governanceoracle

GovernanceOracle - 10 governance tools: board packs, policies, attestations, evidence.

我該用這個嗎

品質與安全性

B
說明品質
88%
結構描述完整度
57%
命名品質
82%
汙染風險
100%
權限相符程度
100%
協定合規性
100%

發現項目(2)

  • LOWTool 'control_status' description lacks action verb在 control_status 中
  • LOWTool 'health_check' description lacks action verb在 health_check 中

根據工具定義與協定合規性的自動化分析。

上下文成本

~927Token(工具定義)
~767 B典型回應大小
中等的注意力影響(128k 上下文的 0.72%)

這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。

安裝

一鍵安裝

將以下內容加入你的 `claude_desktop_config.json` 檔案:

{
  "mcpServers": {
    "governanceoracle": {
      "url": "https://tooloracle.io/governance/mcp/"
    }
  }
}

遠端端點

https://tooloracle.io/governance/mcp/streamable-http

它能做什麼

工具清單

工具(11)

🟢 唯讀🟡 寫入🔴 刪除⚪ 未知
⚪register_finding(finding_id, title, description, severity, source, ...)

Register an audit finding, risk, or control gap.

輸入結構描述

{
  "type": "object",
  "properties": {
    "finding_id": {
      "type": "string"
    },
    "title": {
      "type": "string"
    },
    "description": {
      "type": "string"
    },
    "severity": {
      "type": "string",
      "enum": [
        "critical",
        "high",
        "medium",
        "low",
        "info"
      ]
    },
    "source": {
      "type": "string",
      "description": "audit, pentest, incident, self-assessment"
    },
    "domain": {
      "type": "string",
      "enum": [
        "access_management",
        "change_management",
        "incident_management",
        "business_continuity",
        "third_party_risk",
        "data_protection",
        "network_security",
        "vulnerability_management",
        "logging_monitoring",
        "cryptography",
        "physical_security",
        "awareness_training"
      ]
    },
    "status": {
      "type": "string",
      "enum": [
        "open",
        "in_progress",
        "remediated",
        "accepted",
        "overdue"
      ]
    },
    "owner": {
      "type": "string"
    },
    "due_date": {
      "type": "string"
    },
    "remediation_plan": {
      "type": "string"
    },
    "related_article": {
      "type": "string"
    },
    "evidence_ref": {
      "type": "string"
    },
    "notes": {
      "type": "string"
    }
  },
  "required": [
    "title",
    "severity"
  ],
  "additionalProperties": false
}
🟢list_findings(status, severity, domain, owner)

List findings with optional filters.

輸入結構描述

{
  "type": "object",
  "properties": {
    "status": {
      "type": "string",
      "enum": [
        "open",
        "in_progress",
        "remediated",
        "accepted",
        "overdue"
      ]
    },
    "severity": {
      "type": "string",
      "enum": [
        "critical",
        "high",
        "medium",
        "low",
        "info"
      ]
    },
    "domain": {
      "type": "string",
      "enum": [
        "access_management",
        "change_management",
        "incident_management",
        "business_continuity",
        "third_party_risk",
        "data_protection",
        "network_security",
        "vulnerability_management",
        "logging_monitoring",
        "cryptography",
        "physical_security",
        "awareness_training"
      ]
    },
    "owner": {
      "type": "string"
    }
  },
  "additionalProperties": false
}
⚪board_report(period)

Generate Management Body review pack — executive summary, open findings, risk posture, overdue items.

輸入結構描述

{
  "type": "object",
  "properties": {
    "period": {
      "type": "string",
      "description": "Reporting period (e.g., 'Q1 2026')"
    }
  },
  "additionalProperties": false
}
⚪framework_review

ICT Risk Management Framework annual review — effectiveness assessment per DORA area.

輸入結構描述

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
⚪control_status

Control effectiveness dashboard across all DORA control domains.

輸入結構描述

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
🟡exception_register(add, finding_id, title, risk_description, accepted_by, ...)

View or add risk acceptances / exceptions with expiry tracking.

輸入結構描述

{
  "type": "object",
  "properties": {
    "add": {
      "type": "boolean",
      "description": "Set true to add a new exception"
    },
    "finding_id": {
      "type": "string"
    },
    "title": {
      "type": "string"
    },
    "risk_description": {
      "type": "string"
    },
    "accepted_by": {
      "type": "string"
    },
    "acceptance_date": {
      "type": "string"
    },
    "expiry_date": {
      "type": "string"
    },
    "compensating_controls": {
      "type": "string"
    }
  },
  "additionalProperties": false
}
⚪action_tracker(add, finding_id, title, owner, due_date, ...)

Track remediation actions with deadlines and ownership.

輸入結構描述

{
  "type": "object",
  "properties": {
    "add": {
      "type": "boolean",
      "description": "Set true to add a new action"
    },
    "finding_id": {
      "type": "string"
    },
    "title": {
      "type": "string"
    },
    "owner": {
      "type": "string"
    },
    "due_date": {
      "type": "string"
    },
    "priority": {
      "type": "string",
      "enum": [
        "critical",
        "high",
        "medium",
        "low"
      ]
    }
  },
  "additionalProperties": false
}
⚪kpi_dashboard

ICT Risk KPIs — open findings, overdue rate, remediation rate, exception count.

輸入結構描述

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
⚪annual_review

Annual framework review evidence bundle — checklist, stats, Art. 6(5) compliance.

輸入結構描述

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
⚪board_report_llm(language, additional_context)

AI-powered board executive summary using local Gemma 4 LLM. Generates narrative summary from current findings in German or English.

輸入結構描述

{
  "type": "object",
  "properties": {
    "language": {
      "type": "string",
      "description": "Language: de or en",
      "default": "en"
    },
    "additional_context": {
      "type": "string",
      "description": "Extra context to include (deadlines, events)"
    }
  },
  "additionalProperties": false
}
🟢health_check

Server status.

輸入結構描述

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

社群

為此伺服器評分

證據

近期觀測

已驗證未記錄版本11 個工具
已驗證未記錄版本11 個工具