MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Microsoft 365
23 tools · footprint 41
8 high 14 med 1 low
Paytm for Business
24 tools · footprint 41
2 critical 7 high 5 med 10 low COSOPCI+1 more
Vercel
20 tools · footprint 41
2 critical 3 high 2 med 13 low COSOSOX
Cloudinary
23 tools · footprint 40
1 critical 4 high 15 med 3 low
Freshdesk
24 tools · footprint 40
6 high 14 med 4 low
Netlify
23 tools · footprint 40
2 critical 4 high 4 med 13 low
Zapier
14 tools · footprint 39
1 critical 3 high 3 med 7 low COSOPCI+1 more
Freshservice
23 tools · footprint 38
6 high 15 med 2 low
GitHub
83 tools · footprint 38
1 high 20 med 62 low COSOSOX
Bright Data
25 tools · footprint 37
5 high 17 med 3 low
Snowflake
6 tools · footprint 37
2 critical 3 high 1 med COSOSOX
Brex
25 tools · footprint 36
3 high 17 med 5 low COSOGLBA+2 more
Microsoft Dataverse
15 tools · footprint 35
1 critical 3 high 8 med 3 low
Calendly
35 tools · footprint 34
2 high 13 med 20 low
Lovable
25 tools · footprint 34
1 critical 2 high 9 med 13 low
Smartsheet
42 tools · footprint 34
2 high 9 med 31 low COSOSOX
‹ PrevPage 3 of 19Next ›
JiraDocs ↗
4 med 10 low · 14 tools · 0 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (0 of 14)

None — every tool is low-risk, high-confidence, and outside PCI/HIPAA payload scope.
All other tools (14)
jira.addCommentToJiraIssue low conf mediumallow
Adds a new comment to an issue or overwrites an existing one when a comment ID is supplied; reversible and visible to all issue watchers.
jira.addWorklogToJiraIssue low conf mediumallow
Logs time against an issue, updating time-tracking totals that may feed downstream reporting or billing.
jira.createJiraIssue low conf mediumallow
Creates a new Jira issue or issue link, adding a tracked work item visible to the project's members.
jira.editJiraIssue medium conf mediumaudit
Updates fields on an existing issue, changing tracked work-item state that other users and automation rules depend on.
jira.getIssueLinkTypes low conf mediumallow
Lists the issue link types configured in the instance; read-only reference data.
jira.getJiraIssue low conf mediumallow
Retrieves the full content of a single Jira issue, including its fields, status, and participants.
jira.getJiraIssueRemoteIssueLinks low conf mediumallow
Lists remote links attached to an issue, revealing connected Confluence pages and external resources.
jira.getJiraIssueTypeMetaWithFields low conf mediumallow
Returns create-field metadata for a project and issue type; configuration data only, no record content.
jira.getJiraProjectIssueTypesMetadata low conf mediumallow
Lists the issue types configured in a project; read-only schema information.
jira.getTransitionsForJiraIssue low conf mediumallow
Lists the workflow transitions currently available on an issue; read-only workflow metadata.
jira.getVisibleJiraProjects low conf mediumallow
Lists the Jira projects the caller can access, revealing project keys and names across the instance.
jira.lookupJiraAccountId medium conf mediumaudit
Resolves user names or email addresses to Jira account IDs, exposing directory-level personal data and enabling enumeration of individuals in the workspace.
jira.searchJiraIssuesUsingJql medium conf mediumaudit
Runs an arbitrary JQL query across every issue the caller can see, potentially returning large result sets containing reporter, assignee, and comment personal data.
jira.transitionJiraIssue medium conf mediumaudit
Advances an issue through a workflow transition, changing its status and potentially triggering notifications, SLAs, or automation rules.