generated: '2026-08-27' method: generated source: openapi/drata-api-v2-openapi.yml + conventions/drata-conventions.yml + https://developers.drata.com/ provider: Drata providerId: drata description: >- Packaged Agent Skills for the Drata Public API v2. Every operationId referenced in these skills was read out of the harvested OpenAPI document — none is invented. Each skill carries the cross-cutting rules an agent needs and cannot see in the contract: workspace path scoping, cursor pagination, the 500 req/min per-source-IP limit, the 412 terms-acceptance gate, the absence of idempotency keys, and the absence of any reversal path. provider_published_skills: exists: partially repository: https://github.com/drata/drata-claude-plugin license: Apache-2.0 claim: >- Drata publishes an official Claude plugin marketplace whose README and .claude-plugin/marketplace.json describe a `drata-grc-skills` plugin — "17 job-to-be-done GRC skills plus a built-in help index over the Drata MCP". finding: >- The skill files themselves are NOT in the public repository. As of 2026-08-27 the tree on `main`, and on both `promote/drata-grc-skills-v3.8.12` and `FACE-150/promote-drata-grc-skills-3-8-12`, contains only .claude-plugin/marketplace.json, .github/CODEOWNERS, LICENSE and README.md. The referenced paths (plugins/drata-grc-skills/skills/*/SKILL.md, commands/*.md, shared/*.md, .mcp.json) do not exist on any branch, so `/plugin install drata-grc-skills@drata` cannot resolve. Nothing was copied verbatim because there was nothing to copy — the skills below are generated by API Evangelist from the contract, not harvested from Drata. probed: '2026-08-27' skills: - file: drata-audit-readiness-report.md name: drata-audit-readiness-report writes: false domains: [Frameworks, Controls, Monitoring Tests] operations: 8 - file: drata-evidence-upload.md name: drata-evidence-upload writes: true domains: [Evidence, Evidence Library, Uploads] operations: 9 - file: drata-risk-register-review.md name: drata-risk-register-review writes: true domains: [Risks, Risk Registers] operations: 8 - file: drata-vendor-security-review.md name: drata-vendor-security-review writes: true domains: [Vendors, Vendor Security Reviews] operations: 14 caution: sendSecurityQuestionnaire emails a real person at the vendor and is not idempotent. - file: drata-custom-connection-sync.md name: drata-custom-connection-sync writes: true domains: [Custom Connections, Custom Data Records] operations: 10 caution: Completing a session atomically REPLACES the active dataset.