dora

DORAOracle — 15 tools for DORA Art.5-32: risk register, ICT incidents, TLPT, third-party.

我該用這個嗎

品質與安全性

B
說明品質
86%
結構描述完整度
82%
命名品質
80%
汙染風險
100%
權限相符程度
100%
協定合規性
100%

發現項目(1)

  • LOWTool 'kev_list' description lacks action verb在 kev_list 中

根據工具定義與協定合規性的自動化分析。

上下文成本

~1,722Token(工具定義)
~906 B典型回應大小
中等的注意力影響(128k 上下文的 1.35%)

這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。

安裝

一鍵安裝

將以下內容加入你的 `claude_desktop_config.json` 檔案:

{
  "mcpServers": {
    "dora": {
      "url": "https://tooloracle.io/dora/mcp/"
    }
  }
}

遠端端點

https://tooloracle.io/dora/mcp/streamable-http

它能做什麼

工具清單

工具(15)

🟢 唯讀🟡 寫入🔴 刪除⚪ 未知
🟢cve_search(keyword, vendor, severity, days, limit)

Search CVEs by keyword, vendor or product. Returns CVSS scores, attack vectors, DORA pillar mapping.

輸入結構描述

{
  "type": "object",
  "properties": {
    "keyword": {
      "type": "string",
      "description": "Search keyword e.g. 'authentication bypass', 'remote code execution'"
    },
    "vendor": {
      "type": "string",
      "description": "Vendor/product e.g. 'SAP', 'Cisco', 'Microsoft Exchange'"
    },
    "severity": {
      "type": "string",
      "description": "CVSS severity: CRITICAL, HIGH, MEDIUM, LOW",
      "enum": [
        "CRITICAL",
        "HIGH",
        "MEDIUM",
        "LOW"
      ]
    },
    "days": {
      "type": "integer",
      "description": "Published within last N days (default: 30)",
      "default": 30
    },
    "limit": {
      "type": "integer",
      "description": "Max results 1-20 (default: 10)",
      "default": 10,
      "minimum": 1,
      "maximum": 20
    }
  },
  "additionalProperties": false
}
⚪cve_latest(severity, days, limit, banking_only)

Latest critical CVEs — daily DORA ICT risk briefing. Filter by severity and banking relevance.

輸入結構描述

{
  "type": "object",
  "properties": {
    "severity": {
      "type": "string",
      "description": "CRITICAL, HIGH, MEDIUM (default: CRITICAL)"
    },
    "days": {
      "type": "integer",
      "description": "Last N days (default: 7)",
      "default": 7
    },
    "limit": {
      "type": "integer",
      "description": "Max results 1-20 (default: 10)",
      "default": 10,
      "minimum": 1,
      "maximum": 20
    },
    "banking_only": {
      "type": "boolean",
      "description": "Filter to banking-relevant vendors only (default: false)"
    }
  },
  "additionalProperties": false
}
🟡kev_list(vendor, days, limit, overdue)

CISA Known Exploited Vulnerabilities — actively exploited CVEs with patch deadlines. DORA Art. 9 patch compliance.

輸入結構描述

{
  "type": "object",
  "properties": {
    "vendor": {
      "type": "string",
      "description": "Filter by vendor e.g. 'Cisco', 'Microsoft', 'SAP'"
    },
    "days": {
      "type": "integer",
      "description": "Added to KEV within last N days (default: 30)",
      "default": 30
    },
    "limit": {
      "type": "integer",
      "description": "Max results 1-50 (default: 15)",
      "default": 15,
      "minimum": 1,
      "maximum": 50
    },
    "overdue": {
      "type": "boolean",
      "description": "Show only overdue patches (default: false)"
    }
  },
  "additionalProperties": false
}
🟢kev_check(cve_id)

Check if a specific CVE is in CISA KEV (actively exploited in the wild). Returns DORA incident classification guidance.

輸入結構描述

{
  "type": "object",
  "properties": {
    "cve_id": {
      "type": "string",
      "description": "CVE ID to check e.g. 'CVE-2021-44228' (Log4Shell)"
    }
  },
  "additionalProperties": false
}
⚪cert_advisories(keyword, limit)

CERT-Bund security advisories — authoritative DE source for ICT threats. DORA Art. 17 threat monitoring.

輸入結構描述

{
  "type": "object",
  "properties": {
    "keyword": {
      "type": "string",
      "description": "Filter by keyword e.g. 'Windows', 'Apache', 'Cisco'"
    },
    "limit": {
      "type": "integer",
      "description": "Max results 1-30 (default: 15)",
      "default": 15,
      "minimum": 1,
      "maximum": 30
    }
  },
  "additionalProperties": false
}
🟢breach_check(domain, limit)

HaveIBeenPwned breach database — check domain/company breach exposure. DORA Art. 18 incident assessment.

