MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Intuit QuickBooks
51 tools · footprint 188
15 critical 10 high 17 med 9 low COSOGLBA+3 more
PayPal
33 tools · footprint 86
6 critical 7 high 9 med 11 low COSOGLBA+3 more
Stripe
26 tools · footprint 77
3 critical 7 high 10 med 6 low COSOPCI+2 more
Qonto
25 tools · footprint 76
15 high 9 med 1 low COSOGLBA+3 more
PostHog
36 tools · footprint 69
6 high 22 med 8 low
Supabase
32 tools · footprint 69
4 critical 4 high 8 med 16 low COSOSOX
Datadog
25 tools · footprint 68
1 critical 12 high 11 med 1 low
PostHog
25 tools · footprint 66
3 critical 12 high 10 med
Adobe Workfront
25 tools · footprint 65
2 critical 7 high 13 med 3 low
MailerLite
25 tools · footprint 63
1 critical 11 high 12 med 1 low
MongoDB
25 tools · footprint 63
2 critical 7 high 12 med 4 low
MotherDuck
21 tools · footprint 62
4 critical 5 high 9 med 3 low
Salesforce
32 tools · footprint 60
4 critical 2 high 9 med 17 low COSOSOX
Close
64 tools · footprint 59
5 high 22 med 37 low COSOSOX
Cloudflare
26 tools · footprint 58
3 critical 4 high 6 med 13 low
Webflow
23 tools · footprint 57
2 critical 5 high 10 med 6 low
‹ PrevPage 1 of 19Next ›
Freshservice
6 high 15 med 2 low · 23 tools · 0 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDNIST_CSFPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (6 of 23)

freshservice-api.fetchAgents high conf mediumOBO
Returns the full agent directory including names, emails, and role assignments, exposing the entire IT-staff roster in one call.
freshservice-api.fetchRequesters high conf mediumOBO
Returns every requester on the account with their contact details, exposing the full employee and end-user directory in one call.
freshservice-api.fetchOffboardingRequests high conf mediumOBO
Lists all offboarding requests with departing-employee details, exposing HR-sensitive termination data across the organization at once.
freshservice-api.fetchTickets high conf mediumOBO
Returns every ticket on the account, exposing support content that can include personal data and credentials pasted into descriptions at scale.
freshservice-api.fetchTicketFilter high conf mediumOBO
Runs an arbitrary field-based query across all tickets, letting the caller extract targeted subsets of potentially sensitive ticket data at scale.
freshservice-api.fetchAssets high conf mediumOBO
Returns the full asset inventory (CMDB), exposing hardware, software, and configuration-item records for the entire estate in one call.
All other tools (17)
freshservice-api.createAsset medium conf mediumaudit
Adds a new asset record to the CMDB, expanding the tracked configuration-item inventory.
freshservice-api.createOffboardingRequest medium conf mediumaudit
Initiates an offboarding workflow that deprovisions a departing employee's accounts and access across connected systems.
freshservice-api.createOnboardingRequest medium conf mediumaudit
Opens an onboarding request that triggers provisioning of accounts and access for a new employee across connected systems.
freshservice-api.createSolutionArticle medium conf mediumaudit
Publishes a new knowledge-base article that becomes self-service content visible to requesters.
freshservice-api.createSolutionFolder low conf mediumallow
Creates a new knowledge-base folder to organize solution articles within a category.
freshservice-api.createTicket medium conf mediumaudit
Opens a new service-desk ticket in the account, entering the support queue and notifying assigned agents.
freshservice-api.createTicketNote low conf mediumallow
Appends a note to a ticket's conversation thread, visible to agents or the requester depending on the note's privacy setting.
freshservice-api.fetchAgent medium conf mediumaudit
Reads a single agent's profile including contact details and role, exposing one staff member's personal data.
freshservice-api.fetchAsset medium conf mediumaudit
Reads a single asset record including its configuration and assignment details from the CMDB.
freshservice-api.fetchOffboardingRequestTickets medium conf mediumaudit
Returns the tickets generated for an offboarding request, exposing departing-employee details and outstanding deprovisioning tasks.
freshservice-api.fetchOnboardingRequest medium conf mediumaudit
Reads a new-hire onboarding request including the employee's personal details and requested access, exposing HR-sensitive data.
freshservice-api.fetchRequester medium conf mediumaudit
Reads one requester's profile including name, email, and department, exposing a single individual's personal data.
freshservice-api.fetchTicket medium conf mediumaudit
Reads a single ticket including its description, requester, and conversation, exposing whatever sensitive content that ticket holds.
freshservice-api.placeRequestServiceCatalogItem medium conf mediumaudit
Submits a service catalog request on the account, entering approval and fulfillment workflows for the requested item.
freshservice-api.updateAsset medium conf mediumaudit
Modifies an existing asset's attributes or assignment in the CMDB, altering the recorded configuration state.
freshservice-api.updateSolutionArticle medium conf mediumaudit
Edits an existing knowledge-base article, changing live self-service content shown to requesters.
freshservice-api.updateTicket medium conf mediumaudit
Modifies an existing ticket's fields such as status, priority, or assignee, changing how the request is handled.