incidentoracle
IncidentOracle - 12-tool incident management MCP: triage, BaFin DORA reporting, RCA.
我該用這個嗎
品質與安全性
發現項目(3)
- LOW在 reclassify 中
- LOW在 cyber_threat_notify 中
- LOW在 health_check 中
根據工具定義與協定合規性的自動化分析。
上下文成本
這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。
安裝
一鍵安裝
將以下內容加入你的 `claude_desktop_config.json` 檔案:
{
"mcpServers": {
"incidentoracle": {
"url": "https://tooloracle.io/incident/mcp/"
}
}
}遠端端點
https://tooloracle.io/incident/mcp/streamable-http它能做什麼
工具清單
工具(12)
⚪log_incident(incident_id, title, description, severity, detected_at, ...)
Log a new ICT-related incident. First step in the DORA incident management process (Art. 17).
輸入結構描述
{
"type": "object",
"properties": {
"incident_id": {
"type": "string"
},
"title": {
"type": "string"
},
"description": {
"type": "string"
},
"severity": {
"type": "string",
"enum": [
"critical",
"high",
"medium",
"low"
]
},
"detected_at": {
"type": "string",
"description": "ISO datetime of detection"
},
"affected_systems": {
"type": "string"
},
"affected_services": {
"type": "string"
},
"owner": {
"type": "string"
},
"team": {
"type": "string"
},
"bcm_activated": {
"type": "boolean"
},
"clients_affected": {
"type": "number",
"description": "Percentage of clients affected"
},
"duration_hours": {
"type": "number"
},
"geographic_spread": {
"type": "integer"
},
"data_losses": {
"type": "boolean"
},
"economic_impact_eur": {
"type": "number"
},
"criticality_of_services": {
"type": "boolean"
},
"notes": {
"type": "string"
}
},
"required": [
"title"
],
"additionalProperties": false
}⚪classify_incident(incident_id, clients_affected, duration_hours, geographic_spread, data_losses, ...)
Classify an incident against the 6 DORA criteria (RTS 2024/1772). Determines if MAJOR (triggers 4h/72h/1m reporting) or NON-MAJOR.
輸入結構描述
{
"type": "object",
"properties": {
"incident_id": {
"type": "string"
},
"clients_affected": {
"type": "number",
"description": "% of clients affected"
},
"duration_hours": {
"type": "number"
},
"geographic_spread": {
"type": "integer",
"description": "Number of EU member states"
},
"data_losses": {
"type": "boolean",
"description": "Confidential/personal data affected?"
},
"economic_impact_eur": {
"type": "number"
},
"criticality_of_services": {
"type": "boolean",
"description": "Critical functions affected?"
}
},
"required": [
"incident_id"
],
"additionalProperties": false
}🟢major_incident_check(clients_affected, duration_hours, geographic_spread, data_losses, economic_impact_eur, ...)
Quick check: would these criteria values classify as a MAJOR incident? No incident record needed — use for pre-assessment.
輸入結構描述
{
"type": "object",
"properties": {
"clients_affected": {
"type": "number"
},
"duration_hours": {
"type": "number"
},
"geographic_spread": {
"type": "integer"
},
"data_losses": {
"type": "boolean"
},
"economic_impact_eur": {
"type": "number"
},
"criticality_of_services": {
"type": "boolean"
}
},
"additionalProperties": false
}⚪initial_notification(incident_id, entity_name, entity_lei, authority, affected_states, ...)
Generate the 4h initial notification for a MAJOR incident (ITS 2025/302 Annex I). Must be submitted within 4h of classification, max 24h after detection.
輸入結構描述
{
"type": "object",
"properties": {
"incident_id": {
"type": "string"
},
"entity_name": {
"type": "string"
},
"entity_lei": {
"type": "string"
},
"authority": {
"type": "string",
"description": "Competent authority (e.g., BaFin, FMA)"
},
"affected_states": {
"type": "string",
"description": "Comma-separated EU member states"
},
"discovery_method": {
"type": "string",
"enum": [
"internal_monitoring",
"user_report",
"third_party",
"regulator",
"other"
]
}
},
"required": [
"incident_id"
],
"additionalProperties": false
}⚪intermediate_report(incident_id, description_update, root_cause, containment_actions, recovery_status, ...)
Generate the 72h intermediate report for a MAJOR incident (ITS 2025/302). Must include action plan if incident is not yet resolved.
輸入結構描述
{
"type": "object",
"properties": {
"incident_id": {
"type": "string"
},
"description_update": {
"type": "string"
},
"root_cause": {
"type": "string"
},
"containment_actions": {
"type": "string"
},
"recovery_status": {
"type": "string"
},
"action_plan": {
"type": "string"
},
"expected_resolution": {
"type": "string"
}
},
"required": [
"incident_id"
],
"additionalProperties": false
}⚪final_report(incident_id, root_cause_final, recovery_actions, lessons_learned, preventive_measures, ...)
Generate the 1-month final report with root cause analysis and lessons learned.
輸入結構描述
{
"type": "object",
"properties": {
"incident_id": {
"type": "string"
},
"root_cause_final": {
"type": "string"
},
"recovery_actions": {
"type": "string"
},
"lessons_learned": {
"type": "string"
},
"preventive_measures": {
"type": "string"
},
"client_communication": {
"type": "string"
},
"total_cost_eur": {
"type": "number"
},
"resolved_at": {
"type": "string"
}
},
"required": [
"incident_id"
],
"additionalProperties": false
}⚪deadline_tracker
Track all active MAJOR incident reporting deadlines. Shows overdue and upcoming.
輸入結構描述
{
"type": "object",
"properties": {},
"additionalProperties": false
}⚪reclassify(incident_id, new_classification, reason)
Reclassify an incident (MAJOR to NON-MAJOR or vice versa). Competent authority must be notified of reclassification.
輸入結構描述
{
"type": "object",
"properties": {
"incident_id": {
"type": "string"
},
"new_classification": {
"type": "string",
"enum": [
"MAJOR",
"NON-MAJOR"
]
},
"reason": {
"type": "string"
}
},
"required": [
"incident_id",
"new_classification"
],
"additionalProperties": false
}⚪incident_stats
Dashboard: total/open/major incidents, overdue deadlines, by severity/status.
輸入結構描述
{
"type": "object",
"properties": {},
"additionalProperties": false
}⚪cyber_threat_notify(title, description, threat_type, iocs, ttps, ...)
Voluntary notification of a significant cyber threat (Art. 19(2)). Uses ITS 2025/302 Annex III template.
輸入結構描述
{
"type": "object",
"properties": {
"title": {
"type": "string"
},
"description": {
"type": "string"
},
"threat_type": {
"type": "string"
},
"iocs": {
"type": "string"
},
"ttps": {
"type": "string"
},
"affected_systems": {
"type": "string"
},
"mitigation": {
"type": "string"
},
"source": {
"type": "string"
}
},
"required": [
"title"
],
"additionalProperties": false
}⚪incident_log(status, classification, severity, search)
Full incident register with filters (status, classification, severity, search).
輸入結構描述
{
"type": "object",
"properties": {
"status": {
"type": "string",
"enum": [
"detected",
"classified",
"notified",
"investigating",
"contained",
"resolved",
"closed"
]
},
"classification": {
"type": "string",
"enum": [
"MAJOR",
"NON-MAJOR"
]
},
"severity": {
"type": "string",
"enum": [
"critical",
"high",
"medium",
"low"
]
},
"search": {
"type": "string"
}
},
"additionalProperties": false
}🟢health_check
Server status.
輸入結構描述
{
"type": "object",
"properties": {},
"additionalProperties": false
}社群
證據