Vendors needing review

Seven checks across your current vendors, grouped by what the fix is, with a decision memo available for any single vendor.

PluginAreaAccess
drata-grc-skillsThird-Party & Vendor RiskRead-only, with one optional write

Purpose

  • Finds security reviews never started, past deadline, or last completed over a year ago.
  • Flags overdue next reviews, missing business units, missing security owners and on-hold status.
  • Lists prospective vendors whose review has not started.

Access: Read-only, except that it can create a risk, and only when you explicitly confirm it.

MCP tools used

MCP toolLevelOAuth scope
Get CompanyReadread:company
List VendorsReadread:vendor
Get VendorReadread:vendor
List Vendor Security ReviewsReadread:vendor-security-review
List Vendor DocumentsReadread:vendor-document
Search RisksReadread:risk
Create RiskoptionalWritecreate:risk
This skill uses every scope above that is not marked optional; without them it fails partway through. The one marked optional (create:risk) is not required — the skill degrades cleanly without it. What any tool returns is bounded by your Drata role as well as the scope — see MCP Server setup.

Run it

Copy
Copied
/plugin marketplace add drata/drata-claude-plugin
/plugin install drata-grc-skills@drata

Then run the skill by name:

Copy
Copied
/drata-grc-skills:drata-vendor-identify-gaps

Or ask for it in your own words:

  • "which vendors need review"
  • "overdue security reviews"

Before you start

  • Connect the Drata MCP server. See MCP Server setup.
  • Your MCP OAuth configuration must grant the scopes behind the tools listed above.

Related skills

  • Fix vendors — Work through vendor gaps from a single menu with live counts.
  • Vendor portfolio — Your third-party portfolio at a glance — composition, assessment coverage, inherent against residual exposure, and what is waiting at intake.