You can't inventory the AI agents on your dev laptops. We can.
MoorAI runs on the endpoint and builds a live inventory of every AI agent, harness, model, and MCP server your developers install — content-free by construction. You see what exists and what it can reach, without a single prompt ever leaving the device.
Your developers adopted AI faster than your program could
Roughly 85% of developers now use AI coding tools, and 45% admit to using unsanctioned ones — Copilot, Cursor, Claude Code, and a long tail of harnesses installed directly on their laptops. These aren't sandboxed web apps: they run with the developer's own permissions, reading source trees, .env files, SSH keys, and cloud credentials, and can push that context to model endpoints and third-party MCP servers you never approved.
The connective tissue makes it worse. 91.5% of MCP servers in the official registry use static keys or no auth (only 8.5% OAuth), and roughly 42,000 MCP servers were found exposed to the public internet in Q1 2026. 88% of organizations running AI agents confirmed or suspected a security incident in the past year. Cloud DLP and CASB don't see any of this — the usage is endpoint- and API-direct, so there's no proxy hop to inspect and no SaaS tenant to audit. The agent is on the laptop, and so is the blind spot.
Sources: Stack Overflow Developer Survey 2025 (via JumpCloud); Guild.ai MCP registry analysis; Aembit MCP Security Guide 2026.
How MoorAI discovers them — content-free, on-device
- Deploy the on-device agent. The MIT agent installs on each endpoint (macOS & Windows). It observes locally — it does not proxy traffic or ship prompts anywhere.
- Inventory what's actually running. It detects installed AI harnesses (Claude Code, Cursor, Copilot, and others), the models they call, and the MCP servers they're wired to — a per-device AIBOM (AI Bill of Materials).
- Surface it as a fleet worklist. Every device rolls up to the console as managed or unmanaged; newly discovered agents land on a worklist so your team can triage instead of guess.
- Promote, don't police. Approve an agent and MoorAI auto-promotes it (and future installs of it) to managed — so discovery converges toward a clean inventory instead of an endless queue.
What you get
- Inventory every AI harness — Claude Code, Cursor, Copilot, and other agents installed on each endpoint.
- Map models & MCP servers — which model endpoints and MCP servers each agent is wired to, per device.
- Per-device AIBOM — a live AI Bill of Materials for every laptop: agents, harnesses, models, connectors.
- Managed vs. unmanaged worklist — triage discovered agents from one fleet view; approve once, auto-promote thereafter.
- Content-free by construction — discovery sees that agents and endpoints exist, never what a developer typed.
- Open-core, on the endpoint — MIT on-device agent, proprietary console. Discovery runs where the agents actually live.
Why content-free matters here
Most endpoint security asks platform-eng to accept a new inspection point that reads developer activity — and the answer is usually no, because the tool becomes a new breach surface. MoorAI removes that objection entirely. Discovery is content-free by construction: the agent sees which agents, models, and MCP servers exist, never what a developer typed or what a file contains. Nothing leaves the endpoint unless an admin explicitly turns on a capture tier. There's no policy to negotiate before you get visibility, and no “your security tool is now the risk” conversation to lose.
Start with visibility, not a policy fight.
You can't govern agents you can't see. MoorAI gives you a content-free inventory of every AI agent on your developer fleet — then a worklist to manage them on your terms.