Skip to main content

Overview

Shadow AI is a review queue for MCP servers and skills that people use but that aren’t in your Catalog. Review each item, then add it to the Catalog with the right access, or block it. Until you review an item, the matching Guardrail decides what happens to it. The banner at the top of the page shows whether new items are allowed and monitored or blocked. Click Change in Guardrails to change that default.

How Formal Discovers Items

Formal finds items in proxied traffic only. To capture it, see Capture AI Traffic.

Review an MCP Server

1

Open the queue

Go to Shadow AI and open the MCP Servers tab. Each row shows the server name, its endpoint, and Last Used. Servers reached through Claude’s connector proxy show a Claude Connector badge.
2

Review the server

Click Review. The drawer shows how the server was used and who can use it.
3

Decide

Click Allow to add the server to the Catalog with the access shown in the drawer. Click Block to add it with no access.
Both choices create an MCP Resource and a generated access policy. The server then leaves the queue, and you manage it from the Catalog. Verify: The server appears in the Catalog with the access you chose.

Review a Skill

1

Open the queue

Open the Skills tab. Each row shows whether the skill was Loaded into a conversation or only On device. Filter with All, Available on Device, or Loaded in Conversation.
2

Choose who can use it

Click the skill. Under Who can use this skill?, choose Everyone, Specific Users, or No One.
3

Confirm

The button follows your choice:
  • Add to catalog: Everyone can use the skill.
  • Add with limited access: Only the users and groups you selected can use it.
  • Block skill: Nobody can use it.
Each outcome adds the skill to the Catalog. Add with limited access and Block skill also create an access policy for it. Verify: The skill leaves the queue and appears in the Catalog.

Permissions

Deciding on an item requires permissions to manage both Resources and Policies. Without them, the drawer shows Resource and policy management permissions are required to decide.

Troubleshooting

Cause: No device intercepted MCP traffic to a server without a Formal Resource. Fix: Confirm the Endpoint runs in Transparent Mode with a network rule for mcp traffic. Wait up to 15 minutes for discovery.
Cause: Formal only detects skills in proxied Claude Code requests, and refreshes skills once a day. Skills used by other agents don’t appear. Fix: Confirm that Claude Code traffic reaches Formal, then check again the next day.

Next Steps

Guardrails

Set the default for items you haven’t reviewed

AI Usage

See which AI tools people use