Triage by Risk Level
Shadow MCP Servers
The Runlayer dashboard categorizes discovered shadow servers as Managed available (a matching Runlayer connector exists) or New server (no matching connector). Use these categories alongside the risk assessment framework below to prioritize your response.Shadow Skills
AI Clients, Plugins, and Agents
Detect also inventories the AI clients themselves, their installed plugins and extensions, and agent definitions (agent frameworks in use, plus custom agent files that carry their own instructions and tool access). Triage these by what they can reach rather than by a scanner verdict:- Unapproved AI client — decide whether to allow it. Mark it as Managed from the Shadow AI → Details tab or add it under Settings → AI client allowlist; otherwise ask the user to remove it and consider blocking it on managed devices.
- Plugin or extension — plugins can bundle their own MCP servers and skills. Review the publisher and requested access the same way you review a shadow MCP server.
- Agent or custom agent — read the agent’s instructions like you would a skill: look for prompt-injection patterns, external endpoints, and tool access broader than the user’s need.
Investigation Checklist
Gather Context
Gather Context
- Identify the user and their role
- Determine when the MCP or skill was configured/installed
- Review the stated purpose and actual capabilities
- Check if the MCP connects to external endpoints
- Assess what data the MCP or skill could access
Evaluate MCP Server Source
Evaluate MCP Server Source
- Is it from a known vendor (GitHub, Slack, etc.)?
- Is it an open-source project? Check repository activity and maintainers
- Is it internally developed? Verify with the development team
- Are there any known vulnerabilities or security advisories?
Evaluate Skill Source
Evaluate Skill Source
- Is the skill from a trusted, known repository?
- Does the skill contain instructions that could manipulate AI behavior (prompt injection)?
- Does the skill instruct the AI to send data to external endpoints?
- Is the skill a community skill or internally developed?
- Does the skill’s scope match the user’s legitimate needs?
Determine Business Need
Determine Business Need
- Does the user have a legitimate business reason?
- Could an existing Runlayer-managed MCP or skill fulfill the need?
- Is this a one-off or widespread usage pattern?
Remediation Options
Remediation Options
- Migrate: Help user set up equivalent Runlayer-managed MCP or skill
- Approve: Submit for formal review and add as a managed connector
- Remove: Use MDM to remove configuration from device
- Block on the device: In Protect, add the server to the policy denylist. In Enforce, leave it off the allowlist or remove its existing allowlist entry. This stops future calls without waiting for an MDM change.
Response Workflow
Related Resources
Security Best Practices
Comprehensive MCP security guidelines and threat prevention
Audit Logs
View detailed activity logs for investigations