mcp server
cybershield
CyberShield - 12 cybersecurity tools: NIS2 mapping, MITRE ATT&CK, vulns, threat intel.
Description as published by the maintainer. Source
- version 1.0.0
- slowing
- security
slowing — Registry entry last updated 2026-05-07. Dashed tags are derived by ZBS Index from the published description, not stated by the maintainer.
What this server can do
12 functions, named and described by the server itself. Parameter names are shown because they say more about what a function does than its name usually does.
attack_surface_check(iot_devices, cloud_services, employee_count, web_applications, remote_access_vpn)- Attack surface assessment checklist. Web apps, remote access, cloud, IoT, email. Prioritized security checks.
cve_risk_score(cve_id, cvss_score, epss_score, in_kev_catalog, public_exploit, internet_facing, affected_systems)- CVE risk prioritization combining CVSS, EPSS, KEV catalog, exploit availability. Returns weighted priority score with patching SLA.
dora_ict_risk(learning_evolving, response_recovery, detection_measures, ict_risk_framework, communication_plans, ict_asset_inventory, protection_prevention)- DORA Art. 5-12 ICT risk management compliance check. 8 articles assessed with specific requirements per article.
incident_playbook(incident_type)- Incident response playbook for ransomware, data breach, phishing compromise. Phase-by-phase actions with legal obligations.
iso27001_gap(controls)- ISO 27001:2022 Annex A gap analysis. All 93 controls across 4 themes, new 2022 controls highlighted, certification process.
nis2_compliance(sector, mfa_deployed, access_control, employee_count, risk_management, incident_handling, business_continuity, cryptography_policy, annual_turnover_meur, supply_chain_security, cyber_hygiene_training, vulnerability_management, incident_reporting_process)- NIS2 Directive (EU 2022/2555) compliance assessment. All 10 Art. 21 measures, entity classification, penalties, incident reporting.
nis2_incident_report(severity, incident_type, affected_services, cross_border_impact, affected_users_estimate)- NIS2 incident notification template. 24h early warning, 72h notification, 1-month final report templates.
password_policy- Generate password policy per NIST SP 800-63B (2024) and BSI recommendations. Modern best practices — no forced rotation.
phishing_indicators(subject, sender_email, suspicious_url, creates_urgency, asks_for_credentials, has_unexpected_attachment)- Analyze email/URL for phishing indicators. Scores sender, urgency, attachments, URL patterns. Returns verdict and recommended actions.
risk_matrix(risks)- Risk assessment matrix (likelihood × impact). ISO 31000/27005 methodology. Provide risks for assessment or get template.
security_metrics- Security KPI/metrics dashboard template. MTTD, MTTR, patch compliance, phishing rate. Board-ready reporting guidance.
threat_landscape(sector)- Current cyber threat landscape overview per ENISA categories. Top 8 threats with sector relevance and mitigations.
Last successful function declaration observed on . Source: https://tooloracle.io/cybershield/mcp/. We list what the server declared; we do not call any of these functions.
Endpoint status observed on . Source: https://tooloracle.io/cybershield/mcp/.
Signals
These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.
| Signal | Value | What it measures | Window | Observed | Source |
|---|---|---|---|---|---|
| Latest published version | 1.0.0 | Latest version string the maintainer published to the registry. | as of fetch | Model Context Protocol | |
| Registry record last updated | 2026-05-07 | When the registry record was last updated by its maintainer. | point in time | Model Context Protocol | |
| First listed in the MCP Registry | 2026-05-07 | Date this server was first published to the official MCP Registry. Not a usage or quality measure. | point in time | Model Context Protocol | |
| mcp tools declared | 12 tools | Number of functions the server itself declared when asked to list them. This is what the server offers an agent, not a measure of how well any of them work. | as of probe | tooloracle.io | |
| mcp endpoint status | ok | The server listed 12 functions when asked. | as of probe | tooloracle.io |
Where to get it
Also from tooloracle
-
io.tooloracle/accessoracle
AccessOracle - 10 access control tools: IAM, PAM, recertification, segregation of duties.
-
io.tooloracle/agentguard
AgentGuard — 20-tool AI safety MCP: policy preflight, risk scoring, audit logging, rate limits.
-
io.tooloracle/aml
AMLOracle — 12-tool AML/CFT MCP: 87k sanctions names, PEP screening, adverse media, SAR/STR.
-
io.tooloracle/ampel
AmpelOracle — 50-tool compliance traffic-light: Go/Caution/Stop signals for ESG, MiCA, AML.
-
io.tooloracle/arbitrumoracle
ArbitrumOracle - 12 Arbitrum tools: ERC-20, Camelot, GMX, sequencer, gas, bridge txs.
-
io.tooloracle/baseoracle
BaseOracle - 8 Base L2 tools: ERC-20, Aerodrome, bridge status, txs, gas, holders.
-
io.tooloracle/bnboracle
BNBOracle - 8 BNB Chain tools: BEP-20, PancakeSwap, validators, gas, txs, holders.
-
io.tooloracle/changeoracle
ChangeOracle - 10 change management tools: CAB workflow, risk, impact, post-implementation.
-
io.tooloracle/cloudoracle
CloudOracle - 14-tool multi-cloud compliance MCP: AWS, Azure, GCP posture, IAM, configs.
-
io.tooloracle/conductor
DORA OS Conductor — 16-tool meta-orchestrator for DORA compliance workflow automation.
This record as data
Every field on this page, with its source and observation date, is in the catalog JSON. Fetch the whole kind at once instead of parsing this HTML.
GET /api/v1/entries/mcp_server.json