MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Definely
7 tools · footprint 3
1 med 6 low
Excalidraw App Demo
5 tools · footprint 3
1 med 4 low
Hugging Face
4 tools · footprint 3
1 med 3 low
LSEG (London Stock Exchange Group)
22 tools · footprint 3
1 med 21 low COSOSOX
EDEN by Basecamp Research
2 tools · footprint 2
2 med
Figma
23 tools · footprint 2
1 med 22 low
Figma
16 tools · footprint 2
1 med 15 low
Gamma
4 tools · footprint 2
1 med 3 low
Google Shopping
13 tools · footprint 2
2 med 11 low
GraphOS Tools
13 tools · footprint 2
13 low
HyperFrames by HeyGen
6 tools · footprint 2
2 med 4 low
Synthesize Bio
4 tools · footprint 2
2 med 2 low
Tavily
5 tools · footprint 2
2 med 3 low
alphaXiv
11 tools · footprint 1
1 med 10 low
AWS Marketplace
11 tools · footprint 1
11 low
Blockscout
16 tools · footprint 1
1 med 15 low
‹ PrevPage 15 of 19Next ›
Customer.ioDocs ↗
1 critical 2 high 5 low · 8 tools · 1 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (3 of 8)

customerio-api.cio_delete_api critical conf mediumhuman approval
Issues arbitrary authenticated DELETE calls against any Customer.io endpoint, irreversibly removing customer records, segments, or campaigns with no built-in recovery path.
customerio-api.cio_write_api high conf mediumOBO
Issues arbitrary POST, PUT, and PATCH calls to any endpoint, letting the agent create or edit customer profiles, attributes, segments, and campaigns — including messaging that reaches real recipients.
customerio-api.cio_read_api high conf mediumOBO
Issues arbitrary authenticated GET calls against any endpoint, enabling retrieval and listing of customer profiles, attributes, and behavioral event data at scale.
All other tools (5)
customerio-api.cio_auth_status low conf mediumallow
Reveals the current token's authentication state and the set of workspaces it can reach, exposing the credential's effective access scope.
customerio-api.cio_prime low conf mediumallow
Loads the Customer.io API reference bundle into the agent context; a read-only priming call with no data-plane effect.
customerio-api.cio_schema low conf mediumallow
Enumerates available Customer.io API resources, endpoints, and parameters for discovery before any call is made; read-only metadata.
customerio-api.cio_skills_list low conf mediumallow
Lists the available agent skills — task-specific instruction sets — without executing any of them.
customerio-api.cio_skills_read low conf mediumallow
Returns the full step-by-step content of a named agent skill so the agent can follow the workflow; read-only retrieval.