Install
$ agentstack add skill-openapi-openapi-skills-openapi-risk ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Openapi Risk
Base URL: https://risk.openapi.com — reports and scores on natural and legal persons, sourced from CRIF, the Protest Register and other official registers.
Authentication: Bearer token — see the openapi-auth skill.
Credit score (synchronous, start here)
GET /IT-creditscore-top/{vatCode_taxCode_or_id}— top-level score for an Italian companyGET /IT-creditscore-start/…/GET /IT-creditscore-advanced/…— lighter/deeper variantsGET /IT-verifica_cf/{codice_fiscale}— fiscal code check
Reports (async: POST / → GET //{id} → GET //{id}/download for the PDF)
| Resource | Subject | |---|---| | IT-report-persona, IT-report-persona-top | Natural person report | | IT-patrimoniale-persona, IT-patrimoniale-persona-top | Patrimonial (assets) report | | IT-report-azienda, IT-report-azienda-top | Company report | | IT-crif-persona, IT-crif-azienda | CRIF search (requires a signed delegation: upload via PATCH /{id}, template via GET /{id}/delega) | | IT-eredi-con-accettazione, IT-eredi-senza-accettazione | Heirs reports | | IT-negativita (+ GET /IT-negativita/{id}/dettaglio) | Negative events | | IT-richiesta | Generic request listing/status/download |
Worldwide KYC
POST /WW-kyc-full— full check; targeted:/WW-kyc-pep,/WW-kyc-sanction_list,/WW-kyc-adverse_mediaGET /WW-kyc-evidences,GET /WW-kyc-evidences/{id},GET /WW-kyc-evidences/{id}/{entity_id}— results and evidencesPOST|GET|DELETE /WW-kyc-full-monitor— continuous KYC monitoring
Compliance
- Several Risk services fall under the Italian TULPS regulation (Art. 6 license): the account must have completed identity-document verification in the console before activation.
- Reports are paid and can be expensive — check wallet credit and confirm with the user before launching them.
- Returned personal data is subject to GDPR: use only for the stated purpose, never store it in the repo.
Full spec: https://console.openapi.com/oas/en/risk.openapi.json
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: openapi
- Source: openapi/openapi-skills
- License: MIT
- Homepage: https://openapi.com
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.