Agent skill

Payuni Query

by paid-tw in paid-tw/skills

Implements PAYUNi transaction query functionality using Query API.

MITAuto-check: notesBackend & APIs

Install Payuni Query

skills CLI
$ npx skills add paid-tw/skills --skill payuni-query -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install paid-tw/skills payuni-query --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/paid-tw/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/payuni/skills/payuni-query .claude/skills/payuni-query && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
payuni-query
GitHub stars
284
Token cost
~948 tokens
SKILL.md length
115 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

Implements PAYUNi transaction query functionality using Query API.

  • Works in 4 steps: 確認需求 → 建立查詢功能 → 實作程式碼 → …
  • Building order status checking
  • SKILL.md covers Step 1: 確認需求, Step 2: 建立查詢功能, Step 3: 實作程式碼 and Step 4: 整合到應用, plus 3 more sections
  • Reaches sandbox-api.payuni.com.tw and api.payuni.com.tw; needs PAYUNI_HASH_KEY

What it does

Payuni Query is an agent skill from paid-tw/skills. Implements PAYUNi transaction query functionality using Query API. Use when building order status checking, transaction verification, or payment confirmation features for 統一金流.

Its SKILL.md is about 950 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs. The repository describes itself as: 台灣第三方金流 Skills for AI Agents - 藍新金流、綠界科技 ECPay、統一金流 PAYUNi. The licence is MIT.

When your agent uses it

  • Building order status checking
  • Transaction verification
  • Payment confirmation features for 統一金流

Example prompts

  • “Use the payuni-query skill to implement PAYUNi transaction query functionality using Query API”
  • “/payuni-query”

Requirements

  • Node.js
  • A credential in PAYUNI_HASH_KEY
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash, Grep, Glob

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. 確認需求
  2. 建立查詢功能
  3. 實作程式碼
  4. 整合到應用

What it can do on your machine

Read from SKILL.md and the folder at commit 1cd84bd. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash
    • Grep
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • sandbox-api.payuni.com.tw
    • api.payuni.com.tw

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • PAYUNI_HASH_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Payuni Query loads about 948 tokens when it runs. Until then it costs about 47 tokens; SKILL.md has 115 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~47
When it runs · the whole SKILL.md, loaded when a task matches
~948

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Edit, Bash, Grep, Glob

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from paid-tw/skills at commit 1cd84bd, republished under its MIT licence (© paid-tw). 115 words, ~948 tokens.

Download SKILL.mdSave it as .claude/skills/payuni-query/SKILL.md (or your agent's skills folder).
name
payuni-query
description
Implements PAYUNi transaction query functionality using Query API. Use when building order status checking, transaction verification, or payment confirmation features for 統一金流.
allowed-tools
Read, Write, Edit, Bash, Grep, Glob
argument-hint
[查詢情境: 單筆查詢/批次對帳/狀態確認]
context
fork
agent
general-purpose
disable-model-invocation
true
user-invocable
true

統一金流交易查詢任務

你的任務是在用戶的專案中實作統一金流交易查詢功能。

Step 1: 確認需求

用戶輸入: $ARGUMENTS

詢問用戶:

  1. 查詢情境:需要什麼查詢功能?

    • 單筆訂單查詢(客戶查詢、客服查詢)
    • 批次對帳(每日/定時對帳)
    • 支付狀態確認(NotifyURL 備援)
  2. 專案框架:你使用什麼框架?

    • 確認是否已有 PAYUNi 環境設定

Step 2: 建立查詢功能

在現有的支付模組中加入查詢方法,或建立新模組。

核心功能:

