MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Ashby
17 tools · footprint 16
6 med 11 low
CData Connect AI
8 tools · footprint 16
1 critical 1 high 6 low
DataHub
24 tools · footprint 16
8 med 16 low
Google Compute Engine
25 tools · footprint 16
1 critical 6 med 18 low
Google Drive
7 tools · footprint 16
2 high 2 med 3 low
Guru
5 tools · footprint 16
3 med 2 low
HealthEx
15 tools · footprint 16
1 high 11 med 3 low HIPAA
Lumin PDF
7 tools · footprint 16
2 high 2 med 3 low
Microsoft OneDrive (Work IQ)
17 tools · footprint 16
1 high 4 med 12 low
Mintlify
17 tools · footprint 16
2 high 7 med 8 low
Sumble
25 tools · footprint 16
2 high 2 med 21 low
ThoughtSpot Spotter
12 tools · footprint 16
6 med 6 low
Coupler.io
4 tools · footprint 15
1 high 3 low
Digits
10 tools · footprint 15
5 med 5 low
Dovetail
9 tools · footprint 15
5 med 4 low
Gmail
10 tools · footprint 15
2 high 1 med 7 low
‹ PrevPage 9 of 19Next ›
Freshservice
6 high 15 med 2 low · 23 tools · 0 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDNIST_CSFPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (6 of 23)

freshservice-api.fetchAgents high conf mediumOBO
Returns the full agent directory including names, emails, and role assignments, exposing the entire IT-staff roster in one call.
freshservice-api.fetchRequesters high conf mediumOBO
Returns every requester on the account with their contact details, exposing the full employee and end-user directory in one call.
freshservice-api.fetchOffboardingRequests high conf mediumOBO
Lists all offboarding requests with departing-employee details, exposing HR-sensitive termination data across the organization at once.
freshservice-api.fetchTickets high conf mediumOBO
Returns every ticket on the account, exposing support content that can include personal data and credentials pasted into descriptions at scale.
freshservice-api.fetchTicketFilter high conf mediumOBO
Runs an arbitrary field-based query across all tickets, letting the caller extract targeted subsets of potentially sensitive ticket data at scale.
freshservice-api.fetchAssets high conf mediumOBO
Returns the full asset inventory (CMDB), exposing hardware, software, and configuration-item records for the entire estate in one call.
All other tools (17)
freshservice-api.createAsset medium conf mediumaudit
Adds a new asset record to the CMDB, expanding the tracked configuration-item inventory.
freshservice-api.createOffboardingRequest medium conf mediumaudit
Initiates an offboarding workflow that deprovisions a departing employee's accounts and access across connected systems.
freshservice-api.createOnboardingRequest medium conf mediumaudit
Opens an onboarding request that triggers provisioning of accounts and access for a new employee across connected systems.
freshservice-api.createSolutionArticle medium conf mediumaudit
Publishes a new knowledge-base article that becomes self-service content visible to requesters.
freshservice-api.createSolutionFolder low conf mediumallow
Creates a new knowledge-base folder to organize solution articles within a category.
freshservice-api.createTicket medium conf mediumaudit
Opens a new service-desk ticket in the account, entering the support queue and notifying assigned agents.
freshservice-api.createTicketNote low conf mediumallow
Appends a note to a ticket's conversation thread, visible to agents or the requester depending on the note's privacy setting.
freshservice-api.fetchAgent medium conf mediumaudit
Reads a single agent's profile including contact details and role, exposing one staff member's personal data.
freshservice-api.fetchAsset medium conf mediumaudit
Reads a single asset record including its configuration and assignment details from the CMDB.
freshservice-api.fetchOffboardingRequestTickets medium conf mediumaudit
Returns the tickets generated for an offboarding request, exposing departing-employee details and outstanding deprovisioning tasks.
freshservice-api.fetchOnboardingRequest medium conf mediumaudit
Reads a new-hire onboarding request including the employee's personal details and requested access, exposing HR-sensitive data.
freshservice-api.fetchRequester medium conf mediumaudit
Reads one requester's profile including name, email, and department, exposing a single individual's personal data.
freshservice-api.fetchTicket medium conf mediumaudit
Reads a single ticket including its description, requester, and conversation, exposing whatever sensitive content that ticket holds.
freshservice-api.placeRequestServiceCatalogItem medium conf mediumaudit
Submits a service catalog request on the account, entering approval and fulfillment workflows for the requested item.
freshservice-api.updateAsset medium conf mediumaudit
Modifies an existing asset's attributes or assignment in the CMDB, altering the recorded configuration state.
freshservice-api.updateSolutionArticle medium conf mediumaudit
Edits an existing knowledge-base article, changing live self-service content shown to requesters.
freshservice-api.updateTicket medium conf mediumaudit
Modifies an existing ticket's fields such as status, priority, or assignee, changing how the request is handled.