dora
DORAOracle — 15 tools for DORA Art.5-32: risk register, ICT incidents, TLPT, third-party.
¿Debería usar esto?
Calidad y seguridad
Hallazgos (1)
- LOWen kev_list
Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.
Costo de contexto
Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.
Instalar
Instalación con un clic
Agrega esto a tu archivo `claude_desktop_config.json`:
{
"mcpServers": {
"dora": {
"url": "https://tooloracle.io/dora/mcp/"
}
}
}Puntos de conexión remotos
https://tooloracle.io/dora/mcp/streamable-httpQué puede hacer
Inventario de herramientas
Herramientas (15)
🟢cve_search(keyword, vendor, severity, days, limit)
Search CVEs by keyword, vendor or product. Returns CVSS scores, attack vectors, DORA pillar mapping.
Esquema de entrada
{
"type": "object",
"properties": {
"keyword": {
"type": "string",
"description": "Search keyword e.g. 'authentication bypass', 'remote code execution'"
},
"vendor": {
"type": "string",
"description": "Vendor/product e.g. 'SAP', 'Cisco', 'Microsoft Exchange'"
},
"severity": {
"type": "string",
"description": "CVSS severity: CRITICAL, HIGH, MEDIUM, LOW",
"enum": [
"CRITICAL",
"HIGH",
"MEDIUM",
"LOW"
]
},
"days": {
"type": "integer",
"description": "Published within last N days (default: 30)",
"default": 30
},
"limit": {
"type": "integer",
"description": "Max results 1-20 (default: 10)",
"default": 10,
"minimum": 1,
"maximum": 20
}
},
"additionalProperties": false
}⚪cve_latest(severity, days, limit, banking_only)
Latest critical CVEs — daily DORA ICT risk briefing. Filter by severity and banking relevance.
Esquema de entrada
{
"type": "object",
"properties": {
"severity": {
"type": "string",
"description": "CRITICAL, HIGH, MEDIUM (default: CRITICAL)"
},
"days": {
"type": "integer",
"description": "Last N days (default: 7)",
"default": 7
},
"limit": {
"type": "integer",
"description": "Max results 1-20 (default: 10)",
"default": 10,
"minimum": 1,
"maximum": 20
},
"banking_only": {
"type": "boolean",
"description": "Filter to banking-relevant vendors only (default: false)"
}
},
"additionalProperties": false
}🟡kev_list(vendor, days, limit, overdue)
CISA Known Exploited Vulnerabilities — actively exploited CVEs with patch deadlines. DORA Art. 9 patch compliance.
Esquema de entrada
{
"type": "object",
"properties": {
"vendor": {
"type": "string",
"description": "Filter by vendor e.g. 'Cisco', 'Microsoft', 'SAP'"
},
"days": {
"type": "integer",
"description": "Added to KEV within last N days (default: 30)",
"default": 30
},
"limit": {
"type": "integer",
"description": "Max results 1-50 (default: 15)",
"default": 15,
"minimum": 1,
"maximum": 50
},
"overdue": {
"type": "boolean",
"description": "Show only overdue patches (default: false)"
}
},
"additionalProperties": false
}🟢kev_check(cve_id)
Check if a specific CVE is in CISA KEV (actively exploited in the wild). Returns DORA incident classification guidance.
Esquema de entrada
{
"type": "object",
"properties": {
"cve_id": {
"type": "string",
"description": "CVE ID to check e.g. 'CVE-2021-44228' (Log4Shell)"
}
},
"additionalProperties": false
}⚪cert_advisories(keyword, limit)
CERT-Bund security advisories — authoritative DE source for ICT threats. DORA Art. 17 threat monitoring.
Esquema de entrada
{
"type": "object",
"properties": {
"keyword": {
"type": "string",
"description": "Filter by keyword e.g. 'Windows', 'Apache', 'Cisco'"
},
"limit": {
"type": "integer",
"description": "Max results 1-30 (default: 15)",
"default": 15,
"minimum": 1,
"maximum": 30
}
},
"additionalProperties": false
}🟢breach_check(domain, limit)
HaveIBeenPwned breach database — check domain/company breach exposure. DORA Art. 18 incident assessment.
