A new NPM package, @guardion/shadow-ai, has been released, designed to identify the unauthorized use of AI tools on macOS, Linux, and Windows devices.
What Happened
Developers have introduced @guardion/shadow-ai — a tool for inventorying unauthorized AI assets. The package can detect AI applications, autonomous agents, MCP servers, skills, and plugins. The system assigns a security score to each discovered asset based on risk analysis and tracks configuration drift.
Context
The Shadow AI problem involves employees using unauthorized AI tools with corporate resources, creating risks of sensitive data leaks. With the development of the Model Context Protocol (MCP) and the proliferation of local LLM runners, controlling the extensibility of agentic systems has become critical for cybersecurity.
Why It Matters for the Industry
The emergence of such tools marks a transition from chaotic AI adoption to an era of corporate governance for agentic systems. Support for the MCP protocol allows for standardized control over system extensibility, while the ability to audit local LLM runners and MCP servers lays the foundation for the AI Governance market and AI observability standards.
Why It Matters for Users
System administrators and security specialists gain the ability to see a complete picture of the AI software in use, including hidden components that typically do not appear in standard application lists. This enables real-time risk identification and ensures compliance in distributed agentic environments.
What Is Not Yet Known / Limitations
There is a difference in how the tool is perceived: technical specialists view it as a means of observability and infrastructure management, whereas developers may perceive it solely as a compliance tool that does not affect workflow speed.
Sources
Author
Look at AI, Editorial Team
