# io.tooloracle/ampel (remote · tooloracle.io)

AmpelOracle — 50-tool compliance traffic-light: Go/Caution/Stop signals for ESG, MiCA, AML.

- Trust score: 65/100 (medium)
- Change this week: +4
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- remote · `tooloracle.io`: 65/100 (this document), [markdown](https://verifymcp.io/servers/io-tooloracle-ampel/ampel-mcp.md), [page](https://verifymcp.io/servers/io-tooloracle-ampel/ampel-mcp)

## Channel facts

- Endpoint: `https://tooloracle.io/ampel/mcp/`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Endpoint Security**: 66/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not fully verified: no authorisation is required to call this server, and 50 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe.
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC is configured correctly; the domain's records validate against the full chain to the root.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 70/100
  - AI-judged instruction clarity (good).
  - Tool/resource definitions use about 3166 tokens (~63/item across 50 items; 50 tools + 0 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 27/100
  - Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 90/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 70% of tool parameters carry a description.
- **Capabilities**: 40/100
  - Spec-recency check failed: implements MCP spec 2025-03-26; the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add --transport http io-tooloracle-ampel https://tooloracle.io/ampel/mcp/
```

### Codex

```toml
[mcp_servers.io-tooloracle-ampel]
url = "https://tooloracle.io/ampel/mcp/"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "io-tooloracle-ampel": {
      "type": "remote",
      "url": "https://tooloracle.io/ampel/mcp/",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add io-tooloracle-ampel --url https://tooloracle.io/ampel/mcp/ --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  io-tooloracle-ampel:
    url: "https://tooloracle.io/ampel/mcp/"
```

### Other

```json
{
  "mcpServers": {
    "io-tooloracle-ampel": {
      "type": "http",
      "url": "https://tooloracle.io/ampel/mcp/"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-02 (score 65, +1)

No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-31 (score 64, +2)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 62, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-29 (score 62, +1)

No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-27 (score 61, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-26 (score 60)

First indexed and scored.

## MCP tools (50)

### `readiness_check` (~56 tokens)

Full DORA readiness score + Ampel per article. Returns GREEN/YELLOW/RED/GREY for all 26 articles, score 0-100, days until deadline.

Input parameters:

- `entity_id` (string): Entity ID (optional)

### `article_status` (~54 tokens)

Detailed Ampel for a specific DORA article. Each check with GREEN/YELLOW/RED conditions and evidence.

Input parameters:

- `article` (string): e.g. Art. 28
- `entity_id` (string): Entity ID

### `gap_report` (~38 tokens)

DORA compliance gaps. RED/GREY/YELLOW items with priority and required actions.

Input parameters:

- `entity_id` (string): Entity ID (optional)

### `evidence_summary` (~33 tokens)

All evidence artefacts for an entity with hashes and expiry dates.

Input parameters:

- `entity_id` (string): Entity ID (optional)

### `collect_art10` (~45 tokens)

Collect live Art. 10 evidence from NVD, CISA KEV, CERT-Bund. Auto-assesses.

Input parameters:

- `entity_id` (string): Entity ID (optional)

### `entity_list` (~14 tokens)

List all registered regulated entities.

### `create_entity` (~46 tokens)

Register a new regulated entity.

Input parameters:

- `entity_type` (string): Type
- `jurisdiction` (string)
- `lei` (string)
- `name` (string): Entity name

### `audit_trail` (~34 tokens)

Chain-linked audit log with integrity check.

Input parameters:

- `entity_id` (string)
- `limit` (integer): Max entries

### `generate_report` (~57 tokens)

Generate data-driven DORA Ampel PDF report. Score, gap analysis, provider register, audit trail integrity.

Input parameters:

- `entity_id` (string): Entity ID (optional)
- `format` (string): json (meta) or pdf (download)

### `freshness_check` (~47 tokens)

Run freshness watchdog. Expires stale evidence, downgrades GREEN->YELLOW->GREY if evidence too old.

Input parameters:

- `entity_id` (string): Entity ID (optional, checks all)

### `bridge_report` (~47 tokens)

Bridge gap analysis: classifies gaps by DATA/EVIDENCE/POLICY/WORKFLOW with closure path, owner, effort level.

