incidentoracle

IncidentOracle - 12-tool incident management MCP: triage, BaFin DORA reporting, RCA.

Should I use this

Quality & Safety

B
Description quality
86%
Schema completeness
68%
Naming quality
82%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Findings (3)

  • LOWTool 'reclassify' description lacks action verbin reclassify
  • LOWTool 'cyber_threat_notify' description lacks action verbin cyber_threat_notify
  • LOWTool 'health_check' description lacks action verbin health_check

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~1,297Tokens (tool definitions)
~966 BTypical response size
Moderate attention impact (1.01% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "incidentoracle": {
      "url": "https://tooloracle.io/incident/mcp/"
    }
  }
}

Remote endpoints

https://tooloracle.io/incident/mcp/streamable-http

What it can do

Tool inventory

Tools (12)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
⚪log_incident(incident_id, title, description, severity, detected_at, ...)

Log a new ICT-related incident. First step in the DORA incident management process (Art. 17).

Input Schema

{
  "type": "object",
  "properties": {
    "incident_id": {
      "type": "string"
    },
    "title": {
      "type": "string"
    },
    "description": {
      "type": "string"
    },
    "severity": {
      "type": "string",
      "enum": [
        "critical",
        "high",
        "medium",
        "low"
      ]
    },
    "detected_at": {
      "type": "string",
      "description": "ISO datetime of detection"
    },
    "affected_systems": {
      "type": "string"
    },
    "affected_services": {
      "type": "string"
    },
    "owner": {
      "type": "string"
    },
    "team": {
      "type": "string"
    },
    "bcm_activated": {
      "type": "boolean"
    },
    "clients_affected": {
      "type": "number",
      "description": "Percentage of clients affected"
    },
    "duration_hours": {
      "type": "number"
    },
    "geographic_spread": {
      "type": "integer"
    },
    "data_losses": {
      "type": "boolean"
    },
    "economic_impact_eur": {
      "type": "number"
    },
    "criticality_of_services": {
      "type": "boolean"
    },
    "notes": {
      "type": "string"
    }
  },
  "required": [
    "title"
  ],
  "additionalProperties": false
}
⚪classify_incident(incident_id, clients_affected, duration_hours, geographic_spread, data_losses, ...)

Classify an incident against the 6 DORA criteria (RTS 2024/1772). Determines if MAJOR (triggers 4h/72h/1m reporting) or NON-MAJOR.

Input Schema

{
  "type": "object",
  "properties": {
    "incident_id": {
      "type": "string"
    },
    "clients_affected": {
      "type": "number",
      "description": "% of clients affected"
    },
    "duration_hours": {
      "type": "number"
    },
    "geographic_spread": {
      "type": "integer",
      "description": "Number of EU member states"
    },
    "data_losses": {
      "type": "boolean",
      "description": "Confidential/personal data affected?"
    },
    "economic_impact_eur": {
      "type": "number"
    },
    "criticality_of_services": {
      "type": "boolean",
      "description": "Critical functions affected?"
    }
  },
  "required": [
    "incident_id"
  ],
  "additionalProperties": false
}
🟢major_incident_check(clients_affected, duration_hours, geographic_spread, data_losses, economic_impact_eur, ...)

Quick check: would these criteria values classify as a MAJOR incident? No incident record needed — use for pre-assessment.

Input Schema

{
  "type": "object",
  "properties": {
    "clients_affected": {
      "type": "number"
    },
    "duration_hours": {
      "type": "number"
    },
    "geographic_spread": {
      "type": "integer"
    },
    "data_losses": {
      "type": "boolean"
    },
    "economic_impact_eur": {
      "type": "number"
    },
    "criticality_of_services": {
      "type": "boolean"
    }
  },
  "additionalProperties": false
}
⚪initial_notification(incident_id, entity_name, entity_lei, authority, affected_states, ...)

Generate the 4h initial notification for a MAJOR incident (ITS 2025/302 Annex I). Must be submitted within 4h of classification, max 24h after detection.

