incidentoracle

IncidentOracle - 12-tool incident management MCP: triage, BaFin DORA reporting, RCA.

Sollte ich dies verwenden

Qualität und Sicherheit

B
Qualität der Beschreibung
86%
Vollständigkeit des Schemas
68%
Qualität der Benennung
82%
Risiko der Vergiftung
100%
Übereinstimmung der Berechtigungen
100%
Einhaltung des Protokolls
100%

Befunde (3)

  • LOWTool 'reclassify' description lacks action verbin reclassify
  • LOWTool 'cyber_threat_notify' description lacks action verbin cyber_threat_notify
  • LOWTool 'health_check' description lacks action verbin health_check

Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.

Kontextkosten

~1,297Tokens (Tool-Definitionen)
~966 BTypische Antwortgröße
Mittlere Auswirkung auf die Aufmerksamkeit (1.01% von 128k Kontext)

Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.

Installieren

Installation mit einem Klick

Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:

{
  "mcpServers": {
    "incidentoracle": {
      "url": "https://tooloracle.io/incident/mcp/"
    }
  }
}

Remote-Endpunkte

https://tooloracle.io/incident/mcp/streamable-http

Was es kann

Tool-Inventar

Tools (12)

🟢 Nur lesen🟡 Schreiben🔴 Löschen⚪ Unbekannt
⚪log_incident(incident_id, title, description, severity, detected_at, ...)

Log a new ICT-related incident. First step in the DORA incident management process (Art. 17).

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "incident_id": {
      "type": "string"
    },
    "title": {
      "type": "string"
    },
    "description": {
      "type": "string"
    },
    "severity": {
      "type": "string",
      "enum": [
        "critical",
        "high",
        "medium",
        "low"
      ]
    },
    "detected_at": {
      "type": "string",
      "description": "ISO datetime of detection"
    },
    "affected_systems": {
      "type": "string"
    },
    "affected_services": {
      "type": "string"
    },
    "owner": {
      "type": "string"
    },
    "team": {
      "type": "string"
    },
    "bcm_activated": {
      "type": "boolean"
    },
    "clients_affected": {
      "type": "number",
      "description": "Percentage of clients affected"
    },
    "duration_hours": {
      "type": "number"
    },
    "geographic_spread": {
      "type": "integer"
    },
    "data_losses": {
      "type": "boolean"
    },
    "economic_impact_eur": {
      "type": "number"
    },
    "criticality_of_services": {
      "type": "boolean"
    },
    "notes": {
      "type": "string"
    }
  },
  "required": [
    "title"
  ],
  "additionalProperties": false
}
⚪classify_incident(incident_id, clients_affected, duration_hours, geographic_spread, data_losses, ...)

Classify an incident against the 6 DORA criteria (RTS 2024/1772). Determines if MAJOR (triggers 4h/72h/1m reporting) or NON-MAJOR.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "incident_id": {
      "type": "string"
    },
    "clients_affected": {
      "type": "number",
      "description": "% of clients affected"
    },
    "duration_hours": {
      "type": "number"
    },
    "geographic_spread": {
      "type": "integer",
      "description": "Number of EU member states"
    },
    "data_losses": {
      "type": "boolean",
      "description": "Confidential/personal data affected?"
    },
    "economic_impact_eur": {
      "type": "number"
    },
    "criticality_of_services": {
      "type": "boolean",
      "description": "Critical functions affected?"
    }
  },
  "required": [
    "incident_id"
  ],
  "additionalProperties": false
}
🟢major_incident_check(clients_affected, duration_hours, geographic_spread, data_losses, economic_impact_eur, ...)

Quick check: would these criteria values classify as a MAJOR incident? No incident record needed — use for pre-assessment.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "clients_affected": {
      "type": "number"
    },
    "duration_hours": {
      "type": "number"
    },
    "geographic_spread": {
      "type": "integer"
    },
    "data_losses": {
      "type": "boolean"
    },
    "economic_impact_eur": {
      "type": "number"
    },
    "criticality_of_services": {
      "type": "boolean"
    }
  },
  "additionalProperties": false
}
⚪initial_notification(incident_id, entity_name, entity_lei, authority, affected_states, ...)