Input parameters:

- `entity_id` (string): Entity ID (optional)

### `register_provider` (~190 tokens)

Register an ICT third-party provider for DORA Art. 28 Register of Information. Stores provider data and creates evidence.

Input parameters:

- `annual_cost_eur` (number)
- `certifications` (string)
- `contract_end` (string)
- `contract_start` (string)
- `criticality` (string): critical, important, standard
- `data_location` (string): Where data is stored e.g. EU (Frankfurt)
- `entity_id` (string)
- `headquarters` (string): Country e.g. Luxembourg, Germany
- `lei` (string): Legal Entity Identifier
- `provider_name` (string): Provider name e.g. Amazon Web Services EMEA SARL
- `provider_type` (string): cloud_infrastructure, saas_application, core_banking, cybersecurity, etc.
- `services` (string): Services provided
- `substitutability` (string)

### `check_contract` (~140 tokens)

Check DORA Art. 30 contract clauses for a provider. Returns PASS/WARN/BLOCK with missing clauses and bridge classification.

Input parameters:

- `cif_clauses` (array): CIF clauses if applicable
- `entity_id` (string)
- `exit_strategy` (boolean): Exit strategy documented?
- `is_cif` (boolean): Is this a CIF (Critical/Important Function) provider?
- `provider_id` (string): Provider ID
- `standard_clauses` (array): Present standard clauses: service_description, data_location, data_protection, service_availability_sla, incident_notification, audit_right, termination_notice, cooperation_with_authorities

### `assess_all` (~39 tokens)

Re-run full assessment for an entity. Recomputes Ampel statuses from all available evidence.

Input parameters:

- `entity_id` (string): Entity ID (optional)

### `onboard_entity` (~51 tokens)

Full entity onboarding: creates initial RED assessments for all 39 checks, collects auto-evidence from live sources, re-assesses, and returns readiness score.

Input parameters:

- `entity_id` (string): Entity ID to onboard

### `bridge_resolve` (~109 tokens)

Start bridge resolution workflow. Generates templates (Risk Acceptance, Contract Renegotiation, Concentration Policy, Exit Strategy), tracks approval process. Call bridge_approve to sign off.

Input parameters:

- `check_id` (string): Check to resolve: art30_c1, art30_c2, art30_c3, art8_c3, art31_c1
- `entity_id` (string): Entity ID (optional)
- `expiry_days` (integer): Days until resolution expires (default 30)

### `bridge_approve` (~101 tokens)

Approve or reject a bridge resolution. On approval: creates signed evidence, upgrades Ampel to GREEN, logs to audit chain.

Input parameters:

- `approved_by` (string): Name + role of approver (e.g. Dr. Mueller, CISO)
- `reject` (boolean): Set true to reject instead of approve
- `rejection_reason` (string): Reason for rejection (if rejecting)
- `resolution_id` (string): Resolution ID from bridge_resolve

### `bridge_status` (~40 tokens)

Check status of all bridge resolution workflows for an entity. Shows open, pending, closed, rejected.

Input parameters:

- `entity_id` (string): Entity ID (optional)

### `reg_watchdog` (~68 tokens)

AI Regulatory Watchdog: scrapes EBA/ESMA/BaFin/CERT-Bund for DORA updates. Returns alerts with affected articles and severity. Run daily via cron or on-demand.

Input parameters:

- `days_back` (integer): Check items from last N days (default: 7)

### `azure_ad_check` (~56 tokens)

Live Azure AD integration: MFA registration %, risky users, conditional access policies. DORA Art. 9 evidence. Requires Azure AD config in integrations_config.json.

Input parameters:

- `force_refresh` (boolean): Force fresh API call (default true)

### `servicenow_sync` (~56 tokens)

ServiceNow incident + change management sync. DORA Art. 17/21 evidence. Returns 30-day incident stats, classification, resolution rates.

Input parameters:

- `days_back` (integer): Days to look back (default 30)

### `llm_clause_check` (~81 tokens)

LLM-based DORA Art. 30 contract analysis. Paste contract text, get clause-by-clause PRESENT/PARTIAL/MISSING for all 15 mandatory clauses. Uses Claude API.

