// shadow-AI discovery

Shadow-AI detection for coding agents.

Most AI use at work runs through personal accounts and tools security never approved. MoorAI inventories the AI on each device — the apps, accounts, agents, and extensions — from redacted, content-free signals, so shadow AI stops being a blind spot. On-device, open source, macOS & Windows.

// on each device

What MoorAI discovers.

Signals a network proxy can't see — because they live on the endpoint, not on the wire.

Gateway-based shadow-AI discovery only sees what crosses the corporate egress. A developer off the VPN, an agent calling a model API directly, a locally-configured MCP server, a personal account on a personal network — none of it reaches the proxy, so none of it appears in the inventory. MoorAI reads the device itself, so coverage doesn't depend on the traffic taking a particular path.

Personal vs corporate
Agent accounts
Which account each AI agent (Claude Code, Codex, Copilot CLI) is signed in as — accounts on non-corporate domains flagged as personal. Never the token, only the identity.
Unmanaged tools
AI apps & CLIs
ChatGPT, Claude, Cursor, Ollama, LM Studio and the agent CLIs on the device — sanctioned or not — each rated by data-exposure risk.
Agent posture
MCP servers
The Model Context Protocol servers each agent has wired up — local, container, or remote — with unapproved and risky-config servers flagged.
Browser reach
AI extensions
AI extensions across Chrome, Edge, Brave, Firefox and Safari — and which can read the pages you visit.
// roll-up

From inventory to a readiness score.

Every signal rolls up into a per-device trust score and a per-tenant, board-level AI-readiness number: how many devices report in, how many personal accounts and unapproved MCP servers are in play, how many high-risk AI apps are installed, and what the endpoint posture (antivirus, patch state) looks like. A content-free data-lineage trail shows which data categories left via which agent over time — never the content itself.

// faq

Frequently asked.

Does it capture the account password or token?

Never. MoorAI reads only the account name/identity for reporting, and never the credential.

Can it flag personal vs corporate accounts?

Yes — set your corporate email domains and any agent account on another domain is flagged as personal.

What about MCP tool poisoning?

MoorAI flags MCP servers whose launch config fetches and pipes remote code to a shell — a high-signal proxy for a poisoned tool.

More: on-device AI DLP · OWASP LLM Top 10 tooling · MoorAI vs Netskope

See the shadow AI
on your fleet.

Accounts, apps, MCP, extensions — from content-free signals.

glick.run — AGPL-3.0