incidentoracle

IncidentOracle - 12-tool incident management MCP: triage, BaFin DORA reporting, RCA.

我该使用它吗

质量与安全性

B
描述质量
86%
模式完整度
68%
命名质量
82%
投毒风险
100%
权限匹配度
100%
协议合规性
100%

发现(3)

  • LOWTool 'reclassify' description lacks action verb在 reclassify 中
  • LOWTool 'cyber_threat_notify' description lacks action verb在 cyber_threat_notify 中
  • LOWTool 'health_check' description lacks action verb在 health_check 中

基于对工具定义和协议合规性的自动分析。

上下文开销

~1,297token 数(工具定义)
~966 B典型响应大小
对注意力有中等影响(占 128k 上下文窗口的 1.01%)

这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。

安装

一键安装

将以下内容添加到你的 `claude_desktop_config.json` 文件中:

{
  "mcpServers": {
    "incidentoracle": {
      "url": "https://tooloracle.io/incident/mcp/"
    }
  }
}

远程端点

https://tooloracle.io/incident/mcp/streamable-http

它能做什么

工具清单

工具(12)

🟢 只读🟡 写入🔴 删除⚪ 未知
⚪log_incident(incident_id, title, description, severity, detected_at, ...)

Log a new ICT-related incident. First step in the DORA incident management process (Art. 17).

输入模式

{
  "type": "object",
  "properties": {
    "incident_id": {
      "type": "string"
    },
    "title": {
      "type": "string"
    },
    "description": {
      "type": "string"
    },
    "severity": {
      "type": "string",
      "enum": [
        "critical",
        "high",
        "medium",
        "low"
      ]
    },
    "detected_at": {
      "type": "string",
      "description": "ISO datetime of detection"
    },
    "affected_systems": {
      "type": "string"
    },
    "affected_services": {
      "type": "string"
    },
    "owner": {
      "type": "string"
    },
    "team": {
      "type": "string"
    },
    "bcm_activated": {
      "type": "boolean"
    },
    "clients_affected": {
      "type": "number",
      "description": "Percentage of clients affected"
    },
    "duration_hours": {
      "type": "number"
    },
    "geographic_spread": {
      "type": "integer"
    },
    "data_losses": {
      "type": "boolean"
    },
    "economic_impact_eur": {
      "type": "number"
    },
    "criticality_of_services": {
      "type": "boolean"
    },
    "notes": {
      "type": "string"
    }
  },
  "required": [
    "title"
  ],
  "additionalProperties": false
}
⚪classify_incident(incident_id, clients_affected, duration_hours, geographic_spread, data_losses, ...)

Classify an incident against the 6 DORA criteria (RTS 2024/1772). Determines if MAJOR (triggers 4h/72h/1m reporting) or NON-MAJOR.

输入模式

{
  "type": "object",
  "properties": {
    "incident_id": {
      "type": "string"
    },
    "clients_affected": {
      "type": "number",
      "description": "% of clients affected"
    },
    "duration_hours": {
      "type": "number"
    },
    "geographic_spread": {
      "type": "integer",
      "description": "Number of EU member states"
    },
    "data_losses": {
      "type": "boolean",
      "description": "Confidential/personal data affected?"
    },
    "economic_impact_eur": {
      "type": "number"
    },
    "criticality_of_services": {
      "type": "boolean",
      "description": "Critical functions affected?"
    }
  },
  "required": [
    "incident_id"
  ],
  "additionalProperties": false
}
🟢major_incident_check(clients_affected, duration_hours, geographic_spread, data_losses, economic_impact_eur, ...)

Quick check: would these criteria values classify as a MAJOR incident? No incident record needed — use for pre-assessment.

输入模式

{
  "type": "object",
  "properties": {
    "clients_affected": {
      "type": "number"
    },
    "duration_hours": {
      "type": "number"
    },
    "geographic_spread": {
      "type": "integer"
    },
    "data_losses": {
      "type": "boolean"
    },
    "economic_impact_eur": {
      "type": "number"
    },
    "criticality_of_services": {
      "type": "boolean"
    }
  },
  "additionalProperties": false
}
⚪initial_notification(incident_id, entity_name, entity_lei, authority, affected_states, ...)

Generate the 4h initial notification for a MAJOR incident (ITS 2025/302 Annex I). Must be submitted within 4h of classification, max 24h after detection.