Input parameters:

- `contract_text` (string): Contract text (plain text from PDF). Paste key sections.
- `provider_name` (string): Provider name e.g. Salesforce

### `cross_oracle_assess` (~113 tokens)

Enterprise cross-oracle assessment. Runs 18 checks across CyberShield (NIS2/ISO 27001), SupplyChainOracle (LkSG/CSRD), HealthGuard (MDR/GDPR), CFOCoPilot (XRechnung), TaxOracle (DAC6), LegalTechOracle (DORA contracts). Auto-stores evidence and updates Ampel status.

Input parameters:

- `checks` (string): Comma-separated check IDs or omit for all
- `entity_id` (string): Entity to assess

### `health_check` (~13 tokens)

Server + DB status.

### `ping` (~11 tokens)

Quick connectivity test.

### `bus_status` (~37 tokens)

Oracle Event Bus status: events, cross-refs, connected oracles.

Input parameters:

- `entity_id` (string): Entity ID for cross-refs

### `escalation_status` (~33 tokens)

Get findings, SLA breaches, escalation status per entity.

Input parameters:

- `entity_id` (string): Entity ID (empty=all)

### `run_escalation` (~23 tokens)

Trigger escalation engine: auto-create findings, check SLA, escalate.

### `whatif_provider` (~55 tokens)

Simulate provider failure: which articles/checks are affected, score impact, risk level.

Input parameters:

- `entity_id` (string): Entity ID
- `provider_name` (string): Provider name (e.g. AWS, Finastra)

### `whatif_stale` (~59 tokens)

Simulate stale evidence: what happens if a check stays stale for N days.

Input parameters:

- `check_id` (string): Check ID
- `days` (integer): Days stale (default 30)
- `entity_id` (string): Entity ID

### `board_summary` (~52 tokens)

Executive board summary: overall score, top 5 risks, overdue findings, SLA breaches, concentration risk, evidence health, owner workload. Designed for management/board reporting.

Input parameters:

- `entity_id` (string): Entity ID

### `update_finding` (~158 tokens)

Update finding lifecycle: claim, set remediation plan, request re-test, close, or accept risk. Status flow: open -> in_progress -> retest_pending -> closed | risk_accepted.

Input parameters:

- `accepted_by` (string): Name (for accept_risk)
- `action` (string): claim | plan | request_retest | close | accept_risk
- `actor` (string): Who is performing this action
- `expiry_days` (integer): Risk acceptance expiry days (default 90)
- `finding_id` (string): Finding ID
- `owner` (string): New owner (for claim)
- `reason` (string): Close reason (for close)
- `remediation_plan` (string): Remediation plan text (for plan)

### `retest_finding` (~45 tokens)

Re-test a finding: collect fresh evidence, reassess check, auto-close if GREEN. Full closed-loop.

Input parameters:

- `finding_id` (string): Finding ID to re-test

### `score_trend` (~38 tokens)

Score trend over time: weekly deltas, trajectory, peer benchmark. Shows improvement or decline.

Input parameters:

- `entity_id` (string): Entity ID

### `dependency_graph` (~36 tokens)

Full provider dependency graph: providers, systems, checks, blast radius, SPOF detection.

Input parameters:

- `entity_id` (string): Entity ID

### `incident_flow` (~117 tokens)

DORA incident lifecycle: log, classify, notify (BaFin), close. Each step creates signed evidence.

Input parameters:

- `action` (string): log | classify | notify | close
- `classification` (string)
- `description` (string)
- `entity_id` (string): Entity ID
- `incident_id` (string)
- `lessons_learned` (string)
- `report_type` (string)
- `root_cause` (string)
- `severity` (string)
- `title` (string)

### `evidence_pack` (~70 tokens)

Export evidence pack for article/check/entity. Pruefer-ready: evidence, assessments, findings, audit trail, signatures.

Input parameters:

- `article` (string): DORA article e.g. Art. 10
- `check_id` (string): Specific check ID
- `entity_id` (string): Entity ID

### `provider_country_risk` (~48 tokens)

Enrich provider dependencies with OECD economic risk: GDP, unemployment, CLI per provider country. DORA Art. 28-31 relevant.

Input parameters:

- `entity_id` (string): Entity ID

### `contract_upload` (~105 tokens)

Upload contract text for DORA Art. 30 analysis. Creates document record with SHA-256 hash, version tracking, audit trail.

