Openapi Skills — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Openapi Skills (Plugin) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
Score rose 55 points between these scans.
The primary manifest — the file an agent reads to learn what this artifact does.
<div align="center"> <a href="https://openapi.com/"> <img alt="Openapi Skills" src=".github/assets/images/repo-header-a4.png" > </a>
<h1>🧩 Openapi® Skills</h1> <h4>Agent skills to interact with <a href="https://openapi.com/">Openapi®</a> APIs from Claude Code and any SKILL.md-compatible agent</h4>
Agent skills for using and integrating the services of the Openapi API marketplace — the largest certified API marketplace in Europe.
npx skills add openapi/openapi-skills| Folder | Purpose |
|---|---|
knowledge/ | Curated knowledge base: company profile, services catalog, platform guide (auth, billing, sandbox), FAQ, references, per-service endpoint docs and vendored OpenAPI specs |
skills/ | The agent skills, one folder per domain, each with a SKILL.md |
The two folders have strictly separated roles:
SKILL.md is populated from the knowledge but never links to it: an agent must be able to use a skill without this repository's knowledge/ folder being available.https://console.openapi.com/oas/en/<service>.openapi.json, the docs portal, the status page — not to local copies of them.Maintenance flow: update knowledge/ from the official sources first, then propagate the relevant content into the affected SKILL.md files.
| Skill | Covers |
|---|---|
| openapi-auth | OAuth v2 token lifecycle, scopes, wallet, usage stats (required by all others) |
| openapi-company | Company data: Italy, EU, worldwide |
| openapi-documents | Official documents: visure camerali, balance sheets, DURC, protests (DocuEngine, Visure Camerali, Visengine) |
| openapi-risk | Credit scores, CRIF reports, KYC, negative events |
| openapi-trust | Validation of emails, phones, IPs, URLs, PEC, fiscal codes, plates |
| openapi-geo | Geocoding, zip codes, Italian cadastre, real estate valuations |
| openapi-messaging | SMS v2, PEC, Massive REM, postal mail via Poste Italiane |
| openapi-esignature | eIDAS e-signatures and qualified time stamping |
| openapi-invoicing | Electronic invoicing (Invoice, SDI) and bill payments |
| openapi-automotive | Vehicle data by license plate |
| openapi-utilities | Exchange rates, HTML-to-PDF, .it domains, managed RAG |
Skills expect OPENAPI_EMAIL and OPENAPI_API_KEY (account credentials for oauth.openapi.com) and/or a ready-made OPENAPI_TOKEN Bearer token in the environment. See knowledge/platform-guide.md.
Contributions are always welcome! Whether you want to report bugs, suggest new features, improve documentation, or contribute code, your help is appreciated.
Meet our partners using Openapi or contributing to this project:
We believe in open source and we act on that belief. We became Silver Members of the Linux Foundation because we wanted to formally support the ecosystem we build on every day. Open standards, open collaboration, and open governance are part of how we work and how we think about software.
This project is licensed under the MIT License.
The MIT License is a permissive open-source license that allows you to freely use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the software, provided that the original copyright notice and this permission notice are included in all copies or substantial portions of the software.
For more details, see the full license text at the MIT License page.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.