Compliance action index

1695 actions across 80 platforms
Reset 151–200 of 1695 shown (total 1695)
Platform ID ▼ Category Risk Conf SoD Compliance Business impact
Supabasesupabase.confirm_costAccount ManagementmediummediumSOXCOSOAcknowledges projected cost; precondition for paid resource creation.
Supabasesupabase.apply_migrationDatabasecriticalhigh⚠ SoDSOXCOSOSOC2ISO_27001NIST_CSFApplies a DDL migration to the live database; can alter or drop schema with no review gate.
Stytchstytch.updateConsumerSDKConfigSDK & Auth Configurationcriticalhigh⚠ SoDSOC2ISO_27001NIST_CSFNY_DFS_500GDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIAReconfigures consumer SDK settings, enabled auth products, and permissions; misconfiguration can disable MFA or lock users out at scale.
Stytchstytch.listProjectsProject ManagementlowhighLists Stytch projects in the workspace.
Stytchstytch.getAllRedirectURLsRedirect URLslowhighSOC2Reads registered redirect URLs for the project.
Stytchstytch.getAllPublicTokensPublic TokensmediummediumSOC2ISO_27001Reads public tokens used by client applications; intended public credentials but still a credential.
Stytchstytch.createRedirectURLsRedirect URLshighhigh⚠ SoDSOC2ISO_27001NIST_CSFGDPRUK_GDPRCCPARegisters new authentication callback URLs; an attacker-controlled URL here enables credential interception.
Stytchstytch.createPublicTokenPublic Tokenshighmedium⚠ SoDSOC2ISO_27001NIST_CSFIssues a new public token for a project; expands the set of identifiers that can initiate auth flows.
Stytchstytch.createProjectProject ManagementmediumhighSOC2ISO_27001Creates a new Stytch project; expands the workspace's authentication footprint.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.update_subscriptionRevenue & Pipelinehighhigh⚠ SoDSOXCOSOPCISOC2ISO_27001Changes plan, quantity, or trial state of a recurring billing relationship.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.update_disputeFinancialhighhigh⚠ SoDPCISOXCOSOSOC2ISO_27001PSD2Submits or modifies dispute evidence; affects chargeback outcome and revenue.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.search_stripe_resourcesPlatform & DevOpsmediummediumPCIGDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIASOC2Generic search across Stripe resources; can return PII and financial data.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.search_stripe_documentationPlatform & DevOpslowhighSearches Stripe public documentation; no account data accessed.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.retrieve_balanceFinanciallowhighSOXCOSOSOC2ISO_27001Reads current available and pending Stripe balance.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.list_subscriptionsRevenue & PipelinemediumhighSOXCOSOPCISOC2ISO_27001GDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIAReads recurring billing arrangements including customer, plan, and amount.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.list_productsRevenue & PipelinelowhighReads catalog products; metadata only.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.list_pricesRevenue & PipelinelowhighReads pricing definitions; catalog metadata only.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.list_payment_intentsFinancialmediumhighPCISOXCOSOSOC2ISO_27001PSD2Reads payment attempts including amounts, status, and last-four card data.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.list_invoicesFinancialmediumhighSOXCOSOPCISOC2ISO_27001Reads invoice history including amounts and customer references.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.list_disputesFinancialmediumhighPCISOXCOSOSOC2ISO_27001PSD2Reads chargeback / dispute records including amounts and reason codes.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.list_customersCustomerhighhighGDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIAPCISOC2ISO_27001Bulk read of customer records including billing PII; export risk at scale.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.list_couponsRevenue & PipelinelowhighReads available discount instruments.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.get_stripe_account_infoPlatform & DevOpslowhighSOC2ISO_27001Reads metadata about the connected Stripe account.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.finalize_invoiceFinancialcriticalhigh⚠ SoDSOXCOSOPCISOC2ISO_27001PSD2Locks the invoice and triggers payment collection; commits revenue.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.fetch_stripe_resourcesPlatform & DevOpsmediummediumPCIGDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIASOC2Generic fetch of arbitrary Stripe resources by id; PII and financial exposure depends on target.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.execute_analyticsFinancialmediummediumSOXCOSOPCISOC2ISO_27001Runs aggregate analytics queries across Stripe data; can return broad financial signals.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.create_refundFinancialcriticalhigh⚠ SoDSOXCOSOPCISOC2ISO_27001PSD2Moves money back to the customer; direct GL impact and chargeback exposure.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.create_productRevenue & PipelinemediumhighSOXCOSODefines a new sellable item in the Stripe catalog.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.create_priceRevenue & Pipelinehighhigh⚠ SoDSOXCOSOSOC2ISO_27001Defines pricing applied to subsequent invoices; revenue-recognition relevant.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.create_payment_linkFinancialhighhigh⚠ SoDPCISOXCOSOSOC2ISO_27001PSD2Generates a publicly shareable URL that initiates a payment flow against your account.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.create_invoice_itemFinancialhighhighSOXCOSOPCISOC2ISO_27001Adds line items to a draft invoice; affects amount billed to the customer.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.create_invoiceFinancialcriticalhigh⚠ SoDSOXCOSOPCISOC2ISO_27001Creates a billable invoice in Stripe; revenue recognition event tied to the GL.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.create_customerCustomermediumhighGDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIAPCICreates a customer record holding billing PII (name, email, address).