Generate the 4h initial notification for a MAJOR incident (ITS 2025/302 Annex I). Must be submitted within 4h of classification, max 24h after detection.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "incident_id": {
      "type": "string"
    },
    "entity_name": {
      "type": "string"
    },
    "entity_lei": {
      "type": "string"
    },
    "authority": {
      "type": "string",
      "description": "Competent authority (e.g., BaFin, FMA)"
    },
    "affected_states": {
      "type": "string",
      "description": "Comma-separated EU member states"
    },
    "discovery_method": {
      "type": "string",
      "enum": [
        "internal_monitoring",
        "user_report",
        "third_party",
        "regulator",
        "other"
      ]
    }
  },
  "required": [
    "incident_id"
  ],
  "additionalProperties": false
}
⚪intermediate_report(incident_id, description_update, root_cause, containment_actions, recovery_status, ...)

Generate the 72h intermediate report for a MAJOR incident (ITS 2025/302). Must include action plan if incident is not yet resolved.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "incident_id": {
      "type": "string"
    },
    "description_update": {
      "type": "string"
    },
    "root_cause": {
      "type": "string"
    },
    "containment_actions": {
      "type": "string"
    },
    "recovery_status": {
      "type": "string"
    },
    "action_plan": {
      "type": "string"
    },
    "expected_resolution": {
      "type": "string"
    }
  },
  "required": [
    "incident_id"
  ],
  "additionalProperties": false
}
⚪final_report(incident_id, root_cause_final, recovery_actions, lessons_learned, preventive_measures, ...)

Generate the 1-month final report with root cause analysis and lessons learned.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "incident_id": {
      "type": "string"
    },
    "root_cause_final": {
      "type": "string"
    },
    "recovery_actions": {
      "type": "string"
    },
    "lessons_learned": {
      "type": "string"
    },
    "preventive_measures": {
      "type": "string"
    },
    "client_communication": {
      "type": "string"
    },
    "total_cost_eur": {
      "type": "number"
    },
    "resolved_at": {
      "type": "string"
    }
  },
  "required": [
    "incident_id"
  ],
  "additionalProperties": false
}
⚪deadline_tracker

Track all active MAJOR incident reporting deadlines. Shows overdue and upcoming.

Eingabe-Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
⚪reclassify(incident_id, new_classification, reason)

Reclassify an incident (MAJOR to NON-MAJOR or vice versa). Competent authority must be notified of reclassification.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "incident_id": {
      "type": "string"
    },
    "new_classification": {
      "type": "string",
      "enum": [
        "MAJOR",
        "NON-MAJOR"
      ]
    },
    "reason": {
      "type": "string"
    }
  },
  "required": [
    "incident_id",
    "new_classification"
  ],
  "additionalProperties": false
}
⚪incident_stats

Dashboard: total/open/major incidents, overdue deadlines, by severity/status.

Eingabe-Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
⚪cyber_threat_notify(title, description, threat_type, iocs, ttps, ...)

Voluntary notification of a significant cyber threat (Art. 19(2)). Uses ITS 2025/302 Annex III template.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "title": {
      "type": "string"
    },
    "description": {
      "type": "string"
    },
    "threat_type": {
      "type": "string"
    },
    "iocs": {
      "type": "string"
    },
    "ttps": {
      "type": "string"
    },
    "affected_systems": {
      "type": "string"
    },
    "mitigation": {
      "type": "string"
    },
    "source": {
      "type": "string"
    }
  },
  "required": [
    "title"
  ],
  "additionalProperties": false
}
⚪incident_log(status, classification, severity, search)

Full incident register with filters (status, classification, severity, search).

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "status": {
      "type": "string",
      "enum": [
        "detected",
        "classified",
        "notified",
        "investigating",
        "contained",
        "resolved",
        "closed"
      ]
    },
    "classification": {
      "type": "string",
      "enum": [
        "MAJOR",
        "NON-MAJOR"
      ]
    },
    "severity": {
      "type": "string",
      "enum": [
        "critical",
        "high",
        "medium",
        "low"
      ]
    },
    "search": {
      "type": "string"
    }
  },
  "additionalProperties": false
}
🟢health_check

Server status.

Eingabe-Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

Community

Diesen Server bewerten

Nachweis

Aktuelle Beobachtungen

verifiziertVersion nicht aufgezeichnet12 Tools
verifiziertVersion nicht aufgezeichnet12 Tools
verifiziertVersion nicht aufgezeichnet12 Tools