MCP server for ScalePad — Core, Lifecycle Manager, ControlMap, Backup Radar, and Quoter.
SCALEPAD_API_KEYAPI keyrequiredScalePad platform API key (generated in the ScalePad app by an Administrator)
QUOTER_CLIENT_SECRETOAuth appoptionalOptional Quoter OAuth Client Secret, paired with QUOTER_CLIENT_ID
Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.
scalepad_br_backups_list_healthList all Backup Radar clients with their backup health rollups (healthy / warning / failed counts). Cursor-paginated: pass page_size (1-200, default 50) and the cursor returned by the previous page. history_days controls how many days of backup history feed the health rollup. Filterable by client n…List all Backup Radar clients with their backup health rollups (healthy / warning / failed counts). Cursor-paginated: pass page_size (1-200, default 50) and the cursor returned by the previous page. history_days controls how many days of backup history feed the health rollup. Filterable by client n…
No input schema was published for this tool.
scalepad_br_backups_get_healthGet backup health for a single Backup Radar client by client ID, including per-device backup status. history_days controls how many days of backup history feed the health rollup.Get backup health for a single Backup Radar client by client ID, including per-device backup status. history_days controls how many days of backup history feed the health rollup.
No input schema was published for this tool.
scalepad_br_backups_list_devicesList backup devices across Backup Radar clients. Cursor-paginated: pass page_size (1-200, default 50) and the cursor returned by the previous page. Filterable by device name or device ID; history_days controls how many days of backup history are included per device.List backup devices across Backup Radar clients. Cursor-paginated: pass page_size (1-200, default 50) and the cursor returned by the previous page. Filterable by device name or device ID; history_days controls how many days of backup history are included per device.
No input schema was published for this tool.
scalepad_cm_health_listNo description publishedThis tool published no description. Forge does not invent one.
scalepad_cm_health_getGet compliance health metrics for a single ControlMap client (framework progress, evidence and action-item posture).Get compliance health metrics for a single ControlMap client (framework progress, evidence and action-item posture).
No input schema was published for this tool.
scalepad_cm_reports_listNo description publishedThis tool published no description. Forge does not invent one.
scalepad_cm_reports_get_signed_urlRetrieve a signed URL to download a generated ControlMap report for a client. The URL is time-limited.Retrieve a signed URL to download a generated ControlMap report for a client. The URL is time-limited.
No input schema was published for this tool.
scalepad_cm_risks_searchNo description publishedThis tool published no description. Forge does not invent one.
scalepad_cm_risks_getGet a single ControlMap risk by ID for a client.Get a single ControlMap risk by ID for a client.
No input schema was published for this tool.
scalepad_cm_risks_create⚠ HIGH-IMPACT. Create a risk in a ControlMap client's risk register (name, description, status, department, category, owner, business impact, impact/likelihood scores). Confirm with the user before invoking.⚠ HIGH-IMPACT. Create a risk in a ControlMap client's risk register (name, description, status, department, category, owner, business impact, impact/likelihood scores). Confirm with the user before invoking.
No input schema was published for this tool.
scalepad_cm_risks_update⚠ HIGH-IMPACT. Partially update a ControlMap risk (code, title, description, status, owner, team, department, category). Only the provided fields change. Confirm with the user before invoking.⚠ HIGH-IMPACT. Partially update a ControlMap risk (code, title, description, status, owner, team, department, category). Only the provided fields change. Confirm with the user before invoking.
No input schema was published for this tool.
scalepad_cm_risks_deleteprivileged⚠ DESTRUCTIVE — IRREVERSIBLE. Permanently delete a risk from a ControlMap client's risk register. Confirm with the user before invoking.⚠ DESTRUCTIVE — IRREVERSIBLE. Permanently delete a risk from a ControlMap client's risk register. Confirm with the user before invoking.