Input Schema

{
  "type": "object",
  "properties": {
    "incident_id": {
      "type": "string"
    },
    "entity_name": {
      "type": "string"
    },
    "entity_lei": {
      "type": "string"
    },
    "authority": {
      "type": "string",
      "description": "Competent authority (e.g., BaFin, FMA)"
    },
    "affected_states": {
      "type": "string",
      "description": "Comma-separated EU member states"
    },
    "discovery_method": {
      "type": "string",
      "enum": [
        "internal_monitoring",
        "user_report",
        "third_party",
        "regulator",
        "other"
      ]
    }
  },
  "required": [
    "incident_id"
  ],
  "additionalProperties": false
}
⚪intermediate_report(incident_id, description_update, root_cause, containment_actions, recovery_status, ...)

Generate the 72h intermediate report for a MAJOR incident (ITS 2025/302). Must include action plan if incident is not yet resolved.

Input Schema

{
  "type": "object",
  "properties": {
    "incident_id": {
      "type": "string"
    },
    "description_update": {
      "type": "string"
    },
    "root_cause": {
      "type": "string"
    },
    "containment_actions": {
      "type": "string"
    },
    "recovery_status": {
      "type": "string"
    },
    "action_plan": {
      "type": "string"
    },
    "expected_resolution": {
      "type": "string"
    }
  },
  "required": [
    "incident_id"
  ],
  "additionalProperties": false
}
⚪final_report(incident_id, root_cause_final, recovery_actions, lessons_learned, preventive_measures, ...)

Generate the 1-month final report with root cause analysis and lessons learned.

Input Schema

{
  "type": "object",
  "properties": {
    "incident_id": {
      "type": "string"
    },
    "root_cause_final": {
      "type": "string"
    },
    "recovery_actions": {
      "type": "string"
    },
    "lessons_learned": {
      "type": "string"
    },
    "preventive_measures": {
      "type": "string"
    },
    "client_communication": {
      "type": "string"
    },
    "total_cost_eur": {
      "type": "number"
    },
    "resolved_at": {
      "type": "string"
    }
  },
  "required": [
    "incident_id"
  ],
  "additionalProperties": false
}
⚪deadline_tracker

Track all active MAJOR incident reporting deadlines. Shows overdue and upcoming.

Input Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
⚪reclassify(incident_id, new_classification, reason)

Reclassify an incident (MAJOR to NON-MAJOR or vice versa). Competent authority must be notified of reclassification.

Input Schema

{
  "type": "object",
  "properties": {
    "incident_id": {
      "type": "string"
    },
    "new_classification": {
      "type": "string",
      "enum": [
        "MAJOR",
        "NON-MAJOR"
      ]
    },
    "reason": {
      "type": "string"
    }
  },
  "required": [
    "incident_id",
    "new_classification"
  ],
  "additionalProperties": false
}
⚪incident_stats

Dashboard: total/open/major incidents, overdue deadlines, by severity/status.

Input Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
⚪cyber_threat_notify(title, description, threat_type, iocs, ttps, ...)

Voluntary notification of a significant cyber threat (Art. 19(2)). Uses ITS 2025/302 Annex III template.

Input Schema

{
  "type": "object",
  "properties": {
    "title": {
      "type": "string"
    },
    "description": {
      "type": "string"
    },
    "threat_type": {
      "type": "string"
    },
    "iocs": {
      "type": "string"
    },
    "ttps": {
      "type": "string"
    },
    "affected_systems": {
      "type": "string"
    },
    "mitigation": {
      "type": "string"
    },
    "source": {
      "type": "string"
    }
  },
  "required": [
    "title"
  ],
  "additionalProperties": false
}
⚪incident_log(status, classification, severity, search)

Full incident register with filters (status, classification, severity, search).

Input Schema

{
  "type": "object",
  "properties": {
    "status": {
      "type": "string",
      "enum": [
        "detected",
        "classified",
        "notified",
        "investigating",
        "contained",
        "resolved",
        "closed"
      ]
    },
    "classification": {
      "type": "string",
      "enum": [
        "MAJOR",
        "NON-MAJOR"
      ]
    },
    "severity": {
      "type": "string",
      "enum": [
        "critical",
        "high",
        "medium",
        "low"
      ]
    },
    "search": {
      "type": "string"
    }
  },
  "additionalProperties": false
}
🟢health_check

Server status.

Input Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded12 tools
verifiedversion not recorded12 tools
verifiedversion not recorded12 tools