mcp server
dora
DORAOracle — 15 tools for DORA Art.5-32: risk register, ICT incidents, TLPT, third-party.
Description as published by the maintainer. Source
- version 1.0.0
- slowing
slowing — Registry entry last updated 2026-05-07.
What this server can do
15 functions, named and described by the server itself. Parameter names are shown because they say more about what a function does than its name usually does.
breach_check(limit, domain)- HaveIBeenPwned breach database — check domain/company breach exposure. DORA Art. 18 incident assessment.
cert_advisories(limit, keyword)- CERT-Bund security advisories — authoritative DE source for ICT threats. DORA Art. 17 threat monitoring.
cloud_status(limit, provider)- Live status of AWS, GCP, Azure cloud providers. DORA Art. 28 third-party ICT risk monitoring.
cve_latest(days, limit, severity, banking_only)- Latest critical CVEs — daily DORA ICT risk briefing. Filter by severity and banking relevance.
cve_search(days, limit, vendor, keyword, severity)- Search CVEs by keyword, vendor or product. Returns CVSS scores, attack vectors, DORA pillar mapping.
dora_calendar- DORA compliance milestones and upcoming deadlines for financial institutions. All Art. references included.
dora_news(lang, limit, topic)- EBA/DORA regulatory news for banks. Topics: general, eba, incident, third_party, testing, guidelines, bafin, swift.
health_check- DORAOracle server status and all backend connectivity checks.
incident_timeline(sector, incident_time, classification)- Generate a DORA Art. 19-aligned ICT incident reporting timeline with the regulatory deadline structure. Supports - does not constitute - compliant reporting.
kev_check(cve_id)- Check if a specific CVE is in CISA KEV (actively exploited in the wild). Returns DORA incident classification guidance.
kev_list(days, limit, vendor, overdue)- CISA Known Exploited Vulnerabilities — actively exploited CVEs with patch deadlines. DORA Art. 9 patch compliance.
mitre_techniques(limit, tactic, keyword)- MITRE ATT&CK techniques for DORA TLPT / TIBER-EU penetration testing. Maps to DORA Art. 26.
provider_risk(provider)- DORA Art. 28 ICT third-party risk assessment: CVE history, news, GLEIF registration, contractual checklist.
threat_actors(limit, status, malware)- Feodo Tracker: live C2 botnet servers (Emotet, QakBot, etc.). Actionable IP blocklist for DORA Art. 9.
tlpt_scenarios(focus, sector)- TIBER-EU threat scenarios for DORA resilience testing planning. Banking-specific attack simulations.
Last successful function declaration observed on . Source: https://tooloracle.io/dora/mcp/. We list what the server declared; we do not call any of these functions.
Endpoint status observed on . Source: https://tooloracle.io/dora/mcp/.
Signals
These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.
| Signal | Value | What it measures | Window | Observed | Source |
|---|---|---|---|---|---|
| Latest published version | 1.0.0 | Latest version string the maintainer published to the registry. | as of fetch | Model Context Protocol | |
| Registry record last updated | 2026-05-07 | When the registry record was last updated by its maintainer. | point in time | Model Context Protocol | |
| First listed in the MCP Registry | 2026-05-07 | Date this server was first published to the official MCP Registry. Not a usage or quality measure. | point in time | Model Context Protocol | |
| mcp tools declared | 15 tools | Number of functions the server itself declared when asked to list them. This is what the server offers an agent, not a measure of how well any of them work. | as of probe | tooloracle.io | |
| mcp endpoint status | ok | The server listed 15 functions when asked. | as of probe | tooloracle.io |
Where to get it
Also from tooloracle
-
io.tooloracle/accessoracle
AccessOracle - 10 access control tools: IAM, PAM, recertification, segregation of duties.
-
io.tooloracle/agentguard
AgentGuard — 20-tool AI safety MCP: policy preflight, risk scoring, audit logging, rate limits.
-
io.tooloracle/aml
AMLOracle — 12-tool AML/CFT MCP: 87k sanctions names, PEP screening, adverse media, SAR/STR.
-
io.tooloracle/ampel
AmpelOracle — 50-tool compliance traffic-light: Go/Caution/Stop signals for ESG, MiCA, AML.
-
io.tooloracle/arbitrumoracle
ArbitrumOracle - 12 Arbitrum tools: ERC-20, Camelot, GMX, sequencer, gas, bridge txs.
-
io.tooloracle/baseoracle
BaseOracle - 8 Base L2 tools: ERC-20, Aerodrome, bridge status, txs, gas, holders.
-
io.tooloracle/bnboracle
BNBOracle - 8 BNB Chain tools: BEP-20, PancakeSwap, validators, gas, txs, holders.
-
io.tooloracle/changeoracle
ChangeOracle - 10 change management tools: CAB workflow, risk, impact, post-implementation.
-
io.tooloracle/cloudoracle
CloudOracle - 14-tool multi-cloud compliance MCP: AWS, Azure, GCP posture, IAM, configs.
-
io.tooloracle/conductor
DORA OS Conductor — 16-tool meta-orchestrator for DORA compliance workflow automation.
This record as data
Every field on this page, with its source and observation date, is in the catalog JSON. Fetch the whole kind at once instead of parsing this HTML.
GET /api/v1/entries/mcp_server.json