Controls needing work
Two worklists over your not-ready controls — the ones with nothing mapped, and the ones whose manual evidence is out of date — plus any control missing an owner or a description.
| Plugin | Area | Access |
|---|---|---|
| drata-grc-skills | Compliance & Audit Readiness | Read-only |
Purpose
- Lists controls with no evidence, policy or monitor mapped.
- Lists controls whose manual evidence is no longer current.
- Flags in-scope controls with no owner or no description.
Access: This skill cannot change anything in Drata.
MCP tools used
| MCP tool | Level | OAuth scope |
|---|---|---|
| Get Company | Read | read:company |
| Search Controls | Read | read:controls |
This skill uses every scope listed above; without them it fails partway through. What any tool returns is bounded by your Drata role as well as the scope — see MCP Server setup.
Run it
/plugin marketplace add drata/drata-claude-plugin
/plugin install drata-grc-skills@drataThen run the skill by name:
/drata-grc-skills:drata-control-identify-gapsOr ask for it in your own words:
- "which controls have nothing mapped"
- "controls with no owner"
Before you start
- Connect the Drata MCP server. See MCP Server setup.
- Your MCP OAuth configuration must grant the scopes behind the tools listed above.
Related skills
- Fix controls — Work through control gaps from a single menu with live counts.
- Control readiness — How many of your controls are ready, and why the rest are not — in scope versus out, the ready share, and the not-ready ones broken down by cause.