ZBS Index What actually exists in applied AI, with the source next to it

mcp server

ampel

AmpelOracle — 50-tool compliance traffic-light: Go/Caution/Stop signals for ESG, MiCA, AML.

Description as published by the maintainer. Source

  • version 1.0.0
  • slowing
  • security

slowing — Registry entry last updated 2026-05-07. Dashed tags are derived by ZBS Index from the published description, not stated by the maintainer.

What this server can do

50 functions, named and described by the server itself. Parameter names are shown because they say more about what a function does than its name usually does.

article_status(article, entity_id)
Detailed Ampel for a specific DORA article. Each check with GREEN/YELLOW/RED conditions and evidence.
assess_all(entity_id)
Re-run full assessment for an entity. Recomputes Ampel statuses from all available evidence.
audit_trail(limit, entity_id)
Chain-linked audit log with integrity check.
azure_ad_check(force_refresh)
Live Azure AD integration: MFA registration %, risky users, conditional access policies. DORA Art. 9 evidence. Requires Azure AD config in integrations_config.json.
bafin_approve_send(entity_id, report_id, approver_name, approver_role)
Approve BaFin report for submission (4-eyes principle). Creates signed approval evidence.
bafin_report_draft(title, entity_id, root_cause, description, incident_id, remediation, report_type, classification, affected_clients, affected_services)
Generate ITS 2024/1772 compliant BaFin incident report draft. All mandatory fields per DORA Art. 19/20. Preview mode — requires board approval.
board_summary(entity_id)
Executive board summary: overall score, top 5 risks, overdue findings, SLA breaches, concentration risk, evidence health, owner workload. Designed for management/board reporting.
bridge_approve(reject, approved_by, resolution_id, rejection_reason)
Approve or reject a bridge resolution. On approval: creates signed evidence, upgrades Ampel to GREEN, logs to audit chain.
bridge_report(entity_id)
Bridge gap analysis: classifies gaps by DATA/EVIDENCE/POLICY/WORKFLOW with closure path, owner, effort level.
bridge_resolve(check_id, entity_id, expiry_days)
Start bridge resolution workflow. Generates templates (Risk Acceptance, Contract Renegotiation, Concentration Policy, Exit Strategy), tracks approval process. Call bridge_approve to sign off.
bridge_status(entity_id)
Check status of all bridge resolution workflows for an entity. Shows open, pending, closed, rejected.
bus_status(entity_id)
Oracle Event Bus status: events, cross-refs, connected oracles.
check_contract(is_cif, entity_id, cif_clauses, provider_id, exit_strategy, standard_clauses)
Check DORA Art. 30 contract clauses for a provider. Returns PASS/WARN/BLOCK with missing clauses and bridge classification.
collect_art10(entity_id)
Collect live Art. 10 evidence from NVD, CISA KEV, CERT-Bund. Auto-assesses.
contract_analyze(document_id)
Analyze contract against 15 DORA Art. 30 mandatory clauses. Returns compliance status per clause with confidence score, extracted text, gap reasoning, suggested fix.
contract_status(entity_id)
Overview of all analyzed contracts per entity. Shows clause gaps, review status, document versions.
contract_upload(entity_id, file_name, contract_text, document_type, provider_name)
Upload contract text for DORA Art. 30 analysis. Creates document record with SHA-256 hash, version tracking, audit trail.
create_entity(lei, name, entity_type, jurisdiction)
Register a new regulated entity.
create_trial(providers, entity_name, entity_type, jurisdiction)
Create temporary trial entity (48h) for self-service DORA assessment. No login needed.
cross_oracle_assess(checks, entity_id)
Enterprise cross-oracle assessment. Runs 18 checks across CyberShield (NIS2/ISO 27001), SupplyChainOracle (LkSG/CSRD), HealthGuard (MDR/GDPR), CFOCoPilot (XRechnung), TaxOracle (DAC6), LegalTechOracle (DORA contracts). Auto-stores evidence and updates Ampel status.
cross_regulation_check(entity_id)
Tag findings with cross-regulation impact (DORA + MiCA + AMLR). Shows which DORA findings also affect MiCA insider info or AMLR screening.
cve_asset_map(cve_id, vendor, entity_id)
Map CVE/vulnerability to internal ICT providers and systems. Auto-creates findings for critical matches. DORA Art. 10.
dependency_graph(entity_id)
Full provider dependency graph: providers, systems, checks, blast radius, SPOF detection.
entity_list
List all registered regulated entities.
escalation_status(entity_id)
Get findings, SLA breaches, escalation status per entity.
evidence_pack(article, check_id, entity_id)
Export evidence pack for article/check/entity. Pruefer-ready: evidence, assessments, findings, audit trail, signatures.
evidence_summary(entity_id)
All evidence artefacts for an entity with hashes and expiry dates.
freshness_check(entity_id)
Run freshness watchdog. Expires stale evidence, downgrades GREEN->YELLOW->GREY if evidence too old.
gap_report(entity_id)
DORA compliance gaps. RED/GREY/YELLOW items with priority and required actions.
generate_report(format, entity_id)
Generate data-driven DORA Ampel PDF report. Score, gap analysis, provider register, audit trail integrity.
generate_trial_report(trial_id, entity_id)
Generate watermarked trial report with score, gaps, and CTA.
health_check
Server + DB status.
incident_flow(title, action, severity, entity_id, root_cause, description, incident_id, report_type, classification, lessons_learned)
DORA incident lifecycle: log, classify, notify (BaFin), close. Each step creates signed evidence.
llm_clause_check(contract_text, provider_name)
LLM-based DORA Art. 30 contract analysis. Paste contract text, get clause-by-clause PRESENT/PARTIAL/MISSING for all 15 mandatory clauses. Uses Claude API.
onboard_entity(entity_id)
Full entity onboarding: creates initial RED assessments for all 39 checks, collects auto-evidence from live sources, re-assesses, and returns readiness score.
ping
Quick connectivity test.
policy_draft(entity_id, dora_article)
Generate DORA policy/framework document draft for a specific article. 8 templates available (Art. 5,6,8,10,11,17,28,30). Uses entity data for customization.
provider_country_risk(entity_id)
Enrich provider dependencies with OECD economic risk: GDP, unemployment, CLI per provider country. DORA Art. 28-31 relevant.
readiness_check(entity_id)
Full DORA readiness score + Ampel per article. Returns GREEN/YELLOW/RED/GREY for all 26 articles, score 0-100, days until deadline.
reg_watchdog(days_back)
AI Regulatory Watchdog: scrapes EBA/ESMA/BaFin/CERT-Bund for DORA updates. Returns alerts with affected articles and severity. Run daily via cron or on-demand.
register_provider(lei, services, entity_id, criticality, contract_end, headquarters, data_location, provider_name, provider_type, certifications, contract_start, annual_cost_eur, substitutability)
Register an ICT third-party provider for DORA Art. 28 Register of Information. Stores provider data and creates evidence.
regulation_impact(dora_article)
Show cross-regulation impacts for a specific DORA article. Maps DORA → MiCA + AMLR.
retest_finding(finding_id)
Re-test a finding: collect fresh evidence, reassess check, auto-close if GREEN. Full closed-loop.
run_escalation
Trigger escalation engine: auto-create findings, check SLA, escalate.
run_trial_assessment(trial_id, entity_id)
Run complete DORA+MiCA assessment for trial entity. Returns score, gaps, automation potential.
score_trend(entity_id)
Score trend over time: weekly deltas, trajectory, peer benchmark. Shows improvement or decline.
servicenow_sync(days_back)
ServiceNow incident + change management sync. DORA Art. 17/21 evidence. Returns 30-day incident stats, classification, resolution rates.
update_finding(actor, owner, action, reason, finding_id, accepted_by, expiry_days, remediation_plan)
Update finding lifecycle: claim, set remediation plan, request re-test, close, or accept risk. Status flow: open -> in_progress -> retest_pending -> closed | risk_accepted.
whatif_provider(entity_id, provider_name)
Simulate provider failure: which articles/checks are affected, score impact, risk level.
whatif_stale(days, check_id, entity_id)
Simulate stale evidence: what happens if a check stays stale for N days.

