incidentoracle
IncidentOracle - 12-tool incident management MCP: triage, BaFin DORA reporting, RCA.
사용해야 할까요
품질 및 안전성
발견 사항 (3)
- LOWreclassify에서
- LOWcyber_threat_notify에서
- LOWhealth_check에서
도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.
컨텍스트 비용
이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.
설치
원클릭 설치
`claude_desktop_config.json` 파일에 다음을 추가하세요:
{
"mcpServers": {
"incidentoracle": {
"url": "https://tooloracle.io/incident/mcp/"
}
}
}원격 엔드포인트
https://tooloracle.io/incident/mcp/streamable-http할 수 있는 일
도구 목록
도구 (12)
⚪log_incident(incident_id, title, description, severity, detected_at, ...)
Log a new ICT-related incident. First step in the DORA incident management process (Art. 17).
입력 스키마
{
"type": "object",
"properties": {
"incident_id": {
"type": "string"
},
"title": {
"type": "string"
},
"description": {
"type": "string"
},
"severity": {
"type": "string",
"enum": [
"critical",
"high",
"medium",
"low"
]
},
"detected_at": {
"type": "string",
"description": "ISO datetime of detection"
},
"affected_systems": {
"type": "string"
},
"affected_services": {
"type": "string"
},
"owner": {
"type": "string"
},
"team": {
"type": "string"
},
"bcm_activated": {
"type": "boolean"
},
"clients_affected": {
"type": "number",
"description": "Percentage of clients affected"
},
"duration_hours": {
"type": "number"
},
"geographic_spread": {
"type": "integer"
},
"data_losses": {
"type": "boolean"
},
"economic_impact_eur": {
"type": "number"
},
"criticality_of_services": {
"type": "boolean"
},
"notes": {
"type": "string"
}
},
"required": [
"title"
],
"additionalProperties": false
}⚪classify_incident(incident_id, clients_affected, duration_hours, geographic_spread, data_losses, ...)
Classify an incident against the 6 DORA criteria (RTS 2024/1772). Determines if MAJOR (triggers 4h/72h/1m reporting) or NON-MAJOR.
입력 스키마
{
"type": "object",
"properties": {
"incident_id": {
"type": "string"
},
"clients_affected": {
"type": "number",
"description": "% of clients affected"
},
"duration_hours": {
"type": "number"
},
"geographic_spread": {
"type": "integer",
"description": "Number of EU member states"
},
"data_losses": {
"type": "boolean",
"description": "Confidential/personal data affected?"
},
"economic_impact_eur": {
"type": "number"
},
"criticality_of_services": {
"type": "boolean",
"description": "Critical functions affected?"
}
},
"required": [
"incident_id"
],
"additionalProperties": false
}🟢major_incident_check(clients_affected, duration_hours, geographic_spread, data_losses, economic_impact_eur, ...)
Quick check: would these criteria values classify as a MAJOR incident? No incident record needed — use for pre-assessment.
입력 스키마
{
"type": "object",
"properties": {
"clients_affected": {
"type": "number"
},
"duration_hours": {
"type": "number"
},
"geographic_spread": {
"type": "integer"
},
"data_losses": {
"type": "boolean"
},
"economic_impact_eur": {
"type": "number"
},
"criticality_of_services": {
"type": "boolean"
}
},
"additionalProperties": false
}⚪initial_notification(incident_id, entity_name, entity_lei, authority, affected_states, ...)
Generate the 4h initial notification for a MAJOR incident (ITS 2025/302 Annex I). Must be submitted within 4h of classification, max 24h after detection.
입력 스키마
{
"type": "object",
"properties": {
"incident_id": {
"type": "string"
},
"entity_name": {
"type": "string"
},
"entity_lei": {
"type": "string"
},
"authority": {
"type": "string",
"description": "Competent authority (e.g., BaFin, FMA)"
},
"affected_states": {
"type": "string",
"description": "Comma-separated EU member states"
},
"discovery_method": {
"type": "string",
"enum": [
"internal_monitoring",
"user_report",
"third_party",
"regulator",
"other"
]
}
},
"required": [
"incident_id"
],
"additionalProperties": false
}⚪intermediate_report(incident_id, description_update, root_cause, containment_actions, recovery_status, ...)
Generate the 72h intermediate report for a MAJOR incident (ITS 2025/302). Must include action plan if incident is not yet resolved.
입력 스키마
{
"type": "object",
"properties": {
"incident_id": {
"type": "string"
},
"description_update": {
"type": "string"
},
"root_cause": {
"type": "string"
},
"containment_actions": {
"type": "string"
},
"recovery_status": {
"type": "string"
},
"action_plan": {
"type": "string"
},
"expected_resolution": {
"type": "string"
}
},
"required": [
"incident_id"
],
"additionalProperties": false
}⚪final_report(incident_id, root_cause_final, recovery_actions, lessons_learned, preventive_measures, ...)
Generate the 1-month final report with root cause analysis and lessons learned.
입력 스키마
{
"type": "object",
"properties": {
"incident_id": {
"type": "string"
},
"root_cause_final": {
"type": "string"
},
"recovery_actions": {
"type": "string"
},
"lessons_learned": {
"type": "string"
},
"preventive_measures": {
"type": "string"
},
"client_communication": {
"type": "string"
},
"total_cost_eur": {
"type": "number"
},
"resolved_at": {
"type": "string"
}
},
"required": [
"incident_id"
],
"additionalProperties": false
}⚪deadline_tracker
Track all active MAJOR incident reporting deadlines. Shows overdue and upcoming.
입력 스키마
{
"type": "object",
"properties": {},
"additionalProperties": false
}⚪reclassify(incident_id, new_classification, reason)
Reclassify an incident (MAJOR to NON-MAJOR or vice versa). Competent authority must be notified of reclassification.
입력 스키마
{
"type": "object",
"properties": {
"incident_id": {
"type": "string"
},
"new_classification": {
"type": "string",
"enum": [
"MAJOR",
"NON-MAJOR"
]
},
"reason": {
"type": "string"
}
},
"required": [
"incident_id",
"new_classification"
],
"additionalProperties": false
}⚪incident_stats
Dashboard: total/open/major incidents, overdue deadlines, by severity/status.
입력 스키마
{
"type": "object",
"properties": {},
"additionalProperties": false
}⚪cyber_threat_notify(title, description, threat_type, iocs, ttps, ...)
Voluntary notification of a significant cyber threat (Art. 19(2)). Uses ITS 2025/302 Annex III template.
입력 스키마
{
"type": "object",
"properties": {
"title": {
"type": "string"
},
"description": {
"type": "string"
},
"threat_type": {
"type": "string"
},
"iocs": {
"type": "string"
},
"ttps": {
"type": "string"
},
"affected_systems": {
"type": "string"
},
"mitigation": {
"type": "string"
},
"source": {
"type": "string"
}
},
"required": [
"title"
],
"additionalProperties": false
}⚪incident_log(status, classification, severity, search)
Full incident register with filters (status, classification, severity, search).
입력 스키마
{
"type": "object",
"properties": {
"status": {
"type": "string",
"enum": [
"detected",
"classified",
"notified",
"investigating",
"contained",
"resolved",
"closed"
]
},
"classification": {
"type": "string",
"enum": [
"MAJOR",
"NON-MAJOR"
]
},
"severity": {
"type": "string",
"enum": [
"critical",
"high",
"medium",
"low"
]
},
"search": {
"type": "string"
}
},
"additionalProperties": false
}🟢health_check
Server status.
입력 스키마
{
"type": "object",
"properties": {},
"additionalProperties": false
}커뮤니티
증거