MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
n8n
25 tools · footprint 56
1 critical 7 high 13 med 4 low
PagerDuty
64 tools · footprint 55
5 high 16 med 43 low
Datadog
24 tools · footprint 52
1 critical 11 high 12 med
Attention
25 tools · footprint 51
1 critical 6 high 18 med
Box
37 tools · footprint 50
10 high 14 med 13 low COSOHIPAA+1 more
Gusto
36 tools · footprint 48
12 high 11 med 13 low COSOGLBA+1 more
ActiveCampaign
58 tools · footprint 47
4 high 15 med 39 low COSOSOX
GitHub
24 tools · footprint 47
5 high 12 med 7 low COSOSOX
Sanity
36 tools · footprint 47
1 critical 5 high 12 med 18 low
Amplitude
43 tools · footprint 44
6 high 16 med 21 low
Mem
23 tools · footprint 44
5 high 8 med 10 low
Microsoft SharePoint (Work IQ)
23 tools · footprint 44
1 critical 5 high 13 med 4 low
PagerDuty
25 tools · footprint 44
6 high 18 med 1 low
Coralogix
21 tools · footprint 43
5 high 13 med 3 low
Sentry
25 tools · footprint 43
3 high 14 med 8 low
Clarify
25 tools · footprint 42
3 high 15 med 7 low
‹ PrevPage 2 of 19Next ›
Customer.io
1 critical 2 high 5 low · 8 tools · 1 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (3 of 8)

customerio.cio_delete_api critical conf mediumhuman approval
Permanently removes any Customer.io resource, irreversibly destroying customer profiles, segments, or campaigns through arbitrary DELETE calls.
customerio.cio_read_api high conf mediumOBO
Reads and lists any Customer.io resource, including customer profiles and messaging history, enabling bulk export of personal data via pagination and filtering.
customerio.cio_write_api high conf mediumOBO
Creates or edits any Customer.io resource, letting the agent alter customer profiles, segments, and campaign configuration through arbitrary POST, PUT, and PATCH calls.
All other tools (5)
customerio.cio_auth_status low conf mediumallow
Reveals the current authentication state and which Customer.io workspaces the token can reach, exposing account access scope.
customerio.cio_prime low conf mediumallow
Loads the AI-ready Customer.io API reference so the agent can plan subsequent calls; reads and changes no customer data.
customerio.cio_schema low conf mediumallow
Enumerates available Customer.io API endpoints and their parameters for call planning; exposes no customer data.
customerio.cio_skills_list low conf mediumallow
Lists the available agent skill playbooks for multi-step Customer.io operations; reveals no customer data.
customerio.cio_skills_read low conf mediumallow
Retrieves the full instructions for a specific Customer.io agent skill; exposes workflow guidance only, not customer data.