Last successful function declaration observed on . Source: https://tooloracle.io/ampel/mcp/. We list what the server declared; we do not call any of these functions.

Endpoint status observed on . Source: https://tooloracle.io/ampel/mcp/.

Signals

These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.

Signal Value What it measures Window Observed Source
Latest published version 1.0.0 Latest version string the maintainer published to the registry. as of fetch Model Context Protocol
Registry record last updated 2026-05-07 When the registry record was last updated by its maintainer. point in time Model Context Protocol
First listed in the MCP Registry 2026-05-07 Date this server was first published to the official MCP Registry. Not a usage or quality measure. point in time Model Context Protocol
mcp tools declared 50 tools Number of functions the server itself declared when asked to list them. This is what the server offers an agent, not a measure of how well any of them work. as of probe tooloracle.io
mcp endpoint status ok The server listed 50 functions when asked. as of probe tooloracle.io

Where to get it

Also from tooloracle

This record as data

Every field on this page, with its source and observation date, is in the catalog JSON. Fetch the whole kind at once instead of parsing this HTML.

GET /api/v1/entries/mcp_server.json

Sources

  1. Official MCP Registry — Model Context Protocol, observed , trust tier 1.
  2. Tools declared by the MCP server at https://tooloracle.io/ampel/mcp/ — tooloracle.io, observed , trust tier 1.