Serveur MCP

ampel

io.tooloracle/ampel

Ce que fait ce MCP

Assesses regulated entities and providers against DORA and related ESG, MiCA, and AML requirements, with contract analysis, evidence collection, audit trails, risk findings, and regulatory report generation.

article_status
Detailed Ampel for a specific DORA article. Each check with GREEN/YELLOW/RED conditions and evidence.
Schéma d’entrée
{'type': 'object', 'properties': {'article': {'type': 'string', 'description': 'e.g. Art. 28'}, 'entity_id': {'type': 'string', 'description': 'Entity ID'}}, 'additionalProperties': False}
assess_all
Re-run full assessment for an entity. Recomputes Ampel statuses from all available evidence.
Schéma d’entrée
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID (optional)'}}, 'additionalProperties': False}
audit_trail
Chain-linked audit log with integrity check.
Schéma d’entrée
{'type': 'object', 'properties': {'limit': {'type': 'integer', 'description': 'Max entries'}, 'entity_id': {'type': 'string'}}, 'additionalProperties': False}
azure_ad_check
Live Azure AD integration: MFA registration %, risky users, conditional access policies. DORA Art. 9 evidence. Requires Azure AD config in integrations_config.json.
Schéma d’entrée
{'type': 'object', 'properties': {'force_refresh': {'type': 'boolean', 'description': 'Force fresh API call (default true)'}}, 'additionalProperties': False}
bafin_approve_send
Approve BaFin report for submission (4-eyes principle). Creates signed approval evidence.
Schéma d’entrée
{'type': 'object', 'properties': {'entity_id': {'type': 'string'}, 'report_id': {'type': 'string'}, 'approver_name': {'type': 'string'}, 'approver_role': {'type': 'string'}}, 'additionalProperties': False}
bafin_report_draft
Generate ITS 2024/1772 compliant BaFin incident report draft. All mandatory fields per DORA Art. 19/20. Preview mode — requires board approval.
Schéma d’entrée
{'type': 'object', 'properties': {'title': {'type': 'string'}, 'entity_id': {'type': 'string'}, 'root_cause': {'type': 'string'}, 'description': {'type': 'string'}, 'incident_id': {'type': 'string'}, 'remediation': {'type': 'string'}, 'report_type': {'type': 'string', 'description': 'initial | intermediate | final'}, 'classification': {'type': 'string', 'description': 'major | significant | minor'}, 'affected_clients': {'type': 'string'}, 'affected_services': {'type': 'string'}}, 'additionalProperties': False}
board_summary
Executive board summary: overall score, top 5 risks, overdue findings, SLA breaches, concentration risk, evidence health, owner workload. Designed for management/board reporting.
Schéma d’entrée
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID'}}, 'additionalProperties': False}
bridge_approve
Approve or reject a bridge resolution. On approval: creates signed evidence, upgrades Ampel to GREEN, logs to audit chain.
Schéma d’entrée
{'type': 'object', 'properties': {'reject': {'type': 'boolean', 'description': 'Set true to reject instead of approve'}, 'approved_by': {'type': 'string', 'description': 'Name + role of approver (e.g. Dr. Mueller, CISO)'}, 'resolution_id': {'type': 'string', 'description': 'Resolution ID from bridge_resolve'}, 'rejection_reason': {'type': 'string', 'description': 'Reason for rejection (if rejecting)'}}, 'additionalProperties': False}
bridge_report
Bridge gap analysis: classifies gaps by DATA/EVIDENCE/POLICY/WORKFLOW with closure path, owner, effort level.
Schéma d’entrée
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID (optional)'}}, 'additionalProperties': False}
bridge_resolve
Start bridge resolution workflow. Generates templates (Risk Acceptance, Contract Renegotiation, Concentration Policy, Exit Strategy), tracks approval process. Call bridge_approve to sign off.
Schéma d’entrée
{'type': 'object', 'properties': {'check_id': {'type': 'string', 'description': 'Check to resolve: art30_c1, art30_c2, art30_c3, art8_c3, art31_c1'}, 'entity_id': {'type': 'string', 'description': 'Entity ID (optional)'}, 'expiry_days': {'type': 'integer', 'description': 'Days until resolution expires (default 30)'}}, 'additionalProperties': False}
bridge_status
Check status of all bridge resolution workflows for an entity. Shows open, pending, closed, rejected.
Schéma d’entrée
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID (optional)'}}, 'additionalProperties': False}
bus_status
Oracle Event Bus status: events, cross-refs, connected oracles.
Schéma d’entrée
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID for cross-refs'}}, 'additionalProperties': False}
check_contract
Check DORA Art. 30 contract clauses for a provider. Returns PASS/WARN/BLOCK with missing clauses and bridge classification.
Schéma d’entrée
