MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
LILT
8 tools · footprint 15
4 med 4 low
Malwarebytes
6 tools · footprint 15
1 high 3 med 2 low
Omni Analytics
6 tools · footprint 15
2 high 4 low
Actively AI
11 tools · footprint 14
4 med 7 low
Apollo
4 tools · footprint 14
1 high 2 med 1 low
Asana
25 tools · footprint 14
5 med 20 low
ClickUp
25 tools · footprint 14
4 med 21 low
ClickUp
25 tools · footprint 14
4 med 21 low
Crossbeam
9 tools · footprint 14
4 med 5 low
Fireflies
3 tools · footprint 14
2 high 1 low
GitLab
15 tools · footprint 14
1 high 4 med 10 low COSOSOX
Google BigQuery
5 tools · footprint 14
1 high 4 low COSOSOX
Google Calendar
8 tools · footprint 14
5 med 3 low
Harmonic
7 tools · footprint 14
4 med 3 low
HubSpot CRM API
12 tools · footprint 14
4 med 8 low
HubSpot Meetings API
12 tools · footprint 14
4 med 8 low
‹ PrevPage 10 of 19Next ›
CloudinaryDocs ↗
1 critical 4 high 15 med 3 low · 23 tools · 1 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (5 of 23)

cloudinary.delete-folder critical conf mediumhuman approval
Deletes a folder together with every asset it contains in one call, an irreversible mass removal of customer media with no per-asset confirmation.
cloudinary.delete-asset high conf mediumOBO
Permanently removes a single asset by its immutable ID, taking down its delivery URLs and any dependent transformations.
cloudinary.generate-archive high conf mediumOBO
Packages an arbitrary set of assets into a downloadable ZIP or TGZ, enabling bulk export of media that may contain images of identifiable people.
cloudinary.create-trigger high conf mediumOBO
Registers a webhook that streams product-environment events to an external destination URL, opening an outbound data channel to a third party.
cloudinary.update-trigger high conf mediumOBO
Repoints an existing webhook's callback URL, which can silently redirect event notifications and their payloads to an attacker-controlled endpoint.
All other tools (18)
cloudinary.analyze-ai-vision-general medium conf mediumaudit
Sends an image to a general-purpose AI vision model for open-ended analysis, returning inferred descriptions and attributes about its contents.
cloudinary.analyze-ai-vision-moderation medium conf mediumaudit
Submits media to an AI moderation model that flags unsafe or restricted content, producing automated classifications used to gate assets.
cloudinary.asset-rename medium conf mediumaudit
Changes an asset's public ID, which rewrites its canonical delivery URL and can break every embed or link that referenced the old identifier.
cloudinary.asset-update medium conf mediumaudit
Modifies an existing asset's metadata, tags, and attributes, altering how it is categorized, searched, and surfaced across the media library.
cloudinary.create-asset-relations low conf mediumallow
Links an asset to related assets by ID, adding relationship metadata used for grouping and recommendation surfaces.
cloudinary.create-upload-mapping medium conf mediumaudit
Defines a folder-to-remote-URL fetch mapping, letting the platform pull and cache assets from an external source on demand.
cloudinary.create-upload-preset medium conf mediumaudit
Creates a reusable upload preset whose settings govern default access mode, moderation, and transformations applied to future uploads.
cloudinary.delete-asset-relations low conf mediumallow
Removes relationship links between assets, detaching grouping metadata without affecting the underlying media.
cloudinary.delete-derived-assets medium conf mediumaudit
Purges cached derived renditions of assets, forcing regeneration on next request and temporarily increasing transformation load and delivery latency.
cloudinary.delete-trigger medium conf mediumaudit
Removes a configured webhook, halting event notifications to its downstream consumer and potentially breaking dependent automation.
cloudinary.download-asset-backup medium conf mediumaudit
Retrieves a stored backup copy of an asset, exposing original media that may include personal or sensitive imagery outside the live library.
cloudinary.get-usage-details low conf mediumallow
Returns aggregate account usage metrics such as storage, bandwidth, and transformation counts for the product environment.
cloudinary.move-folder medium conf mediumaudit
Relocates or renames an entire folder and all its assets, changing every contained asset's delivery URL and breaking existing references at scale.
cloudinary.search-assets medium conf mediumaudit
Runs an arbitrary expression query across the asset library, returning asset details and metadata that could surface sensitive media in bulk.
cloudinary.update-upload-mapping medium conf mediumaudit
Changes the remote URL template of an existing upload mapping, redirecting where fetched assets originate from for a given folder.
cloudinary.update-upload-preset medium conf mediumaudit
Alters an existing upload preset's configuration, which can weaken default moderation or make future uploads publicly accessible.
cloudinary.upload-asset medium conf mediumaudit
Ingests new image, video, or raw files into the product environment, adding externally-sourced media that downstream delivery and transformations will serve.
cloudinary.visual-search-assets medium conf mediumaudit
Finds images by visual similarity or content, which can be used to locate photos of a specific person and raises biometric-matching concerns.