Vendor portfolio

Your third-party portfolio at a glance — composition, assessment coverage, inherent against residual exposure, and what is waiting at intake.

PluginAreaAccess
drata-grc-skillsThird-Party & Vendor RiskRead-only

Purpose

  • Shows the portfolio split across current, prospective and archived vendors.
  • Reports assessment coverage and an inherent by residual grid.
  • Breaks exposure down by category, with a single intake bar for prospective vendors.

Access: This skill cannot change anything in Drata.

MCP tools used

MCP toolLevelOAuth scope
Get CompanyReadread:company
List VendorsReadread:vendor

This skill uses every scope listed above; without them it fails partway through. What any tool returns is bounded by your Drata role as well as the scope — see MCP Server setup.

Run it

Copy
Copied
/plugin marketplace add drata/drata-claude-plugin
/plugin install drata-grc-skills@drata

Then run the skill by name:

Copy
Copied
/drata-grc-skills:drata-vendor-report

Or ask for it in your own words:

  • "vendor risk overview"
  • "unassessed vendors"

Before you start

  • Connect the Drata MCP server. See MCP Server setup.
  • Your MCP OAuth configuration must grant the scopes behind the tools listed above.

Related skills

  • Vendors needing review — Seven checks across your current vendors, grouped by what the fix is, with a decision memo available for any single vendor.
  • Fix vendors — Work through vendor gaps from a single menu with live counts.