MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Intuit QuickBooks
51 tools · footprint 188
15 critical 10 high 17 med 9 low COSOGLBA+3 more
PayPal
33 tools · footprint 86
6 critical 7 high 9 med 11 low COSOGLBA+3 more
Stripe
26 tools · footprint 77
3 critical 7 high 10 med 6 low COSOPCI+2 more
Qonto
25 tools · footprint 76
15 high 9 med 1 low COSOGLBA+3 more
PostHog
36 tools · footprint 69
6 high 22 med 8 low
Supabase
32 tools · footprint 69
4 critical 4 high 8 med 16 low COSOSOX
Datadog
25 tools · footprint 68
1 critical 12 high 11 med 1 low
PostHog
25 tools · footprint 66
3 critical 12 high 10 med
Adobe Workfront
25 tools · footprint 65
2 critical 7 high 13 med 3 low
MailerLite
25 tools · footprint 63
1 critical 11 high 12 med 1 low
MongoDB
25 tools · footprint 63
2 critical 7 high 12 med 4 low
MotherDuck
21 tools · footprint 62
4 critical 5 high 9 med 3 low
Salesforce
32 tools · footprint 60
4 critical 2 high 9 med 17 low COSOSOX
Close
64 tools · footprint 59
5 high 22 med 37 low COSOSOX
Cloudflare
26 tools · footprint 58
3 critical 4 high 6 med 13 low
Webflow
23 tools · footprint 57
2 critical 5 high 10 med 6 low
‹ PrevPage 1 of 19Next ›
PagerDutyDocs ↗
6 high 18 med 1 low · 25 tools · 1 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDNIST_CSFPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (6 of 25)

pagerduty-api.create_user high conf mediumOBO
Provisions a new PagerDuty account with on-call and incident-response access, silently and with no invitation email — an unreviewed identity in the paging system.
pagerduty-api.delete_team high conf mediumOBO
Destroys a team and its access boundary, severing associations to services, schedules, and escalation policies and disrupting who is responsible for incidents.
pagerduty-api.list_users high conf mediumhuman approval
Bulk-reads the account's user directory — names, email addresses, and contact methods — exposing personal data of every responder at once.
pagerduty-api.create_webhook_subscription high conf mediumOBO
Opens a persistent channel that streams incident and event payloads — including responder identities — to an arbitrary external URL, a standing data-exfiltration path.
pagerduty-api.update_webhook_subscription high conf mediumOBO
Redirects or reconfigures where incident and event data is delivered, letting an attacker point the stream at an external endpoint they control.
pagerduty-api.delete_schedule_v3 high conf mediumOBO
Destroys an on-call schedule, removing coverage so incidents on dependent escalation policies may reach no responder at all.
All other tools (19)
pagerduty-api.add_responders medium conf mediumaudit
Pages additional users into an active incident, notifying them and pulling them into the response.
pagerduty-api.add_team_member medium conf mediumaudit
Adds a user to a team, granting them the team's visibility and on-call scope; reversible but expands who can act on the team's services.
pagerduty-api.append_event_orchestration_router_rule medium conf mediumaudit
Adds a routing rule that changes which service catches matching events, altering alert delivery for the orchestration.
pagerduty-api.create_escalation_policy medium conf mediumaudit
Defines a new chain of who gets paged and when; a flawed policy leaves incidents without a responder.
pagerduty-api.create_incident medium conf mediumaudit
Opens a new incident that pages on-call responders and starts escalation timers for the target service.
pagerduty-api.create_schedule medium conf mediumaudit
Establishes a new on-call schedule that determines which responders are reachable during incidents.
pagerduty-api.create_schedule_override medium conf mediumaudit
Temporarily replaces who is on call for a window, redirecting pages to a different responder.
pagerduty-api.create_service medium conf mediumaudit
Registers a new service that events route to and incidents open against, defining a unit of monitored infrastructure.
pagerduty-api.create_status_page_post medium conf mediumaudit
Publishes a customer-facing status page post, a public statement about service health with direct reputational impact.
pagerduty-api.create_team medium conf mediumaudit
Creates a new team that acts as an access and ownership boundary for services, schedules, and escalation policies.
pagerduty-api.delete_webhook_subscription medium conf mediumaudit
Removes an event-delivery subscription, silently breaking downstream integrations and automation that depend on incident notifications.
pagerduty-api.get_responder_load_metrics low conf mediumallow
Surfaces per-responder on-call workload metrics tied to identifiable employees, personal data that can drive performance judgments about individuals.
pagerduty-api.manage_incidents medium conf mediumaudit
Bulk-changes incident status, urgency, assignment, or resolution, and can resolve active incidents or reassign responders across many records at once.
pagerduty-api.remove_team_member medium conf mediumaudit
Removes a user from a team, potentially stripping their on-call coverage and leaving gaps in incident response for the team's services.
pagerduty-api.start_incident_workflow medium conf mediumaudit
Triggers an automated incident-response workflow that can run notifications and downstream actions without further human review.
pagerduty-api.update_escalation_policy medium conf mediumaudit
Changes who is notified during an incident and in what order; a bad edit can silently route alerts away from the right responders.
pagerduty-api.update_event_orchestration_router medium conf mediumaudit
Rewrites how incoming events are routed to services; misconfiguration can silently drop or misdirect alerts so incidents go unpaged.
pagerduty-api.update_schedule medium conf mediumaudit
Alters on-call rotations; a mistaken change can leave hours with no responder assigned and incidents unattended.
pagerduty-api.update_service medium conf mediumaudit
Changes service configuration such as its escalation policy or alert grouping, affecting how incidents are triaged and routed.