> ## Documentation Index
> Fetch the complete documentation index at: https://docs.formal.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Review Shadow AI

> Find the MCP servers and skills people use outside your Catalog, then allow or block each one

## Overview

[Shadow AI](https://app.formal.ai/shadow-ai) is a review queue for MCP servers and skills that people use but that aren't in your [Catalog](/docs/guides/ai-governance/overview#the-catalog). Review each item, then add it to the Catalog with the right access, or block it.

Until you review an item, the matching [Guardrail](/docs/guides/ai-governance/guardrails) decides what happens to it. The banner at the top of the page shows whether new items are **allowed and monitored** or **blocked**. Click **Change in Guardrails** to change that default.

## How Formal Discovers Items

| Tab | Source | Refresh |
| - | - | - |
| **MCP Servers** | MCP requests that the [Formal Endpoint](/docs/guides/client-apps/desktop-app) intercepted for servers with no Formal Resource | Every 15 minutes |
| **Skills** | Skills that Claude Code requests list as available or loaded | Every 24 hours |

Formal finds items in proxied traffic only. To capture it, see [Capture AI Traffic](/docs/guides/ai-governance/overview#capture-ai-traffic).

## Review an MCP Server

<Steps>
  <Step title="Open the queue">
    Go to [Shadow AI](https://app.formal.ai/shadow-ai) and open the **MCP Servers** tab. Each row shows the server name, its endpoint, and **Last Used**. Servers reached through Claude's connector proxy show a **Claude Connector** badge.
  </Step>

  <Step title="Review the server">
    Click **Review**. The drawer shows how the server was used and who can use it.
  </Step>

  <Step title="Decide">
    Click **Allow** to add the server to the Catalog with the access shown in the drawer. Click **Block** to add it with no access.
  </Step>
</Steps>

Both choices create an MCP Resource and a generated access policy. The server then leaves the queue, and you manage it from the Catalog.

**Verify:** The server appears in the [Catalog](https://app.formal.ai/catalog) with the access you chose.

## Review a Skill

<Steps>
  <Step title="Open the queue">
    Open the **Skills** tab. Each row shows whether the skill was **Loaded** into a conversation or only **On device**. Filter with **All**, **Available on Device**, or **Loaded in Conversation**.
  </Step>

  <Step title="Choose who can use it">
    Click the skill. Under **Who can use this skill?**, choose **Everyone**, **Specific Users**, or **No One**.
  </Step>

  <Step title="Confirm">
    The button follows your choice:

    * **Add to catalog:** Everyone can use the skill.
    * **Add with limited access:** Only the users and groups you selected can use it.
    * **Block skill:** Nobody can use it.
  </Step>
</Steps>

Each outcome adds the skill to the Catalog. **Add with limited access** and **Block skill** also create an access policy for it.

**Verify:** The skill leaves the queue and appears in the Catalog.

## Permissions

Deciding on an item requires permissions to manage both Resources and Policies. Without them, the drawer shows **Resource and policy management permissions are required to decide.**

## Troubleshooting

<AccordionGroup>
  <Accordion title="The MCP Servers tab is empty">
    **Cause:** No device intercepted MCP traffic to a server without a Formal Resource. **Fix:** Confirm the Endpoint runs in Transparent Mode with a network rule for `mcp` traffic. Wait up to 15 minutes for discovery.
  </Accordion>

  <Accordion title="A skill I know people use doesn't appear">
    **Cause:** Formal only detects skills in proxied Claude Code requests, and refreshes skills once a day. Skills used by other agents don't appear. **Fix:** Confirm that Claude Code traffic reaches Formal, then check again the next day.
  </Accordion>
</AccordionGroup>

## Next Steps

<CardGroup cols={2}>
  <Card title="Guardrails" icon="lock" href="/docs/guides/ai-governance/guardrails">
    Set the default for items you haven't reviewed
  </Card>

  <Card title="AI Usage" icon="chart-line" href="/docs/guides/ai-governance/usage">
    See which AI tools people use
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.