Vendor portfolio
Your third-party portfolio at a glance — composition, assessment coverage, inherent against residual exposure, and what is waiting at intake.
| Plugin | Area | Access |
|---|---|---|
| drata-grc-skills | Third-Party & Vendor Risk | Read-only |
Purpose
- Shows the portfolio split across current, prospective and archived vendors.
- Reports assessment coverage and an inherent by residual grid.
- Breaks exposure down by category, with a single intake bar for prospective vendors.
Access: This skill cannot change anything in Drata.
MCP tools used
| MCP tool | Level | OAuth scope |
|---|---|---|
| Get Company | Read | read:company |
| List Vendors | Read | read:vendor |
This skill uses every scope listed above; without them it fails partway through. What any tool returns is bounded by your Drata role as well as the scope — see MCP Server setup.
Run it
/plugin marketplace add drata/drata-claude-plugin
/plugin install drata-grc-skills@drataThen run the skill by name:
/drata-grc-skills:drata-vendor-reportOr ask for it in your own words:
- "vendor risk overview"
- "unassessed vendors"
Before you start
- Connect the Drata MCP server. See MCP Server setup.
- Your MCP OAuth configuration must grant the scopes behind the tools listed above.
Related skills
- Vendors needing review — Seven checks across your current vendors, grouped by what the fix is, with a decision memo available for any single vendor.
- Fix vendors — Work through vendor gaps from a single menu with live counts.