  1. generateQueryParams(orderNo) - 產生查詢參數
  2. queryTrade(orderNo) - 查詢單筆交易

Step 3: 實作程式碼

Node.js/TypeScript 範例
typescript
import crypto from 'crypto';

const config = {
  merchantId: process.env.PAYUNI_MERCHANT_ID!,
  hashKey: process.env.PAYUNI_HASH_KEY!,
  hashIV: process.env.PAYUNI_HASH_IV!,
  isTest: process.env.PAYUNI_TEST_MODE === 'true',
};

function getQueryEndpoint(): string {
  return config.isTest
    ? 'https://sandbox-api.payuni.com.tw/api/query'
    : 'https://api.payuni.com.tw/api/query';
}

function encrypt(data: string): string {
  const key = Buffer.from(config.hashKey.padEnd(32, '\0').slice(0, 32), 'utf8');
  const iv = Buffer.from(config.hashIV.padEnd(16, '\0').slice(0, 16), 'utf8');
  
  const cipher = crypto.createCipheriv('aes-256-cbc', key, iv);
  let encrypted = cipher.update(data, 'utf8', 'hex');
  encrypted += cipher.final('hex');
  return encrypted;
}

function generateHashInfo(encryptInfo: string): string {
  return crypto
    .createHash('sha256')
    .update(encryptInfo)
    .digest('hex')
    .toUpperCase();
}

async function queryTrade(orderNo: string): Promise<{
  success: boolean;
  data?: any;
  error?: string;
}> {
  try {
    const queryData = {
      MerID: config.merchantId,
      MerTradeNo: orderNo,
    };
    
    const queryString = new URLSearchParams(queryData).toString();
    const encryptInfo = encrypt(queryString);
    const hashInfo = generateHashInfo(encryptInfo);
    
    const response = await fetch(getQueryEndpoint(), {
      method: 'POST',
      headers: { 'Content-Type': 'application/x-www-form-urlencoded' },
      body: new URLSearchParams({
        MerID: config.merchantId,
        EncryptInfo: encryptInfo,
        HashInfo: hashInfo,
      }),
    });
    
    const result = await response.json();
    
    return {
      success: result.Status === 'SUCCESS',
      data: result,
    };
  } catch (error) {
    return {
      success: false,
      error: error instanceof Error ? error.message : 'Query failed',
    };
  }
}

// 使用範例
const result = await queryTrade('ORDER-123');
if (result.success) {
  console.log('交易狀態:', result.data.TradeStatus);
}

Step 4: 整合到應用

建議整合方式:

  • API 端點: GET /api/orders/:orderNo/status
  • 管理後台: 訂單詳情頁顯示即時狀態
  • 定時任務: 對帳排程

API 參考

端點
環境URL
測試https://sandbox-api.payuni.com.tw/api/query
正式https://api.payuni.com.tw/api/query
請求參數
參數類型必填說明
MerIDString✓商店代號
EncryptInfoString✓加密後的查詢參數
HashInfoString✓SHA256 雜湊值
EncryptInfo 內容
參數類型必填說明
MerIDString✓商店代號
MerTradeNoString✓商店訂單編號
交易狀態 (TradeStatus)
值說明
0未付款
1已付款
2付款失敗
3已取消
6已退款

詳細參考文件


常見錯誤

代碼說明解決方式
TRA10001查無此筆交易確認訂單編號正確
TRA10002驗證錯誤確認加密參數正確
TRA10003商店代號錯誤確認 MerchantID 正確

© paid-tw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/payuni/skills/payuni-query of paid-tw/skills.

Open the folder on GitHubat commit 1cd84bd

Compare with similar skills

Payuni Query next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Payuni Query compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Payuni Query this skillpaid-tw/skills284—~948Automated safety check: NotesMIT
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
Nestjs Best Practicesrolling-scopes/rsschool-app10k6 repos~1.2kAutomated safety check: PassMIT
Sub2API AdminWei-Shaw/sub2api44k1 repos~717Automated safety check: PassLGPL-3.0
Firecrawl Build Onboardingfirecrawl/firecrawl190k1 repos~1.4kAutomated safety check: NotesISC
Obsidian BasesAtmosphere/atmosphere3.8k22 repos~3.2kAutomated safety check: PassApache-2.0

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Nestjs Best Practices

    rolling-scopes/rsschool-app

    NestJS best practices and architecture patterns for building production-ready applications.

    10k GitHub starsUsed in 6 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Sub2API Admin

    Wei-Shaw/sub2api

    Manages a Sub2API deployment from the command line: accounts, redeem and invitation codes, groups, proxies, imports, exports and raw admin API calls.

    44k GitHub starsUsed in 1 repo~717 tokens
    Backend & APIsAuto-check passed
  • Firecrawl Build Onboarding

    firecrawl/firecrawl

    Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.