{'type': 'object', 'properties': {'is_cif': {'type': 'boolean', 'description': 'Is this a CIF (Critical/Important Function) provider?'}, 'entity_id': {'type': 'string'}, 'cif_clauses': {'type': 'array', 'items': {'type': 'string'}, 'description': 'CIF clauses if applicable'}, 'provider_id': {'type': 'string', 'description': 'Provider ID'}, 'exit_strategy': {'type': 'boolean', 'description': 'Exit strategy documented?'}, 'standard_clauses': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Present standard clauses: service_description, data_location, data_protection, service_availability_sla, incident_notification, audit_right, termination_notice, cooperation_with_authorities'}}, 'additionalProperties': False}
collect_art10
Collect live Art. 10 evidence from NVD, CISA KEV, CERT-Bund. Auto-assesses.
Schéma d’entrée
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID (optional)'}}, 'additionalProperties': False}
contract_analyze
Analyze contract against 15 DORA Art. 30 mandatory clauses. Returns compliance status per clause with confidence score, extracted text, gap reasoning, suggested fix.
Schéma d’entrée
{'type': 'object', 'properties': {'document_id': {'type': 'string', 'description': 'Document ID from contract_upload'}}, 'additionalProperties': False}
contract_status
Overview of all analyzed contracts per entity. Shows clause gaps, review status, document versions.
Schéma d’entrée
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID'}}, 'additionalProperties': False}
contract_upload
Upload contract text for DORA Art. 30 analysis. Creates document record with SHA-256 hash, version tracking, audit trail.
Schéma d’entrée
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID'}, 'file_name': {'type': 'string', 'description': 'Original file name'}, 'contract_text': {'type': 'string', 'description': 'Contract text (extracted from PDF)'}, 'document_type': {'type': 'string', 'description': 'ict_outsourcing_agreement | dpa | sla | master_service_agreement'}, 'provider_name': {'type': 'string', 'description': 'Provider name'}}, 'additionalProperties': False}
create_entity
Register a new regulated entity.
Schéma d’entrée
{'type': 'object', 'properties': {'lei': {'type': 'string'}, 'name': {'type': 'string', 'description': 'Entity name'}, 'entity_type': {'type': 'string', 'description': 'Type'}, 'jurisdiction': {'type': 'string'}}, 'additionalProperties': False}
create_trial
Create temporary trial entity (48h) for self-service DORA assessment. No login needed.
Schéma d’entrée
{'type': 'object', 'properties': {'providers': {'enum': ['AWS', 'SWIFT'], 'type': 'string', 'description': 'Comma-separated provider names: AWS,SWIFT,Finastra'}, 'entity_name': {'type': 'string', 'description': 'Institute name'}, 'entity_type': {'type': 'string', 'description': 'credit_institution|payment_institution|insurance_undertaking|asset_management|credit_institution_casp'}, 'jurisdiction': {'type': 'string', 'description': 'DE|AT|FR|etc'}}, 'additionalProperties': False}
cross_oracle_assess
Enterprise cross-oracle assessment. Runs 18 checks across CyberShield (NIS2/ISO 27001), SupplyChainOracle (LkSG/CSRD), HealthGuard (MDR/GDPR), CFOCoPilot (XRechnung), TaxOracle (DAC6), LegalTechOracle (DORA contracts). Auto-stores evidence and updates Ampel status.
Schéma d’entrée
{'type': 'object', 'properties': {'checks': {'type': 'string', 'description': 'Comma-separated check IDs or omit for all'}, 'entity_id': {'type': 'string', 'description': 'Entity to assess'}}, 'additionalProperties': False}
cross_regulation_check
Tag findings with cross-regulation impact (DORA + MiCA + AMLR). Shows which DORA findings also affect MiCA insider info or AMLR screening.
Schéma d’entrée
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID'}}, 'additionalProperties': False}
cve_asset_map
Map CVE/vulnerability to internal ICT providers and systems. Auto-creates findings for critical matches. DORA Art. 10.
Schéma d’entrée
{'type': 'object', 'properties': {'cve_id': {'type': 'string', 'description': 'CVE identifier'}, 'vendor': {'type': 'string', 'description': 'Vendor/software name to check'}, 'entity_id': {'type': 'string'}}, 'additionalProperties': False}
dependency_graph
Full provider dependency graph: providers, systems, checks, blast radius, SPOF detection.
Schéma d’entrée
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID'}}, 'additionalProperties': False}
entity_list
List all registered regulated entities.
Schéma d’entrée
{'type': 'object', 'properties': {}, 'additionalProperties': False}
escalation_status
Get findings, SLA breaches, escalation status per entity.
Schéma d’entrée
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID (empty=all)'}}, 'additionalProperties': False}
evidence_pack
Export evidence pack for article/check/entity. Pruefer-ready: evidence, assessments, findings, audit trail, signatures.
Schéma d’entrée
{'type': 'object', 'properties': {'article': {'type': 'string', 'description': 'DORA article e.g. Art. 10'}, 'check_id': {'type': 'string', 'description': 'Specific check ID'}, 'entity_id': {'type': 'string', 'description': 'Entity ID'}}, 'additionalProperties': False}
