Evaluate VibeSec AI BOM Governance
You can evaluate how VibeSec helps organizations gain visibility into the MCP (Model Context Protocol) servers used by AI coding assistants and control how those MCP servers and tools are used.
During this evaluation, you explore the following key AI BOM capabilities:
Visibility: Discover the MCP servers used by you or your organization and review their activity.
Governance: Control access to MCP servers and individual MCP tools and verify that AI assistants enforce your organization's policy.
Before you begin your VibeSec evaluation, check the installation and the Activity Log functioning.
Visibility
The Agent AI BOM provides visibility into the MCP servers used by AI coding assistants across your organization.
After an AI assistant invokes an MCP server, VibeSec discovers the MCP server and collects information such as its usage, available tools, and users. You can use this information to understand which MCP servers are being used and how they are being accessed.
Review MCP activity
In your AI coding assistant, submit a prompt with the action that you want. For example, in case you're using the Atlassian MCP:
Get me my open Jira tickets.Verify that the AI assistant successfully performs the required action; in our example, it was supposed to retrieve the Jira tickets.
In the OX platform, go to OX.VibeSec > AI Inventory: MCPs.

Locate the MCP server that is relevant to your request and select; in our example, it is the Atlassian MCP server.
Review the information collected for the MCP server you selected: the tool that was used and the user details.

Governance
The Agent AI BOM enables administrators to control how AI assistants use MCP servers.
You can enable or disable an entire MCP server, or allow the MCP server while restricting access to selected MCP tools. When an AI assistant attempts to invoke a blocked MCP tool, VibeSec prevents the request from reaching the MCP server and records the event in the Agent Activity Log.
Restrict access to an MCP tool
Go to AI Inventory > MCPs, and open the MCP server.
Select the Tools tab.
For this example, disable the MCP tool used to retrieve Jira issues:
searchJiraIssuesUsingJql

Verify that the MCP status changes to Allowed with some tools blocked.

Verify policy enforcement
Run the same prompt that uses the blocked MCP tool; in our example, the request is
Get me my open Jira tickets.Verify that the AI assistant reports that the MCP request was blocked by your organization's policy.

Review the blocked activity
Go to OX.VibeSec > Agent Activity Log.
Locate the blocked MCP request.
Review the recorded activity.
Restore access
In the MCP details dialog, enable the MCP tool.

Run the same request again.
Verify that the AI assistant successfully completes the request.
For example, rerun: Get me my open Jira tickets. The request succeeds after the tool is re-enabled.
Last updated
