shadow-ai-discovery

Detects unauthorized AI tools by scanning GitHub, Slack, and SSO signals across an organization.

1|Updated Feb 26, 2026
One-click install
npx skills add https://github.com/webrix-ai/agent-skills --skill shadow-ai-discovery
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: shadow-ai-discovery
Source: https://github.com/webrix-ai/agent-skills/tree/main/skills/shadow-ai-discovery
Command: npx skills add https://github.com/webrix-ai/agent-skills --skill shadow-ai-discovery

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps security and compliance teams discover unapproved AI tools being used across the organization, so they can understand exposure and respond before policy or data risk grows.

Core Features & Use Cases

  • Organization-wide Discovery: Scans GitHub repositories, Slack workspaces, and SSO or network signals for shadow AI indicators.
  • Risk Classification: Scores each finding by risk level, data exposure, user count, business value, and compliance impact.
  • Remediation Planning: Recommends whether to approve, restrict, replace, or block each tool and produces communication templates for affected users.
  • Use Case: A security team wants to audit personal AI accounts, hidden repo configs, and unauthorized Slack bots before a compliance review.

Quick Start

Ask for a shadow AI audit using your approved tool list, organization details, and available GitHub, Slack, and SSO signals to generate an inventory and remediation plan.

Frequently Asked Questions about shadow-ai-discovery

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I detect unauthorized AI tools being used across my organization?

Shadow AI discovery scans GitHub repositories, Slack workspaces, and SSO or network signals to identify unauthorized AI tools. This process inventories hidden AI integrations and personal accounts to reveal unapproved tool adoption across your organization.

What is shadow AI and how does it impact compliance reviews?

Shadow AI refers to unapproved AI tools used without security oversight, impacting compliance reviews by introducing unknown data exposure risks. It typically manifests through unauthorized Slack bots, personal AI accounts, and hidden repository configurations.

How do I classify shadow AI findings by risk and data exposure?

Classify shadow AI findings by scoring each detected tool against risk level, data exposure, user count, business value, and compliance impact. This classification framework prioritizes remediation actions based on the severity and organizational footprint of the unauthorized usage.

What is the best way to remediate shadow AI usage discovered in a security audit?

The best way to remediate shadow AI usage is to evaluate each finding's risk and business value to recommend whether to approve, restrict, replace, or block the tool. This remediation strategy includes generating targeted communication templates to notify affected users.

Can I use SSO and network signals to find hidden AI integrations?

Yes, you can use SSO and network signals to find hidden AI integrations. Combining these signals with GitHub repository and Slack workspace scans provides a comprehensive view of shadow AI activity across the organization.