MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Ashby
17 tools · footprint 16
6 med 11 low
CData Connect AI
8 tools · footprint 16
1 critical 1 high 6 low
DataHub
24 tools · footprint 16
8 med 16 low
Google Compute Engine
25 tools · footprint 16
1 critical 6 med 18 low
Google Drive
7 tools · footprint 16
2 high 2 med 3 low
Guru
5 tools · footprint 16
3 med 2 low
HealthEx
15 tools · footprint 16
1 high 11 med 3 low HIPAA
Lumin PDF
7 tools · footprint 16
2 high 2 med 3 low
Microsoft OneDrive (Work IQ)
17 tools · footprint 16
1 high 4 med 12 low
Mintlify
17 tools · footprint 16
2 high 7 med 8 low
Sumble
25 tools · footprint 16
2 high 2 med 21 low
ThoughtSpot Spotter
12 tools · footprint 16
6 med 6 low
Coupler.io
4 tools · footprint 15
1 high 3 low
Digits
10 tools · footprint 15
5 med 5 low
Dovetail
9 tools · footprint 15
5 med 4 low
Gmail
10 tools · footprint 15
2 high 1 med 7 low
‹ PrevPage 9 of 19Next ›
Google Drive
2 high 2 med 3 low · 7 tools · 0 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (2 of 7)

google-drive.read_file_content high conf highOBO
Pulls a Drive file's contents into the agent context; high exposure if the file contains PII, financial, or regulated data.
google-drive.download_file_content high conf highOBO
Downloads a binary file from Drive; same exfiltration profile as content read.
All other tools (5)
google-drive.create_file medium conf highaudit
Writes new content into the user's Drive; can introduce malicious or noncompliant material.
google-drive.get_file_metadata low conf highallow
Reads metadata (name, owner, mtime) for a single file.
google-drive.get_file_permissions low conf highallow
Reads who has access to a file.
google-drive.list_recent_files low conf highallow
Lists files recently touched by the user.
google-drive.search_files medium conf highaudit
Searches across the user's Drive; can surface regulated documents the agent wasn't intended to see.