← Back to search

io.github.CSOAI-ORG/meok-dora-tlpt-planner-mcp

CSOAI-ORG Scanned 25d ago

DORA Article 26 Threat-Led Penetration Testing planner — TIBER-EU pathway scoping, white-tea...

B
75.6 / 100

Versions

1.0.1latest
first seen Jun 5, 2026
1.0.3
first seen May 19, 2026
PermissionsTool SafetyAuthAnnotationsCode QualityStabilitySpecVuln HistoryAuthorTransparencyCommunity

Tools 6

pricing
annotations: none low

Pricing for MEOK DORA TLPT Planner.

scope_tlpt
annotations: none low

Generate a DORA Article 26 TLPT scope document for a financial entity. Args: entity_name: Legal name of the financial entity (e.g., "Acme Bank N.V."). entity_type: One of credit-institution / investment-firm / insurance / pension-fund / payment-institution / e-money-institution / market-infrastructure / CCP. sector: ISIC sector code (default: credit-institution). critical_functions: List of critical/important functions to be scoped (per Art. 26(2)). E.g., ["retail-payments", "trading-platform", "customer-onboarding"]. last_tlpt_date: ISO date of last TLPT (YYYY-MM-DD) — DORA mandates 3-year cycle. annual_budget_estimate_eur: Estimated TLPT engagement budget (drives RT-provider tier). Returns: Structured scope document with phase plan, deliverables, RACI, and budget breakdown.

sector str entity_name str entity_type str last_tlpt_date string critical_functions string annual_budget_estimate_eur string
threat_intel_brief
annotations: none low

Generate a Targeted Threat Intelligence (TTI) brief template per ECB TIBER-EU v2.0. This is a SCAFFOLD. Real TTI must be authored by an accredited threat-intel provider with current intelligence feeds. Use this template to brief them. Args: entity_name: Legal name of the financial entity. entity_sector: One of retail-banking, wholesale-banking, insurance, asset-management, market-infrastructure, payments, e-money. geographic_footprint: List of country codes where entity operates (e.g., ["DE", "NL", "IE"]). critical_functions: List of critical functions for which threats must be modelled. Returns: TTI template with sections aligned to TIBER-EU + ECB standards.

entity_name str entity_sector str critical_functions string geographic_footprint string
remediation_milestones
annotations: none low

Generate a 90/180/365-day remediation milestone plan based on TLPT findings. Args: findings_count: Total number of findings from the red-team report. severity_distribution: Dict with keys 'critical', 'high', 'medium', 'low' and counts. Returns: Milestone plan with required closure timelines per severity.

findings_count int severity_distribution string
signed_tlpt_attestation
annotations: none low

Produce an HMAC-signed TLPT attestation via the public meok-attestation-api. Args: entity_name: Legal name of the financial entity. scope_summary: 1-3 sentence summary of test scope. test_phase: One of preparation / testing / closure. findings_summary: Dict with findings_count, severity_distribution, and summary text. signing_role: Role of the signer (default white-team-lead). Returns: Signed attestation with verification URL.

test_phase str entity_name str signing_role str scope_summary str findings_summary string
list_phases
annotations: none low

List the 3 TIBER-EU TLPT phases with deliverables.

Permissions 3

network medium
Server uses network capabilities via: urllib
filesystem low
Server uses filesystem capabilities via: os
env_vars low
Server uses env_vars capabilities via: os.environ

Scan Findings 31

low
Tool 'scope_tlpt' has no annotations annotation_checker · 100%
low
Tool 'threat_intel_brief' has no annotations annotation_checker · 100%
low
Tool 'remediation_milestones' has no annotations annotation_checker · 100%
low
Tool 'signed_tlpt_attestation' has no annotations annotation_checker · 100%
low
Tool 'list_phases' has no annotations annotation_checker · 100%
low
Tool 'pricing' has no annotations annotation_checker · 100%
info
Sandbox failed to start for behavioral verification behavioral_verifier · 100%
medium
Vulnerable dependency: mcp@1.2.0 (GHSA-3qhf-m339-9g5v) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.2.0 (GHSA-9h52-p55h-vw2f) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.2.0 (GHSA-j975-95f5-7wqh) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.2.0 (GHSA-jpw9-pfvf-9f58) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.2.0 (GHSA-vj7q-gjh5-988w) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.2.0 (PYSEC-2026-1616) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.2.0 (PYSEC-2026-1617) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.2.0 (PYSEC-2026-1618) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.2.0 (PYSEC-2026-3482) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.2.0 (PYSEC-2026-3483) dependency_analyzer · 95%
info
pyproject.toml metadata manifest_parser · 100%
info
Tool: scope_tlpt manifest_parser · 90%
info
Tool: threat_intel_brief manifest_parser · 90%
info
Tool: remediation_milestones manifest_parser · 90%
info
Tool: signed_tlpt_attestation manifest_parser · 90%
info
Tool: list_phases manifest_parser · 90%
info
Tool: pricing manifest_parser · 90%
info
Required env vars (1) manifest_parser · 80%
info
Sandbox failed to start for output poisoning scan output_poisoning · 100%
medium
Permission: network access detected permission_analyzer · 80%
low
Permission: filesystem access detected permission_analyzer · 70%
low
Permission: env_vars access detected permission_analyzer · 90%
info
No dependency files found for SBOM generation sbom_generator · 100%
medium
No build provenance detected (SLSA L0) slsa_assessor · 90%