evidence_summary
All evidence artefacts for an entity with hashes and expiry dates.
Schéma d’entrée
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID (optional)'}}, 'additionalProperties': False}
freshness_check
Run freshness watchdog. Expires stale evidence, downgrades GREEN->YELLOW->GREY if evidence too old.
Schéma d’entrée
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID (optional, checks all)'}}, 'additionalProperties': False}
gap_report
DORA compliance gaps. RED/GREY/YELLOW items with priority and required actions.
Schéma d’entrée
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID (optional)'}}, 'additionalProperties': False}
generate_report
Generate data-driven DORA Ampel PDF report. Score, gap analysis, provider register, audit trail integrity.
Schéma d’entrée
{'type': 'object', 'properties': {'format': {'type': 'string', 'default': 'json', 'description': 'json (meta) or pdf (download)'}, 'entity_id': {'type': 'string', 'description': 'Entity ID (optional)'}}, 'additionalProperties': False}
generate_trial_report
Generate watermarked trial report with score, gaps, and CTA.
Schéma d’entrée
{'type': 'object', 'properties': {'trial_id': {'type': 'string'}, 'entity_id': {'type': 'string'}}, 'additionalProperties': False}
health_check
Server + DB status.
Schéma d’entrée
{'type': 'object', 'properties': {}, 'additionalProperties': False}
incident_flow
DORA incident lifecycle: log, classify, notify (BaFin), close. Each step creates signed evidence.
Schéma d’entrée
{'type': 'object', 'properties': {'title': {'type': 'string'}, 'action': {'type': 'string', 'description': 'log | classify | notify | close'}, 'severity': {'type': 'string'}, 'entity_id': {'type': 'string', 'description': 'Entity ID'}, 'root_cause': {'type': 'string'}, 'description': {'type': 'string'}, 'incident_id': {'type': 'string'}, 'report_type': {'type': 'string'}, 'classification': {'type': 'string'}, 'lessons_learned': {'type': 'string'}}, 'additionalProperties': False}
llm_clause_check
LLM-based DORA Art. 30 contract analysis. Paste contract text, get clause-by-clause PRESENT/PARTIAL/MISSING for all 15 mandatory clauses. Uses Claude API.
Schéma d’entrée
{'type': 'object', 'properties': {'contract_text': {'type': 'string', 'description': 'Contract text (plain text from PDF). Paste key sections.'}, 'provider_name': {'type': 'string', 'description': 'Provider name e.g. Salesforce'}}, 'additionalProperties': False}
onboard_entity
Full entity onboarding: creates initial RED assessments for all 39 checks, collects auto-evidence from live sources, re-assesses, and returns readiness score.
Schéma d’entrée
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID to onboard'}}, 'additionalProperties': False}
ping
Quick connectivity test.
Schéma d’entrée
{'type': 'object', 'properties': {}, 'additionalProperties': False}
policy_draft
Generate DORA policy/framework document draft for a specific article. 8 templates available (Art. 5,6,8,10,11,17,28,30). Uses entity data for customization.
Schéma d’entrée
{'type': 'object', 'properties': {'entity_id': {'type': 'string'}, 'dora_article': {'type': 'string', 'description': 'dora_art5|dora_art6|dora_art8|dora_art10|dora_art11|dora_art17|dora_art28|dora_art30'}}, 'additionalProperties': False}
provider_country_risk
Enrich provider dependencies with OECD economic risk: GDP, unemployment, CLI per provider country. DORA Art. 28-31 relevant.
Schéma d’entrée
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID'}}, 'additionalProperties': False}
readiness_check
Full DORA readiness score + Ampel per article. Returns GREEN/YELLOW/RED/GREY for all 26 articles, score 0-100, days until deadline.
Schéma d’entrée
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID (optional)'}}, 'additionalProperties': False}
register_provider
Register an ICT third-party provider for DORA Art. 28 Register of Information. Stores provider data and creates evidence.
Schéma d’entrée
{'type': 'object', 'properties': {'lei': {'type': 'string', 'description': 'Legal Entity Identifier'}, 'services': {'type': 'string', 'description': 'Services provided'}, 'entity_id': {'type': 'string'}, 'criticality': {'type': 'string', 'description': 'critical, important, standard'}, 'contract_end': {'type': 'string'}, 'headquarters': {'type': 'string', 'description': 'Country e.g. Luxembourg, Germany'}, 'data_location': {'type': 'string', 'description': 'Where data is stored e.g. EU (Frankfurt)'}, 'provider_name': {'type': 'string', 'description': 'Provider name e.g. Amazon Web Services EMEA SARL'}, 'provider_type': {'type': 'string', 'description': 'cloud_infrastructure, saas_application, core_banking, cybersecurity, etc.'}, 'certifications': {'type': 'string'}, 'contract_start': {'type': 'string'}, 'annual_cost_eur': {'type': 'number'}, 'substitutability': {'type': 'string'}}, 'additionalProperties': False}
