MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Intuit QuickBooks
51 tools · footprint 188
15 critical 10 high 17 med 9 low COSOGLBA+3 more
PayPal
33 tools · footprint 86
6 critical 7 high 9 med 11 low COSOGLBA+3 more
Stripe
26 tools · footprint 77
3 critical 7 high 10 med 6 low COSOPCI+2 more
Qonto
25 tools · footprint 76
15 high 9 med 1 low COSOGLBA+3 more
PostHog
36 tools · footprint 69
6 high 22 med 8 low
Supabase
32 tools · footprint 69
4 critical 4 high 8 med 16 low COSOSOX
Datadog
25 tools · footprint 68
1 critical 12 high 11 med 1 low
PostHog
25 tools · footprint 66
3 critical 12 high 10 med
Adobe Workfront
25 tools · footprint 65
2 critical 7 high 13 med 3 low
MailerLite
25 tools · footprint 63
1 critical 11 high 12 med 1 low
MongoDB
25 tools · footprint 63
2 critical 7 high 12 med 4 low
MotherDuck
21 tools · footprint 62
4 critical 5 high 9 med 3 low
Salesforce
32 tools · footprint 60
4 critical 2 high 9 med 17 low COSOSOX
Close
64 tools · footprint 59
5 high 22 med 37 low COSOSOX
Cloudflare
26 tools · footprint 58
3 critical 4 high 6 med 13 low
Webflow
23 tools · footprint 57
2 critical 5 high 10 med 6 low
‹ PrevPage 1 of 19Next ›
JamDocs ↗
1 high 11 med 10 low · 22 tools · 0 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (1 of 22)

jam.getNetworkRequests high conf mediumOBO
Dumps every captured web request as JSON, potentially exposing auth headers, cookies, and personal data carried in request payloads.
All other tools (21)
jam.analyzeVideo medium conf mediumaudit
Analyzes a recorded session video to extract insights, surfacing on-screen and spoken content in structured form.
jam.createComment low conf mediumallow
Adds a Markdown comment to a Jam, annotating a captured session.
jam.createRecordingLink medium conf mediumaudit
Creates a reusable link that silently collects browser-session recordings into the workspace, widening the session-capture surface.
jam.getConsoleLogs medium conf mediumaudit
Pulls the captured browser console logs, which can surface tokens, identifiers, or error data emitted during the recorded session.
jam.getDetails low conf mediumallow
Returns a snapshot of a Jam's author and activity, orienting the agent before deeper reads.
jam.getFrames medium conf mediumaudit
Extracts screen frames from a video Jam, revealing on-screen contents at chosen points across the recording.
jam.getMetadata medium conf mediumaudit
Reads custom capture metadata such as user IDs, app versions, and feature flags attached to the recorded session.
jam.getRecordingLink low conf mediumallow
Returns a single recording link's configuration by its public ID.
jam.getRecordingUrlVerifyLink medium conf mediumaudit
Begins verifying a connected recording domain, authorizing it as a sanctioned source for capturing sessions.
jam.getScreenshot medium conf mediumaudit
Returns every screenshot from a Jam, potentially revealing whatever personal data was visible on the user's screen.
jam.getUserEvents medium conf mediumaudit
Replays each captured click, input, and navigation, potentially exposing text the user typed into the page.
jam.getVideoTranscript medium conf mediumaudit
Returns the spoken transcript of a recorded session, exposing anything said aloud while the microphone was live.
jam.listFolders low conf mediumallow
Lists the workspace's folders used to organize Jams.
jam.listJams low conf mediumallow
Searches and filters the workspace's Jams by text, author, URL, or date, mapping the available captured sessions.
jam.listMembers low conf mediumallow
Reveals the full team-member roster, exposing colleagues' names and account identities to the agent.
jam.listRecordingLinkJams low conf mediumallow
Lists the Jams collected through a given recording link, exposing which captured sessions are tied to that link.
jam.listRecordingLinks low conf mediumallow
Enumerates every recording link including revoked ones, mapping the workspace's session-collection surface.
jam.listRecordingUrls low conf mediumallow
Lists the team's connected recording domains, exposing which sites are wired for session capture.
jam.revokeRecordingLink medium conf mediumaudit
Revokes a recording link, cutting off future capture through it while leaving already-collected Jams intact.
jam.updateJam low conf mediumallow
Moves a Jam between folders, reorganizing where a captured session lives in the workspace.
jam.updateRecordingLink medium conf mediumaudit
Alters a recording link's folder, expiration, or metadata, changing where and how long captured sessions are collected.