Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
1 critical 12 high 11 med 1 low · 25 tools · 6 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDNIST_CSFPIPEDAPIPLPOPIASOC2UK_GDPR
Tools needing tighter control (13 of 25)
datadog.execute_code critical conf mediumhuman approval
Runs arbitrary agent-authored TypeScript in a Datadog-managed sandbox that can query logs, metrics, traces, incidents, and dashboards across the org — an open-ended code-execution surface.
datadog.datadog_remote_action_restricted_shell_run_command high conf mediumOBO
Executes read-only shell commands on a monitored host, exposing file contents and system state directly from production machines.
datadog.datadog_secrets_scan high conf mediumOBO
Scans source code for hardcoded secrets and credentials, surfacing AWS keys, API keys, passwords, and database credentials.
datadog.update_datadog_workflow_with_agent_trigger high conf mediumhuman approval
Adds an agent trigger and publishes a workflow, enabling AI agents to execute it without a separate review step.
datadog.update_datadog_security_detection_rule high conf mediumOBO
Replaces an existing detection rule in full, potentially weakening or disabling threat detection for the organization.
datadog.delete_datadog_security_detection_rules high conf mediumhuman approval
Permanently deletes custom security detection rules, creating threat-monitoring blind spots that cannot be undone.
datadog.create_datadog_security_suppression high conf mediumhuman approval
Creates a suppression that stops a detection rule from generating security signals for matching conditions, hiding activity from responders.
datadog.upsert_datadog_security_denylist_entry high conf mediumOBO
Blocks or updates a block on an IP, user, or user agent, cutting off their access via App and API Protection.
datadog.upsert_datadog_security_passlist high conf mediumhuman approval
Creates or updates a WAF exclusion filter that suppresses App and API Protection rules for a specific service or endpoint.
datadog.ddsql_run_query high conf mediumOBO
Runs arbitrary DDSQL queries spanning logs, metrics, RUM, spans, and infrastructure, enabling broad ad-hoc extraction of personal data.
datadog.analyze_datadog_logs high conf mediumOBO
Runs SQL aggregations across Datadog logs, which frequently contain user identifiers, IPs, and other personal data.
datadog.search_datadog_logs high conf mediumhuman approval
Searches and returns raw Datadog log records, which can expose personal data captured in application and infrastructure logs.
datadog.search_datadog_rum_events high conf mediumhuman approval
Searches Real User Monitoring events containing end-user session, device, and behavioral data tied to identifiable visitors.
All other tools (12)
datadog.analyze_datadog_security_findings medium conf mediumaudit
Runs SQL analysis over live security findings, exposing the organization's posture, misconfigurations, and vulnerability details.
datadog.create_datadog_monitor low conf mediumallow
Creates a Datadog monitor in draft mode at low priority, which sends no notifications until it is activated.
datadog.create_datadog_security_detection_rule medium conf mediumaudit
Creates a new security detection rule, changing which conditions generate Cloud SIEM and threat-detection signals.
datadog.delete_datadog_dashboard medium conf mediumaudit
Permanently deletes a Datadog dashboard and all its widgets, with no way to recover the configuration.
datadog.delete_datadog_security_suppression medium conf mediumaudit
Deletes a security suppression rule, re-enabling the detection signals it previously silenced.
datadog.edit_synthetics_tests medium conf mediumaudit
Edits Synthetic HTTP API tests, which can carry request headers and credentials used to probe production endpoints.
datadog.execute_datadog_workflow medium conf mediumaudit
Runs a published Datadog workflow with an agent trigger, invoking whatever automated actions the workflow's steps perform.
datadog.mute_datadog_security_findings medium conf mediumaudit
Mutes security findings so they no longer surface in alerts or dashboards, hiding them from responders until unmuted.
datadog.update_datadog_feature_flag_environment medium conf mediumaudit
Updates a feature flag's configuration in a specific environment, changing application behavior for targeted users.
datadog.update_datadog_security_signals_triage medium conf mediumaudit
Bulk-updates the triage state or assignee of up to 500 security signals in a single call.
datadog.update_rum_retention_filter medium conf mediumaudit
Changes a RUM retention filter, altering which end-user monitoring events are retained and indexed for the application.
datadog.upsert_datadog_dashboard medium conf mediumaudit
Creates or updates a Datadog dashboard, changing how observability data is presented across the organization.