Shadow MCP
Shadow MCP refers to unauthorized or unmanaged MCP server instances running inside an organization's environment without the knowledge or approval of IT or security teams. It is the MCP-layer extension of shadow IT: employees installing and connecting AI agent tools outside of centralized governance.
Why It Matters
MCP servers are designed to be easy to install. A developer can clone a repository, run a command, and have a working MCP server connected to their AI agent in minutes. That frictionless experience drives adoption, and it is exactly what creates the governance gap.
Shadow MCP differs from shadow IT in one important way: frequency of execution. A shadow SaaS app runs when a human opens it. A shadow MCP server runs every time the agent starts a session. A server a person uses five times a day might be called hundreds of times by an autonomous workflow. Every call is a trust crossing that no one is monitoring.
OWASP recognized this in its MCP Top 10 (MCP09:2025), describing shadow MCP as unapproved deployments of MCP instances operating outside an organization's formal security governance. The risk is not malice. It is inventory and control: you cannot govern what you cannot see.