cybershield

CyberShield - 12 cybersecurity tools: NIS2 mapping, MITRE ATT&CK, vulns, threat intel.

Should I use this

Quality & Safety

A
Description quality
96%
Schema completeness
70%
Naming quality
80%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Findings (1)

  • LOWTool 'threat_landscape' description lacks action verbin threat_landscape

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~1,102Tokens (tool definitions)
~693 BTypical response size
Moderate attention impact (0.86% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "cybershield": {
      "url": "https://tooloracle.io/cybershield/mcp/"
    }
  }
}

Remote endpoints

https://tooloracle.io/cybershield/mcp/streamable-http

What it can do

Tool inventory

Tools (12)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
⚪threat_landscape(sector)

Current cyber threat landscape overview per ENISA categories. Top 8 threats with sector relevance and mitigations.

Input Schema

{
  "type": "object",
  "properties": {
    "sector": {
      "type": "string",
      "description": "energy|finance|healthcare|manufacturing|public_admin|general"
    }
  },
  "additionalProperties": false
}
⚪cve_risk_score(cve_id, cvss_score, epss_score, in_kev_catalog, public_exploit, ...)

CVE risk prioritization combining CVSS, EPSS, KEV catalog, exploit availability. Returns weighted priority score with patching SLA.

Input Schema

{
  "type": "object",
  "properties": {
    "cve_id": {
      "type": "string"
    },
    "cvss_score": {
      "type": "number"
    },
    "epss_score": {
      "type": "number",
      "description": "0-1 EPSS probability"
    },
    "in_kev_catalog": {
      "type": "boolean"
    },
    "public_exploit": {
      "type": "boolean"
    },
    "internet_facing": {
      "type": "boolean"
    },
    "affected_systems": {
      "type": "integer"
    }
  },
  "additionalProperties": false
}
🟢attack_surface_check(web_applications, remote_access_vpn, cloud_services, iot_devices, employee_count)

Attack surface assessment checklist. Web apps, remote access, cloud, IoT, email. Prioritized security checks.

Input Schema

{
  "type": "object",
  "properties": {
    "web_applications": {
      "type": "boolean"
    },
    "remote_access_vpn": {
      "type": "boolean"
    },
    "cloud_services": {
      "type": "boolean"
    },
    "iot_devices": {
      "type": "boolean"
    },
    "employee_count": {
      "type": "integer"
    }
  },
  "additionalProperties": false
}
🟢phishing_indicators(sender_email, subject, suspicious_url, creates_urgency, has_unexpected_attachment, ...)

Analyze email/URL for phishing indicators. Scores sender, urgency, attachments, URL patterns. Returns verdict and recommended actions.

Input Schema

{
  "type": "object",
  "properties": {
    "sender_email": {
      "type": "string"
    },
    "subject": {
      "type": "string"
    },
    "suspicious_url": {
      "type": "string"
    },
    "creates_urgency": {
      "type": "boolean"
    },
    "has_unexpected_attachment": {
      "type": "boolean"
    },
    "asks_for_credentials": {
      "type": "boolean"
    }
  },
  "additionalProperties": false
}
⚪nis2_compliance(sector, employee_count, annual_turnover_meur, risk_management, incident_handling, ...)

NIS2 Directive (EU 2022/2555) compliance assessment. All 10 Art. 21 measures, entity classification, penalties, incident reporting.

Input Schema

{
  "type": "object",
  "properties": {
    "sector": {
      "type": "string"
    },
    "employee_count": {
      "type": "integer"
    },
    "annual_turnover_meur": {
      "type": "number"
    },
    "risk_management": {
      "type": "boolean"
    },
    "incident_handling": {
      "type": "boolean"
    },
    "business_continuity": {
      "type": "boolean"
    },
    "supply_chain_security": {
      "type": "boolean"
    },
    "vulnerability_management": {
      "type": "boolean"
    },
    "cyber_hygiene_training": {
      "type": "boolean"
    },
    "cryptography_policy": {
      "type": "boolean"
    },
    "access_control": {
      "type": "boolean"
    },
    "mfa_deployed": {
      "type": "boolean"
    },
    "incident_reporting_process": {
      "type": "boolean"
    }
  },
  "additionalProperties": false
}
⚪nis2_incident_report(incident_type, severity, affected_services, affected_users_estimate, cross_border_impact)

NIS2 incident notification template. 24h early warning, 72h notification, 1-month final report templates.

Input Schema

{
  "type": "object",
  "properties": {
    "incident_type": {
      "type": "string"
    },
    "severity": {
      "type": "string"
    },
    "affected_services": {
      "type": "string"
    },
    "affected_users_estimate": {
      "type": "integer"
    },
    "cross_border_impact": {
      "type": "boolean"
    }
  },
  "additionalProperties": false
}
⚪iso27001_gap(controls)

ISO 27001:2022 Annex A gap analysis. All 93 controls across 4 themes, new 2022 controls highlighted, certification process.

Input Schema

{
  "type": "object",
  "properties": {
    "controls": {
      "type": "object",
      "description": "Optional: status of specific controls"
    }
  },
  "additionalProperties": false
}
⚪dora_ict_risk(ict_risk_framework, ict_asset_inventory, protection_prevention, detection_measures, response_recovery, ...)

DORA Art. 5-12 ICT risk management compliance check. 8 articles assessed with specific requirements per article.

Input Schema

{
  "type": "object",
  "properties": {
    "ict_risk_framework": {
      "type": "boolean"
    },
    "ict_asset_inventory": {
      "type": "boolean"
    },
    "protection_prevention": {
      "type": "boolean"
    },
    "detection_measures": {
      "type": "boolean"
    },
    "response_recovery": {
      "type": "boolean"
    },
    "learning_evolving": {
      "type": "boolean"
    },
    "communication_plans": {
      "type": "boolean"
    }
  },
  "additionalProperties": false
}
⚪password_policy

Generate password policy per NIST SP 800-63B (2024) and BSI recommendations. Modern best practices — no forced rotation.

Input Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
⚪incident_playbook(incident_type)

Incident response playbook for ransomware, data breach, phishing compromise. Phase-by-phase actions with legal obligations.

Input Schema

{
  "type": "object",
  "properties": {
    "incident_type": {
      "type": "string",
      "description": "ransomware | data_breach | phishing_compromise"
    }
  },
  "additionalProperties": false
}
🟢risk_matrix(risks)

Risk assessment matrix (likelihood × impact). ISO 31000/27005 methodology. Provide risks for assessment or get template.

Input Schema

{
  "type": "object",
  "properties": {
    "risks": {
      "type": "string",
      "description": "JSON array [{name, likelihood(1-5), impact(1-5)}]"
    }
  },
  "additionalProperties": false
}
🟡security_metrics

Security KPI/metrics dashboard template. MTTD, MTTR, patch compliance, phishing rate. Board-ready reporting guidance.

Input Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded12 tools
verifiedversion not recorded12 tools
verifiedversion not recorded12 tools