Risks needing work

Only the risks where the record is incomplete or contradictory and someone owes an edit. Risks already assessed and treated are counted, not listed.

PluginAreaAccess
drata-grc-skillsRisk ManagementRead-only

Purpose

  • Lists risks that are untreated, unowned or unscored.
  • Flags records with no residual score, no reduction, or a residual above inherent.
  • Lists treatments that are overdue or have no date.

Access: This skill cannot change anything in Drata.

MCP tools used

MCP toolLevelOAuth scope
Get CompanyReadread:company
List Risk RegistersReadread:risk-registers
Search RisksReadread:risk
Search ControlsReadread:controls

This skill uses every scope listed above; without them it fails partway through. What any tool returns is bounded by your Drata role as well as the scope — see MCP Server setup.

Run it

Copy
Copied
/plugin marketplace add drata/drata-claude-plugin
/plugin install drata-grc-skills@drata

Then run the skill by name:

Copy
Copied
/drata-grc-skills:drata-risk-identify-gaps

Or ask for it in your own words:

  • "which risks need attention"
  • "overdue treatments"

Before you start

  • Connect the Drata MCP server. See MCP Server setup.
  • Your MCP OAuth configuration must grant the scopes behind the tools listed above.

Related skills

  • Fix risks — Work the register from a single menu with live counts.
  • Risk posture — The visual risk dashboard — headline numbers, a likelihood-by-impact heat map, treatment status per register, and where risk concentrates.