Compliance action index

1695 actions across 80 platforms
Reset 851–900 of 1695 shown (total 1695)
Platform ID ▼ Category Risk Conf SoD Compliance Business impact
Google Drivegoogle-drive.download_file_contentData AccesshighhighGDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIASOC2ISO_27001Downloads a binary file from Drive; same exfiltration profile as content read.
Google Drivegoogle-drive.create_fileContent ManagementmediumhighSOC2ISO_27001Writes new content into the user's Drive; can introduce malicious or noncompliant material.
Google Calendargoogle-calendar.update_eventEventsmediumhighGDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIAModifies an existing event; can reschedule meetings and notify attendees.
Google Calendargoogle-calendar.suggest_timeEventslowhighGDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIAComputes free/busy windows across attendees to suggest a meeting time.
Google Calendargoogle-calendar.respond_to_eventEventslowhighResponds to a meeting invitation on the user's behalf.
Google Calendargoogle-calendar.list_eventsEventsmediumhighGDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIASOC2Reads events across calendars; titles and attendees can reveal confidential meetings (M&A, layoffs, customer escalations).
Google Calendargoogle-calendar.list_calendarsCalendarslowhighEnumerates calendars the user has access to.
Google Calendargoogle-calendar.get_eventEventsmediumhighGDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIASOC2Reads a single event including attendees, description, and conferencing details.
Google Calendargoogle-calendar.delete_eventEventsmediumhighGDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIACancels an event; sends cancellation notices to attendees and removes scheduling history.
Google Calendargoogle-calendar.create_eventEventsmediumhighGDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIASchedules a meeting on the user's calendar; sends invites to attendees on the user's behalf.
Gmailgmail.unlabel_threadLabelslowhighRemoves a label from all messages in a thread.
Gmailgmail.unlabel_messageLabelslowhighRemoves a label from a message.
Gmailgmail.search_threadsMessaginghighhighGDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIASOC2ISO_27001Searches the user's mailbox; can surface PII, credentials, contracts, and material non-public information across all correspondence.
Gmailgmail.list_labelsLabelslowhighLists existing mailbox labels.
Gmailgmail.list_draftsMessaginglowhighGDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIAEnumerates the user's saved drafts.
Gmailgmail.label_threadLabelslowhighApplies a label to all messages in a thread.
Gmailgmail.label_messageLabelslowhighApplies a label to a message; minor mailbox organization change.
Gmailgmail.get_threadMessaginghighhighGDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIASOC2ISO_27001Reads an entire email thread; full message body and attachments enter agent context.
Gmailgmail.create_labelLabelslowhighCreates a new mailbox label.
Gmailgmail.create_draftMessagingmediumhighGDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIASOC2Composes an email draft on the user's behalf; not auto-sent but visible to the user as their outgoing communication.
GitLabgitlab.semantic_code_searchSearchmediummediumSOC2ISO_27001Semantic search across source; aggregates code context across repos and may expose secrets-in-code or IP.
GitLabgitlab.search_labelsSearchlowhighLooks up labels in a project or group.
GitLabgitlab.searchSearchmediumhighSOC2ISO_27001Search across the GitLab instance; can surface code, issues, and merge requests beyond the agent's intended scope.
GitLabgitlab.manage_pipelinePipelineshighmedium⚠ SoDSOXCOSOSOC2ISO_27001NIST_CSFCreates, retries, or cancels CI/CD pipelines; can trigger or block production deployments.
GitLabgitlab.get_workitem_notesIssueslowhighReads comments on a work item.
GitLabgitlab.get_pipeline_jobsPipelineslowhighReads CI job metadata and status.
GitLabgitlab.get_merge_request_pipelinesPipelineslowhighLists CI pipelines associated with a merge request.
GitLabgitlab.get_merge_request_diffsCode & ReleasemediummediumSOC2ISO_27001Reads code diffs; can surface secrets, customer data, or proprietary logic embedded in source.
GitLabgitlab.get_merge_request_commitsCode & ReleaselowhighLists commits attached to a merge request.
GitLabgitlab.get_merge_requestCode & ReleaselowhighReads merge request metadata and description.
GitLabgitlab.get_mcp_server_versionPlatformlowhighReturns the MCP server version string.
GitLabgitlab.get_issueIssueslowhighReads a single issue's contents.
