incidentoracle
IncidentOracle - 12-tool incident management MCP: triage, BaFin DORA reporting, RCA.
我该使用它吗
质量与安全性
发现(3)
- LOW在 reclassify 中
- LOW在 cyber_threat_notify 中
- LOW在 health_check 中
基于对工具定义和协议合规性的自动分析。
上下文开销
这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。
安装
一键安装
将以下内容添加到你的 `claude_desktop_config.json` 文件中:
{
"mcpServers": {
"incidentoracle": {
"url": "https://tooloracle.io/incident/mcp/"
}
}
}远程端点
https://tooloracle.io/incident/mcp/streamable-http它能做什么
工具清单
工具(12)
⚪log_incident(incident_id, title, description, severity, detected_at, ...)
Log a new ICT-related incident. First step in the DORA incident management process (Art. 17).
输入模式
{
"type": "object",
"properties": {
"incident_id": {
"type": "string"
},
"title": {
"type": "string"
},
"description": {
"type": "string"
},
"severity": {
"type": "string",
"enum": [
"critical",
"high",
"medium",
"low"
]
},
"detected_at": {
"type": "string",
"description": "ISO datetime of detection"
},
"affected_systems": {
"type": "string"
},
"affected_services": {
"type": "string"
},
"owner": {
"type": "string"
},
"team": {
"type": "string"
},
"bcm_activated": {
"type": "boolean"
},
"clients_affected": {
"type": "number",
"description": "Percentage of clients affected"
},
"duration_hours": {
"type": "number"
},
"geographic_spread": {
"type": "integer"
},
"data_losses": {
"type": "boolean"
},
"economic_impact_eur": {
"type": "number"
},
"criticality_of_services": {
"type": "boolean"
},
"notes": {
"type": "string"
}
},
"required": [
"title"
],
"additionalProperties": false
}⚪classify_incident(incident_id, clients_affected, duration_hours, geographic_spread, data_losses, ...)
Classify an incident against the 6 DORA criteria (RTS 2024/1772). Determines if MAJOR (triggers 4h/72h/1m reporting) or NON-MAJOR.
输入模式
{
"type": "object",
"properties": {
"incident_id": {
"type": "string"
},
"clients_affected": {
"type": "number",
"description": "% of clients affected"
},
"duration_hours": {
"type": "number"
},
"geographic_spread": {
"type": "integer",
"description": "Number of EU member states"
},
"data_losses": {
"type": "boolean",
"description": "Confidential/personal data affected?"
},
"economic_impact_eur": {
"type": "number"
},
"criticality_of_services": {
"type": "boolean",
"description": "Critical functions affected?"
}
},
"required": [
"incident_id"
],
"additionalProperties": false
}🟢major_incident_check(clients_affected, duration_hours, geographic_spread, data_losses, economic_impact_eur, ...)
Quick check: would these criteria values classify as a MAJOR incident? No incident record needed — use for pre-assessment.
输入模式
{
"type": "object",
"properties": {
"clients_affected": {
"type": "number"
},
"duration_hours": {
"type": "number"
},
"geographic_spread": {
"type": "integer"
},
"data_losses": {
"type": "boolean"
},
"economic_impact_eur": {
"type": "number"
},
"criticality_of_services": {
"type": "boolean"
}
},
"additionalProperties": false
}⚪initial_notification(incident_id, entity_name, entity_lei, authority, affected_states, ...)
Generate the 4h initial notification for a MAJOR incident (ITS 2025/302 Annex I). Must be submitted within 4h of classification, max 24h after detection.
输入模式
{
"type": "object",
"properties": {
"incident_id": {
"type": "string"
},
"entity_name": {
"type": "string"
},
"entity_lei": {
"type": "string"
},
"authority": {
"type": "string",
"description": "Competent authority (e.g., BaFin, FMA)"
},
"affected_states": {
"type": "string",
"description": "Comma-separated EU member states"
},
"discovery_method": {
"type": "string",
"enum": [
"internal_monitoring",
"user_report",
"third_party",
"regulator",
"other"
]
}
},
"required": [
"incident_id"
],
"additionalProperties": false
}⚪intermediate_report(incident_id, description_update, root_cause, containment_actions, recovery_status, ...)
Generate the 72h intermediate report for a MAJOR incident (ITS 2025/302). Must include action plan if incident is not yet resolved.
输入模式
{
"type": "object",
"properties": {
"incident_id": {
"type": "string"
},
"description_update": {
"type": "string"
},
"root_cause": {
"type": "string"
},
"containment_actions": {
"type": "string"
},
"recovery_status": {
"type": "string"
},
"action_plan": {
"type": "string"
},
"expected_resolution": {
"type": "string"
}
},
"required": [
"incident_id"
],
"additionalProperties": false
}⚪final_report(incident_id, root_cause_final, recovery_actions, lessons_learned, preventive_measures, ...)
Generate the 1-month final report with root cause analysis and lessons learned.
输入模式
{
"type": "object",
"properties": {
"incident_id": {
"type": "string"
},
"root_cause_final": {
"type": "string"
},
"recovery_actions": {
"type": "string"
},
"lessons_learned": {
"type": "string"
},
"preventive_measures": {
"type": "string"
},
"client_communication": {
"type": "string"
},
"total_cost_eur": {
"type": "number"
},
"resolved_at": {
"type": "string"
}
},
"required": [
"incident_id"
],
"additionalProperties": false
}⚪deadline_tracker
Track all active MAJOR incident reporting deadlines. Shows overdue and upcoming.
输入模式
{
"type": "object",
"properties": {},
"additionalProperties": false
}⚪reclassify(incident_id, new_classification, reason)
Reclassify an incident (MAJOR to NON-MAJOR or vice versa). Competent authority must be notified of reclassification.
输入模式
{
"type": "object",
"properties": {
"incident_id": {
"type": "string"
},
"new_classification": {
"type": "string",
"enum": [
"MAJOR",
"NON-MAJOR"
]
},
"reason": {
"type": "string"
}
},
"required": [
"incident_id",
"new_classification"
],
"additionalProperties": false
}⚪incident_stats
Dashboard: total/open/major incidents, overdue deadlines, by severity/status.
输入模式
{
"type": "object",
"properties": {},
"additionalProperties": false
}⚪cyber_threat_notify(title, description, threat_type, iocs, ttps, ...)
Voluntary notification of a significant cyber threat (Art. 19(2)). Uses ITS 2025/302 Annex III template.
输入模式
{
"type": "object",
"properties": {
"title": {
"type": "string"
},
"description": {
"type": "string"
},
"threat_type": {
"type": "string"
},
"iocs": {
"type": "string"
},
"ttps": {
"type": "string"
},
"affected_systems": {
"type": "string"
},
"mitigation": {
"type": "string"
},
"source": {
"type": "string"
}
},
"required": [
"title"
],
"additionalProperties": false
}⚪incident_log(status, classification, severity, search)
Full incident register with filters (status, classification, severity, search).
输入模式
{
"type": "object",
"properties": {
"status": {
"type": "string",
"enum": [
"detected",
"classified",
"notified",
"investigating",
"contained",
"resolved",
"closed"
]
},
"classification": {
"type": "string",
"enum": [
"MAJOR",
"NON-MAJOR"
]
},
"severity": {
"type": "string",
"enum": [
"critical",
"high",
"medium",
"low"
]
},
"search": {
"type": "string"
}
},
"additionalProperties": false
}🟢health_check
Server status.
输入模式
{
"type": "object",
"properties": {},
"additionalProperties": false
}社区
证据