Skip to main content
Inventory is the catalogue of what discovery found on your developers’ machines, sanctioned or not.

What’s on the page

Sub-tabs

Opening Inventory without a sub-tab lands on Tools.

Tools

The tools found across your fleet run down the left, each with its plan and how many profiles carry it. Selecting one shows Profiles Discovered and Config Files Scanned for that tool, above the developers using it.
The plan shown against a tool is the tier the developer is actually signed in with on that device — not the seat you bought them. Where the two differ, that session is running under consumer terms your agreement does not cover. Reported for Claude Code, Cursor — the editor and the CLI — and the Auggie CLI; no other tool shows one. An Account Access policy is how you stop a session signed in with an unsanctioned account — see Security Policies.

MCP Servers

Publishers, Agents and Top Users charts, above a table that folds the same server published under different names into one group — anything that does not group sits under Ungrouped. A group expands to the servers inside it.

Skills and Config Files

Both are one row per distinct file, with the same columns. Config Files covers the rules and instruction files the tools on a device read, whatever each one is called — global files and per-project files alike, including the ones a tool keeps somewhere other than its best-known location.

Filters and controls

The Tools sub-tab has a tool picker at the head of its list; MCP Servers, Skills and Config Files each have a search box.

What you can do

File page

Risk Assessment names what was found, not just how bad it is. Findings fall into a fixed set of types: prompt injection, data exfiltration, credential access, code execution, hardcoded secrets, obfuscation, agent directives that override the developer’s own instructions, self-modification, social engineering, supply-chain references, and text hidden with invisible Unicode. A file can carry findings of more than one type, and its level follows the most severe. Marking a finding a false positive removes it from that file’s score everywhere the file appears. Categories is a separate axis — what the file is about, not what is wrong with it — so a file can be categorised Testing & Error Handling and still carry a Critical finding.
Config file and skill addresses identify the content, not the device. Two machines carrying an identical rules file open the same page, so that page shows how widely a given instruction has spread across your fleet.

Messages you may see