Skip to main content
vet ai discover is an alias for vet endpoint scan --kind ai-tool --kind agent-skill. It scans the local system and project directory to inventory AI tool usage signals: coding agents, MCP servers, CLI tools, IDE extensions, project configuration files, and agent skills. When SafeDep credentials are configured, discovered items sync to SafeDep Cloud’s Endpoint Hub automatically. See Inventory.

Prerequisites

Usage

Discover all AI tool usage signals on the current system and project:

Scope Filtering

Limit discovery to system-level or project-level signals:

JSON Output

Write a structured JSON inventory for downstream processing:

What Gets Discovered

vet ai discover reports usage signals, not unique tools. The same tool may appear multiple times because it can be configured at different scopes. Each row represents a distinct configuration entry. For example, Claude Code might produce:

Signal Types

The --kind flag on vet endpoint scan controls which signal types are collected. vet ai discover always collects all of them.

Scope

  • system refers to user-global config (e.g. ~/.claude/settings.json, ~/.cursor/mcp.json)
  • project refers to repo-scoped config (e.g. .mcp.json, .cursorrules, CLAUDE.md)

What Gets Scanned

App configuration is read from well-known system and project-level config paths for each supported application. System-level configs indicate the tool is installed; project-level configs indicate the project is set up for a tool. CLI binaries are discovered by searching $PATH for known binary names. Each candidate is executed with a version flag and the output verified against known patterns. IDE extensions are discovered by reading extension manifests from supported IDE distributions and matching against a curated list of known AI extension identifiers. Agent skill directories are discovered by scanning known per-agent skill paths at system and project scope.

Security

Discovery makes no network calls. All scanning reads the local filesystem and $PATH. Environment variable and header values are never captured; only key names are recorded. CLI arguments matching secret patterns (--token=, --api-key=, --password=, etc.) are redacted. Sync to SafeDep Cloud is a separate step that runs only when credentials are configured.

Inventory

Sync discovered AI tools and skills to SafeDep Cloud’s Endpoint Hub

Shadow AI in Code

Detect AI SDK usage in source code and generate AI-enriched SBOMs

xBOM Concepts

Learn about extended Bill of Materials and signature-based detection