Risks needing work
Only the risks where the record is incomplete or contradictory and someone owes an edit. Risks already assessed and treated are counted, not listed.
| Plugin | Area | Access |
|---|---|---|
| drata-grc-skills | Risk Management | Read-only |
Purpose
- Lists risks that are untreated, unowned or unscored.
- Flags records with no residual score, no reduction, or a residual above inherent.
- Lists treatments that are overdue or have no date.
Access: This skill cannot change anything in Drata.
MCP tools used
| MCP tool | Level | OAuth scope |
|---|---|---|
| Get Company | Read | read:company |
| List Risk Registers | Read | read:risk-registers |
| Search Risks | Read | read:risk |
| Search Controls | Read | read:controls |
This skill uses every scope listed above; without them it fails partway through. What any tool returns is bounded by your Drata role as well as the scope — see MCP Server setup.
Run it
/plugin marketplace add drata/drata-claude-plugin
/plugin install drata-grc-skills@drataThen run the skill by name:
/drata-grc-skills:drata-risk-identify-gapsOr ask for it in your own words:
- "which risks need attention"
- "overdue treatments"
Before you start
- Connect the Drata MCP server. See MCP Server setup.
- Your MCP OAuth configuration must grant the scopes behind the tools listed above.
Related skills
- Fix risks — Work the register from a single menu with live counts.
- Risk posture — The visual risk dashboard — headline numbers, a likelihood-by-impact heat map, treatment status per register, and where risk concentrates.