輸入結構描述

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Company domain e.g. 'meinbank.de' (optional — omit for latest breaches)"
    },
    "limit": {
      "type": "integer",
      "description": "Max results 1-50 (default: 20)",
      "default": 20,
      "minimum": 1,
      "maximum": 50
    }
  },
  "additionalProperties": false
}
⚪threat_actors(malware, status, limit)

Feodo Tracker: live C2 botnet servers (Emotet, QakBot, etc.). Actionable IP blocklist for DORA Art. 9.

輸入結構描述

{
  "type": "object",
  "properties": {
    "malware": {
      "type": "string",
      "description": "Filter by malware family: Emotet, QakBot, Dridex, TrickBot"
    },
    "status": {
      "type": "string",
      "description": "Filter by status: online, offline"
    },
    "limit": {
      "type": "integer",
      "description": "Max results 1-100 (default: 20)",
      "default": 20,
      "minimum": 1,
      "maximum": 100
    }
  },
  "additionalProperties": false
}
⚪incident_timeline(incident_time, classification, sector)

Generate a DORA Art. 19-aligned ICT incident reporting timeline with the regulatory deadline structure. Supports - does not constitute - compliant reporting.

輸入結構描述

{
  "type": "object",
  "properties": {
    "incident_time": {
      "type": "string",
      "description": "ISO timestamp of incident e.g. '2026-03-19T14:00:00Z' (default: now)"
    },
    "classification": {
      "type": "string",
      "description": "Incident class: major, significant, minor (default: major)"
    },
    "sector": {
      "type": "string",
      "description": "Sector: banking, insurance, payment (default: banking)"
    }
  },
  "additionalProperties": false
}
⚪mitre_techniques(tactic, keyword, limit)

MITRE ATT&CK techniques for DORA TLPT / TIBER-EU penetration testing. Maps to DORA Art. 26.

輸入結構描述

{
  "type": "object",
  "properties": {
    "tactic": {
      "type": "string",
      "description": "Filter by tactic: Initial Access, Lateral Movement, Impact, Persistence, etc."
    },
    "keyword": {
      "type": "string",
      "description": "Search keyword e.g. 'ransomware', 'phishing', 'credential'"
    },
    "limit": {
      "type": "integer",
      "description": "Max results 1-20 (default: 10)",
      "default": 10,
      "minimum": 1,
      "maximum": 20
    }
  },
  "additionalProperties": false
}
⚪tlpt_scenarios(sector, focus)

TIBER-EU threat scenarios for DORA resilience testing planning. Banking-specific attack simulations.

輸入結構描述

{
  "type": "object",
  "properties": {
    "sector": {
      "type": "string",
      "description": "Sector: banking (default: banking)"
    },
    "focus": {
      "type": "string",
      "description": "Focus area: swift, ransomware, insider, ddos, cloud (default: all)"
    }
  },
  "additionalProperties": false
}
⚪cloud_status(provider, limit)

Live status of AWS, GCP, Azure cloud providers. DORA Art. 28 third-party ICT risk monitoring.

輸入結構描述

{
  "type": "object",
  "properties": {
    "provider": {
      "type": "string",
      "description": "Provider: aws, gcp, azure, all (default: all)"
    },
    "limit": {
      "type": "integer",
      "description": "Max incidents per provider (default: 10)",
      "default": 10
    }
  },
  "additionalProperties": false
}
⚪provider_risk(provider)

DORA Art. 28 ICT third-party risk assessment: CVE history, news, GLEIF registration, contractual checklist.

輸入結構描述

{
  "type": "object",
  "properties": {
    "provider": {
      "type": "string",
      "description": "Provider name e.g. 'SAP', 'Salesforce', 'AWS', 'Temenos'"
    }
  },
  "additionalProperties": false
}
⚪dora_news(topic, lang, limit)

EBA/DORA regulatory news for banks. Topics: general, eba, incident, third_party, testing, guidelines, bafin, swift.

輸入結構描述

{
  "type": "object",
  "properties": {
    "topic": {
      "type": "string",
      "description": "Topic: general, eba, incident, third_party, testing, guidelines, bafin, swift, fintech"
    },
    "lang": {
      "type": "string",
      "description": "Language: en or de (default: en)"
    },
    "limit": {
      "type": "integer",
      "description": "Max articles 1-20 (default: 10)",
      "default": 10,
      "minimum": 1,
      "maximum": 20
    }
  },
  "additionalProperties": false
}
⚪dora_calendar

DORA compliance milestones and upcoming deadlines for financial institutions. All Art. references included.

輸入結構描述

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
🟢health_check

DORAOracle server status and all backend connectivity checks.

輸入結構描述

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

社群

為此伺服器評分

證據

近期觀測

已驗證未記錄版本15 個工具
已驗證未記錄版本15 個工具
已驗證未記錄版本15 個工具