Agent Skills (Beta)
๐งช Beta Feature: Skills are available alongside the MCP Server, which is currently in early access.
Skills are packaged workflows for AI assistants connected to your Drata account through the Drata MCP server. Each one is named for the job it does: report to see where you stand, identify-gaps to get a worklist of what needs work, and resolve-gaps to make the changes.
Install once, then run a skill by name or just ask for it in your own words.
/plugin marketplace add drata/drata-claude-plugin
/plugin install drata-grc-skills@drataRead-only by default. Most skills only read. 4 skills can change your Drata data and are marked Write: Fix controls, Fix evidence, Fix risks, Fix vendors. One more can make a single write only when you confirm it: Vendors needing review. Every change is previewed for your confirmation before it is applied, and what any skill can reach is bounded by the scopes you grant and your Drata role.
One install, one grant. Installing the plugin brings all 18 skills, and you authorise the Drata MCP server once โ so the scopes you grant are the union of what every skill needs (27 scopes, 11 of them writes), not a per-skill choice. The tables on each page tell you what that skill uses, not what you can grant it alone.
Connect to Drata
The skills authenticate through the Drata MCP Server over OAuth โ nothing stores a credential. You need administrator access to create the OAuth configuration in Settings โ MCP Configuration, then point your client at the endpoint for your region:
- US:
https://mcp.drata.com/mcp/ - EU:
https://mcp-euc1.drata.com/mcp/ - APAC:
https://mcp-apse2.drata.com/mcp/
Start Here
What needs attention today
A cross-domain briefing of everything needing attention right now โ failing controls and tests, high open risks, expired evidence, overdue vendor reviews, non-compliant personnel.
Find the right skill
Lists every skill grouped by domain, explains the naming grammar, and points you at the best fit for what you are trying to do.
Compliance & Audit Readiness
Framework readiness
How ready a workspace is for a given framework โ readiness percentage, pass rates per area, and the requirements that are not yet met.
Control readiness
How many of your controls are ready, and why the rest are not โ in scope versus out, the ready share, and the not-ready ones broken down by cause.
Controls needing work
Two worklists over your not-ready controls โ the ones with nothing mapped, and the ones whose manual evidence is out of date โ plus any control missing an owner or a description.
Fix controls
Work through control gaps from a single menu with live counts. Pick a gap, answer one question, and confirm one previewed batch before anything changes.
Monitoring coverage
Where your monitoring stands โ how many tests are enabled, how many pass, fail or error, how long anything has been failing, and which check types account for the failures.
Evidence freshness
How current your evidence library is โ the share that is valid against what needs an artifact, is expiring soon, or has expired โ and why evidence goes stale.
Evidence needing work
Your evidence library sorted into four workable buckets, so an audit-prep sweep or a renewal plan starts from a list rather than a hunt.
Fix evidence
Work through evidence gaps from a single menu with live counts. Pick a gap, answer one question, and confirm one previewed batch before anything changes.
Risk Management
Risk posture
The visual risk dashboard โ headline numbers, a likelihood-by-impact heat map, treatment status per register, and where risk concentrates.
Risks needing work
Only the risks where the record is incomplete or contradictory and someone owes an edit. Risks already assessed and treated are counted, not listed.
Third-Party & Vendor Risk
Vendor portfolio
Your third-party portfolio at a glance โ composition, assessment coverage, inherent against residual exposure, and what is waiting at intake.
Vendors needing review
Seven checks across your current vendors, grouped by what the fix is, with a decision memo available for any single vendor.
Personnel & Access Compliance
Reporting & Stakeholder Communications
Examples
Paste any of these to see a skill run.
1. Control readiness โ "How ready are my controls for SOC 2?" Runs Control readiness: a readiness dashboard โ controls in scope versus out, the ready share, and the not-ready ones broken down by cause.
2. Failing evidence, prioritized โ "Which evidence is failing and what should I fix first?" Runs Evidence needing work: a named, prioritized worklist of the evidence that is missing or not satisfying readiness.
3. Third-party risk โ "Give me a third-party risk report for our vendors." Runs Vendor portfolio: a vendor overview โ risk posture, review coverage, and where the gaps are.
Privacy
The skills operate on your own Drata data, in your session, through your own OAuth grant. The plugin repository holds only natural-language prompts and a pointer to the Drata MCP endpoint โ no customer data, no credentials, and no Drata backend code. Your data is handled under Drata's privacy policy; for how Drata secures its platform, see the Trust Center.
Support
- Documentation and help: help.drata.com
- Security questions or reports:
[email protected]
When you reach out about a skill, include the skill name and the prompt you used โ that is enough to reproduce it.