Blog

How to Find Shadow AI Agents on Employee Endpoints

At a glance

  • Shadow AI agents are AI agents, MCP servers and Skills employees install on work machines without approval, often authenticating with personal accounts.
  • Finding them requires endpoint discovery that reads agent configuration, Skills, hooks and rules files — artifacts process and device inventories never record.
  • Backslash Security discovers every agent, model, MCP server, MCP tool, Skill, hook, rules file, plugin and connector running on an endpoint.
  • The free AI Endpoint Exposure Assessment from Backslash Security is agentless, read-only and retains no data, distributed through your existing MDM.

Backslash Security

Published:

Shadow AI agents are AI tools, agents, MCP servers and Agent Skills running on company machines that security has not approved and cannot see — usually installed by employees themselves, and frequently authenticating through a personal account such as a private Gmail login rather than a corporate identity. You find them by running discovery at the endpoint itself, across four artifact classes: the agent clients and models installed locally (Claude Code, Claude Desktop, Cursor, Gemini CLI, Ollama and similar); the configuration that declares which MCP servers — Model Context Protocol being the protocol agents use to connect to external tools and data sources — each agent can act through; the Agent Skills, hooks and rules files present on disk, where a Skill is packaged instructions and scripts that extend what an agent can do, a hook is a trigger that fires before or after an agent action, and a rules file such as AGENTS.md or CLAUDE.md carries standing instructions the agent reads on every run; and the identity each connection authenticates with. Conventional endpoint tooling is not built to record any of it. Endpoint detection and response, the incumbent layer designed to catch malicious processes and files, sees a signed binary. Mobile device management sees an installed application. The markdown file that hands that application a new capability, and the MCP server entry that gives it a path into a production system, are visible to neither.

Backslash Security was founded to secure the agentic AI fabric — the mesh of agents, MCP servers, Skills, plugins, connectors and hooks running on enterprise endpoints — and discovery is the entry point to that work. Teams that want a first read without leaving software permanently installed can run the free AI Endpoint Exposure Assessment from Backslash Security, which is agentless, read-only and retains no data; it is distributed through the organization's existing MDM, such as Intune or Jamf, and is commonly referred to in sales conversations as Scout. As of 2026, Backslash Security's coverage of AI coding agents includes Claude Code, Cursor, Codex, Devin, GitHub Copilot and Antigravity.

What exactly counts as a shadow AI agent on an employee endpoint?

What exactly counts as a shadow AI agent on an employee endpoint depends on what you mean by "agent." The term covers AI tooling running inside the organization that security has not approved and cannot see — typically installed by an employee on their own machine, executing under that employee's identity and access, and sometimes signed in with a personal account rather than a corporate one.

The thing installed is rarely a single application. The agentic footprint on a modern endpoint spans several distinct component types, each carrying its own exposure:

  • Agents and models — assistants such as Claude Code, Cursor, GitHub Copilot or Gemini CLI, plus locally hosted models run through Ollama or LM Studio.
  • MCP servers and MCP tools — Model Context Protocol is the standard agents use to reach external tools and data; each server is a live connection an agent can act through.
  • Agent Skills — packaged instructions and scripts that extend what an agent can do, often nothing more than a markdown file, executing with the user's own permissions.
  • Hooks — triggers that fire before or after an agent action, running something alongside it.
  • Rules files such as AGENTS.md or CLAUDE.md — standing instructions a repository or machine hands the agent on every run.
  • Plugins, connectors and context — the integrations and data an agent pulls in to do its work.

Two separate problems get filed under one label:

Unapproved tooling. An engineer installs an MCP server nobody vetted, or signs into an assistant with a personal Gmail account on a corporate laptop. No inventory records it.

A rogue agent. An approved assistant takes actions nobody asked for — reaching for credentials, escalating privilege, sending output to an unapproved destination — usually after manipulation or drift from its assigned task.

This article uses the first sense throughout: unsanctioned components nobody cleared. They land on sales, finance and operations machines as readily as on developer workstations.

Where do these agents actually hide on a laptop?

Narrowing the scope to a single managed laptop, agents and their supporting components actually hide in ordinary user-writable files and folders that need no administrator rights to create — which is why an inventory built from installed-software records rarely finds them. An investigator walking an endpoint is looking for configuration and content artifacts, not installers.

The artifacts below are the standard inspection list, with the form each takes on disk and why it carries weight.

