dora

DORAOracle — 15 tools for DORA Art.5-32: risk register, ICT incidents, TLPT, third-party.

使うべきか

品質と安全性

B
説明の品質
86%
スキーマの完全性
82%
命名の品質
80%
ポイズニングのリスク
100%
権限の一致
100%
プロトコルへの準拠
100%

検出事項(1)

  • LOWTool 'kev_list' description lacks action verbkev_list 内

ツール定義とプロトコルへの準拠に関する自動分析に基づいています。

コンテキストコスト

~1,722トークン数(ツール定義)
~906 B一般的なレスポンスサイズ
注意への影響は中程度(128k コンテキストの 1.35%)

これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。

インストール

ワンクリックインストール

これを `claude_desktop_config.json` ファイルに追加してください:

{
  "mcpServers": {
    "dora": {
      "url": "https://tooloracle.io/dora/mcp/"
    }
  }
}

リモートエンドポイント

https://tooloracle.io/dora/mcp/streamable-http

できること

ツール一覧

ツール(15)

🟢 読み取り専用🟡 書き込み🔴 削除⚪ 不明
🟢cve_search(keyword, vendor, severity, days, limit)

Search CVEs by keyword, vendor or product. Returns CVSS scores, attack vectors, DORA pillar mapping.

入力スキーマ

{
  "type": "object",
  "properties": {
    "keyword": {
      "type": "string",
      "description": "Search keyword e.g. 'authentication bypass', 'remote code execution'"
    },
    "vendor": {
      "type": "string",
      "description": "Vendor/product e.g. 'SAP', 'Cisco', 'Microsoft Exchange'"
    },
    "severity": {
      "type": "string",
      "description": "CVSS severity: CRITICAL, HIGH, MEDIUM, LOW",
      "enum": [
        "CRITICAL",
        "HIGH",
        "MEDIUM",
        "LOW"
      ]
    },
    "days": {
      "type": "integer",
      "description": "Published within last N days (default: 30)",
      "default": 30
    },
    "limit": {
      "type": "integer",
      "description": "Max results 1-20 (default: 10)",
      "default": 10,
      "minimum": 1,
      "maximum": 20
    }
  },
  "additionalProperties": false
}
⚪cve_latest(severity, days, limit, banking_only)

Latest critical CVEs — daily DORA ICT risk briefing. Filter by severity and banking relevance.

入力スキーマ

{
  "type": "object",
  "properties": {
    "severity": {
      "type": "string",
      "description": "CRITICAL, HIGH, MEDIUM (default: CRITICAL)"
    },
    "days": {
      "type": "integer",
      "description": "Last N days (default: 7)",
      "default": 7
    },
    "limit": {
      "type": "integer",
      "description": "Max results 1-20 (default: 10)",
      "default": 10,
      "minimum": 1,
      "maximum": 20
    },
    "banking_only": {
      "type": "boolean",
      "description": "Filter to banking-relevant vendors only (default: false)"
    }
  },
  "additionalProperties": false
}
🟡kev_list(vendor, days, limit, overdue)

CISA Known Exploited Vulnerabilities — actively exploited CVEs with patch deadlines. DORA Art. 9 patch compliance.

入力スキーマ

{
  "type": "object",
  "properties": {
    "vendor": {
      "type": "string",
      "description": "Filter by vendor e.g. 'Cisco', 'Microsoft', 'SAP'"
    },
    "days": {
      "type": "integer",
      "description": "Added to KEV within last N days (default: 30)",
      "default": 30
    },
    "limit": {
      "type": "integer",
      "description": "Max results 1-50 (default: 15)",
      "default": 15,
      "minimum": 1,
      "maximum": 50
    },
    "overdue": {
      "type": "boolean",
      "description": "Show only overdue patches (default: false)"
    }
  },
  "additionalProperties": false
}
🟢kev_check(cve_id)

Check if a specific CVE is in CISA KEV (actively exploited in the wild). Returns DORA incident classification guidance.

入力スキーマ

{
  "type": "object",
  "properties": {
    "cve_id": {
      "type": "string",
      "description": "CVE ID to check e.g. 'CVE-2021-44228' (Log4Shell)"
    }
  },
  "additionalProperties": false
}
⚪cert_advisories(keyword, limit)

CERT-Bund security advisories — authoritative DE source for ICT threats. DORA Art. 17 threat monitoring.

入力スキーマ

{
  "type": "object",
  "properties": {
    "keyword": {
      "type": "string",
      "description": "Filter by keyword e.g. 'Windows', 'Apache', 'Cisco'"
    },
    "limit": {
      "type": "integer",
      "description": "Max results 1-30 (default: 15)",
      "default": 15,
      "minimum": 1,
      "maximum": 30
    }
  },
  "additionalProperties": false
}
🟢breach_check(domain, limit)

HaveIBeenPwned breach database — check domain/company breach exposure. DORA Art. 18 incident assessment.

