Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

io.tooloracle/ampel

REMOTE · TOOLORACLE.IO · SCANNED AUG 3

AmpelOracle — 50-tool compliance traffic-light: Go/Caution/Stop signals for ESG, MiCA, AML.

Available components

+4 this week 65 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →

Endpoint Security66
  • The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
  • Authorisation not fully verified: no authorisation is required to call this server, and 50 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
  • HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
  • The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
  • DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
Schema Quality & AI Usability70
  • AI-judged instruction clarity (good).Pass
  • Tool/resource definitions use about 3166 tokens (~63/item across 50 items; 50 tools + 0 resources), lean.Pass
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
  • Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage90
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 70% of tool parameters carry a description.Partial
Capabilities40
  • Spec-recency check failed: implements MCP spec 2025-03-26; the latest is 2026-07-28. See how to fix → Fail
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

remote · tooloracle.io

# add to Claude Code
claude mcp add --transport http io-tooloracle-ampel https://tooloracle.io/ampel/mcp/
# ~/.codex/config.toml
[mcp_servers.io-tooloracle-ampel]
url = "https://tooloracle.io/ampel/mcp/"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "io-tooloracle-ampel": {
      "type": "remote",
      "url": "https://tooloracle.io/ampel/mcp/",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add io-tooloracle-ampel --url https://tooloracle.io/ampel/mcp/ --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  io-tooloracle-ampel:
    url: "https://tooloracle.io/ampel/mcp/"
// mcp.json
{
  "mcpServers": {
    "io-tooloracle-ampel": {
      "type": "http",
      "url": "https://tooloracle.io/ampel/mcp/"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 2 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.

  • 31 Jul 26 +2
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 29 Jul 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

  • 27 Jul 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 26 Jul 26 60

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Aug 2026 · Probed https://tooloracle.io/ampel/mcp/

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=tooloracle.io CN=YE1,O=Let's Encrypt,C=US 15 Jul 2026 13 Oct 2026 ECDSA 256 ECDSA-SHA384 5f17476491787e67dfd3d995c4c2b1679c9
SANs: mcp.tooloracle.io, tooloracle.io, www.tooloracle.io
CN=YE1,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 5ddd70dd31f801c85c186a7a04b80afe
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd
DNSSEC secure

Validation of tooloracle.io. Secure

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
io. present 57355 8 Verified
tooloracle.io. present 45856 8 Verified
tooloracle.io. Verified address RRset verified with the apex keys
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Header Value
strict-transport-security max-age=31536000; includeSubDomains; preload
content-security-policy default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: https:; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://api.feedoracle.io https://tooloracle.io https://*.tooloracle.io https://fonts.googleapis.com wss://*.tooloracle.io; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none';
x-content-type-options nosniff
x-frame-options DENY
referrer-policy strict-origin-when-cross-origin
permissions-policy geolocation=(), microphone=(), camera=()
Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://tooloracle.io/ampel/mcp/ Verified 200
http (plaintext) http://tooloracle.io/ampel/mcp/ HTTPS enforced 308 https://tooloracle.io/ampel/mcp/
MCP tools — 50 exposed · ~3,166 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
article_status ~54

Detailed Ampel for a specific DORA article. Each check with GREEN/YELLOW/RED conditions and evidence.

NameTypeReqDescription
articlestringe.g. Art. 28
entity_idstringEntity ID

No output schema declared.

No examples provided.

assess_all ~39

Re-run full assessment for an entity. Recomputes Ampel statuses from all available evidence.

NameTypeReqDescription
entity_idstringEntity ID (optional)

No output schema declared.

No examples provided.

audit_trail ~34

Chain-linked audit log with integrity check.

NameTypeReqDescription
entity_idstring
limitintegerMax entries

No output schema declared.

No examples provided.

azure_ad_check ~56

Live Azure AD integration: MFA registration %, risky users, conditional access policies. DORA Art. 9 evidence. Requires Azure AD config in integrations_config.json.

NameTypeReqDescription
force_refreshbooleanForce fresh API call (default true)

No output schema declared.

No examples provided.

bafin_approve_send ~63

Approve BaFin report for submission (4-eyes principle). Creates signed approval evidence.

NameTypeReqDescription
approver_namestring
approver_rolestring
entity_idstring
report_idstring

No output schema declared.

