What problem does it solve?
Legacy data loss prevention (DLP) tools are built for network-centric, on-prem environments and completely miss AI-era exfiltration channels including LLM prompts, MCP tool-call arguments, RAG retrievals, embedding-store queries, and code-completion telemetry. This Skill eliminates the risk of false compliance confidence by identifying these gaps and mapping them to real-world threat patterns and cross-jurisdictional privacy requirements.
Core Features & Use Cases
- Multi-Framework Gap Mapping: Flags insufficient controls across 10+ global compliance regimes including NIST 800-53, ISO 27001, GDPR, HIPAA, SOC 2, and 35 other AI/security frameworks.
- AI-Channel DLP Audit: Enumerates and assesses coverage for modern exfiltration channels including LLM prompt egress, MCP tool argument inspection, RAG corpus retrieval, embedding-store membership inference, and IDE telemetry leaks.
- Prioritized Remediation Guidance: Uses the RWEP scoring model aligned with MITRE ATLAS v2026.06 and ATT&CK v19.1 TTPs to prioritize gaps based on real-world exploitation risk, AI-acceleration potential, and regulatory exposure.
- Use Case: A healthcare compliance team can use this Skill to identify that their existing boundary DLP controls cannot inspect LLM prompt content containing PHI under TLS, and implement SDK-level prompt logging and MCP gateway inspection as auditable compensating controls.
Quick Start
Use the dlp-gap-analysis skill to run a full audit of your organization's DLP coverage for AI-era exfiltration channels and generate a prioritized gap report mapped to your applicable compliance frameworks.