No input schema was published for this tool.
scalepad_cm_risks_list_summariesNo description publishedThis tool published no description. Forge does not invent one.
scalepad_cm_risks_map⚠ HIGH-IMPACT. Map a ControlMap risk to related records: assets, asset types, threats, vulnerabilities, vendors, objectives, controls, and/or action items. Confirm with the user before invoking.⚠ HIGH-IMPACT. Map a ControlMap risk to related records: assets, asset types, threats, vulnerabilities, vendors, objectives, controls, and/or action items. Confirm with the user before invoking.
No input schema was published for this tool.
scalepad_cm_risks_unmap⚠ HIGH-IMPACT. Bulk-remove mappings between a ControlMap risk and related records (assets, asset types, threats, vulnerabilities, vendors, objectives, controls, action items). Confirm with the user before invoking.⚠ HIGH-IMPACT. Bulk-remove mappings between a ControlMap risk and related records (assets, asset types, threats, vulnerabilities, vendors, objectives, controls, action items). Confirm with the user before invoking.
No input schema was published for this tool.
scalepad_cm_risks_get_categoryGet a single ControlMap risk category by ID for a client.Get a single ControlMap risk category by ID for a client.
No input schema was published for this tool.
scalepad_cm_risks_list_departmentsList the risk departments configured for a ControlMap client.List the risk departments configured for a ControlMap client.
No input schema was published for this tool.
scalepad_cm_controls_searchNo description publishedThis tool published no description. Forge does not invent one.
scalepad_cm_controls_getGet a single ControlMap control by ID for a client.Get a single ControlMap control by ID for a client.
No input schema was published for this tool.
scalepad_cm_controls_create⚠ HIGH-IMPACT. Create a control for a ControlMap client (type, name, description, tag, contributors, owner, control set / family). Confirm with the user before invoking.⚠ HIGH-IMPACT. Create a control for a ControlMap client (type, name, description, tag, contributors, owner, control set / family). Confirm with the user before invoking.
No input schema was published for this tool.
scalepad_cm_controls_update⚠ HIGH-IMPACT. Partially update a ControlMap control (name, description, code, status, owner, type, frequency, team, implementation notes, control family). Only the provided fields change. Confirm with the user before invoking.⚠ HIGH-IMPACT. Partially update a ControlMap control (name, description, code, status, owner, type, frequency, team, implementation notes, control family). Only the provided fields change. Confirm with the user before invoking.
No input schema was published for this tool.
scalepad_cm_controls_deleteprivileged⚠ DESTRUCTIVE — IRREVERSIBLE. Permanently delete a control from a ControlMap client. Confirm with the user before invoking.⚠ DESTRUCTIVE — IRREVERSIBLE. Permanently delete a control from a ControlMap client. Confirm with the user before invoking.
No input schema was published for this tool.
scalepad_cm_controls_map⚠ HIGH-IMPACT. Map a ControlMap control to related items: evidence, policies, risks, action items, procedures, governance, and/or framework objectives. Confirm with the user before invoking.⚠ HIGH-IMPACT. Map a ControlMap control to related items: evidence, policies, risks, action items, procedures, governance, and/or framework objectives. Confirm with the user before invoking.
No input schema was published for this tool.
scalepad_cm_controls_unmap⚠ HIGH-IMPACT. Bulk-remove mappings between a ControlMap control and related items (evidence, policies, risks, action items, procedures, governance, objectives). Confirm with the user before invoking.⚠ HIGH-IMPACT. Bulk-remove mappings between a ControlMap control and related items (evidence, policies, risks, action items, procedures, governance, objectives). Confirm with the user before invoking.
No input schema was published for this tool.
scalepad_cm_controls_list_setsNo description publishedThis tool published no description. Forge does not invent one.
scalepad_cm_controls_list_familiesNo description publishedThis tool published no description. Forge does not invent one.
scalepad_cm_controls_list_summariesNo description publishedThis tool published no description. Forge does not invent one.
scalepad_cm_controls_get_summaryGet the control summary for a single ControlMap client (counts by status).Get the control summary for a single ControlMap client (counts by status).
