← Back to search

io.github.CSOAI-ORG/ai-incident-reporting-mcp

CSOAI-ORG Scanned 17d ago

AI Incident Reporting Compliance MCP. Unified classification + reporting-clock tracker across EU...

B
80.9 / 100

Versions

1.0.2latest
first seen May 19, 2026
PermissionsTool SafetyAuthAnnotationsCode QualityStabilitySpecVuln HistoryAuthorTransparencyCommunity

Tools 3

classify_incident
annotations: none low

Classify an incident against every regime in scope. Returns the multi-regime decision tree: which clocks start, who to notify, on what form, by when.

api_key str entity_type str cross_border bool duration_hours float is_nis2_entity bool is_high_risk_ai bool economic_impact_eur float is_financial_entity bool incident_description str affected_people_count int is_iso42001_certified bool personal_data_breached bool is_frontier_model_developer bool
list_regime_clocks
annotations: none low

List the reporting clocks + authorities for every regime this MCP covers.

api_key str
sign_incident_response_attestation
annotations: none low

Generate a cryptographically signed AI incident-response attestation (Pro+). Captures: which regimes were notified, within which SLAs, what the response score was. Auditors consume the verify_url as evidence of post-incident compliance.

api_key str entity_name str incident_id str findings_csv str response_score float include_pdf_base64 bool regimes_notified_csv str

Permissions 3

network medium
Server uses network capabilities via: urllib
filesystem low
Server uses filesystem capabilities via: open(), os
env_vars low
Server uses env_vars capabilities via: os.environ

Scan Findings 25

info
Sandbox failed to start for behavioral verification behavioral_verifier · 100%
medium
Vulnerable dependency: mcp@1.0.0 (GHSA-3qhf-m339-9g5v) dependency_analyzer · 95%
low
Tool 'classify_incident' has no annotations annotation_checker · 100%
low
Tool 'list_regime_clocks' has no annotations annotation_checker · 100%
low
Tool 'sign_incident_response_attestation' has no annotations annotation_checker · 100%
medium
Vulnerable dependency: mcp@1.0.0 (GHSA-9h52-p55h-vw2f) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.0.0 (GHSA-j975-95f5-7wqh) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.0.0 (GHSA-jpw9-pfvf-9f58) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.0.0 (GHSA-vj7q-gjh5-988w) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.0.0 (PYSEC-2026-1616) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.0.0 (PYSEC-2026-1617) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.0.0 (PYSEC-2026-1618) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.0.0 (PYSEC-2026-3482) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.0.0 (PYSEC-2026-3483) dependency_analyzer · 95%
info
pyproject.toml metadata manifest_parser · 100%
info
Tool: classify_incident manifest_parser · 90%
info
Tool: list_regime_clocks manifest_parser · 90%
info
Tool: sign_incident_response_attestation manifest_parser · 90%
info
Required env vars (5) manifest_parser · 80%
info
Sandbox failed to start for output poisoning scan output_poisoning · 100%
medium
Permission: network access detected permission_analyzer · 80%
low
Permission: filesystem access detected permission_analyzer · 80%
low
Permission: env_vars access detected permission_analyzer · 90%
info
No dependency files found for SBOM generation sbom_generator · 100%
medium
No build provenance detected (SLSA L0) slsa_assessor · 90%