New: Mondoo expands vulnerability management to shadow AI. Find and fix it · See it live at Black Hat USA, Booth 5100, AI Zone, August 1 to 6.
Log inGet Assessment

Find and Fix Shadow AI: Mondoo Expands Vulnerability Management to Your AI Estate

Mondoo now discovers every AI agent, plugin, MCP server, skill, and model across your fleet, assesses the risk, and governs what is allowed to run.

Dominik Richter
Dominik Richter
·7 min read·
Find and Fix Shadow AI: Mondoo Expands Vulnerability Management to Your AI Estate

When we released AI Skills Check earlier this year, we expected to find problems. We didn't expect the numbers we got. Of the 58,000+ AI agent skills we've scanned across public registries, only about one in five comes back fully clean. Academic research puts it more bluntly: more than one in four publicly available skills contain at least one security vulnerability, and one prolific actor alone accounted for 54% of confirmed malicious ones. Someone built a factory for this.

But the skills are only half the story. The other half is where they run, and who's running them.

Everyone is adopting AI. That's the point.

This isn't just a developer phenomenon anymore. HR, sales, finance, operations: everyone is incentivized to adopt AI at breakneck speed, and they should be. The productivity upside is real, and companies that move fast will win. The last thing we want is for security to become the blocker.

But speed creates exposure. Coding agents, IDE assistants, browser plugins, and third-party skills execute commands, hold credentials, modify code, and reach into internal systems, many through MCP servers, chaining actions across applications. In the past year, 82% of organizations discovered at least one AI agent that security or IT didn't know about, and 65% had an AI agent security incident. Only 29% say they're ready to secure agentic AI.

Shadow IT never acted on its own. Shadow AI does. And it all lands in one place: the employee endpoint. That's where agents install, plugins load, MCP servers get configured, and credentials sit on disk. The laptop has become the control plane for enterprise AI, and for most security teams it's a blind spot.

What we're announcing

Today Mondoo expands its platform to find and fix shadow AI. Auto-discovery is the foundation: hook us up and Mondoo inventories your entire AI estate, agentless, rolled out via Microsoft Intune or CrowdStrike Falcon. The full announcement is in our press release. From there, four things you couldn't do yesterday:

Find dangerous software. Some AI tools are useful and terrifying in equal measure. Take OpenClaw: an autonomous daemon whose depth of system connection surprises even the developers who install it. Mondoo detects tools like it across your fleet and helps you manage them, whether that means governing their configuration or removing them entirely.

Find vulnerable AI agents. Agents are software. Outdated versions, dangerous modes, and risky configurations are vulnerabilities like any other. Mondoo brings them into scope of your vulnerability management: versions checked against known CVEs, configurations against best practices.

Find vulnerable skills. This is where Mondoo is special. We fully evaluate skills using proprietary AI techniques, grounded in Google DeepMind's published AI Agent Traps research, detecting prompt injection, credential theft, hidden instructions, and behavior that doesn't match what the skill claims. It's the same intelligence behind AI Skills Check, now applied continuously to every skill on your fleet.

Understand what your AI tools can access. Visibility into tools is half the picture; the other half is reach. Mondoo collects access data across all your AI tools and builds the full picture: what each agent can touch, which MCP servers expose production systems, and which keys and credentials are in use.

Underneath all four sits AI governance: you define what's allowed to run and what isn't, Mondoo enforces it across the fleet, and findings close through Microsoft Intune and CrowdStrike Falcon, the tools your team already operates.

Prevention, not just observation

A number of tools now watch agent activity and raise a flag when something misbehaves. That's useful, after the agent is already operating. Our approach is preventive control: govern AI tooling before it can be misused. Malicious skills never run. Banned agents don't operate. Unapproved models never touch company data.

And critically, this is how security becomes the enabler of AI adoption rather than its blocker. Blanket bans fail; employees route around them, and the business loses speed. Governance means teams keep moving fast while security knows exactly what's running, what it can access, and that it's within policy.

This is still vulnerability management

You don't need a new program, a new console, or a new agent on the endpoint. The AI-BOM extends the inventory you already maintain. AI findings land next to your CVEs, prioritized by business impact and exploitability. Remediation flows through the ITSM and endpoint management integrations you already use. Shadow AI becomes what every other risk class eventually became: visible, measurable, and managed.

See it live at Black Hat

We'll be demoing all of this at Black Hat USA 2026, August 1-6, Booth 5100 in the AI Zone at Mandalay Bay: discovering a fleet's entire AI estate, flagging a dangerous agent, catching a malicious skill before it ever runs, mapping what AI tools can access, and remediating through Microsoft Intune. Live.

Can't make it to Las Vegas? Schedule a demo. And if you want to see the problem for yourself right now, scan any skill your team uses at mondoo.com/ai-agent-security: free, no subscription, across any agent and any registry.

The agents are already on your fleet. Time to see them.

About the Author

Dominik Richter

Dominik Richter

Co-Founder & CPO

Dom is a founder, coder, and hacker and one of the creators of Mondoo. He helped shape the DevOps and security space with projects like Chef InSpec and Dev-Sec.io. Dom worked in security and automation at companies like Google, Chef, and Deutsche Telekom. Beyond his work, he loves to dive deep into hacker and nerd culture, science and the mind, and making colorful pasta from scratch.

Ready to Get Started?

See how Mondoo can help secure your infrastructure.