MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
n8n
25 tools · footprint 56
1 critical 7 high 13 med 4 low
PagerDuty
64 tools · footprint 55
5 high 16 med 43 low
Datadog
24 tools · footprint 52
1 critical 11 high 12 med
Attention
25 tools · footprint 51
1 critical 6 high 18 med
Box
37 tools · footprint 50
10 high 14 med 13 low COSOHIPAA+1 more
Gusto
36 tools · footprint 48
12 high 11 med 13 low COSOGLBA+1 more
ActiveCampaign
58 tools · footprint 47
4 high 15 med 39 low COSOSOX
GitHub
24 tools · footprint 47
5 high 12 med 7 low COSOSOX
Sanity
36 tools · footprint 47
1 critical 5 high 12 med 18 low
Amplitude
43 tools · footprint 44
6 high 16 med 21 low
Mem
23 tools · footprint 44
5 high 8 med 10 low
Microsoft SharePoint (Work IQ)
23 tools · footprint 44
1 critical 5 high 13 med 4 low
PagerDuty
25 tools · footprint 44
6 high 18 med 1 low
Coralogix
21 tools · footprint 43
5 high 13 med 3 low
Sentry
25 tools · footprint 43
3 high 14 med 8 low
Clarify
25 tools · footprint 42
3 high 15 med 7 low
‹ PrevPage 2 of 19Next ›
PagerDutyDocs ↗
6 high 18 med 1 low · 25 tools · 1 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDNIST_CSFPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (6 of 25)

pagerduty-api.create_user high conf mediumOBO
Provisions a new PagerDuty account with on-call and incident-response access, silently and with no invitation email — an unreviewed identity in the paging system.
pagerduty-api.delete_team high conf mediumOBO
Destroys a team and its access boundary, severing associations to services, schedules, and escalation policies and disrupting who is responsible for incidents.
pagerduty-api.list_users high conf mediumhuman approval
Bulk-reads the account's user directory — names, email addresses, and contact methods — exposing personal data of every responder at once.
pagerduty-api.create_webhook_subscription high conf mediumOBO
Opens a persistent channel that streams incident and event payloads — including responder identities — to an arbitrary external URL, a standing data-exfiltration path.
pagerduty-api.update_webhook_subscription high conf mediumOBO
Redirects or reconfigures where incident and event data is delivered, letting an attacker point the stream at an external endpoint they control.
pagerduty-api.delete_schedule_v3 high conf mediumOBO
Destroys an on-call schedule, removing coverage so incidents on dependent escalation policies may reach no responder at all.
All other tools (19)
pagerduty-api.add_responders medium conf mediumaudit
Pages additional users into an active incident, notifying them and pulling them into the response.
pagerduty-api.add_team_member medium conf mediumaudit
Adds a user to a team, granting them the team's visibility and on-call scope; reversible but expands who can act on the team's services.
pagerduty-api.append_event_orchestration_router_rule medium conf mediumaudit
Adds a routing rule that changes which service catches matching events, altering alert delivery for the orchestration.
pagerduty-api.create_escalation_policy medium conf mediumaudit
Defines a new chain of who gets paged and when; a flawed policy leaves incidents without a responder.
pagerduty-api.create_incident medium conf mediumaudit
Opens a new incident that pages on-call responders and starts escalation timers for the target service.
pagerduty-api.create_schedule medium conf mediumaudit
Establishes a new on-call schedule that determines which responders are reachable during incidents.
pagerduty-api.create_schedule_override medium conf mediumaudit
Temporarily replaces who is on call for a window, redirecting pages to a different responder.
pagerduty-api.create_service medium conf mediumaudit
Registers a new service that events route to and incidents open against, defining a unit of monitored infrastructure.
pagerduty-api.create_status_page_post medium conf mediumaudit
Publishes a customer-facing status page post, a public statement about service health with direct reputational impact.
pagerduty-api.create_team medium conf mediumaudit
Creates a new team that acts as an access and ownership boundary for services, schedules, and escalation policies.
pagerduty-api.delete_webhook_subscription medium conf mediumaudit
Removes an event-delivery subscription, silently breaking downstream integrations and automation that depend on incident notifications.
pagerduty-api.get_responder_load_metrics low conf mediumallow
Surfaces per-responder on-call workload metrics tied to identifiable employees, personal data that can drive performance judgments about individuals.
pagerduty-api.manage_incidents medium conf mediumaudit
Bulk-changes incident status, urgency, assignment, or resolution, and can resolve active incidents or reassign responders across many records at once.
pagerduty-api.remove_team_member medium conf mediumaudit
Removes a user from a team, potentially stripping their on-call coverage and leaving gaps in incident response for the team's services.
pagerduty-api.start_incident_workflow medium conf mediumaudit
Triggers an automated incident-response workflow that can run notifications and downstream actions without further human review.
pagerduty-api.update_escalation_policy medium conf mediumaudit
Changes who is notified during an incident and in what order; a bad edit can silently route alerts away from the right responders.
pagerduty-api.update_event_orchestration_router medium conf mediumaudit
Rewrites how incoming events are routed to services; misconfiguration can silently drop or misdirect alerts so incidents go unpaged.
pagerduty-api.update_schedule medium conf mediumaudit
Alters on-call rotations; a mistaken change can leave hours with no responder assigned and incidents unattended.
pagerduty-api.update_service medium conf mediumaudit
Changes service configuration such as its escalation policy or alert grouping, affecting how incidents are triaged and routed.