MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Intuit QuickBooks
51 tools · footprint 188
15 critical 10 high 17 med 9 low COSOGLBA+3 more
PayPal
33 tools · footprint 86
6 critical 7 high 9 med 11 low COSOGLBA+3 more
Stripe
26 tools · footprint 77
3 critical 7 high 10 med 6 low COSOPCI+2 more
Qonto
25 tools · footprint 76
15 high 9 med 1 low COSOGLBA+3 more
PostHog
36 tools · footprint 69
6 high 22 med 8 low
Supabase
32 tools · footprint 69
4 critical 4 high 8 med 16 low COSOSOX
Datadog
25 tools · footprint 68
1 critical 12 high 11 med 1 low
PostHog
25 tools · footprint 66
3 critical 12 high 10 med
Adobe Workfront
25 tools · footprint 65
2 critical 7 high 13 med 3 low
MailerLite
25 tools · footprint 63
1 critical 11 high 12 med 1 low
MongoDB
25 tools · footprint 63
2 critical 7 high 12 med 4 low
MotherDuck
21 tools · footprint 62
4 critical 5 high 9 med 3 low
Salesforce
32 tools · footprint 60
4 critical 2 high 9 med 17 low COSOSOX
Close
64 tools · footprint 59
5 high 22 med 37 low COSOSOX
Cloudflare
26 tools · footprint 58
3 critical 4 high 6 med 13 low
Webflow
23 tools · footprint 57
2 critical 5 high 10 med 6 low
‹ PrevPage 1 of 19Next ›
Confluence (Atlassian Rovo MCP Server)
1 med 15 low · 16 tools · 0 SoD-flagged
regimes none

Tools needing tighter control (0 of 16)

None — every tool is low-risk, high-confidence, and outside PCI/HIPAA payload scope.
All other tools (16)
confluence.atlassianUserInfo low conf mediumallow
Returns the authenticated caller's own account profile — display name, email, and account ID — scoped to the requesting identity.
confluence.createConfluenceFooterComment low conf mediumallow
Posts a footer comment or reply on a page, attributed to the caller and visible to everyone with access to that page.
confluence.createConfluenceInlineComment low conf mediumallow
Attaches an inline comment to selected page text, attributed to the caller and visible to page readers.
confluence.createConfluencePage low conf mediumallow
Publishes a new Confluence page or live doc into a space, adding content the wider team may treat as authoritative.
confluence.fetchAtlassian low conf mediumallow
Retrieves a single Jira or Confluence item by Atlassian Resource Identifier, returning its full content to the caller.
confluence.getAccessibleAtlassianResources low conf mediumallow
Enumerates every Atlassian site and app the caller can reach, exposing cloudId values that map the organization's tenant topology.
confluence.getConfluenceCommentChildren low conf mediumallow
Lists the reply comments under a parent comment, returning the nested discussion thread and its participants.
confluence.getConfluencePage low conf mediumallow
Returns the full body of a single Confluence page or live doc by ID to the caller.
confluence.getConfluencePageDescendants low conf mediumallow
Lists the descendant pages beneath a parent page, revealing the sub-tree structure of the documentation.
confluence.getConfluencePageFooterComments low conf mediumallow
Lists the footer comments on a page, returning discussion threads that may include named participants.
confluence.getConfluencePageInlineComments low conf mediumallow
Lists inline comments anchored to page text, returning reviewer remarks alongside their authors.
confluence.getConfluenceSpaces low conf mediumallow
Lists the Confluence spaces visible to the caller, revealing how the knowledge base is partitioned across the organization.
confluence.getPagesInConfluenceSpace low conf mediumallow
Lists the pages within a given space, exposing document titles and identifiers for that area of the wiki.
confluence.searchAtlassian low conf mediumallow
Runs a natural-language search across all reachable Jira and Confluence content, surfacing whatever the caller is permitted to read.
confluence.searchConfluenceUsingCql low conf mediumallow
Executes an arbitrary CQL query against Confluence content, returning any pages and metadata the caller is permitted to see.
confluence.updateConfluencePage medium conf mediumaudit
Overwrites the body of an existing Confluence page; prior content is recoverable through version history but the live doc changes immediately for all readers.