MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Microsoft 365
23 tools · footprint 41
8 high 14 med 1 low
Paytm for Business
24 tools · footprint 41
2 critical 7 high 5 med 10 low COSOPCI+1 more
Vercel
20 tools · footprint 41
2 critical 3 high 2 med 13 low COSOSOX
Cloudinary
23 tools · footprint 40
1 critical 4 high 15 med 3 low
Freshdesk
24 tools · footprint 40
6 high 14 med 4 low
Netlify
23 tools · footprint 40
2 critical 4 high 4 med 13 low
Zapier
14 tools · footprint 39
1 critical 3 high 3 med 7 low COSOPCI+1 more
Freshservice
23 tools · footprint 38
6 high 15 med 2 low
GitHub
83 tools · footprint 38
1 high 20 med 62 low COSOSOX
Bright Data
25 tools · footprint 37
5 high 17 med 3 low
Snowflake
6 tools · footprint 37
2 critical 3 high 1 med COSOSOX
Brex
25 tools · footprint 36
3 high 17 med 5 low COSOGLBA+2 more
Microsoft Dataverse
15 tools · footprint 35
1 critical 3 high 8 med 3 low
Calendly
35 tools · footprint 34
2 high 13 med 20 low
Lovable
25 tools · footprint 34
1 critical 2 high 9 med 13 low
Smartsheet
42 tools · footprint 34
2 high 9 med 31 low COSOSOX
‹ PrevPage 3 of 19Next ›
Microsoft DataverseDocs ↗
1 critical 3 high 8 med 3 low · 15 tools · 2 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDNIST_CSFPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (4 of 15)

dataverse.delete_table critical conf mediumhuman approval
Drops an entire Dataverse table and every row it holds — irreversible loss of all business and customer data stored in that table.
dataverse.read_query high conf mediumhuman approval
Runs arbitrary SQL SELECT queries across Dataverse tables, capable of returning large volumes of records including personal data in a single call.
dataverse.delete_record high conf mediumOBO
Permanently removes a row from a Dataverse table, destroying a business record that may contain personal data with no built-in recovery.
dataverse.file_download high conf mediumOBO
Generates a SAS URL that grants direct download access to a stored Dataverse file, whose contents may include personal or confidential data.
All other tools (11)
dataverse.commit_file_upload low conf mediumallow
Finalizes a previously staged file upload, attaching the uploaded content to Dataverse.
dataverse.create_record medium conf mediumaudit
Inserts a new row into a Dataverse table, creating a business record that may contain personal data about identifiable individuals.
dataverse.create_table medium conf mediumaudit
Adds a new table and schema to the Dataverse environment, altering the data model that downstream apps and flows depend on.
dataverse.delete_skill medium conf mediumaudit
Removes a Dataverse skill or playbook, disabling automation that dependent agents or apps rely on.
dataverse.describe low conf mediumallow
Retrieves detailed contents of tables, records, schemas, and skills from search results, which can expose personal data held in matched rows.
dataverse.init_file_upload medium conf mediumaudit
Generates a time-limited SAS URL granting write access to Dataverse file storage, staging content to be attached to records.
dataverse.search low conf mediumallow
Searches table schemas and business skills by keyword, returning metadata only without exposing row-level data.
dataverse.search_data medium conf mediumaudit
Searches structured and unstructured Dataverse data, surfacing matching records that may include personal or customer information.
dataverse.update_record medium conf mediumaudit
Overwrites fields on an existing Dataverse row, changing a business record that may hold personal or customer data.
dataverse.update_table medium conf mediumaudit
Alters the schema or metadata of an existing table, which can break dependent apps, forms, and integrations relying on the old shape.
dataverse.upsert_skill medium conf mediumaudit
Adds or updates a Dataverse skill or playbook, changing reusable automation logic that agents and apps execute against the environment.