Threat alert
Shadow MCP: the 1,200 unofficial AI apps in your enterprise
By Prof. Abhik Roychoudhury, Co-founder & Chief Expert, Verigrey · Provost's Chair Professor, NUS · ACM Fellow1 min readUpdated
How shadow MCP proliferates
The rise of the Model Context Protocol has made it trivial for individual teams to connect an agent to internal systems without going through a security review. Our field research found a median enterprise has well over a thousand of these unofficial connections active at any time.
Why it’s the biggest blind spot
Each one is a potential path for a compromised or manipulated agent to reach systems the security team doesn’t know exist. We outline how to inventory shadow MCP usage and what assurance coverage looks like once you find it.
Frequently asked questions
What is shadow MCP?
- Shadow MCP is the ungoverned use of Model Context Protocol connections — agents wired to internal or external systems by individual teams without passing through security review, invisible to central governance.
How do you inventory shadow MCP usage?
- Start by discovering active MCP connections across the environment, attribute each to an owner and a data scope, then bring them under assurance coverage so every connection an agent can reach is tested against policy.
