mcpserver.lol
registry/incidentoracle
Connection check verified live · 26h ago

incidentoracle

IncidentOracle - 12-tool incident management MCP: triage, BaFin DORA reporting, RCA.

Tools 12
GitHub stars
Installs / wk
Licence
Transport streamable-http
Last checked 26h ago

Tools & capabilities

12 tools

Read from the running server on 26h ago.

classify_incident data_lossesincident_id*duration_hoursclients_affectedgeographic_spreadeconomic_impact_eur +1
Classify an incident against the 6 DORA criteria (RTS 2024/1772). Determines if MAJOR (triggers 4h/72h/1m reporting) or NON-MAJOR.
cyber_threat_notify iocsttpstitle*sourcemitigationdescription +2
Voluntary notification of a significant cyber threat (Art. 19(2)). Uses ITS 2025/302 Annex III template.
deadline_tracker
Track all active MAJOR incident reporting deadlines. Shows overdue and upcoming.
final_report incident_id*resolved_attotal_cost_eurlessons_learnedrecovery_actionsroot_cause_final +2
Generate the 1-month final report with root cause analysis and lessons learned.
health_check
Server status.
incident_log searchstatusseverityclassification
Full incident register with filters (status, classification, severity, search).
incident_stats
Dashboard: total/open/major incidents, overdue deadlines, by severity/status.
initial_notification authorityentity_leientity_nameincident_id*affected_statesdiscovery_method
Generate the 4h initial notification for a MAJOR incident (ITS 2025/302 Annex I). Must be submitted within 4h of classification, max 24h after detection.
intermediate_report root_causeaction_planincident_id*recovery_statusdescription_updatecontainment_actions +1
Generate the 72h intermediate report for a MAJOR incident (ITS 2025/302). Must include action plan if incident is not yet resolved.
log_incident teamnotesownertitle*severitydata_losses +11
Log a new ICT-related incident. First step in the DORA incident management process (Art. 17).
major_incident_check data_lossesduration_hoursclients_affectedgeographic_spreadeconomic_impact_eurcriticality_of_services
Quick check: would these criteria values classify as a MAJOR incident? No incident record needed — use for pre-assessment.
reclassify reasonincident_id*new_classification*
Reclassify an incident (MAJOR to NON-MAJOR or vice versa). Competent authority must be notified of reclassification.