What is AI agent discovery?+
AI agent discovery identifies the clients, tools and capabilities present in an environment. Oktsec Node reads supported local configurations for MCP servers and agent capabilities. The result supports component review and policy decisions; configuration does not prove execution.
What information can Node discover?+
MCP discovery records clients, configuration locations, server commands, arguments and environment-variable names. Supported capability records include kind, source, execution class, declared tools and manifest hash, with origin and version when available. Coverage varies by client and Node version.
Does discovery cover every AI service in our organization?+
No. Local configuration discovery does not establish a complete inventory of browser-based AI, SaaS agents or unsupported clients. Confirm the machines, users, configuration sources and versions included in the evaluation.
How are incomplete results handled?+
Unreadable configurations are reported separately from empty findings. Partial capability scans identify incomplete inspection. Missing versions and origins remain unknown. A file modification timestamp is not a last-execution timestamp.
Are secret values included in the inventory?+
The MCP inventory projection retains environment-variable names and drops their values. Commands and arguments can still contain sensitive details and need review before sharing. The capability projection omits instruction prose, absolute paths and hook commands, retaining a manifest hash.
Does discovery automatically enforce policy or monitor advisories?+
Discovery provides observations. Enforcing an action requires a configured Control integration. Signal’s external monitoring tied to Node inventory is in development. Confirm the inventory exchange supported by your Node and Cloud versions.