AI agent discovery & inventory

Find the tools behind your agents.

Discover configured MCP servers, skills and hooks with Oktsec Node. Give your team a clear starting point for reviewing what agents use and the access those components bring.

Look inside the configuration

Different components. Different access.

A server connects to systems. A skill carries instructions. A hook can run on its own. Each needs a different review.

Illustrative local inventorySelect a component to inspect
What Node identifies

A connection to another system.

The client configuration declares a server command, arguments and credential-variable names.

Found in
Client configuration
Available context
Command · arguments · environment references

Which repositories can this server access?

Review the server’s permissions before deciding which tools the agent may call.

Illustrative entries, not a customer snapshot. Available fields depend on the client, configuration and Node version. Configuration does not prove execution.

Know what was observed

Keep the gaps visible.

A useful inventory shows where the inspection stopped, as well as what it found.

Found

A component is configured.

Review its source and declared capabilities. Confirm who uses it and which permissions it receives.

Unreadable or partial

The inspection is incomplete.

Resolve access or scan limits before treating the inventory as complete.

Version unknown

The source did not provide it.

Verify the version separately. A name or file timestamp is not evidence of the installed release.

Discovery reads supported local configurations. It is not a complete inventory of browser AI or SaaS agents.

Check client coverage
Common questions

What to know before you start.

What is AI agent discovery?

AI agent discovery identifies the clients, tools and capabilities present in an environment. Oktsec Node reads supported local configurations for MCP servers and agent capabilities. The result supports component review and policy decisions; configuration does not prove execution.

What information can Node discover?

MCP discovery records clients, configuration locations, server commands, arguments and environment-variable names. Supported capability records include kind, source, execution class, declared tools and manifest hash, with origin and version when available. Coverage varies by client and Node version.

Does discovery cover every AI service in our organization?

No. Local configuration discovery does not establish a complete inventory of browser-based AI, SaaS agents or unsupported clients. Confirm the machines, users, configuration sources and versions included in the evaluation.

How are incomplete results handled?

Unreadable configurations are reported separately from empty findings. Partial capability scans identify incomplete inspection. Missing versions and origins remain unknown. A file modification timestamp is not a last-execution timestamp.

Are secret values included in the inventory?

The MCP inventory projection retains environment-variable names and drops their values. Commands and arguments can still contain sensitive details and need review before sharing. The capability projection omits instruction prose, absolute paths and hook commands, retaining a manifest hash.

Does discovery automatically enforce policy or monitor advisories?

Discovery provides observations. Enforcing an action requires a configured Control integration. Signal’s external monitoring tied to Node inventory is in development. Confirm the inventory exchange supported by your Node and Cloud versions.

Start with Oktsec

See what one team’s agents depend on.

Bring a representative environment. We’ll compare discovered components with the tools your team actually uses.

Review your agent inventory