See all MCPs, skills, plugins and agents in use
Scan managed devices for unsanctioned or risky AI clients, MCP connections, and skill & plugin artifacts, and agent harnesses.
Runlayer Watch
Discover unmanaged MCPs, skills, plugins, or agents, then decide what to approve, migrate, remove, or block.
Book a Demo
Scan managed devices for unsanctioned or risky AI clients, MCP connections, and skill & plugin artifacts, and agent harnesses.
Review each finding with its source file, detected client, exposed tools, stale artifacts, prevalence across devices, and recommended response.
For supported clients, Watch evaluates requests to shadow MCP servers against configured policy before they run.
Watch starts with device-based discovery, then adds enforcement where the client, user group, or risk profile calls for it.
Scheduled scans support macOS, Windows, and Linux, with MDM rollout guides for macOS and Windows.
Find agents, clients, MCPs, skills, and plugins. See source paths and risk context for each finding.
Control supported clients on macOS today, including Cursor, Claude Code, and Codex.
Watch finds agents, AI clients (such as Claude Code, Codex, and Cursor), MCP servers, skills, and plugins used on managed devices. It shows what is managed, shadow, outdated, or risky.