GitLabgitlab.create_workitem_noteIssueslowhighAdds a comment to a work item.
GitLabgitlab.create_merge_requestCode & ReleasemediumhighSOC2ISO_27001Opens a merge request; entry point to production code change.
GitLabgitlab.create_issueIssueslowhighOpens a new issue in a project.
Website
https://github.com/github/github-mcp-server
Maintainer
https://github.com/github/github-mcp-server/issues
GitHubgithub.update_pull_request_branchCode & ReleasemediummediumSOXCOSOSOC2ISO_27001Updates a PR head branch with the latest from base; rewrites branch state and can mask in-flight review feedback in change-controlled repos.
Website
https://github.com/github/github-mcp-server
Maintainer
https://github.com/github/github-mcp-server/issues
GitHubgithub.update_pull_requestCode & ReleaselowhighSOC2ISO_27001Updates pull request metadata such as title, body, base branch, or assignees.
Website
https://github.com/github/github-mcp-server
Maintainer
https://github.com/github/github-mcp-server/issues
GitHubgithub.update_gistRepositorymediumhighSOC2ISO_27001Updates an existing gist; public gists remain a leak surface for secrets and customer data.
Website
https://github.com/github/github-mcp-server
Maintainer
https://github.com/github/github-mcp-server/issues
GitHubgithub.unstar_repositoryOperationslowhighRemoves a star on a repository as the authenticated user.
Website
https://github.com/github/github-mcp-server
Maintainer
https://github.com/github/github-mcp-server/issues
GitHubgithub.sub_issue_writeIssueslowmediumCreates, links, or removes a sub-issue parent/child relationship.
Website
https://github.com/github/github-mcp-server
Maintainer
https://github.com/github/github-mcp-server/issues
GitHubgithub.star_repositoryOperationslowhighAdds a star on a repository as the authenticated user.
Website
https://github.com/github/github-mcp-server
Maintainer
https://github.com/github/github-mcp-server/issues
GitHubgithub.search_usersIdentity & AdminlowhighGDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIASearches GitHub users by login, name, or email; returns identifiable PII at scale.
Website
https://github.com/github/github-mcp-server
Maintainer
https://github.com/github/github-mcp-server/issues
GitHubgithub.search_repositoriesRepositorylowhighSearches repositories by name, description, or topic.
Website
https://github.com/github/github-mcp-server
Maintainer
https://github.com/github/github-mcp-server/issues
GitHubgithub.search_pull_requestsCode & ReleaselowhighSearches pull requests across accessible repositories.
Website
https://github.com/github/github-mcp-server
Maintainer
https://github.com/github/github-mcp-server/issues
GitHubgithub.search_orgsIdentity & AdminlowhighSearches GitHub organizations by name or attribute.
Website
https://github.com/github/github-mcp-server
Maintainer
https://github.com/github/github-mcp-server/issues
GitHubgithub.search_issuesIssueslowmediumGDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIASearches issues across accessible repositories; can surface PII reported in issue bodies at scale.
Website
https://github.com/github/github-mcp-server
Maintainer
https://github.com/github/github-mcp-server/issues
GitHubgithub.search_codeRepositorymediumhighSOC2ISO_27001GDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIASearches code across accessible repositories; can surface secrets, credentials, or PII at scale and constitutes a data-exfiltration vector.
Website
https://github.com/github/github-mcp-server
Maintainer
https://github.com/github/github-mcp-server/issues
GitHubgithub.request_copilot_reviewOperationslowhighRequests an AI Copilot code review on a pull request; review verdict is advisory and does not satisfy required-reviewer rules.
Website
https://github.com/github/github-mcp-server
Maintainer
https://github.com/github/github-mcp-server/issues
GitHubgithub.push_filesRepositorymediumhighSOXCOSOSOC2ISO_27001Commits a batch of file changes directly to a branch; combined with merge_pull_request, this enables ship-without-review.
Website
https://github.com/github/github-mcp-server
Maintainer
https://github.com/github/github-mcp-server/issues
GitHubgithub.pull_request_review_writeCode & Releasehighhigh⚠ SoDSOXCOSOSOC2ISO_27001NIST_CSFSubmits a pull request review (approve, request changes, comment); the same principal can author and approve a PR, the textbook segregation-of-duties violation.