No examples provided.

bafin_report_draft ~133

Generate ITS 2024/1772 compliant BaFin incident report draft. All mandatory fields per DORA Art. 19/20. Preview mode — requires board approval.

NameTypeReqDescription
affected_clientsstring
affected_servicesstring
classificationstringmajor | significant | minor
descriptionstring
entity_idstring
incident_idstring
remediationstring
report_typestringinitial | intermediate | final
root_causestring
titlestring

No output schema declared.

No examples provided.

board_summary ~52

Executive board summary: overall score, top 5 risks, overdue findings, SLA breaches, concentration risk, evidence health, owner workload. Designed for management/board reporting.

NameTypeReqDescription
entity_idstringEntity ID

No output schema declared.

No examples provided.

bridge_approve ~101

Approve or reject a bridge resolution. On approval: creates signed evidence, upgrades Ampel to GREEN, logs to audit chain.

NameTypeReqDescription
approved_bystringName + role of approver (e.g. Dr. Mueller, CISO)
rejectbooleanSet true to reject instead of approve
rejection_reasonstringReason for rejection (if rejecting)
resolution_idstringResolution ID from bridge_resolve

No output schema declared.

No examples provided.

bridge_report ~47

Bridge gap analysis: classifies gaps by DATA/EVIDENCE/POLICY/WORKFLOW with closure path, owner, effort level.

NameTypeReqDescription
entity_idstringEntity ID (optional)

No output schema declared.

No examples provided.

bridge_resolve ~109

Start bridge resolution workflow. Generates templates (Risk Acceptance, Contract Renegotiation, Concentration Policy, Exit Strategy), tracks approval process. Call bridge_approve to sign off.

NameTypeReqDescription
check_idstringCheck to resolve: art30_c1, art30_c2, art30_c3, art8_c3, art31_c1
entity_idstringEntity ID (optional)
expiry_daysintegerDays until resolution expires (default 30)

No output schema declared.

No examples provided.

bridge_status ~40

Check status of all bridge resolution workflows for an entity. Shows open, pending, closed, rejected.

NameTypeReqDescription
entity_idstringEntity ID (optional)

No output schema declared.

No examples provided.

bus_status ~37

Oracle Event Bus status: events, cross-refs, connected oracles.

NameTypeReqDescription
entity_idstringEntity ID for cross-refs

No output schema declared.

No examples provided.

check_contract ~140

Check DORA Art. 30 contract clauses for a provider. Returns PASS/WARN/BLOCK with missing clauses and bridge classification.

NameTypeReqDescription
cif_clausesarrayCIF clauses if applicable
entity_idstring
exit_strategybooleanExit strategy documented?
is_cifbooleanIs this a CIF (Critical/Important Function) provider?
provider_idstringProvider ID
standard_clausesarrayPresent standard clauses: service_description, data_location, data_protection, service_availability_sla, incident_notification, audit_right, termination_notice, cooperation_with_authorities

No output schema declared.

No examples provided.

collect_art10 ~45

Collect live Art. 10 evidence from NVD, CISA KEV, CERT-Bund. Auto-assesses.

NameTypeReqDescription
entity_idstringEntity ID (optional)

No output schema declared.

No examples provided.

contract_analyze ~54

Analyze contract against 15 DORA Art. 30 mandatory clauses. Returns compliance status per clause with confidence score, extracted text, gap reasoning, suggested fix.

NameTypeReqDescription
document_idstringDocument ID from contract_upload

No output schema declared.

No examples provided.

contract_status ~36

Overview of all analyzed contracts per entity. Shows clause gaps, review status, document versions.

NameTypeReqDescription
entity_idstringEntity ID

No output schema declared.

No examples provided.

contract_upload ~105

Upload contract text for DORA Art. 30 analysis. Creates document record with SHA-256 hash, version tracking, audit trail.

NameTypeReqDescription
contract_textstringContract text (extracted from PDF)
document_typestringict_outsourcing_agreement | dpa | sla | master_service_agreement
entity_idstringEntity ID
file_namestringOriginal file name
provider_namestringProvider name

No output schema declared.

No examples provided.

create_entity ~46

Register a new regulated entity.

NameTypeReqDescription
entity_typestringType
jurisdictionstring
leistring
namestringEntity name

No output schema declared.

No examples provided.

create_trial ~100

Create temporary trial entity (48h) for self-service DORA assessment. No login needed.

