mcp server
incidentoracle
IncidentOracle - 12-tool incident management MCP: triage, BaFin DORA reporting, RCA.
Description as published by the maintainer. Source
- version 1.0.0
- slowing
- analytics
slowing — Registry entry last updated 2026-05-07. Dashed tags are derived by ZBS Index from the published description, not stated by the maintainer.
What this server can do
12 functions, named and described by the server itself. Parameter names are shown because they say more about what a function does than its name usually does.
classify_incident(data_losses, incident_id, duration_hours, clients_affected, geographic_spread, economic_impact_eur, criticality_of_services)- Classify an incident against the 6 DORA criteria (RTS 2024/1772). Determines if MAJOR (triggers 4h/72h/1m reporting) or NON-MAJOR. Required: incident_id.
cyber_threat_notify(iocs, ttps, title, source, mitigation, description, threat_type, affected_systems)- Voluntary notification of a significant cyber threat (Art. 19(2)). Uses ITS 2025/302 Annex III template. Required: title.
deadline_tracker- Track all active MAJOR incident reporting deadlines. Shows overdue and upcoming.
final_report(incident_id, resolved_at, total_cost_eur, lessons_learned, recovery_actions, root_cause_final, preventive_measures, client_communication)- Generate the 1-month final report with root cause analysis and lessons learned. Required: incident_id.
health_check- Server status.
incident_log(search, status, severity, classification)- Full incident register with filters (status, classification, severity, search).
incident_stats- Dashboard: total/open/major incidents, overdue deadlines, by severity/status.
initial_notification(authority, entity_lei, entity_name, incident_id, affected_states, discovery_method)- Generate the 4h initial notification for a MAJOR incident (ITS 2025/302 Annex I). Must be submitted within 4h of classification, max 24h after detection. Required: incident_id.
intermediate_report(root_cause, action_plan, incident_id, recovery_status, description_update, containment_actions, expected_resolution)- Generate the 72h intermediate report for a MAJOR incident (ITS 2025/302). Must include action plan if incident is not yet resolved. Required: incident_id.
log_incident(team, notes, owner, title, severity, data_losses, description, detected_at, incident_id, bcm_activated, duration_hours, affected_systems, clients_affected, affected_services, geographic_spread, economic_impact_eur, criticality_of_services)- Log a new ICT-related incident. First step in the DORA incident management process (Art. 17). Required: title.
major_incident_check(data_losses, duration_hours, clients_affected, geographic_spread, economic_impact_eur, criticality_of_services)- Quick check: would these criteria values classify as a MAJOR incident? No incident record needed — use for pre-assessment.
reclassify(reason, incident_id, new_classification)- Reclassify an incident (MAJOR to NON-MAJOR or vice versa). Competent authority must be notified of reclassification. Required: incident_id, new_classification.
Last successful function declaration observed on . Source: https://tooloracle.io/incident/mcp/. We list what the server declared; we do not call any of these functions.
Endpoint status observed on . Source: https://tooloracle.io/incident/mcp/.
Signals
These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.
| Signal | Value | What it measures | Window | Observed | Source |
|---|---|---|---|---|---|
| Latest published version | 1.0.0 | Latest version string the maintainer published to the registry. | as of fetch | Model Context Protocol | |
| Registry record last updated | 2026-05-07 | When the registry record was last updated by its maintainer. | point in time | Model Context Protocol | |
| First listed in the MCP Registry | 2026-05-07 | Date this server was first published to the official MCP Registry. Not a usage or quality measure. | point in time | Model Context Protocol | |
| mcp tools declared | 12 tools | Number of functions the server itself declared when asked to list them. This is what the server offers an agent, not a measure of how well any of them work. | as of probe | tooloracle.io | |
| mcp endpoint status | ok | The server listed 12 functions when asked. | as of probe | tooloracle.io |
Where to get it
Also from tooloracle
-
io.tooloracle/accessoracle
AccessOracle - 10 access control tools: IAM, PAM, recertification, segregation of duties.
-
io.tooloracle/agentguard
AgentGuard — 20-tool AI safety MCP: policy preflight, risk scoring, audit logging, rate limits.
-
io.tooloracle/aml
AMLOracle — 12-tool AML/CFT MCP: 87k sanctions names, PEP screening, adverse media, SAR/STR.
-
io.tooloracle/ampel
AmpelOracle — 50-tool compliance traffic-light: Go/Caution/Stop signals for ESG, MiCA, AML.
-
io.tooloracle/arbitrumoracle
ArbitrumOracle - 12 Arbitrum tools: ERC-20, Camelot, GMX, sequencer, gas, bridge txs.
-
io.tooloracle/baseoracle
BaseOracle - 8 Base L2 tools: ERC-20, Aerodrome, bridge status, txs, gas, holders.
-
io.tooloracle/bnboracle
BNBOracle - 8 BNB Chain tools: BEP-20, PancakeSwap, validators, gas, txs, holders.
-
io.tooloracle/changeoracle
ChangeOracle - 10 change management tools: CAB workflow, risk, impact, post-implementation.
-
io.tooloracle/cloudoracle
CloudOracle - 14-tool multi-cloud compliance MCP: AWS, Azure, GCP posture, IAM, configs.
-
io.tooloracle/conductor
DORA OS Conductor — 16-tool meta-orchestrator for DORA compliance workflow automation.
This record as data
Every field on this page, with its source and observation date, is in the catalog JSON. Fetch the whole kind at once instead of parsing this HTML.
GET /api/v1/entries/mcp_server.json