Drata Inspector Expert
Interpret drata-inspector findings generated from drata-cli workflows and turn Drata control, monitor, evidence, personnel, and integration posture into GRC action.
Drata Inspector Expert
Use this skill when reviewing drata-inspector output or planning remediation from Drata workflow findings.
Source
drata-inspector wraps the MIT-licensed drata-cli workflow commands. It does not reimplement Drata APIs and does not require Drata MCP.
Output Shape
Findings are written to:
~/.cache/claude-grc/findings/drata-inspector/<run_id>.json
Resource types:
drata_tenant: summary status across controls, monitors, personnel, and integrationsdrata_control: failing or incomplete controls fromdrata controls failingdrata_monitor: failed automated checks fromdrata monitors failingdrata_connection: disconnected, failed, or never-connected integrationsdrata_personnel: personnel/device compliance issuesdrata_evidence: stale or expiring evidence fromdrata evidence expiring
Review Guidance
- Treat Drata-native control codes as source metadata. The connector emits SCF IDs for normalized downstream reporting.
- Keep Drata as the evidence source of record; use these Findings for cross-framework gap analysis and engineering remediation.
inconclusivemeans adrata-cliworkflow failed or permissions were insufficient.
Remediation Patterns
- Assign owners for ownerless controls.
- Refresh stale evidence and repair disconnected evidence sources.
- Investigate failed monitors before assuming a control is ineffective.
- Resolve personnel device compliance failures or document approved exceptions.
- Reconnect Drata integrations that feed automated evidence.
No additional documents ship with this skill.
Related Skills
AI Governance Reviewer Skill
Use this skill when the user wants an AI governance, legal-risk, privacy, compliance, procurement, or vendor-risk review of an internal AI use case, …
ai-inventory
EU AI Act per-system inventory — track each AI system's role (provider, deployer, importer, distributor, authorized representative, product manufactu…
ai-inventory-anthropics
EU AI Act per-system inventory — track each AI system's role (provider, deployer, importer, distributor, authorized representative, product manufactu…
aia-generation
Run an AI impact assessment — structured intake, risk analysis, regulatory classification per regime in scope, policy consistency diff, and recommend…