NameTypeReqDescription
entity_namestringInstitute name
entity_typestringcredit_institution|payment_institution|insurance_undertaking|asset_management|credit_institution_casp
jurisdictionstringDE|AT|FR|etc
providersstringComma-separated provider names: AWS,SWIFT,Finastra

No output schema declared.

No examples provided.

cross_oracle_assess ~113

Enterprise cross-oracle assessment. Runs 18 checks across CyberShield (NIS2/ISO 27001), SupplyChainOracle (LkSG/CSRD), HealthGuard (MDR/GDPR), CFOCoPilot (XRechnung), TaxOracle (DAC6), LegalTechOracle (DORA contracts). Auto-stores evidence and updates Ampel status.

NameTypeReqDescription
checksstringComma-separated check IDs or omit for all
entity_idstringEntity to assess

No output schema declared.

No examples provided.

cross_regulation_check ~53

Tag findings with cross-regulation impact (DORA + MiCA + AMLR). Shows which DORA findings also affect MiCA insider info or AMLR screening.

NameTypeReqDescription
entity_idstringEntity ID

No output schema declared.

No examples provided.

cve_asset_map ~69

Map CVE/vulnerability to internal ICT providers and systems. Auto-creates findings for critical matches. DORA Art. 10.

NameTypeReqDescription
cve_idstringCVE identifier
entity_idstring
vendorstringVendor/software name to check

No output schema declared.

No examples provided.

dependency_graph ~36

Full provider dependency graph: providers, systems, checks, blast radius, SPOF detection.

NameTypeReqDescription
entity_idstringEntity ID

No output schema declared.

No examples provided.

entity_list ~14

List all registered regulated entities.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

escalation_status ~33

Get findings, SLA breaches, escalation status per entity.

NameTypeReqDescription
entity_idstringEntity ID (empty=all)

No output schema declared.

No examples provided.

evidence_pack ~70

Export evidence pack for article/check/entity. Pruefer-ready: evidence, assessments, findings, audit trail, signatures.

NameTypeReqDescription
articlestringDORA article e.g. Art. 10
check_idstringSpecific check ID
entity_idstringEntity ID

No output schema declared.

No examples provided.

evidence_summary ~33

All evidence artefacts for an entity with hashes and expiry dates.

NameTypeReqDescription
entity_idstringEntity ID (optional)

No output schema declared.

No examples provided.

freshness_check ~47

Run freshness watchdog. Expires stale evidence, downgrades GREEN->YELLOW->GREY if evidence too old.

NameTypeReqDescription
entity_idstringEntity ID (optional, checks all)

No output schema declared.

No examples provided.

gap_report ~38

DORA compliance gaps. RED/GREY/YELLOW items with priority and required actions.

NameTypeReqDescription
entity_idstringEntity ID (optional)

No output schema declared.

No examples provided.

generate_report ~57

Generate data-driven DORA Ampel PDF report. Score, gap analysis, provider register, audit trail integrity.

NameTypeReqDescription
entity_idstringEntity ID (optional)
formatstringjson (meta) or pdf (download)

No output schema declared.

No examples provided.

generate_trial_report ~38

Generate watermarked trial report with score, gaps, and CTA.

NameTypeReqDescription
entity_idstring
trial_idstring

No output schema declared.

No examples provided.

health_check ~13

Server + DB status.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

incident_flow ~117

DORA incident lifecycle: log, classify, notify (BaFin), close. Each step creates signed evidence.

NameTypeReqDescription
actionstringlog | classify | notify | close
classificationstring
descriptionstring
entity_idstringEntity ID
incident_idstring
lessons_learnedstring
report_typestring
root_causestring
severitystring
titlestring

No output schema declared.

No examples provided.

llm_clause_check ~81

LLM-based DORA Art. 30 contract analysis. Paste contract text, get clause-by-clause PRESENT/PARTIAL/MISSING for all 15 mandatory clauses. Uses Claude API.

NameTypeReqDescription
contract_textstringContract text (plain text from PDF). Paste key sections.
provider_namestringProvider name e.g. Salesforce

No output schema declared.

No examples provided.

onboard_entity ~51

Full entity onboarding: creates initial RED assessments for all 39 checks, collects auto-evidence from live sources, re-assesses, and returns readiness score.

NameTypeReqDescription
entity_idstringEntity ID to onboard

No output schema declared.

