Marketplace Create skill Sign in

Drata Inspector Expert

Interpret drata-inspector findings generated from drata-cli workflows and turn Drata control, monitor, evidence, personnel, and integration posture into GRC action.

ID: 440e1e1a-dd1c-43fa-8836-b6ce886bec9c Version: 0.1.0 License: MIT Author: GRCEngClub Language: en Added: 2026-06-15
⬇ Download

Drata Inspector Expert

Use this skill when reviewing drata-inspector output or planning remediation from Drata workflow findings.

Source

drata-inspector wraps the MIT-licensed drata-cli workflow commands. It does not reimplement Drata APIs and does not require Drata MCP.

Output Shape

Findings are written to:

~/.cache/claude-grc/findings/drata-inspector/<run_id>.json

Resource types:

  • drata_tenant: summary status across controls, monitors, personnel, and integrations
  • drata_control: failing or incomplete controls from drata controls failing
  • drata_monitor: failed automated checks from drata monitors failing
  • drata_connection: disconnected, failed, or never-connected integrations
  • drata_personnel: personnel/device compliance issues
  • drata_evidence: stale or expiring evidence from drata evidence expiring

Review Guidance

  • Treat Drata-native control codes as source metadata. The connector emits SCF IDs for normalized downstream reporting.
  • Keep Drata as the evidence source of record; use these Findings for cross-framework gap analysis and engineering remediation.
  • inconclusive means a drata-cli workflow failed or permissions were insufficient.

Remediation Patterns

  • Assign owners for ownerless controls.
  • Refresh stale evidence and repair disconnected evidence sources.
  • Investigate failed monitors before assuming a control is ineffective.
  • Resolve personnel device compliance failures or document approved exceptions.
  • Reconnect Drata integrations that feed automated evidence.

Comments

Loading…

Related Skills

GENERAL · regulatory

Transaction screening workflow (concepts)

Educational map of transaction-centric compliance screening—transfer as the atomic unit, deposit vs withdrawal direction, single and CSV import, tran…

NeverSight
GENERAL · regulatory

TPRM Issue Summarization

Summarize Third-Party Risk Management issues including vendor risk exposure, assessment gaps, remediation status, and compliance impact across the TP…

GENERAL · regulatory

SWIFT Customer Security Programme (CSP) — CSCF v2025

Expert SWIFT Customer Security Programme (CSP) advisor covering the Customer Security Controls Framework (CSCF v2025). Use this skill whenever a user…

Sushegaad
GENERAL · regulatory

Legislation Knowledge Search

Search legislation text and knowledge base using semantic similarity under any supported legislation

rob-otix-ai
GENERAL · regulatory

Screening Alert Adjudication

Adjudicates whether a hit generated by sanctions, PEP, or adverse-media screening is a true positive, false positive, or requires human escalation. U…

Amir Fadavi