accessoracle

AccessOracle - 10 access control tools: IAM, PAM, recertification, segregation of duties.

我该使用它吗

质量与安全性

B
描述质量
89%
模式完整度
51%
命名质量
82%
投毒风险
100%
权限匹配度
100%
协议合规性
100%

发现(2)

  • LOWTool 'access_gap_analysis' description lacks action verb在 access_gap_analysis 中
  • LOWTool 'health_check' description lacks action verb在 health_check 中

基于对工具定义和协议合规性的自动分析。

上下文开销

~709token 数(工具定义)
~585 B典型响应大小
对注意力有中等影响(占 128k 上下文窗口的 0.55%)

这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。

安装

一键安装

将以下内容添加到你的 `claude_desktop_config.json` 文件中:

{
  "mcpServers": {
    "accessoracle": {
      "url": "https://tooloracle.io/access/mcp/"
    }
  }
}

远程端点

https://tooloracle.io/access/mcp/streamable-http

它能做什么

工具清单

工具(10)

🟢 只读🟡 写入🔴 删除⚪ 未知
⚪register_account(account_id, username, account_type, system, owner, ...)

Register a privileged/service/shared account for IAM tracking.

输入模式

{
  "type": "object",
  "properties": {
    "account_id": {
      "type": "string"
    },
    "username": {
      "type": "string"
    },
    "account_type": {
      "type": "string",
      "enum": [
        "privileged",
        "service",
        "shared",
        "standard",
        "break_glass"
      ]
    },
    "system": {
      "type": "string"
    },
    "owner": {
      "type": "string"
    },
    "department": {
      "type": "string"
    },
    "mfa_method": {
      "type": "string",
      "enum": [
        "totp",
        "fido2",
        "smartcard",
        "push",
        "sms",
        "none"
      ]
    },
    "mfa_enabled": {
      "type": "boolean"
    },
    "is_shared": {
      "type": "boolean"
    },
    "criticality": {
      "type": "string",
      "enum": [
        "critical",
        "important",
        "standard"
      ]
    },
    "remote_access": {
      "type": "boolean"
    },
    "cif_access": {
      "type": "boolean"
    },
    "notes": {
      "type": "string"
    }
  },
  "required": [
    "username",
    "account_type"
  ],
  "additionalProperties": false
}
🟢list_accounts(account_type, system, no_mfa)

List accounts with filters.

输入模式

{
  "type": "object",
  "properties": {
    "account_type": {
      "type": "string"
    },
    "system": {
      "type": "string"
    },
    "no_mfa": {
      "type": "boolean"
    }
  },
  "additionalProperties": false
}
🟢mfa_compliance

Check MFA coverage against DORA Art. 9(4)(d) requirements.

输入模式

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
🟡access_review(add, account_id, reviewer, decision, review_date, ...)

Track access recertification reviews. Set add=true to log a review.

输入模式

{
  "type": "object",
  "properties": {
    "add": {
      "type": "boolean"
    },
    "account_id": {
      "type": "string"
    },
    "reviewer": {
      "type": "string"
    },
    "decision": {
      "type": "string",
      "enum": [
        "confirmed",
        "revoked",
        "modified"
      ]
    },
    "review_date": {
      "type": "string"
    },
    "overdue_days": {
      "type": "integer"
    },
    "notes": {
      "type": "string"
    }
  },
  "additionalProperties": false
}
⚪sod_matrix

Detect Segregation of Duties conflicts across accounts.

输入模式

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
⚪privileged_audit

Privileged account audit — MFA, shared, review status.

输入模式

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
🟡jml_process(log_event, event_type, username, date, actions_taken, ...)

Joiner/Mover/Leaver process tracking. Set log_event=true to log.

输入模式

{
  "type": "object",
  "properties": {
    "log_event": {
      "type": "boolean"
    },
    "event_type": {
      "type": "string",
      "enum": [
        "joiner",
        "mover",
        "leaver"
      ]
    },
    "username": {
      "type": "string"
    },
    "date": {
      "type": "string"
    },
    "actions_taken": {
      "type": "string"
    },
    "verified_by": {
      "type": "string"
    }
  },
  "additionalProperties": false
}
🟡break_glass_log(log, account_id, reason, used_by, approved_by, ...)

Emergency access logging. Set log=true to record usage.

输入模式

{
  "type": "object",
  "properties": {
    "log": {
      "type": "boolean"
    },
    "account_id": {
      "type": "string"
    },
    "reason": {
      "type": "string"
    },
    "used_by": {
      "type": "string"
    },
    "approved_by": {
      "type": "string"
    },
    "duration_minutes": {
      "type": "integer"
    }
  },
  "additionalProperties": false
}
⚪access_gap_analysis

Gap analysis against RTS Art. 21 requirements.

输入模式

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
🟢health_check

Server status.

输入模式

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

社区

评价此服务器

证据

最近观测

已验证未记录版本10 个工具
已验证未记录版本10 个工具
已验证未记录版本10 个工具