Product · Inventory
One bounded inventory of AI that lives on the endpoint
Local models, desktop AI apps, IDE AI, agent CLIs, MCP servers, browser extensions, SDK dependencies, provider-key presence, and the autonomy configured around them — each tied to what the scanner actually observed.
How it works
Read the endpoint, not the traffic
The inventory is built from bounded local sources and current process identity. AI SaaS usage, browsing history, prompt content, and network activity are out of scope.
- 01
Run bounded collectors
Each collector reads fixed or explicitly supplied roots and reports both observations and coverage gaps.
- 02
Compute a safe identity
Each asset gets a stable identity derived from sanitized identity metadata — never from prompts, source code, or configuration content.
- 03
Compare dated snapshots
TEAM compares normalized snapshots so additions, removals, changes, and running-state transitions remain attributable to an endpoint.
What it inventories
The endpoint-resident AI surface
Coverage is broad but never presented as total. Each category is included only where a deterministic collector can support it.
Apps, models, and runtimes
Desktop AI applications, local model weights and runtimes, agent CLIs, and current process identity.
IDEs and extensions
Supported IDE products, AI extensions, browser AI extension identity, profiles, and workspaces.
Agents and MCP
Agent clients, MCP configurations, skills, plugins, hooks, rule-source identity, and declared service connectors.
Projects and credentials
AI SDK dependencies in explicit project roots and provider-key presence without secret values.
What we see
Identity, never contents
The line is the same one every KeepRails surface holds, stated here for the asset types this page covers.
Recorded
Safe identity, version, categorical source dimensions, provenance, declared permissions, running state, and a stable fingerprint where supported.
Never recorded
Tool inputs and outputs. Secret and environment-variable values. Server source. CLAUDE.md contents. Prompts and responses. A detector may report that a secret is present without reporting the value.
Coverage
What the inventory does not claim
Stated up front, because an inventory that overclaims is worse than no inventory.
Not whether it is used
Installation is not use. That question needs an observed window, and the answer is a labelled state, not a yes or no.
Not whether it is approved
Locally, provenance is verifiable or unverifiable. Approved is a claim only a team baseline can make.
Not AI SaaS activity
Visited sites, prompt content, clipboard content, and network activity are permanently out of scope.
Where it stops
No payloads are read. A tool the collectors cannot defensibly match is counted as unattributable rather than guessed into a category.
Related
Each surface feeds the next: what the scan finds becomes a finding, and a finding becomes a reversible change.
FAQs about Inventory
What does the endpoint scan inventory?
Local model weights, desktop AI apps, IDE AI and extensions, agent CLIs, MCP servers, browser AI extension identity, AI SDK dependencies, provider-key presence, and supported permission or autonomy settings. The scan output declares which collectors ran and what was not scanned.
Do you analyze CLAUDE.md?
No. CLAUDE.md may be acknowledged as present, but it is not analyzed, scored, rewritten, or remediated, and its contents never leave the device. KeepRails is not a CLAUDE.md editor.
What is a canonical fingerprint?
A stable identifier computed from an asset's safe identity — not from its contents. It is what lets the same MCP server be recognized as the same server across two developers' machines even when their configuration differs, which is what makes a team comparison possible later.
Why does scope matter so much here?
Because the effective configuration is often not the one someone reads. An asset defined at both user and project scope resolves to one of them, silently. Recording scope per asset is what turns that from a surprise into a finding.
Can you tell me an asset is unused?
Not from an inventory. An inventory proves what is installed. Whether something runs needs an observation window, and even then the answer is "observed used" or "not observed in the selected window" — never "unused" unless a deterministic configuration fact proves it.
Does the inventory get uploaded?
Not from the anonymous audit — that sends nothing. If you later connect an account, the fields that would sync are previewed first, and what syncs is safe identity, version, scope, provenance category, and fingerprint. Not contents.
See what your fleet is actually running
The scan runs locally and reports in your terminal. No account, no upload.
keeprails scan