Shadow MCP
Shadow MCP refers to unauthorized or unmanaged MCP server instances running inside an organization's environment without the knowledge or approval of IT or security teams. It is the MCP-layer extension of shadow IT: employees installing and connecting AI agent tools outside of centralized governance.
Why It Matters
MCP servers are designed to be easy to install. A developer can clone a repository, run a command, and have a working MCP server connected to their AI agent in minutes. That frictionless experience drives adoption, and it is exactly what creates the governance gap.
Shadow MCP differs from shadow IT in one important way: frequency of execution. A shadow SaaS app runs when a human opens it. A shadow MCP server runs every time the agent starts a session. A server a person uses five times a day might be called hundreds of times by an autonomous workflow. Every call is a trust crossing that no one is monitoring.
OWASP names it in the beta MCP Top 10 as MCP09:2025, Shadow MCP Servers, describing unapproved or unsupervised deployments that operate outside an organization's formal security governance. The risk is not malice. It is inventory and control: you cannot govern what you cannot see.