入力スキーマ

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Company domain e.g. 'meinbank.de' (optional — omit for latest breaches)"
    },
    "limit": {
      "type": "integer",
      "description": "Max results 1-50 (default: 20)",
      "default": 20,
      "minimum": 1,
      "maximum": 50
    }
  },
  "additionalProperties": false
}
⚪threat_actors(malware, status, limit)

Feodo Tracker: live C2 botnet servers (Emotet, QakBot, etc.). Actionable IP blocklist for DORA Art. 9.

入力スキーマ

{
  "type": "object",
  "properties": {
    "malware": {
      "type": "string",
      "description": "Filter by malware family: Emotet, QakBot, Dridex, TrickBot"
    },
    "status": {
      "type": "string",
      "description": "Filter by status: online, offline"
    },
    "limit": {
      "type": "integer",
      "description": "Max results 1-100 (default: 20)",
      "default": 20,
      "minimum": 1,
      "maximum": 100
    }
  },
  "additionalProperties": false
}
⚪incident_timeline(incident_time, classification, sector)

Generate a DORA Art. 19-aligned ICT incident reporting timeline with the regulatory deadline structure. Supports - does not constitute - compliant reporting.

入力スキーマ

{
  "type": "object",
  "properties": {
    "incident_time": {
      "type": "string",
      "description": "ISO timestamp of incident e.g. '2026-03-19T14:00:00Z' (default: now)"
    },
    "classification": {
      "type": "string",
      "description": "Incident class: major, significant, minor (default: major)"
    },
    "sector": {
      "type": "string",
      "description": "Sector: banking, insurance, payment (default: banking)"
    }
  },
  "additionalProperties": false
}
⚪mitre_techniques(tactic, keyword, limit)

MITRE ATT&CK techniques for DORA TLPT / TIBER-EU penetration testing. Maps to DORA Art. 26.

入力スキーマ

{
  "type": "object",
  "properties": {
    "tactic": {
      "type": "string",
      "description": "Filter by tactic: Initial Access, Lateral Movement, Impact, Persistence, etc."
    },
    "keyword": {
      "type": "string",
      "description": "Search keyword e.g. 'ransomware', 'phishing', 'credential'"
    },
    "limit": {
      "type": "integer",
      "description": "Max results 1-20 (default: 10)",
      "default": 10,
      "minimum": 1,
      "maximum": 20
    }
  },
  "additionalProperties": false
}
⚪tlpt_scenarios(sector, focus)

TIBER-EU threat scenarios for DORA resilience testing planning. Banking-specific attack simulations.

入力スキーマ

{
  "type": "object",
  "properties": {
    "sector": {
      "type": "string",
      "description": "Sector: banking (default: banking)"
    },
    "focus": {
      "type": "string",
      "description": "Focus area: swift, ransomware, insider, ddos, cloud (default: all)"
    }
  },
  "additionalProperties": false
}
⚪cloud_status(provider, limit)

Live status of AWS, GCP, Azure cloud providers. DORA Art. 28 third-party ICT risk monitoring.

入力スキーマ

{
  "type": "object",
  "properties": {
    "provider": {
      "type": "string",
      "description": "Provider: aws, gcp, azure, all (default: all)"
    },
    "limit": {
      "type": "integer",
      "description": "Max incidents per provider (default: 10)",
      "default": 10
    }
  },
  "additionalProperties": false
}
⚪provider_risk(provider)

DORA Art. 28 ICT third-party risk assessment: CVE history, news, GLEIF registration, contractual checklist.

入力スキーマ

{
  "type": "object",
  "properties": {
    "provider": {
      "type": "string",
      "description": "Provider name e.g. 'SAP', 'Salesforce', 'AWS', 'Temenos'"
    }
  },
  "additionalProperties": false
}
⚪dora_news(topic, lang, limit)

EBA/DORA regulatory news for banks. Topics: general, eba, incident, third_party, testing, guidelines, bafin, swift.

入力スキーマ

{
  "type": "object",
  "properties": {
    "topic": {
      "type": "string",
      "description": "Topic: general, eba, incident, third_party, testing, guidelines, bafin, swift, fintech"
    },
    "lang": {
      "type": "string",
      "description": "Language: en or de (default: en)"
    },
    "limit": {
      "type": "integer",
      "description": "Max articles 1-20 (default: 10)",
      "default": 10,
      "minimum": 1,
      "maximum": 20
    }
  },
  "additionalProperties": false
}
⚪dora_calendar

DORA compliance milestones and upcoming deadlines for financial institutions. All Art. references included.

入力スキーマ

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
🟢health_check

DORAOracle server status and all backend connectivity checks.

入力スキーマ

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

コミュニティ

このサーバーを評価する

エビデンス

最近の観測

検証済みバージョンは記録されていませんツール 15 件
検証済みバージョンは記録されていませんツール 15 件