all repositories in the primary GitHub or GitLab namespace and identifying excluded categories like private or archived repos.
    2. Execute pattern matching against the source control for MCP client configs, framework files like agents.yaml, and LLM-calling CI workflows.
    3. Classify findings by opening each hit to verify it is a functional configuration rather than a code comment or tutorial file.
    4. Generate the inventory as a consolidated report or automated script that dedupes findings and assigns confidence tiers.

    Frameworks & tools

    The skill targets MCP (Model Context Protocol), LangGraph, CrewAI, AutoGen, and OpenAI configuration standards. It integrates with GitHub and GitLab APIs for organizational-scale scanning.

    Why this beats prompting it yourself

    Generic prompts often fail to distinguish between a tutorial file and a production agent, leading to high false-positive rates. This skill enforces strict content-reading rules and provides a defensible audit methodology that accounts for repository-scale deduplication and CI-invocation signals.

    Use cases

    • Conduct a pre-audit discovery to see which teams are using unapproved MCP servers.
    • Build a baseline inventory before migrating to an enterprise AI governance platform.
    • Monitor for "config drift" where developers commit new agent scaffolds into existing repos.

    Known limitations

    Cannot detect agents wired in interactive sessions or configs stored in gitignored local directories. Static scanning does not monitor live network traffic or browser extensions.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 1 day ago

    • Passed all security checks, Safe to install

    Listed1 day ago

    What's inside

    Frequently Asked Questions