No input schema was published for this tool.
scalepad_cm_evidence_searchNo description publishedThis tool published no description. Forge does not invent one.
scalepad_cm_evidence_list_summariesNo description publishedThis tool published no description. Forge does not invent one.
scalepad_cm_evidence_create⚠ HIGH-IMPACT. Create an evidence record for a ControlMap client (title, description, owner, assignee, refresh schedule, initial mappings). Confirm with the user before invoking.⚠ HIGH-IMPACT. Create an evidence record for a ControlMap client (title, description, owner, assignee, refresh schedule, initial mappings). Confirm with the user before invoking.
No input schema was published for this tool.
scalepad_cm_evidence_getGet a single ControlMap evidence record by ID for a client.Get a single ControlMap evidence record by ID for a client.
No input schema was published for this tool.
scalepad_cm_evidence_update⚠ HIGH-IMPACT. Update a ControlMap evidence record (title, description, owner, schedule). Only the provided fields change. Confirm with the user before invoking.⚠ HIGH-IMPACT. Update a ControlMap evidence record (title, description, owner, schedule). Only the provided fields change. Confirm with the user before invoking.
No input schema was published for this tool.
scalepad_cm_evidence_deleteprivileged⚠ DESTRUCTIVE — IRREVERSIBLE. Permanently delete a ControlMap evidence record (and its requests). Confirm with the user before invoking.⚠ DESTRUCTIVE — IRREVERSIBLE. Permanently delete a ControlMap evidence record (and its requests). Confirm with the user before invoking.
No input schema was published for this tool.
scalepad_cm_evidence_delete_scheduleprivileged⚠ DESTRUCTIVE — IRREVERSIBLE. Delete the refresh schedule from a ControlMap evidence record. schedule_action controls how pending scheduled requests are handled. Confirm with the user before invoking.⚠ DESTRUCTIVE — IRREVERSIBLE. Delete the refresh schedule from a ControlMap evidence record. schedule_action controls how pending scheduled requests are handled. Confirm with the user before invoking.
No input schema was published for this tool.
scalepad_cm_evidence_requests_listList the requests attached to a ControlMap evidence record (each request collects one round of evidence).List the requests attached to a ControlMap evidence record (each request collects one round of evidence).
No input schema was published for this tool.
scalepad_cm_evidence_requests_create⚠ HIGH-IMPACT. Create a new (empty) request in a ControlMap evidence record. Confirm with the user before invoking.⚠ HIGH-IMPACT. Create a new (empty) request in a ControlMap evidence record. Confirm with the user before invoking.
No input schema was published for this tool.
scalepad_cm_evidence_requests_create_with_urls⚠ HIGH-IMPACT. Create an evidence request on a ControlMap evidence record and get signed upload URLs for the named file (preferred for files over 10 MB). Confirm with the user before invoking.⚠ HIGH-IMPACT. Create an evidence request on a ControlMap evidence record and get signed upload URLs for the named file (preferred for files over 10 MB). Confirm with the user before invoking.
No input schema was published for this tool.
scalepad_cm_evidence_requests_signed_urls⚠ HIGH-IMPACT. Generate signed upload URLs for a document on an existing ControlMap evidence request (preferred for files over 10 MB). Confirm with the user before invoking.⚠ HIGH-IMPACT. Generate signed upload URLs for a document on an existing ControlMap evidence request (preferred for files over 10 MB). Confirm with the user before invoking.
No input schema was published for this tool.
scalepad_cm_evidence_requests_upload_documentprivileged⚠ HIGH-IMPACT. Upload a document (multipart, up to 10 MB) to an existing ControlMap evidence request. For larger files use the signed-URL flow (scalepad_cm_evidence_requests_signed_urls). Confirm with the user before invoking.⚠ HIGH-IMPACT. Upload a document (multipart, up to 10 MB) to an existing ControlMap evidence request. For larger files use the signed-URL flow (scalepad_cm_evidence_requests_signed_urls). Confirm with the user before invoking.
No input schema was published for this tool.
30 of 40 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
MCP server for ScalePad — Core, Lifecycle Manager, ControlMap, Backup Radar, and Quoter.
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.