regulation_impact
Show cross-regulation impacts for a specific DORA article. Maps DORA → MiCA + AMLR.
Schéma d’entrée
{'type': 'object', 'properties': {'dora_article': {'type': 'string', 'description': 'DORA article ID (e.g. dora_art28)'}}, 'additionalProperties': False}
reg_watchdog
AI Regulatory Watchdog: scrapes EBA/ESMA/BaFin/CERT-Bund for DORA updates. Returns alerts with affected articles and severity. Run daily via cron or on-demand.
Schéma d’entrée
{'type': 'object', 'properties': {'days_back': {'type': 'integer', 'description': 'Check items from last N days (default: 7)'}}, 'additionalProperties': False}
retest_finding
Re-test a finding: collect fresh evidence, reassess check, auto-close if GREEN. Full closed-loop.
Schéma d’entrée
{'type': 'object', 'properties': {'finding_id': {'type': 'string', 'description': 'Finding ID to re-test'}}, 'additionalProperties': False}
run_escalation
Trigger escalation engine: auto-create findings, check SLA, escalate.
Schéma d’entrée
{'type': 'object', 'properties': {}, 'additionalProperties': False}
run_trial_assessment
Run complete DORA+MiCA assessment for trial entity. Returns score, gaps, automation potential.
Schéma d’entrée
{'type': 'object', 'properties': {'trial_id': {'type': 'string'}, 'entity_id': {'type': 'string'}}, 'additionalProperties': False}
score_trend
Score trend over time: weekly deltas, trajectory, peer benchmark. Shows improvement or decline.
Schéma d’entrée
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID'}}, 'additionalProperties': False}
servicenow_sync
ServiceNow incident + change management sync. DORA Art. 17/21 evidence. Returns 30-day incident stats, classification, resolution rates.
Schéma d’entrée
{'type': 'object', 'properties': {'days_back': {'type': 'integer', 'description': 'Days to look back (default 30)'}}, 'additionalProperties': False}
update_finding
Update finding lifecycle: claim, set remediation plan, request re-test, close, or accept risk. Status flow: open -> in_progress -> retest_pending -> closed | risk_accepted.
Schéma d’entrée
{'type': 'object', 'properties': {'actor': {'type': 'string', 'description': 'Who is performing this action'}, 'owner': {'type': 'string', 'description': 'New owner (for claim)'}, 'action': {'type': 'string', 'description': 'claim | plan | request_retest | close | accept_risk'}, 'reason': {'type': 'string', 'description': 'Close reason (for close)'}, 'finding_id': {'type': 'string', 'description': 'Finding ID'}, 'accepted_by': {'type': 'string', 'description': 'Name (for accept_risk)'}, 'expiry_days': {'type': 'integer', 'description': 'Risk acceptance expiry days (default 90)'}, 'remediation_plan': {'type': 'string', 'description': 'Remediation plan text (for plan)'}}, 'additionalProperties': False}
whatif_provider
Simulate provider failure: which articles/checks are affected, score impact, risk level.
Schéma d’entrée
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID'}, 'provider_name': {'type': 'string', 'description': 'Provider name (e.g. AWS, Finastra)'}}, 'additionalProperties': False}
whatif_stale
Simulate stale evidence: what happens if a check stays stale for N days.
Schéma d’entrée
{'type': 'object', 'properties': {'days': {'type': 'integer', 'description': 'Days stale (default 30)'}, 'check_id': {'type': 'string', 'description': 'Check ID'}, 'entity_id': {'type': 'string', 'description': 'Entity ID'}}, 'additionalProperties': False}
Ajouté
generate_trial_report
17 September 2026 12:53
Ajouté
run_trial_assessment
17 September 2026 12:53
Ajouté
create_trial
17 September 2026 12:53
Ajouté
policy_draft
17 September 2026 12:53
Ajouté
cve_asset_map
17 September 2026 12:53
Ajouté
bafin_approve_send
17 September 2026 12:53
Ajouté
bafin_report_draft
17 September 2026 12:53
Ajouté
regulation_impact
17 September 2026 12:53
Ajouté
cross_regulation_check
17 September 2026 12:53
Ajouté
contract_status
17 September 2026 12:53
Ajouté
contract_analyze
17 September 2026 12:53
Ajouté
contract_upload
17 September 2026 12:53
Ajouté
provider_country_risk
17 September 2026 12:53
Ajouté
evidence_pack
17 September 2026 12:53
Ajouté
incident_flow
17 September 2026 12:53
Ajouté
dependency_graph
17 September 2026 12:53
Ajouté
score_trend
17 September 2026 12:53
Ajouté
retest_finding
17 September 2026 12:53
Ajouté
update_finding
17 September 2026 12:53
Ajouté
board_summary
17 September 2026 12:53
Ajouté
whatif_stale
17 September 2026 12:53
Ajouté
whatif_provider
17 September 2026 12:53
Ajouté
run_escalation
17 September 2026 12:53
Ajouté
escalation_status
17 September 2026 12:53
Ajouté
bus_status
17 September 2026 12:53
Ajouté
ping
17 September 2026 12:53
Ajouté
health_check
17 September 2026 12:53
Ajouté
cross_oracle_assess
17 September 2026 12:53
Ajouté
llm_clause_check
17 September 2026 12:53
Ajouté
servicenow_sync
17 September 2026 12:53