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.create_couponRevenue & Pipelinemediumhigh⚠ SoDSOXCOSOSOC2Creates a discount instrument; can be applied to reduce future invoice amounts.
Website
https://github.com/stripe/agent-toolkit
Maintainer
https://github.com/stripe/agent-toolkit/issues
Stripestripe.cancel_subscriptionRevenue & Pipelinehighhigh⚠ SoDSOXCOSOPCISOC2ISO_27001Ends a recurring revenue stream; reverses future-period revenue recognition.
Website
https://github.com/square/square-mcp-server
Maintainer
https://github.com/square/square-mcp-server/issues
Squaresquare.make_api_requestAPI Executioncriticalhigh⚠ SoDSOXCOSOPCIGLBAPSD2GDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIASOC2ISO_27001Generic dispatcher that executes any Square API call: payments, refunds, customer PII, orders, catalog, payouts. Effective scope equals the connected merchant's full Square access.
Website
https://github.com/square/square-mcp-server
Maintainer
https://github.com/square/square-mcp-server/issues
Squaresquare.get_type_infoDiscoverylowhighReturns parameter requirements for a Square API type; documentation read.
Website
https://github.com/square/square-mcp-server
Maintainer
https://github.com/square/square-mcp-server/issues
Squaresquare.get_service_infoDiscoverylowhighLists methods available for a Square API service; documentation read.
Snowflakesnowflake.SYSTEM_EXECUTE_SQLData Accesscriticalhigh⚠ SoDSOXCOSOGDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIASOC2ISO_27001NIST_CSFRuns arbitrary SQL with the connected role's full privileges; can read or modify any table the role can reach.
Snowflakesnowflake.sql_exec_toolData Accesscriticalhigh⚠ SoDSOXCOSOGDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIASOC2ISO_27001NIST_CSFCanonical Snowflake-published name for the SQL execution tool; same blast radius as SYSTEM_EXECUTE_SQL.
Snowflakesnowflake.GENERICGeneric / User-DefinedmediumlowSOC2ISO_27001Catch-all type for user-defined functions and stored procedures exposed as MCP tools; risk depends on the UDF body.
Snowflakesnowflake.CORTEX_SEARCH_SERVICE_QUERYCortex Search & AnalysthighhighGDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIASOC2ISO_27001Queries indexed unstructured content (documents, support cases, contracts) via Cortex Search; can surface PII or proprietary text.
Snowflakesnowflake.CORTEX_ANALYST_MESSAGECortex Search & AnalysthighhighSOXCOSOGDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIASOC2ISO_27001Natural-language query over a semantic view; returns structured business metrics that can include revenue or PII.
Snowflakesnowflake.CORTEX_AGENT_RUNCortex Search & Analysthighmedium⚠ SoDSOXCOSOGDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIASOC2ISO_27001NIST_CSFInvokes a managed Cortex Agent which can in turn call SQL, search, and custom tools; effective privileges are the agent's.
Smartsheetsmartsheet.update_rowsRowsmediummediumGDPRUK_GDPRCCPAPIPEDALGPDAPPIPIPLPOPIASOC2Modifies tracked row data; can alter project status, financial figures, or PII.
Smartsheetsmartsheet.update_commentDiscussions & CommentslowhighModifies the text of an existing comment.
Smartsheetsmartsheet.update_columnColumnsmediumhighSOC2Changes column properties; can silently alter data validation or formulas.
Smartsheetsmartsheet.searchDiscovery & NavigationlowhighSearches accessible Smartsheet assets by name or content; read surface.
Smartsheetsmartsheet.list_workspacesDiscovery & NavigationlowhighEnumerates accessible workspaces; surface mapping for the agent.
Smartsheetsmartsheet.list_sheet_discussionsDiscussions & CommentslowhighReads all discussions on a sheet.