MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Klaviyo
29 tools · footprint 21
2 high 7 med 20 low
Mercury
13 tools · footprint 21
3 high 8 med 2 low COSOGLBA+2 more
Notion
18 tools · footprint 20
2 high 6 med 10 low
Zoom for Claude
13 tools · footprint 20
3 high 3 med 7 low HIPAA
Asana
23 tools · footprint 19
1 high 4 med 18 low
monday.com
17 tools · footprint 19
1 high 4 med 12 low
Orion by Gravity
20 tools · footprint 19
2 high 6 med 12 low
10x Genomics Cloud
27 tools · footprint 18
1 high 5 med 21 low HIPAA
Airtable
25 tools · footprint 18
1 high 6 med 18 low
Base44
7 tools · footprint 18
2 high 1 med 4 low
ClickHouse
4 tools · footprint 18
1 critical 1 med 2 low
DataGrail (Vera)
23 tools · footprint 18
8 med 15 low
Dropbox
23 tools · footprint 18
1 high 6 med 16 low
Felt Maps
23 tools · footprint 18
2 high 8 med 13 low
HubSpot
12 tools · footprint 18
1 high 3 med 8 low
incident.io
25 tools · footprint 18
1 high 6 med 18 low
‹ PrevPage 7 of 19Next ›
Customer.ioDocs ↗
1 critical 2 high 5 low · 8 tools · 1 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (3 of 8)

customerio-api.cio_delete_api critical conf mediumhuman approval
Issues arbitrary authenticated DELETE calls against any Customer.io endpoint, irreversibly removing customer records, segments, or campaigns with no built-in recovery path.
customerio-api.cio_write_api high conf mediumOBO
Issues arbitrary POST, PUT, and PATCH calls to any endpoint, letting the agent create or edit customer profiles, attributes, segments, and campaigns — including messaging that reaches real recipients.
customerio-api.cio_read_api high conf mediumOBO
Issues arbitrary authenticated GET calls against any endpoint, enabling retrieval and listing of customer profiles, attributes, and behavioral event data at scale.
All other tools (5)
customerio-api.cio_auth_status low conf mediumallow
Reveals the current token's authentication state and the set of workspaces it can reach, exposing the credential's effective access scope.
customerio-api.cio_prime low conf mediumallow
Loads the Customer.io API reference bundle into the agent context; a read-only priming call with no data-plane effect.
customerio-api.cio_schema low conf mediumallow
Enumerates available Customer.io API resources, endpoints, and parameters for discovery before any call is made; read-only metadata.
customerio-api.cio_skills_list low conf mediumallow
Lists the available agent skills — task-specific instruction sets — without executing any of them.
customerio-api.cio_skills_read low conf mediumallow
Returns the full step-by-step content of a named agent skill so the agent can follow the workflow; read-only retrieval.