shadow ai discovery governance radar
Detect, inventory, and risk-score unofficial AI agents, custom GPTs, and MCP tools across your organization.
$5
Works with the AI tools you already use
shadow ai discovery governance radar
Example session with this skill installed
Run a shadow AI audit on the /infrastructure and /docs directories. Identify any bots or custom GPT configurations and map their data access risks.
- Read your context and instructions
- Compiled the shadow ai discovery
| Asset | Type | Owner | Data Access | Risk | Gap | Remediation |
|---|---|---|---|---|---|---|
| terraform-gen-bot | MCP Tool | DevOps | AWS Config, GitHub | High | No Audit Trail | Enable logging & register |
| finance-gpt | Custom GPT | Finance | Expense CSVs | Medium | Third-party host | Move to internal instance |
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
The problem
Employees often deploy custom GPTs, MCP servers, and unofficial AI bots without IT oversight, creating massive blind spots for data privacy and security. These "shadow AI" assets bypass standard DLP and governance protocols, leaving sensitive company data exposed to unvetted third-party providers.
What it does
- Scans code repos, configuration files, and API gateways to inventory unofficial AI agents and bots.
- Maps asset ownership, data access levels, and specific permissions (Read/Write/Admin).
- Categorizes assets into types like Custom GPTs, MCP Tools, and Copilots.
- Performs risk scoring based on data exposure, compliance violations (GDPR/HIPAA), and authentication strength.
- Generates structured remediation plans to bridge identified governance gaps.
Why this beats prompting it yourself
General prompts lack the structured logic required to cross-reference network traffic, cloud logs, and registry files for AI-specific signatures. This skill provides a systematic framework for classification and risk scoring that ensures no asset is missed, transforming vague concerns into an actionable governance registry.
Use cases
- Conducting a pre-audit inventory of AI tools before a security compliance review.
- Identifying high-risk custom GPTs that have write access to sensitive CRMs.
- Mapping the footprint of MCP (Model Context Protocol) tools across developer environments.
- Establishing a formal AI registry by surfacing and vetting existing shadow deployments.
Known limitations
Discovery is limited to data sources the agent has authorized access to scan. It cannot detect AI usage within encrypted personal traffic or on unmanaged hardware.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 23 days ago
- Passed all security checks, Safe to install