incidentoracle

IncidentOracle - 12-tool incident management MCP: triage, BaFin DORA reporting, RCA.

我該用這個嗎

品質與安全性

B
說明品質
86%
結構描述完整度
68%
命名品質
82%
汙染風險
100%
權限相符程度
100%
協定合規性
100%

發現項目(3)

  • LOWTool 'reclassify' description lacks action verb在 reclassify 中
  • LOWTool 'cyber_threat_notify' description lacks action verb在 cyber_threat_notify 中
  • LOWTool 'health_check' description lacks action verb在 health_check 中

根據工具定義與協定合規性的自動化分析。

上下文成本

~1,297Token(工具定義)
~966 B典型回應大小
中等的注意力影響(128k 上下文的 1.01%)

這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。

安裝

一鍵安裝

將以下內容加入你的 `claude_desktop_config.json` 檔案:

{
  "mcpServers": {
    "incidentoracle": {
      "url": "https://tooloracle.io/incident/mcp/"
    }
  }
}

遠端端點

https://tooloracle.io/incident/mcp/streamable-http

它能做什麼

工具清單

工具(12)

🟢 唯讀🟡 寫入🔴 刪除⚪ 未知
⚪log_incident(incident_id, title, description, severity, detected_at, ...)

Log a new ICT-related incident. First step in the DORA incident management process (Art. 17).

輸入結構描述

{
  "type": "object",
  "properties": {
    "incident_id": {
      "type": "string"
    },
    "title": {
      "type": "string"
    },
    "description": {
      "type": "string"
    },
    "severity": {
      "type": "string",
      "enum": [
        "critical",
        "high",
        "medium",
        "low"
      ]
    },
    "detected_at": {
      "type": "string",
      "description": "ISO datetime of detection"
    },
    "affected_systems": {
      "type": "string"
    },
    "affected_services": {
      "type": "string"
    },
    "owner": {
      "type": "string"
    },
    "team": {
      "type": "string"
    },
    "bcm_activated": {
      "type": "boolean"
    },
    "clients_affected": {
      "type": "number",
      "description": "Percentage of clients affected"
    },
    "duration_hours": {
      "type": "number"
    },
    "geographic_spread": {
      "type": "integer"
    },
    "data_losses": {
      "type": "boolean"
    },
    "economic_impact_eur": {
      "type": "number"
    },
    "criticality_of_services": {
      "type": "boolean"
    },
    "notes": {
      "type": "string"
    }
  },
  "required": [
    "title"
  ],
  "additionalProperties": false
}
⚪classify_incident(incident_id, clients_affected, duration_hours, geographic_spread, data_losses, ...)

Classify an incident against the 6 DORA criteria (RTS 2024/1772). Determines if MAJOR (triggers 4h/72h/1m reporting) or NON-MAJOR.

輸入結構描述

{
  "type": "object",
  "properties": {
    "incident_id": {
      "type": "string"
    },
    "clients_affected": {
      "type": "number",
      "description": "% of clients affected"
    },
    "duration_hours": {
      "type": "number"
    },
    "geographic_spread": {
      "type": "integer",
      "description": "Number of EU member states"
    },
    "data_losses": {
      "type": "boolean",
      "description": "Confidential/personal data affected?"
    },
    "economic_impact_eur": {
      "type": "number"
    },
    "criticality_of_services": {
      "type": "boolean",
      "description": "Critical functions affected?"
    }
  },
  "required": [
    "incident_id"
  ],
  "additionalProperties": false
}
🟢major_incident_check(clients_affected, duration_hours, geographic_spread, data_losses, economic_impact_eur, ...)

Quick check: would these criteria values classify as a MAJOR incident? No incident record needed — use for pre-assessment.

輸入結構描述

{
  "type": "object",
  "properties": {
    "clients_affected": {
      "type": "number"
    },
    "duration_hours": {
      "type": "number"
    },
    "geographic_spread": {
      "type": "integer"
    },
    "data_losses": {
      "type": "boolean"
    },
    "economic_impact_eur": {
      "type": "number"
    },
    "criticality_of_services": {
      "type": "boolean"
    }
  },
  "additionalProperties": false
}
⚪initial_notification(incident_id, entity_name, entity_lei, authority, affected_states, ...)

Generate the 4h initial notification for a MAJOR incident (ITS 2025/302 Annex I). Must be submitted within 4h of classification, max 24h after detection.

