Documentation Index

Fetch the complete documentation index at: https://help.scrut.io/llms.txt

Use this file to discover all available pages before exploring further.

Supported Scrut MCP Tools

Prev Next

Now that you've connected Scrut MCP to your AI tool, here's what each tool does so you know what your AI assistant can find, read, answer, and file on your behalf.

How These Tools Work

You don't need to name a specific tool in your prompts. Describe what you're trying to do, and your AI assistant selects the right tool, or combination of tools, automatically. For example, asking for a compliance digest might call the frameworks, controls, evidence, and test tools together in a single response.

Scrut MCP Tools

Tool

What does it do?

Use this to

Sample Prompts

scrut_list_frameworks

Lists your enabled compliance frameworks, such as SOC 2, ISO 27001, or GDPR, along with each one's next audit date.

Get a quick view of which frameworks are active and when they're next up for audit.

  • What frameworks do we currently have enabled, and when's each one's next audit?

  • Give me a quick status check on all our active frameworks.

scrut_list_controls

Lists framework controls, including code, domain, owner, and status. Can be filtered by framework or product.

See which controls exist under a framework and who owns them.

  • Show me the SOC 2 controls that don't have evidence mapped yet.

  • When's our next SOC 2 audit, and who owns the controls that are still open?

scrut_get_control

Retrieves full details for a single control.

Check the specifics of one control before reporting on it or acting on it.

  • Pull the details for control [Control Code] so I can report on it in this week's audit sync.

  • Who owns [Control Code], and what's its current status?

scrut_list_policies

Lists your compliance policies, including status, owner, and review date. Can be filtered by framework, product, or status.

Find policies that are in draft, in review, or past their review date.

  • Which policies are still in review, and who owns them?

  • Show me any policies that are past their review date.

scrut_get_policy

Retrieves full details for a single policy, including its owners, approvers, mapped frameworks and controls, and current policy document.

Check the status and ownership of a specific policy before an audit or review.

  • Pull the full text of our Data Retention Policy and check if it still mentions our old backup vendor.

  • Who are the approvers on our Access Control Policy, and which controls does it map to?

scrut_list_evidence

Lists evidence items, including status, assignee, and review date. Can be filtered by framework, product, or status.

Find evidence that's stale, missing, or coming up for review.

  • Show me evidence that's overdue for review.

  • What evidence is missing under ISO 27001 right now?

scrut_get_evidence

Retrieves full details for a single evidence item, including its status, owner, mapped controls, and currently uploaded documents.

Check what's currently attached to a specific piece of evidence.

  • Pull up the current status and owner for the [Evidence Name] evidence item.

  • What's currently attached to our access review evidence, and when was it last updated?

scrut_list_tests

Lists your automated tests, including cloud provider and pass or fail status.

See which cloud tests are currently failing across your program.

  • Which cloud tests are currently failing?

  • Which SOC 2 cloud tests are currently failing, and which ones should I prioritize?

scrut_get_test

Retrieves full details for a single continuous test, including the cloud provider, test level, and mapped controls.

Get the specifics of one failing test before working on a fix.

  • Pull the details for this failing test [Test_Name] and help me fix the underlying infrastructure-as-code.

  • What controls are mapped to this failing test, and which cloud provider is it running against?

scrut_answer_question

Returns a synthesized, sourced answer to a question, drawn from your published policies, Trust Vault, and Vault documents. If it isn't confident in an answer, it says so and flags the gap instead of guessing.

Draft security questionnaire answers or get a quick, sourced answer to a compliance question mid-task.

  • Draft answers to this security questionnaire based on our compliance posture and cite each source.

  • Here's a vendor security questionnaire. Answer what you can from our knowledge base, and flag any question you're not confident about.

scrut_get_document_

content

Retrieves the full text of one specific policy or evidence document.

Quote or verify exact wording in a document, or check whether a document still reflects a recent change.

  • Pull the full text of our Incident Response Policy so I can check the escalation steps.

  • Get the content of this evidence document and check if it references our old MDM vendor.

scrut_search_

documents

Finds a document by name across policies, evidence, and Trust Vault.

Locate a specific document when you don't have its exact ID or category.

  • Find our latest SOC 2 Type II report and summarize what it covers in three bullet points for a customer email.

  • Find our Vendor Risk Management policy. I don't remember which category it's filed under.

scrut_upload_file

Uploads a file and returns a document object. Doesn't attach it to anything on its own; pair it with scrut_attach_evidence_document.

Get a newly generated file, like an access review or config export, into Scrut.

  • Upload this access review and attach it to the access-review evidence, dated today, with a note that it was generated from the quarterly review.

  • Upload this pen test report as a standalone document so I can attach it to evidence later.

scrut_attach_evidence_

document

Attaches an uploaded document or an external link to an evidence item, with an optional date and note.

File a document or link to the right evidence item as soon as it's ready.

  • Attach this uploaded config export to the cloud-backup evidence, dated today, with a note that it's from the Q3 review.

  • Link this external doc to the vendor-access evidence item and show me what you're about to attach before you do it.

Good to Know

  • Every tool returns clean, readable output by default. List tools return results in pages. If your program has many frameworks, controls, or evidence, ask your AI assistant to show you more, and it will automatically pull the next page.

  • Write actions are bounded. Scrut MCP can upload and attach evidence, but it cannot delete, overwrite, or freely edit anything already in your compliance program.

  • There is no tool to download the contents of an existing policy or evidence file. Read tools return the document's details and reference information, not the file itself.

Tips for Better Outputs

  • Name the framework when it matters, for example, SOC 2 or ISO 27001. A vague prompt may pull from every framework you have enabled.

  • State your goal, not just the data you want. Tell your AI assistant what you're trying to accomplish, and it selects the right tools on its own.

  • Ask for sources when the answer matters. Scrut's answer tool always returns sources, but asking explicitly makes sure your AI assistant surfaces them in its reply. This is super helpful for questionnaire answers you plan to send externally.

  • Review before you rely on it. MCP gives you a faster starting point, not a final answer. Check evidence decisions and questionnaire responses before you send them.

  • Confirm before filing evidence. Add "show me what you're about to attach before you do it" for anything you want to double-check first.

  • Chain a search with an action in one prompt: "Check whether we have evidence for X, and if we do, tell me its current status."


Reach out to support@scrut.io or contact your CSM for further assistance.