输入模式

{
  "type": "object",
  "properties": {
    "incident_id": {
      "type": "string"
    },
    "entity_name": {
      "type": "string"
    },
    "entity_lei": {
      "type": "string"
    },
    "authority": {
      "type": "string",
      "description": "Competent authority (e.g., BaFin, FMA)"
    },
    "affected_states": {
      "type": "string",
      "description": "Comma-separated EU member states"
    },
    "discovery_method": {
      "type": "string",
      "enum": [
        "internal_monitoring",
        "user_report",
        "third_party",
        "regulator",
        "other"
      ]
    }
  },
  "required": [
    "incident_id"
  ],
  "additionalProperties": false
}
⚪intermediate_report(incident_id, description_update, root_cause, containment_actions, recovery_status, ...)

Generate the 72h intermediate report for a MAJOR incident (ITS 2025/302). Must include action plan if incident is not yet resolved.

输入模式

{
  "type": "object",
  "properties": {
    "incident_id": {
      "type": "string"
    },
    "description_update": {
      "type": "string"
    },
    "root_cause": {
      "type": "string"
    },
    "containment_actions": {
      "type": "string"
    },
    "recovery_status": {
      "type": "string"
    },
    "action_plan": {
      "type": "string"
    },
    "expected_resolution": {
      "type": "string"
    }
  },
  "required": [
    "incident_id"
  ],
  "additionalProperties": false
}
⚪final_report(incident_id, root_cause_final, recovery_actions, lessons_learned, preventive_measures, ...)

Generate the 1-month final report with root cause analysis and lessons learned.

输入模式

{
  "type": "object",
  "properties": {
    "incident_id": {
      "type": "string"
    },
    "root_cause_final": {
      "type": "string"
    },
    "recovery_actions": {
      "type": "string"
    },
    "lessons_learned": {
      "type": "string"
    },
    "preventive_measures": {
      "type": "string"
    },
    "client_communication": {
      "type": "string"
    },
    "total_cost_eur": {
      "type": "number"
    },
    "resolved_at": {
      "type": "string"
    }
  },
  "required": [
    "incident_id"
  ],
  "additionalProperties": false
}
⚪deadline_tracker

Track all active MAJOR incident reporting deadlines. Shows overdue and upcoming.

输入模式

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
⚪reclassify(incident_id, new_classification, reason)

Reclassify an incident (MAJOR to NON-MAJOR or vice versa). Competent authority must be notified of reclassification.

输入模式

{
  "type": "object",
  "properties": {
    "incident_id": {
      "type": "string"
    },
    "new_classification": {
      "type": "string",
      "enum": [
        "MAJOR",
        "NON-MAJOR"
      ]
    },
    "reason": {
      "type": "string"
    }
  },
  "required": [
    "incident_id",
    "new_classification"
  ],
  "additionalProperties": false
}
⚪incident_stats

Dashboard: total/open/major incidents, overdue deadlines, by severity/status.

输入模式

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
⚪cyber_threat_notify(title, description, threat_type, iocs, ttps, ...)

Voluntary notification of a significant cyber threat (Art. 19(2)). Uses ITS 2025/302 Annex III template.

输入模式

{
  "type": "object",
  "properties": {
    "title": {
      "type": "string"
    },
    "description": {
      "type": "string"
    },
    "threat_type": {
      "type": "string"
    },
    "iocs": {
      "type": "string"
    },
    "ttps": {
      "type": "string"
    },
    "affected_systems": {
      "type": "string"
    },
    "mitigation": {
      "type": "string"
    },
    "source": {
      "type": "string"
    }
  },
  "required": [
    "title"
  ],
  "additionalProperties": false
}
⚪incident_log(status, classification, severity, search)

Full incident register with filters (status, classification, severity, search).

输入模式

{
  "type": "object",
  "properties": {
    "status": {
      "type": "string",
      "enum": [
        "detected",
        "classified",
        "notified",
        "investigating",
        "contained",
        "resolved",
        "closed"
      ]
    },
    "classification": {
      "type": "string",
      "enum": [
        "MAJOR",
        "NON-MAJOR"
      ]
    },
    "severity": {
      "type": "string",
      "enum": [
        "critical",
        "high",
        "medium",
        "low"
      ]
    },
    "search": {
      "type": "string"
    }
  },
  "additionalProperties": false
}
🟢health_check

Server status.

输入模式

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

社区

评价此服务器

证据

最近观测

已验证未记录版本12 个工具
已验证未记录版本12 个工具
已验证未记录版本12 个工具