Didit

io.github.pipeworx-io/didit

Provides identity and compliance capabilities including AML screening against sanctions and PEP lists, business verification, ben…

Compliance & Sanções

io.github.mcp-dir/compliance-mcp

Performs Brazilian due-diligence checks across PEP, sanctions, criminal, regulatory, fraud, tax, and government restriction datab…

WhiteIntel — Ownership Intelligence

dev.whiteintel/whiteintel

Resolves companies and people and maps ownership, beneficial ownership, sanctions, offshore exposure, financials, corporate filin…

outris-identity-mcp

io.github.outris-dev-user/outris-identity-mcp

Performs identity, KYC, fraud, business, phone, email, bank-account, PAN, GST, vehicle, and due-diligence lookups, including digi…

Ni Biashara Shelves — Africa FX, freight & compliance checks (x402)

biz.nibiashara/shelves

Provides African FX rates, freight carrier and broker authority checks, safety checks, OFAC sanctions screening, and Texas insura…

tlpt

io.tooloracle/tlpt

Supports TIBER-EU and DORA threat-led penetration testing with scenario generation, MITRE mapping, findings, evidence, scheduling…

Stipple — Document Verification & Extraction

sh.stipple/openwarrant

Inspects documents for authenticity, tampering, AI-generation indicators, extracted fields, citations, identity evidence, sanctio…

ContinueOps Public MCP

com.continueops/continueops-public

Provides compliance framework information, DORA readiness checks, business continuity plan structures, runbook templates, and res…