MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Ashby
17 tools · footprint 16
6 med 11 low
CData Connect AI
8 tools · footprint 16
1 critical 1 high 6 low
DataHub
24 tools · footprint 16
8 med 16 low
Google Compute Engine
25 tools · footprint 16
1 critical 6 med 18 low
Google Drive
7 tools · footprint 16
2 high 2 med 3 low
Guru
5 tools · footprint 16
3 med 2 low
HealthEx
15 tools · footprint 16
1 high 11 med 3 low HIPAA
Lumin PDF
7 tools · footprint 16
2 high 2 med 3 low
Microsoft OneDrive (Work IQ)
17 tools · footprint 16
1 high 4 med 12 low
Mintlify
17 tools · footprint 16
2 high 7 med 8 low
Sumble
25 tools · footprint 16
2 high 2 med 21 low
ThoughtSpot Spotter
12 tools · footprint 16
6 med 6 low
Coupler.io
4 tools · footprint 15
1 high 3 low
Digits
10 tools · footprint 15
5 med 5 low
Dovetail
9 tools · footprint 15
5 med 4 low
Gmail
10 tools · footprint 15
2 high 1 med 7 low
‹ PrevPage 9 of 19Next ›
Customer.ioDocs ↗
1 critical 2 high 5 low · 8 tools · 1 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (3 of 8)

customerio-api.cio_delete_api critical conf mediumhuman approval
Issues arbitrary authenticated DELETE calls against any Customer.io endpoint, irreversibly removing customer records, segments, or campaigns with no built-in recovery path.
customerio-api.cio_write_api high conf mediumOBO
Issues arbitrary POST, PUT, and PATCH calls to any endpoint, letting the agent create or edit customer profiles, attributes, segments, and campaigns — including messaging that reaches real recipients.
customerio-api.cio_read_api high conf mediumOBO
Issues arbitrary authenticated GET calls against any endpoint, enabling retrieval and listing of customer profiles, attributes, and behavioral event data at scale.
All other tools (5)
customerio-api.cio_auth_status low conf mediumallow
Reveals the current token's authentication state and the set of workspaces it can reach, exposing the credential's effective access scope.
customerio-api.cio_prime low conf mediumallow
Loads the Customer.io API reference bundle into the agent context; a read-only priming call with no data-plane effect.
customerio-api.cio_schema low conf mediumallow
Enumerates available Customer.io API resources, endpoints, and parameters for discovery before any call is made; read-only metadata.
customerio-api.cio_skills_list low conf mediumallow
Lists the available agent skills — task-specific instruction sets — without executing any of them.
customerio-api.cio_skills_read low conf mediumallow
Returns the full step-by-step content of a named agent skill so the agent can follow the workflow; read-only retrieval.