Esquema de entrada
{
"type": "object",
"properties": {
"domain": {
"type": "string",
"description": "Company domain e.g. 'meinbank.de' (optional — omit for latest breaches)"
},
"limit": {
"type": "integer",
"description": "Max results 1-50 (default: 20)",
"default": 20,
"minimum": 1,
"maximum": 50
}
},
"additionalProperties": false
}⚪threat_actors(malware, status, limit)
Feodo Tracker: live C2 botnet servers (Emotet, QakBot, etc.). Actionable IP blocklist for DORA Art. 9.
Esquema de entrada
{
"type": "object",
"properties": {
"malware": {
"type": "string",
"description": "Filter by malware family: Emotet, QakBot, Dridex, TrickBot"
},
"status": {
"type": "string",
"description": "Filter by status: online, offline"
},
"limit": {
"type": "integer",
"description": "Max results 1-100 (default: 20)",
"default": 20,
"minimum": 1,
"maximum": 100
}
},
"additionalProperties": false
}⚪incident_timeline(incident_time, classification, sector)
Generate a DORA Art. 19-aligned ICT incident reporting timeline with the regulatory deadline structure. Supports - does not constitute - compliant reporting.
Esquema de entrada
{
"type": "object",
"properties": {
"incident_time": {
"type": "string",
"description": "ISO timestamp of incident e.g. '2026-03-19T14:00:00Z' (default: now)"
},
"classification": {
"type": "string",
"description": "Incident class: major, significant, minor (default: major)"
},
"sector": {
"type": "string",
"description": "Sector: banking, insurance, payment (default: banking)"
}
},
"additionalProperties": false
}⚪mitre_techniques(tactic, keyword, limit)
MITRE ATT&CK techniques for DORA TLPT / TIBER-EU penetration testing. Maps to DORA Art. 26.
Esquema de entrada
{
"type": "object",
"properties": {
"tactic": {
"type": "string",
"description": "Filter by tactic: Initial Access, Lateral Movement, Impact, Persistence, etc."
},
"keyword": {
"type": "string",
"description": "Search keyword e.g. 'ransomware', 'phishing', 'credential'"
},
"limit": {
"type": "integer",
"description": "Max results 1-20 (default: 10)",
"default": 10,
"minimum": 1,
"maximum": 20
}
},
"additionalProperties": false
}⚪tlpt_scenarios(sector, focus)
TIBER-EU threat scenarios for DORA resilience testing planning. Banking-specific attack simulations.
Esquema de entrada
{
"type": "object",
"properties": {
"sector": {
"type": "string",
"description": "Sector: banking (default: banking)"
},
"focus": {
"type": "string",
"description": "Focus area: swift, ransomware, insider, ddos, cloud (default: all)"
}
},
"additionalProperties": false
}⚪cloud_status(provider, limit)
Live status of AWS, GCP, Azure cloud providers. DORA Art. 28 third-party ICT risk monitoring.
Esquema de entrada
{
"type": "object",
"properties": {
"provider": {
"type": "string",
"description": "Provider: aws, gcp, azure, all (default: all)"
},
"limit": {
"type": "integer",
"description": "Max incidents per provider (default: 10)",
"default": 10
}
},
"additionalProperties": false
}⚪provider_risk(provider)
DORA Art. 28 ICT third-party risk assessment: CVE history, news, GLEIF registration, contractual checklist.
Esquema de entrada
{
"type": "object",
"properties": {
"provider": {
"type": "string",
"description": "Provider name e.g. 'SAP', 'Salesforce', 'AWS', 'Temenos'"
}
},
"additionalProperties": false
}⚪dora_news(topic, lang, limit)
EBA/DORA regulatory news for banks. Topics: general, eba, incident, third_party, testing, guidelines, bafin, swift.
Esquema de entrada
{
"type": "object",
"properties": {
"topic": {
"type": "string",
"description": "Topic: general, eba, incident, third_party, testing, guidelines, bafin, swift, fintech"
},
"lang": {
"type": "string",
"description": "Language: en or de (default: en)"
},
"limit": {
"type": "integer",
"description": "Max articles 1-20 (default: 10)",
"default": 10,
"minimum": 1,
"maximum": 20
}
},
"additionalProperties": false
}⚪dora_calendar
DORA compliance milestones and upcoming deadlines for financial institutions. All Art. references included.
Esquema de entrada
{
"type": "object",
"properties": {},
"additionalProperties": false
}🟢health_check
DORAOracle server status and all backend connectivity checks.
Esquema de entrada
{
"type": "object",
"properties": {},
"additionalProperties": false
}Comunidad
Evidencia