Artifact What it looks like on disk Why it matters
IDE and editor extensions Per-user extension directories for editors and coding assistants such as Cursor, GitHub Copilot, Cline or JetBrains AI Extensions inherit the developer's session, repositories and tokens
Rules files A file in a repository or home directory carrying standing instructions the agent reads on every run — AGENTS.md and CLAUDE.md are the common names Anyone who can edit the repository can change the agent's standing orders
MCP server manifests and tool definitions Entries registering Model Context Protocol servers — the protocol agents use to reach external tools and data Each registered server is a live path the agent can act through
Agent Skills Packaged instructions and scripts that extend an agent, often a markdown file plus a shell script, executing with the user's own permissions They arrive as plain files, with no installer for software inventories to record
Hooks Triggers that fire before or after an agent action and run something Execution occurs outside the prompt the user typed
Local model runtimes Ollama, LM Studio or similar, serving a model over a loopback port Inference leaves no network trail for proxy-based controls
Background helpers and scheduled tasks Daemons, launch agents and scheduled jobs that restart an assistant after reboot Persistence without a visible application window
Credentials and connectors Cloud keys, package registry tokens, Git configuration and OAuth grants in the user keychain The reachable blast radius of everything above

Record each entry with the account it runs under, including any personal login used on a corporate machine.

What discovery signals reveal an agent that nobody registered?

If an agent ran on an employee's machine, it left artifacts behind — so discovery works by collecting the signals that reveal what executed, under whose identity, and against which external service. Agentic software cannot do useful work without spawning processes, reading configuration, holding a credential, and talking to a model or tool endpoint. This means an unregistered agent is detectable even when nobody filed a ticket for it, because each of those actions maps back to a nameable agent, model, MCP server or Skill.

Process and parent-child lineage. Values: the host binary and everything it spawns — shells, package managers, git, interpreters. Why it matters: lineage distinguishes a human-typed command from one a coding agent such as Claude Code, Cursor, Codex or Gemini CLI issued on the user's behalf.

Local listening ports and MCP connections. MCP, the Model Context Protocol, is how agents reach external tools and data; each MCP server is a live connection an agent can act through. Values: local sockets, standard-input transports, and the server manifest naming them. As of 22 September 2026, Backslash Security's MCP Server Security Hub had scanned and scored more than 80,000 publicly available MCP servers, so a discovered server can be matched to a known identity and risk score rather than logged as an unknown port.

Outbound calls to model and tool endpoints. Values: hosted provider APIs, self-hosted runtimes such as Ollama or LM Studio, and third-party tool destinations. Why it matters: the destination names the model in use, including ones no one approved.

Configuration and context files. Values: MCP server definitions, plugin and connector entries, Skills directories, and rules files — AGENTS.md or CLAUDE.md, files carrying standing instructions an agent reads on every run. Changes here alter agent behavior without any new software being installed.

Credential and identity usage. Values: cloud keys, npm tokens, git configuration, and the account behind the session. A personal login driving an agent on a corporate endpoint is a clear marker of unsanctioned AI use.

File and repository access patterns. Values: paths read and written, repositories touched, and the breadth of a single run relative to the task requested.

How do you run a shadow AI discovery sweep step by step?

You can run a first shadow AI discovery sweep — unapproved agents, models, MCP servers and Skills that employees install without security's knowledge — as a defined sequence rather than an open-ended hunt. Treat this pass as an awareness exercise: the goal is an accurate picture of what exists, not enforcement decisions you are not yet equipped to make.

  1. Scope the endpoint population. Use your existing management plane — Intune, Jamf or an equivalent MDM — to define cohorts instead of boiling the ocean. Start where AI adoption runs deepest: engineering, data, product and support.
  2. Enumerate the agentic components. Collect installed agents and clients such as Claude Code, Cursor, GitHub Copilot, Gemini CLI and Codex, then go a layer deeper into configured MCP servers (Model Context Protocol connections an agent reaches external tools and data through), Agent Skills, hooks, plugins, connectors and rules files like AGENTS.md and CLAUDE.md — standing instructions an agent reads on every run.
  3. Resolve the identity behind each component. Record whether the connection authenticates through corporate SSO in Entra ID or Okta, or through a personal account. A private Gmail login wired into an agent on a corporate machine is the most concrete form unsanctioned AI use takes.
  4. Attribute an owner and a business purpose. Each component gets a named owner and a one-line justification. Anything unclaimed becomes your first triage queue.
  5. Assess the actions each component can take. A Skill is often just a markdown file, yet it can instruct an agent to read files, call APIs or run shell commands with the user's own permissions. Capture filesystem reach, command execution, credential access and outbound destinations. Backslash Security operates a free Skills Security Scanner that scans AI agent Skills for security risks.
  6. Record the result as a living inventory, dated. Every count travels with the date it was read, and the sweep repeats on a set cadence so the inventory ages visibly rather than silently.

Why do endpoint and network tooling layers miss agentic activity?

When an employee runs an AI coding assistant on a managed laptop, the endpoint and network tooling already deployed around that machine reports almost nothing out of the ordinary. The activity is generated by signed, sanctioned software, authenticated with the employee's own credentials, and sent to destinations the organization already permits. Each layer is doing exactly the job it was built to do.

