Fix risks

Work the register from a single menu with live counts. Pick a gap, answer one question, and confirm one previewed batch before anything changes.

PluginAreaAccess
drata-grc-skillsRisk ManagementWrite

Purpose

  • Offers one flat menu: untreated, no owner, not scored, residual missing or wrong, treatment date passed or missing.
  • Previews every change as a batch and waits for your confirmation.
  • Logs, closes or deletes risks on request.

Access: This skill can change your Drata data: create / update / delete risk. Every change is previewed and confirmed before it is applied.

MCP tools used

MCP toolLevelOAuth scope
Get CompanyReadread:company
List Risk RegistersReadread:risk-registers
Search RisksReadread:risk
Create RiskWritecreate:risk
Update RiskWriteupdate:risk
Delete RiskWritedelete:risk

This skill uses every scope listed above; without them it fails partway through. What any tool returns is bounded by your Drata role as well as the scope — see MCP Server setup.

Run it

Copy
Copied
/plugin marketplace add drata/drata-claude-plugin
/plugin install drata-grc-skills@drata

Then run the skill by name:

Copy
Copied
/drata-grc-skills:drata-risk-resolve-gaps

Or ask for it in your own words:

  • "work the register"
  • "treat this risk"
  • "mark risk accepted"

Before you start

  • Connect the Drata MCP server. See MCP Server setup.
  • Your MCP OAuth configuration must grant the scopes behind the tools listed above.

Related skills

  • Risks needing work — Only the risks where the record is incomplete or contradictory and someone owes an edit.