Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/openapi/openapi-skills/openapi-risknpx skills add openapi/openapi-skills --skill openapi-riskgit clone --depth 1 https://github.com/openapi/openapi-skillsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00059 | $0.00642 |
| Opus 5 | $0.00030 | $0.00321 |
| Sonnet 5 | $0.00012 | $0.00128 |
| Haiku 4.5 | $0.00006 | $0.00064 |
Grade A, and why
openapi-risk scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Openapi Risk
Base URL: https://risk.openapi.com — reports and scores on natural and legal persons, sourced from CRIF, the Protest Register and other official registers.
Authentication: Bearer token — see the openapi-auth skill.
Credit score (synchronous, start here)
GET /IT-creditscore-top/{vatCode_taxCode_or_id}— top-level score for an Italian companyGET /IT-creditscore-start/…/GET /IT-creditscore-advanced/…— lighter/deeper variantsGET /IT-verifica_cf/{codice_fiscale}— fiscal code check
Reports (async: POST /<type> → GET /<type>/{id} → GET /<type>/{id}/download for the PDF)
| Resource | Subject |
|---|---|
IT-report-persona, IT-report-persona-top |
Natural person report |
IT-patrimoniale-persona, IT-patrimoniale-persona-top |
Patrimonial (assets) report |
IT-report-azienda, IT-report-azienda-top |
Company report |
IT-crif-persona, IT-crif-azienda |
CRIF search (requires a signed delegation: upload via PATCH /{id}, template via GET /{id}/delega) |
IT-eredi-con-accettazione, IT-eredi-senza-accettazione |
Heirs reports |
IT-negativita (+ GET /IT-negativita/{id}/dettaglio) |
Negative events |
IT-richiesta |
Generic request listing/status/download |
Worldwide KYC
POST /WW-kyc-full— full check; targeted:/WW-kyc-pep,/WW-kyc-sanction_list,/WW-kyc-adverse_mediaGET /WW-kyc-evidences,GET /WW-kyc-evidences/{id},GET /WW-kyc-evidences/{id}/{entity_id}— results and evidencesPOST|GET|DELETE /WW-kyc-full-monitor— continuous KYC monitoring
Compliance
- Several Risk services fall under the Italian TULPS regulation (Art. 6 license): the account must have completed identity-document verification in the console before activation.
- Reports are paid and can be expensive — check wallet credit and confirm with the user before launching them.
- Returned personal data is subject to GDPR: use only for the stated purpose, never store it in the repo.
Full spec: https://console.openapi.com/oas/en/risk.openapi.json
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 42 lines · 59 tokens per session scan A 24fe37d9f147
openapi-risk is a skill published in the GitHub repository openapi/openapi-skills (2 stars, last pushed 2mo ago), licensed MIT. It adds 59 tokens to every session and 642 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
openapi-glossary
Use consistent OpenAPI terminology and definitions when writing documentation, educational material, and tooling guidance.
scalar-docs
Skill for writing and updating scalar.config.json — Scalar Docs configuration reference for users and LLMs.
scalar-design-system
Scalar's design system — design tokens, theming (@scalar/themes), CSS variables, and the @scalar/components library. Use when designing or implementing Scalar UI, especially with Paper (code-to-design / design-to-code), so output matches real Scalar tokens, colors, typography, spacing, and components instead of…
cloud-agents-starter
Minimal starter runbook for cloud agents to install dependencies, run packages, execute tests, and troubleshoot the Scalar monorepo quickly.
mock-server
Build, customize, and troubleshoot OpenAPI mock servers with @scalar/mock-server, including x-handler, x-seed, authentication, and Docker.
tests
Write clear, maintainable Vitest and Playwright tests with precise assertions, consistent structure, and strong behavioral coverage.