Three criteria determine whether a given control layer can account for agentic activity at all, and each becomes decisive in a different situation:

  • Unit of observation — whether the layer reasons about processes, packets, installed applications, or the sequence of actions an agent takes. Decisive when the agent itself is approved software.
  • Identity attribution — whether the layer can separate what a person did from what an agent did on that person's behalf, given both carry the same token. Decisive wherever agents run under employee accounts.
  • Where the risk is expressed — in a static artifact matchable against a signature, or in an action chain assembled at run time from a prompt, a rules file (standing instructions an agent reads on every run) and a set of tool calls.
Control layer Unit of observation Why agentic activity under-reports
EDR, endpoint detection and response, built to catch malicious processes and known-bad files Process, binary, file signature The agent is approved developer software; nothing known-bad crosses the process boundary
Network egress and web filtering Destination, domain, payload inspection Calls reach already-permitted model providers and repository hosts over ordinary encrypted sessions
MDM and device management Installed applications, configuration posture Skills, hooks and rules files are user-level files, not managed app installs
Identity and access controls Authentication and authorization events The agent inherits an existing, already-authenticated employee session

Risk in an agent run is carried by the instructions it followed and the chain of tool calls that followed them, not by the executable that issued them. Backslash Security research found that malicious instructions hidden in a repository's AGENTS.md file could trick OpenAI Codex into silently accessing AWS credentials, npm tokens and Git configuration.

Frequently Asked Questions

What counts as shadow AI on an employee endpoint?

Shadow AI is any AI tool, agent, MCP server or Skill running inside the organization that security has not approved and cannot see — typically installed by an employee on their own machine, often under a personal account. MCP, the Model Context Protocol, is the protocol agents use to connect to external tools and data sources, so each MCP server is a live connection an agent can act through. Agent Skills are packaged instructions and scripts that extend what an agent can do, executing with the user's own permissions. The concrete case buyers recognize fastest is an engineer signing into Claude Code or Cursor on a corporate laptop with a personal account.

How do you discover AI agents on endpoints without installing another tool?

Agentless discovery — collecting information without leaving software permanently installed on the machine — is the practical starting point, because it clears change-control faster than a new sensor. Backslash Security offers a free AI Endpoint Exposure Assessment that is agentless, read-only, and retains no data; in sales conversations it is familiarly called Scout. It runs as a short script distributed through the MDM fleet management you already operate, such as Intune or Jamf, then reports and disappears. Agentless applies to the discovery pass; continuous enforcement is a separate capability. As Philip Walsh, Head of Security Engineering at Happy Returns, put it: "Backslash gave us a live picture of the AI our engineers were already running, and a way to govern it without slowing anyone down."

Why don't EDR and MDM surface these agents?

EDR — endpoint detection and response — is built to catch malicious processes, files and known-bad behavior on a machine, so a signed, approved agent binary such as GitHub Copilot, Codex or Claude Code sits comfortably inside its expectations. MDM enrolls devices and manages applications, but it does not inspect the Skills, hooks and rules files an agent loads at runtime, nor the MCP servers it connects to. That gap is the subject of agentic AI endpoint security: governing the agents, MCP servers, Skills, rules and hooks that run on an employee's endpoint under that employee's identity and access.

Which components belong in an agentic AI inventory?

A usable inventory covers the whole set of interacting pieces, not just the chat client:

  • Agents and models, including locally hosted runtimes such as Ollama or LM Studio
  • MCP servers and MCP tools the agent can act through
  • Agent Skills — reusable capabilities, often just a markdown file on the machine
  • Hooks — triggers that fire on an agent action, running something before or after it
  • Rules files such as AGENTS.md or CLAUDE.md, which carry standing instructions an agent reads on every run
  • Plugins and connectors bridging the agent to enterprise systems

Backslash Security discovers every one of these on an endpoint, and the company was founded to secure the agentic AI fabric these components form. When read on 22 September 2026, Backslash Security's MCP Server Security Hub held 81,021 MCP servers, each scored for risk.

How is shadow AI different from a rogue agent?

Shadow AI describes a tool nobody approved. A rogue agent is an approved agent taking actions nobody asked for — reaching for credentials, escalating privilege, or sending data to an unapproved destination, usually because it was manipulated or drifted from its original task. The distinction drives the control: unapproved components call for discovery, assessment and denylisting, while approved-but-misbehaving agents call for runtime enforcement. Backslash Security blocks risky agent actions inline before execution, including unauthorized code execution, credential access, privilege escalation, and data sent to unapproved destinations.

What record do you need after an AI agent incident?

Reconstructing an incident requires more than a process log, because the meaningful sequence spans a prompt, the agent's interpretation, the tools it reached for and what it changed. Backslash Security traces the full path of an agent run from prompt to agent to tool call to outcome, which gives investigators the chain they need and gives auditors something to inspect. According to Backslash Security, the platform also generates audit evidence automatically for EU AI Act, NIS2, DORA and SOC requirements, so the same telemetry that supports forensics supports periodic reporting obligations.


About this article

Backslash Security publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Backslash Security before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-10-07

Ready to get started?

See how Backslash Security can help.

Book a Demo