輸入結構描述

{
  "type": "object",
  "properties": {
    "incident_id": {
      "type": "string"
    },
    "entity_name": {
      "type": "string"
    },
    "entity_lei": {
      "type": "string"
    },
    "authority": {
      "type": "string",
      "description": "Competent authority (e.g., BaFin, FMA)"
    },
    "affected_states": {
      "type": "string",
      "description": "Comma-separated EU member states"
    },
    "discovery_method": {
      "type": "string",
      "enum": [
        "internal_monitoring",
        "user_report",
        "third_party",
        "regulator",
        "other"
      ]
    }
  },
  "required": [
    "incident_id"
  ],
  "additionalProperties": false
}
⚪intermediate_report(incident_id, description_update, root_cause, containment_actions, recovery_status, ...)

Generate the 72h intermediate report for a MAJOR incident (ITS 2025/302). Must include action plan if incident is not yet resolved.

輸入結構描述

{
  "type": "object",
  "properties": {
    "incident_id": {
      "type": "string"
    },
    "description_update": {
      "type": "string"
    },
    "root_cause": {
      "type": "string"
    },
    "containment_actions": {
      "type": "string"
    },
    "recovery_status": {
      "type": "string"
    },
    "action_plan": {
      "type": "string"
    },
    "expected_resolution": {
      "type": "string"
    }
  },
  "required": [
    "incident_id"
  ],
  "additionalProperties": false
}
⚪final_report(incident_id, root_cause_final, recovery_actions, lessons_learned, preventive_measures, ...)

Generate the 1-month final report with root cause analysis and lessons learned.

輸入結構描述

{
  "type": "object",
  "properties": {
    "incident_id": {
      "type": "string"
    },
    "root_cause_final": {
      "type": "string"
    },
    "recovery_actions": {
      "type": "string"
    },
    "lessons_learned": {
      "type": "string"
    },
    "preventive_measures": {
      "type": "string"
    },
    "client_communication": {
      "type": "string"
    },
    "total_cost_eur": {
      "type": "number"
    },
    "resolved_at": {
      "type": "string"
    }
  },
  "required": [
    "incident_id"
  ],
  "additionalProperties": false
}
⚪deadline_tracker

Track all active MAJOR incident reporting deadlines. Shows overdue and upcoming.

輸入結構描述

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
⚪reclassify(incident_id, new_classification, reason)

Reclassify an incident (MAJOR to NON-MAJOR or vice versa). Competent authority must be notified of reclassification.

輸入結構描述

{
  "type": "object",
  "properties": {
    "incident_id": {
      "type": "string"
    },
    "new_classification": {
      "type": "string",
      "enum": [
        "MAJOR",
        "NON-MAJOR"
      ]
    },
    "reason": {
      "type": "string"
    }
  },
  "required": [
    "incident_id",
    "new_classification"
  ],
  "additionalProperties": false
}
⚪incident_stats

Dashboard: total/open/major incidents, overdue deadlines, by severity/status.

輸入結構描述

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
⚪cyber_threat_notify(title, description, threat_type, iocs, ttps, ...)

Voluntary notification of a significant cyber threat (Art. 19(2)). Uses ITS 2025/302 Annex III template.

輸入結構描述

{
  "type": "object",
  "properties": {
    "title": {
      "type": "string"
    },
    "description": {
      "type": "string"
    },
    "threat_type": {
      "type": "string"
    },
    "iocs": {
      "type": "string"
    },
    "ttps": {
      "type": "string"
    },
    "affected_systems": {
      "type": "string"
    },
    "mitigation": {
      "type": "string"
    },
    "source": {
      "type": "string"
    }
  },
  "required": [
    "title"
  ],
  "additionalProperties": false
}
⚪incident_log(status, classification, severity, search)

Full incident register with filters (status, classification, severity, search).

輸入結構描述

{
  "type": "object",
  "properties": {
    "status": {
      "type": "string",
      "enum": [
        "detected",
        "classified",
        "notified",
        "investigating",
        "contained",
        "resolved",
        "closed"
      ]
    },
    "classification": {
      "type": "string",
      "enum": [
        "MAJOR",
        "NON-MAJOR"
      ]
    },
    "severity": {
      "type": "string",
      "enum": [
        "critical",
        "high",
        "medium",
        "low"
      ]
    },
    "search": {
      "type": "string"
    }
  },
  "additionalProperties": false
}
🟢health_check

Server status.

輸入結構描述

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

社群

為此伺服器評分

證據

近期觀測

已驗證未記錄版本12 個工具
已驗證未記錄版本12 個工具