Scan managed devices for unsanctioned or risky AI clients, MCP connections, and skill & plugin artifacts, and agent harnesses.
Prioritize what needs action
Review each finding with its source file, detected client, exposed tools, stale artifacts, prevalence across devices, and recommended response.
Block risky
shadow usage
For supported clients, Runlayer evaluates requests to shadow MCP servers against configured policy before they run.
Deployment and enforcement scope
Runlayer starts with device-based discovery, then adds enforcement where the client, user group, or risk profile calls for it.
Device coverage
Scheduled scans support macOS, Windows, and Linux, with MDM rollout guides for macOS and Windows.
Artifacts
Find agents, clients, MCPs, skills, and plugins. See source paths and risk context for each finding.
Enforcement
Control supported clients on macOS today, including Cursor, Claude Code, and Codex.
Frequently asked questions
Runlayer finds agents, AI clients (such as Claude Code, Codex, and Cursor), MCP servers, skills, and plugins used on managed devices. It shows what is managed, shadow, outdated, or risky.
Runlayer focuses on the MCP, skill, plugin, and client configuration layer that agents use to reach tools. When agents or AI clients rely on unmanaged MCP servers or plugins on managed devices, Runlayer surfaces those artifacts for review and response.
Runlayer deploys through existing MDM, so teams can scan managed devices for shadow MCPs, skills, plugins, and client configs without asking employees to install or approve anything.
Teams can migrate useful MCPs and skills into Runlayer, approve trusted usage with ownership and policy, remove stale configuration, or block high-risk shadow MCP activity.
Runlayer scans supported clients on macOS, Windows, and Linux. MDM rollout guides cover macOS and Windows, with custom and manual options for other environments.
Runlayer can block shadow MCP activity in Cursor, Claude Code, and Codex on macOS today, with Windows and additional clients in development.
IT & Security leads response. Platform and AI Transformation use the same inventory to see which capabilities employees are already trying to use.