MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Microsoft 365
23 tools · footprint 41
8 high 14 med 1 low
Paytm for Business
24 tools · footprint 41
2 critical 7 high 5 med 10 low COSOPCI+1 more
Vercel
20 tools · footprint 41
2 critical 3 high 2 med 13 low COSOSOX
Cloudinary
23 tools · footprint 40
1 critical 4 high 15 med 3 low
Freshdesk
24 tools · footprint 40
6 high 14 med 4 low
Netlify
23 tools · footprint 40
2 critical 4 high 4 med 13 low
Zapier
14 tools · footprint 39
1 critical 3 high 3 med 7 low COSOPCI+1 more
Freshservice
23 tools · footprint 38
6 high 15 med 2 low
GitHub
83 tools · footprint 38
1 high 20 med 62 low COSOSOX
Bright Data
25 tools · footprint 37
5 high 17 med 3 low
Snowflake
6 tools · footprint 37
2 critical 3 high 1 med COSOSOX
Brex
25 tools · footprint 36
3 high 17 med 5 low COSOGLBA+2 more
Microsoft Dataverse
15 tools · footprint 35
1 critical 3 high 8 med 3 low
Calendly
35 tools · footprint 34
2 high 13 med 20 low
Lovable
25 tools · footprint 34
1 critical 2 high 9 med 13 low
Smartsheet
42 tools · footprint 34
2 high 9 med 31 low COSOSOX
‹ PrevPage 3 of 19Next ›
MemDocs ↗
5 high 8 med 10 low · 23 tools · 5 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDNIST_CSFPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (5 of 23)

mem.list_notes high conf mediumhuman approval
Paginates through every note the caller can see, enabling wholesale enumeration of a personal or team knowledge base that routinely holds contact details, meeting content, and confidential plans.
mem.extended_search_notes high conf mediumhuman approval
Searches note bodies alongside linked PDFs, images, audio recordings, calendar events, and emails, surfacing private correspondence and meeting material in a single query.
mem.search_notes high conf mediumhuman approval
Relevance-ranked retrieval across the caller's whole note corpus; a targeted query can pull out personal or commercially sensitive passages without opening individual notes.
mem.set_note_created_at high conf mediumhuman approval
Backdates a note's visible creation time, letting a single principal misrepresent when knowledge was recorded and undermining the record's evidentiary value.
mem.delete_collection high conf mediumhuman approval
Hard-deletes a collection resource with no trash or restore path, permanently losing its organizing structure even though member notes survive.
All other tools (18)
mem.add_note_to_collection low conf mediumallow
Creates a membership link between an existing note and collection; contents of both are untouched.
mem.answer_question_about_attachment medium conf mediumaudit
Interrogates the contents of an attached file or recording, returning extracted details from material the caller never has to open directly.
mem.create_collection low conf mediumallow
Adds a new collection to the workspace; organizational change with no effect on note contents.
mem.create_note low conf mediumallow
Adds a new note to the workspace, optionally at a caller-chosen ID and pre-linked to collections; reversible via trash.
mem.find_related_notes medium conf mediumaudit
Surfaces semantically adjacent notes the caller may not have known existed, widening exposure from one note to a cluster of related personal or confidential material.
mem.get_audio_recording medium conf mediumaudit
Returns the full transcript of a recorded conversation or meeting, exposing participants' spoken words and any personal details discussed.
mem.get_collection low conf mediumallow
Reads title, description, and timestamps for one collection; no note contents are returned.
mem.get_note medium conf mediumaudit
Returns a note's complete body, including notes already moved to trash, so deleted-but-retained content remains readable to the agent.
mem.get_note_attachment_download_url medium conf mediumaudit
Mints a signed URL that grants file access to anyone holding the link, moving an attachment outside the platform's own authentication boundary for the life of the token.
mem.list_collections low conf mediumallow
Enumerates collection metadata visible to the caller; reveals how the workspace is organized without returning note contents.
mem.move_note low conf mediumallow
Shifts a note's collection membership, which can change who encounters it during normal browsing of the workspace.
mem.read_attachment medium conf mediumaudit
Extracts the parsed contents of an attached email, calendar event, document, or recording, exposing private correspondence held alongside a note.
mem.remove_note_from_collection low conf mediumallow
Drops the membership link between a note and a collection; the note stays active but disappears from that collection's view.
mem.restore_note low conf mediumallow
Returns a trashed note to the active set, making content someone had discarded searchable and visible again.
mem.search_collections low conf mediumallow
Relevance-ranked lookup over collection names and descriptions; returns organizational metadata only.
mem.trash_note medium conf mediumaudit
Removes a note from the active set, hiding it from search and daily use; recoverable only if someone notices and calls restore_note.
mem.update_collection low conf mediumallow
Renames a collection or rewrites its description; other users lose the label they navigate by, but no note content changes.
mem.update_note medium conf mediumaudit
Replaces a note's entire body rather than patching it, so an incomplete submission silently discards prior content including any personal details it held.