incidentoracle
IncidentOracle - 12-tool incident management MCP: triage, BaFin DORA reporting, RCA.
Sollte ich dies verwenden
Qualität und Sicherheit
Befunde (3)
- LOWin reclassify
- LOWin cyber_threat_notify
- LOWin health_check
Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.
Kontextkosten
Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.
Installieren
Installation mit einem Klick
Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:
{
"mcpServers": {
"incidentoracle": {
"url": "https://tooloracle.io/incident/mcp/"
}
}
}Remote-Endpunkte
https://tooloracle.io/incident/mcp/streamable-httpWas es kann
Tool-Inventar
Tools (12)
⚪log_incident(incident_id, title, description, severity, detected_at, ...)
Log a new ICT-related incident. First step in the DORA incident management process (Art. 17).
Eingabe-Schema
{
"type": "object",
"properties": {
"incident_id": {
"type": "string"
},
"title": {
"type": "string"
},
"description": {
"type": "string"
},
"severity": {
"type": "string",
"enum": [
"critical",
"high",
"medium",
"low"
]
},
"detected_at": {
"type": "string",
"description": "ISO datetime of detection"
},
"affected_systems": {
"type": "string"
},
"affected_services": {
"type": "string"
},
"owner": {
"type": "string"
},
"team": {
"type": "string"
},
"bcm_activated": {
"type": "boolean"
},
"clients_affected": {
"type": "number",
"description": "Percentage of clients affected"
},
"duration_hours": {
"type": "number"
},
"geographic_spread": {
"type": "integer"
},
"data_losses": {
"type": "boolean"
},
"economic_impact_eur": {
"type": "number"
},
"criticality_of_services": {
"type": "boolean"
},
"notes": {
"type": "string"
}
},
"required": [
"title"
],
"additionalProperties": false
}⚪classify_incident(incident_id, clients_affected, duration_hours, geographic_spread, data_losses, ...)
Classify an incident against the 6 DORA criteria (RTS 2024/1772). Determines if MAJOR (triggers 4h/72h/1m reporting) or NON-MAJOR.
Eingabe-Schema
{
"type": "object",
"properties": {
"incident_id": {
"type": "string"
},
"clients_affected": {
"type": "number",
"description": "% of clients affected"
},
"duration_hours": {
"type": "number"
},
"geographic_spread": {
"type": "integer",
"description": "Number of EU member states"
},
"data_losses": {
"type": "boolean",
"description": "Confidential/personal data affected?"
},
"economic_impact_eur": {
"type": "number"
},
"criticality_of_services": {
"type": "boolean",
"description": "Critical functions affected?"
}
},
"required": [
"incident_id"
],
"additionalProperties": false
}🟢major_incident_check(clients_affected, duration_hours, geographic_spread, data_losses, economic_impact_eur, ...)
Quick check: would these criteria values classify as a MAJOR incident? No incident record needed — use for pre-assessment.
Eingabe-Schema
{
"type": "object",
"properties": {
"clients_affected": {
"type": "number"
},
"duration_hours": {
"type": "number"
},
"geographic_spread": {
"type": "integer"
},
"data_losses": {
"type": "boolean"
},
"economic_impact_eur": {
"type": "number"
},
"criticality_of_services": {
"type": "boolean"
}
},
"additionalProperties": false
}⚪initial_notification(incident_id, entity_name, entity_lei, authority, affected_states, ...)
Generate the 4h initial notification for a MAJOR incident (ITS 2025/302 Annex I). Must be submitted within 4h of classification, max 24h after detection.
Eingabe-Schema
{
"type": "object",
"properties": {
"incident_id": {
"type": "string"
},
"entity_name": {
"type": "string"
},
"entity_lei": {
"type": "string"
},
"authority": {
"type": "string",
"description": "Competent authority (e.g., BaFin, FMA)"
},
"affected_states": {
"type": "string",
"description": "Comma-separated EU member states"
},
"discovery_method": {
"type": "string",
"enum": [
"internal_monitoring",
"user_report",
"third_party",
"regulator",
"other"
]
}
},
"required": [
"incident_id"
],
"additionalProperties": false
}⚪intermediate_report(incident_id, description_update, root_cause, containment_actions, recovery_status, ...)
Generate the 72h intermediate report for a MAJOR incident (ITS 2025/302). Must include action plan if incident is not yet resolved.
Eingabe-Schema
{
"type": "object",
"properties": {
"incident_id": {
"type": "string"
},
"description_update": {
"type": "string"
},
"root_cause": {
"type": "string"
},
"containment_actions": {
"type": "string"
},
"recovery_status": {
"type": "string"
},
"action_plan": {
"type": "string"
},
"expected_resolution": {
"type": "string"
}
},
"required": [
"incident_id"
],
"additionalProperties": false
}⚪final_report(incident_id, root_cause_final, recovery_actions, lessons_learned, preventive_measures, ...)
Generate the 1-month final report with root cause analysis and lessons learned.
Eingabe-Schema
{
"type": "object",
"properties": {
"incident_id": {
"type": "string"
},
"root_cause_final": {
"type": "string"
},
"recovery_actions": {
"type": "string"
},
"lessons_learned": {
"type": "string"
},
"preventive_measures": {
"type": "string"
},
"client_communication": {
"type": "string"
},
"total_cost_eur": {
"type": "number"
},
"resolved_at": {
"type": "string"
}
},
"required": [
"incident_id"
],
"additionalProperties": false
}⚪deadline_tracker
Track all active MAJOR incident reporting deadlines. Shows overdue and upcoming.
Eingabe-Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}⚪reclassify(incident_id, new_classification, reason)
Reclassify an incident (MAJOR to NON-MAJOR or vice versa). Competent authority must be notified of reclassification.
Eingabe-Schema
{
"type": "object",
"properties": {
"incident_id": {
"type": "string"
},
"new_classification": {
"type": "string",
"enum": [
"MAJOR",
"NON-MAJOR"
]
},
"reason": {
"type": "string"
}
},
"required": [
"incident_id",
"new_classification"
],
"additionalProperties": false
}⚪incident_stats
Dashboard: total/open/major incidents, overdue deadlines, by severity/status.
Eingabe-Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}⚪cyber_threat_notify(title, description, threat_type, iocs, ttps, ...)
Voluntary notification of a significant cyber threat (Art. 19(2)). Uses ITS 2025/302 Annex III template.
Eingabe-Schema
{
"type": "object",
"properties": {
"title": {
"type": "string"
},
"description": {
"type": "string"
},
"threat_type": {
"type": "string"
},
"iocs": {
"type": "string"
},
"ttps": {
"type": "string"
},
"affected_systems": {
"type": "string"
},
"mitigation": {
"type": "string"
},
"source": {
"type": "string"
}
},
"required": [
"title"
],
"additionalProperties": false
}⚪incident_log(status, classification, severity, search)
Full incident register with filters (status, classification, severity, search).
Eingabe-Schema
{
"type": "object",
"properties": {
"status": {
"type": "string",
"enum": [
"detected",
"classified",
"notified",
"investigating",
"contained",
"resolved",
"closed"
]
},
"classification": {
"type": "string",
"enum": [
"MAJOR",
"NON-MAJOR"
]
},
"severity": {
"type": "string",
"enum": [
"critical",
"high",
"medium",
"low"
]
},
"search": {
"type": "string"
}
},
"additionalProperties": false
}🟢health_check
Server status.
Eingabe-Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}Community
Nachweis