MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Magic Patterns
23 tools · footprint 28
2 high 8 med 13 low
WordPress.com
19 tools · footprint 28
3 high 6 med 10 low COSOSOX
Grain
15 tools · footprint 27
1 high 10 med 4 low
Oracle NetSuite
11 tools · footprint 27
3 high 3 med 5 low COSOSOX
Databricks
5 tools · footprint 26
1 critical 2 high 2 med COSOSOX
Lusha
22 tools · footprint 26
1 critical 6 high 15 low
Outlook Mail
10 tools · footprint 26
6 high 4 med
Airwallex Developer MCP
18 tools · footprint 25
1 critical 8 med 9 low COSOGLBA+3 more
Calendly
22 tools · footprint 25
15 med 7 low
Metabase
13 tools · footprint 25
1 critical 4 high 8 low
Atlassian Rovo
54 tools · footprint 24
13 med 41 low
Cognito Forms
9 tools · footprint 24
2 high 6 med 1 low HIPAA
Local Falcon
25 tools · footprint 24
1 high 9 med 15 low
ZoomInfo
15 tools · footprint 24
5 high 4 med 6 low
Braze
40 tools · footprint 23
1 high 5 med 34 low COSOSOX
Glean
11 tools · footprint 23
3 high 7 med 1 low
‹ PrevPage 5 of 19Next ›
incident.ioDocs ↗
1 high 6 med 18 low · 25 tools · 0 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (1 of 25)

incident-io.investigation_sync high conf highOBO
Downloads a complete incident investigation as an archive of timeline, telemetry, and communications, creating an offline copy of potentially sensitive operational and personal data outside incident.io's controls.
All other tools (24)
incident-io.alert_list low conf highallow
Searches and browses alerts across configured sources.
incident-io.alert_show low conf highallow
Returns full alert details and its linked incidents for one alert.
incident-io.analysis_start low conf highallow
Kicks off a structured operational analysis using playbooks and a report template, creating a new analysis workspace.
incident-io.ask medium conf mediumaudit
Runs the on-call AI agent that answers queries and takes schedule-management actions, giving broad natural-language reach across on-call state in a single call.
incident-io.ask_incident medium conf mediumaudit
Runs the incident AI agent that investigates and takes management actions on incidents, so a single prompt can mutate live incident state.
incident-io.ask_telemetry medium conf mediumaudit
Queries logs, metrics, traces, and dashboards through the telemetry AI agent, exposing observability data that may include internal identifiers or secrets.
incident-io.catalog_entry_show low conf highallow
Returns a full catalog entry with all attributes, exposing service or ownership metadata for one resource.
incident-io.catalog_type_list low conf highallow
Lists catalog types such as Service and Team defined in the organisation.
incident-io.escalation_list low conf highallow
Searches escalations (pages), surfacing recent and active paging activity.
incident-io.escalation_path_show low conf highallow
Reveals who would be paged at each level of an escalation path, exposing the responder contact chain.
incident-io.escalation_respond medium conf highaudit
Acknowledges or declines a page, redirecting who owns the live response to an escalation.
incident-io.escalation_stats low conf highallow
Returns paging counts by path, priority, and time of day, exposing on-call load patterns.
incident-io.feedback low conf highallow
Submits feedback about the MCP tools back to incident.io.
incident-io.follow_up_create low conf highallow
Adds a post-incident follow-up item, recording a remediation commitment against the incident.
incident-io.incident_create medium conf highaudit
Opens a new incident record, kicking off on-call paging and response workflows for the affected team.
incident-io.incident_list low conf highallow
Lists and filters incidents, surfacing the incident backlog and its workload distribution.
incident-io.incident_show low conf highallow
Returns full incident details including investigation notes and post-mortem, exposing the complete response record for one incident.
incident-io.incident_stats low conf highallow
Returns aggregate incident counts and workload across many dimensions, revealing operational health metrics.
incident-io.incident_update medium conf highaudit
Changes incident status, severity, roles, or custom fields, altering both the live response and the post-incident record.
incident-io.resource_show low conf highallow
Reads organisation configuration, analysis playbooks, or telemetry datasources, exposing platform setup details.
incident-io.schedule_list low conf highallow
Lists on-call schedules configured across the organisation.
incident-io.schedule_show low conf highallow
Shows an on-call schedule with current and upcoming shifts, revealing which named individuals are on call and when.
incident-io.team_list low conf highallow
Lists teams defined in the organisation.
incident-io.team_show low conf highallow
Returns team details including owned escalation paths, alert sources, and schedules.