    190k GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check: notes
  • Obsidian Bases

    Atmosphere/atmosphere

    Create and edit Obsidian Bases (.base files) with views, filters, formulas, and summaries.

    3.8k GitHub starsUsed in 22 repos~3.2k tokens
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed

More from paid-tw/skills

All 15 skills in this repo
  • Kryptogo Pay Checkout

    paid-tw/skills

    Implements KryptoGO Payment checkout integration including Payment Intent creation, React SDK usePayment hook, and Direct API integration.

    284 GitHub stars~1.5k tokensUpdated 7 mo ago
    Auto-check: notes
  • Kryptogo Pay Transfer

    paid-tw/skills

    Implements KryptoGO Payment token transfer/withdrawal functionality using the Asset Pro Transfer API.

    284 GitHub stars~597 tokensUpdated 7 mo ago
    Auto-check: notes
  • Kryptogo Pay Webhook

    paid-tw/skills

    Implements KryptoGO Payment webhook/callback handling for receiving payment status notifications.

    284 GitHub stars~695 tokensUpdated 7 mo ago
    Auto-check: notes
  • Newebpay Checkout

    paid-tw/skills

    Implements NewebPay MPG checkout integration including AES256 encryption, form submission, and payment callback handling.

    284 GitHub stars~850 tokensUpdated 7 mo ago
    Auto-check: notes
  • Payuni Checkout

    paid-tw/skills

    Implements PAYUNi UPP checkout integration including AES256 encryption, form submission, and payment callback handling.

    284 GitHub stars~1.3k tokensUpdated 7 mo ago
    Auto-check: notes
  • Payuni Webhook

    paid-tw/skills

    Implements PAYUNi webhook handling including signature verification, replay attack prevention, and payment status updates.

    284 GitHub stars~1.6k tokensUpdated 7 mo ago
    Auto-check: notes

Categories

Questions about Payuni Query

What does Payuni Query do?

Implements PAYUNi transaction query functionality using Query API. Payuni Query is an agent skill from paid-tw/skills. Implements PAYUNi transaction query functionality using Query API.

When should I use Payuni Query?

Payuni Query fits situations like: building order status checking; transaction verification; payment confirmation features for 統一金流.

How do I install Payuni Query in Claude Code?

Run `npx skills add paid-tw/skills --skill payuni-query -a claude-code`. Or copy the skill folder (plugins/payuni/skills/payuni-query in paid-tw/skills) into .claude/skills/payuni-query in your project. Claude Code loads it when a task matches its description.

How do I install Payuni Query in Codex?

Run `npx skills add paid-tw/skills --skill payuni-query -a codex`. Or copy the skill folder (plugins/payuni/skills/payuni-query in paid-tw/skills) into .agents/skills/payuni-query in your project. Codex loads it when a task matches its description.

Can I use Payuni Query in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add paid-tw/skills --skill payuni-query -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/payuni-query, .gemini/skills/payuni-query, .github/skills/payuni-query and .opencode/skills/payuni-query in your project.

What does Payuni Query need to run?

Going by SKILL.md and its folder, Payuni Query needs credentials named PAYUNI_HASH_KEY. Our summary lists: Node.js; A credential in PAYUNI_HASH_KEY. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash, Grep, Glob.

Does Payuni Query access the network?

SKILL.md names 2 domains. In commands or code: sandbox-api.payuni.com.tw and api.payuni.com.tw; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Payuni Query safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Payuni Query use?

Payuni Query is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Payuni Query use?

About 948 tokens (SKILL.md is roughly 3.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Payuni Query?

Skills that share tags, products or a category with Payuni Query: Configuring Horizon (coollabsio/coolify, 63k stars), Nestjs Best Practices (rolling-scopes/rsschool-app, 10k stars), Sub2API Admin (Wei-Shaw/sub2api, 44k stars) and Firecrawl Build Onboarding (firecrawl/firecrawl, 190k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Payuni Query?

paid-tw (a GitHub organization) maintains it in paid-tw/skills, which has 284 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on March 7, 2026.

Source: paid-tw/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.