Input parameters:

- `contract_text` (string): Contract text (extracted from PDF)
- `document_type` (string): ict_outsourcing_agreement | dpa | sla | master_service_agreement
- `entity_id` (string): Entity ID
- `file_name` (string): Original file name
- `provider_name` (string): Provider name

### `contract_analyze` (~54 tokens)

Analyze contract against 15 DORA Art. 30 mandatory clauses. Returns compliance status per clause with confidence score, extracted text, gap reasoning, suggested fix.

Input parameters:

- `document_id` (string): Document ID from contract_upload

### `contract_status` (~36 tokens)

Overview of all analyzed contracts per entity. Shows clause gaps, review status, document versions.

Input parameters:

- `entity_id` (string): Entity ID

### `cross_regulation_check` (~53 tokens)

Tag findings with cross-regulation impact (DORA + MiCA + AMLR). Shows which DORA findings also affect MiCA insider info or AMLR screening.

Input parameters:

- `entity_id` (string): Entity ID

### `regulation_impact` (~52 tokens)

Show cross-regulation impacts for a specific DORA article. Maps DORA → MiCA + AMLR.

Input parameters:

- `dora_article` (string): DORA article ID (e.g. dora_art28)

### `bafin_report_draft` (~133 tokens)

Generate ITS 2024/1772 compliant BaFin incident report draft. All mandatory fields per DORA Art. 19/20. Preview mode — requires board approval.

Input parameters:

- `affected_clients` (string)
- `affected_services` (string)
- `classification` (string): major | significant | minor
- `description` (string)
- `entity_id` (string)
- `incident_id` (string)
- `remediation` (string)
- `report_type` (string): initial | intermediate | final
- `root_cause` (string)
- `title` (string)

### `bafin_approve_send` (~63 tokens)

Approve BaFin report for submission (4-eyes principle). Creates signed approval evidence.

Input parameters:

- `approver_name` (string)
- `approver_role` (string)
- `entity_id` (string)
- `report_id` (string)

### `cve_asset_map` (~69 tokens)

Map CVE/vulnerability to internal ICT providers and systems. Auto-creates findings for critical matches. DORA Art. 10.

Input parameters:

- `cve_id` (string): CVE identifier
- `entity_id` (string)
- `vendor` (string): Vendor/software name to check

### `policy_draft` (~107 tokens)

Generate DORA policy/framework document draft for a specific article. 8 templates available (Art. 5,6,8,10,11,17,28,30). Uses entity data for customization.

Input parameters:

- `dora_article` (string): dora_art5|dora_art6|dora_art8|dora_art10|dora_art11|dora_art17|dora_art28|dora_art30
- `entity_id` (string)

### `create_trial` (~100 tokens)

Create temporary trial entity (48h) for self-service DORA assessment. No login needed.

Input parameters:

- `entity_name` (string): Institute name
- `entity_type` (string): credit_institution|payment_institution|insurance_undertaking|asset_management|credit_institution_casp
- `jurisdiction` (string): DE|AT|FR|etc
- `providers` (string): Comma-separated provider names: AWS,SWIFT,Finastra

### `run_trial_assessment` (~46 tokens)

Run complete DORA+MiCA assessment for trial entity. Returns score, gaps, automation potential.

Input parameters:

- `entity_id` (string)
- `trial_id` (string)

### `generate_trial_report` (~38 tokens)

Generate watermarked trial report with score, gaps, and CTA.

Input parameters:

- `entity_id` (string)
- `trial_id` (string)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/io-tooloracle-ampel/ampel-mcp#diagnostics

## Score history

- 2026-08-03: 65
- 2026-08-02: 65
- 2026-08-01: 64
- 2026-07-31: 64
- 2026-07-30: 62
- 2026-07-29: 62
- 2026-07-28: 61
- 2026-07-27: 61
- 2026-07-26: 60

## Links

- Remote endpoint: https://tooloracle.io/ampel/mcp/
- Repository: https://github.com/ToolOracle/ampel
- Changelog RSS feed: https://verifymcp.io/servers/io-tooloracle-ampel/ampel-mcp/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/io-tooloracle-ampel/ampel-mcp/changelog.json
- HTML version of this page: https://verifymcp.io/servers/io-tooloracle-ampel/ampel-mcp
