AI Discovery
AI Discovery helps admins discover and govern MCP servers, skills, and AI tools running on developer machines across the organization.

Overview
AI Discovery deploys a lightweight Willow Scan Agent to managed devices. The agent periodically scans for MCP server configurations, AI coding tool skills, and AI agent installations, then reports findings back to Willow.
Admins can use AI Discovery to inventory developer AI usage, identify unmanaged capabilities, and allow, warn on, or block them with enforcement policy rules, from one dashboard.
Willow Scan Agent
The Willow Scan Agent runs as a background service on macOS and Windows. It discovers:
| Signal | Description |
|---|---|
| MCP servers | stdio, SSE, and HTTP servers configured in Cursor, Claude Desktop, VS Code, Windsurf, and other AI coding tools |
| Skills | Claude Code SKILL.md files, Cursor rules, and other AI skill definitions |
| AI agents | AI coding tools installed on each machine |
Willow Guard browser extension
Willow Guard is a browser extension for monitoring and governing OAuth flows and web AI agent access in the browser. Deploy it when you need visibility into browser-based AI usage in addition to local developer tool configuration.
The extension reads serverUrl and authToken from Chrome managed storage when deployed through a managed Chrome policy.
Deploy the Scan Agent
Download the agent packages from the Scan Agent Setup flow in the Willow dashboard, then choose a deployment path:
| Option | Use when | Guide |
|---|---|---|
| MDM deployment | You manage employee devices through Jamf, JumpCloud, Iru, Intune, GPO, or another device management platform. | Deploy Scan Agent with MDM |
| Manual installation | You are testing on a small number of devices or validating the package before broad deployment. | Install the Scan Agent manually |
| Browser extension | You need browser-based AI visibility through Chrome managed policy. | Deploy Willow Guard Browser Extension |
| Webhook API | You already collect device scan data through another system and want to send findings directly to Willow. | Scan Agent reference |
For the agent's connection values, management commands, install paths, and configuration fields, see the Scan Agent reference.
View and govern discoveries
Once devices report, everything they find surfaces in the AI Discovery dashboard, where you review it and act on it.
| Page | What it covers |
|---|---|
| The AI Discovery dashboard | The seven tabs of discovered inventory: an Overview risk rollup, MCP Servers, Skills, AI Agents, Devices, and Auth Discovery, plus the Guard Check. |
| Policy Rules | Enforcement rules that allow, warn on, or block discovered capabilities, scoped to users, groups, or devices. |