No examples provided.

ping ~11

Quick connectivity test.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

policy_draft ~107

Generate DORA policy/framework document draft for a specific article. 8 templates available (Art. 5,6,8,10,11,17,28,30). Uses entity data for customization.

NameTypeReqDescription
dora_articlestringdora_art5|dora_art6|dora_art8|dora_art10|dora_art11|dora_art17|dora_art28|dora_art30
entity_idstring

No output schema declared.

No examples provided.

provider_country_risk ~48

Enrich provider dependencies with OECD economic risk: GDP, unemployment, CLI per provider country. DORA Art. 28-31 relevant.

NameTypeReqDescription
entity_idstringEntity ID

No output schema declared.

No examples provided.

readiness_check ~56

Full DORA readiness score + Ampel per article. Returns GREEN/YELLOW/RED/GREY for all 26 articles, score 0-100, days until deadline.

NameTypeReqDescription
entity_idstringEntity ID (optional)

No output schema declared.

No examples provided.

reg_watchdog ~68

AI Regulatory Watchdog: scrapes EBA/ESMA/BaFin/CERT-Bund for DORA updates. Returns alerts with affected articles and severity. Run daily via cron or on-demand.

NameTypeReqDescription
days_backintegerCheck items from last N days (default: 7)

No output schema declared.

No examples provided.

register_provider ~190

Register an ICT third-party provider for DORA Art. 28 Register of Information. Stores provider data and creates evidence.

NameTypeReqDescription
annual_cost_eurnumber
certificationsstring
contract_endstring
contract_startstring
criticalitystringcritical, important, standard
data_locationstringWhere data is stored e.g. EU (Frankfurt)
entity_idstring
headquartersstringCountry e.g. Luxembourg, Germany
leistringLegal Entity Identifier
provider_namestringProvider name e.g. Amazon Web Services EMEA SARL
provider_typestringcloud_infrastructure, saas_application, core_banking, cybersecurity, etc.
servicesstringServices provided
substitutabilitystring

No output schema declared.

No examples provided.

regulation_impact ~52

Show cross-regulation impacts for a specific DORA article. Maps DORA → MiCA + AMLR.

NameTypeReqDescription
dora_articlestringDORA article ID (e.g. dora_art28)

No output schema declared.

No examples provided.

retest_finding ~45

Re-test a finding: collect fresh evidence, reassess check, auto-close if GREEN. Full closed-loop.

NameTypeReqDescription
finding_idstringFinding ID to re-test

No output schema declared.

No examples provided.

run_escalation ~23

Trigger escalation engine: auto-create findings, check SLA, escalate.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

run_trial_assessment ~46

Run complete DORA+MiCA assessment for trial entity. Returns score, gaps, automation potential.

NameTypeReqDescription
entity_idstring
trial_idstring

No output schema declared.

No examples provided.

score_trend ~38

Score trend over time: weekly deltas, trajectory, peer benchmark. Shows improvement or decline.

NameTypeReqDescription
entity_idstringEntity ID

No output schema declared.

No examples provided.

servicenow_sync ~56

ServiceNow incident + change management sync. DORA Art. 17/21 evidence. Returns 30-day incident stats, classification, resolution rates.

NameTypeReqDescription
days_backintegerDays to look back (default 30)

No output schema declared.

No examples provided.

update_finding ~158

Update finding lifecycle: claim, set remediation plan, request re-test, close, or accept risk. Status flow: open -> in_progress -> retest_pending -> closed | risk_accepted.

NameTypeReqDescription
accepted_bystringName (for accept_risk)
actionstringclaim | plan | request_retest | close | accept_risk
actorstringWho is performing this action
expiry_daysintegerRisk acceptance expiry days (default 90)
finding_idstringFinding ID
ownerstringNew owner (for claim)
reasonstringClose reason (for close)
remediation_planstringRemediation plan text (for plan)

No output schema declared.

No examples provided.

whatif_provider ~55

Simulate provider failure: which articles/checks are affected, score impact, risk level.

NameTypeReqDescription
entity_idstringEntity ID
provider_namestringProvider name (e.g. AWS, Finastra)

No output schema declared.

No examples provided.

whatif_stale ~59

Simulate stale evidence: what happens if a check stays stale for N days.

NameTypeReqDescription
check_idstringCheck ID
daysintegerDays stale (default 30)
entity_idstringEntity ID

No output schema declared.

No examples provided.