Skip to main content

AI Discovery

AI Discovery helps admins discover and govern MCP servers, skills, and AI tools running on developer machines across the organization.

The AI Discovery dashboard on the Overview tab, showing MCP Servers and Skills cards with managed and shadow counts, Devices and AI Agents counts, and a Risk Summary panel

Overview

AI Discovery deploys a lightweight Willow Scan Agent to managed devices. The agent periodically scans for MCP server configurations, AI coding tool skills, and AI agent installations, then reports findings back to Willow.

Admins can use AI Discovery to inventory developer AI usage, identify unmanaged capabilities, and allow, warn on, or block them with enforcement policy rules, from one dashboard.

Willow Scan Agent

The Willow Scan Agent runs as a background service on macOS and Windows. It discovers:

SignalDescription
MCP serversstdio, SSE, and HTTP servers configured in Cursor, Claude Desktop, VS Code, Windsurf, and other AI coding tools
SkillsClaude Code SKILL.md files, Cursor rules, and other AI skill definitions
AI agentsAI coding tools installed on each machine

Willow Guard browser extension

Willow Guard is a browser extension for monitoring and governing OAuth flows and web AI agent access in the browser. Deploy it when you need visibility into browser-based AI usage in addition to local developer tool configuration.

The extension reads serverUrl and authToken from Chrome managed storage when deployed through a managed Chrome policy.

Deploy the Scan Agent

Download the agent packages from the Scan Agent Setup flow in the Willow dashboard, then choose a deployment path:

OptionUse whenGuide
MDM deploymentYou manage employee devices through Jamf, JumpCloud, Iru, Intune, GPO, or another device management platform.Deploy Scan Agent with MDM
Manual installationYou are testing on a small number of devices or validating the package before broad deployment.Install the Scan Agent manually
Browser extensionYou need browser-based AI visibility through Chrome managed policy.Deploy Willow Guard Browser Extension
Webhook APIYou already collect device scan data through another system and want to send findings directly to Willow.Scan Agent reference

For the agent's connection values, management commands, install paths, and configuration fields, see the Scan Agent reference.

View and govern discoveries

Once devices report, everything they find surfaces in the AI Discovery dashboard, where you review it and act on it.

PageWhat it covers
The AI Discovery dashboardThe seven tabs of discovered inventory: an Overview risk rollup, MCP Servers, Skills, AI Agents, Devices, and Auth Discovery, plus the Guard Check.
Policy RulesEnforcement rules that allow, warn on, or block discovered capabilities, scoped to users, groups, or devices.