# Why Shadow IT Tools Miss Local MCP Server Sprawl

DevFeed: [Why Shadow IT Tools Miss Local MCP Server Sprawl](<https://devfeed.tech/articles/the-tools-that-caught-shadow-it-can-t-see-mcp-sprawl-16031.md>)

Original publisher: [Read original article](<https://workos.com/blog/mcp-sprawl-invisible-to-shadow-it-tools>)

Author: WorkOS

Published: 2026-08-10T00:00:00Z

Content type: opinion

Language: en

Sources: [WorkOS Blog](<https://devfeed.tech/sources/workos-blog.md>)

Topics: [Model Context Protocol](<https://devfeed.tech/topics/model-context-protocol.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>)

Tags: [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [network](<https://devfeed.tech/tags/network.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

The article argues that traditional shadow-IT discovery tools miss much of MCP server sprawl because many MCP servers run locally as subprocesses over stdio inside developer environments. It explains that the security risk has shifted from data leaving through unsanctioned applications to actions taken through them.

## Source excerpt

In AI agent governance, most MCP servers run as local processes that never cross the network boundary older shadow-IT tools were built to watch. The risk changed too: from data leaving through an unsanctioned app to actions taken through one.