B24phpsdk Maintainer
bitrix24/b24phpsdk
A skill your agent uses whenever working with GitHub issues in the bitrix24/b24phpsdk repository: creating new issues, reading existing ones, planning implementation from an issue, referencing an…
A skill your agent uses when reviewing PRs that add or modify a payment Provider in yansongda/pay - covers plugin pipeline, multi-tenant safety, signature verification, docs, and naming conventions.
$ npx skills add yansongda/pay --skill pr-review-provider -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install yansongda/pay pr-review-provider --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/yansongda/pay.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/pr-review-provider .claude/skills/pr-review-provider && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "pr-review-provider" agent skill from https://github.com/yansongda/pay/tree/master/.agents/skills/pr-review-provider into .claude/skills/pr-review-provider/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pr-review-provider", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/yansongda/pay/tree/master/.agents/skills/pr-review-providerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add yansongda/pay --skill pr-review-provider -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install yansongda/pay pr-review-provider --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yansongda/pay.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/pr-review-provider .agents/skills/pr-review-provider && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "pr-review-provider" agent skill from https://github.com/yansongda/pay/tree/master/.agents/skills/pr-review-provider into .agents/skills/pr-review-provider/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pr-review-provider", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yansongda/pay --skill pr-review-provider -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install yansongda/pay pr-review-provider --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yansongda/pay.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/pr-review-provider .cursor/skills/pr-review-provider && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "pr-review-provider" agent skill from https://github.com/yansongda/pay/tree/master/.agents/skills/pr-review-provider into .cursor/skills/pr-review-provider/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pr-review-provider", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/yansongda/pay.git --path .agents/skills/pr-review-provider--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add yansongda/pay --skill pr-review-provider -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install yansongda/pay pr-review-provider --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yansongda/pay.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/pr-review-provider .gemini/skills/pr-review-provider && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "pr-review-provider" agent skill from https://github.com/yansongda/pay/tree/master/.agents/skills/pr-review-provider into .gemini/skills/pr-review-provider/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pr-review-provider", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install yansongda/pay pr-review-providerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add yansongda/pay --skill pr-review-provider -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/yansongda/pay.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/pr-review-provider .github/skills/pr-review-provider && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "pr-review-provider" agent skill from https://github.com/yansongda/pay/tree/master/.agents/skills/pr-review-provider into .github/skills/pr-review-provider/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pr-review-provider", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yansongda/pay --skill pr-review-provider -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install yansongda/pay pr-review-provider --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yansongda/pay.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/pr-review-provider .opencode/skills/pr-review-provider && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "pr-review-provider" agent skill from https://github.com/yansongda/pay/tree/master/.agents/skills/pr-review-provider into .opencode/skills/pr-review-provider/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pr-review-provider", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
pr-review-providerA skill your agent uses when reviewing PRs that add or modify a payment Provider in yansongda/pay - covers plugin pipeline, multi-tenant safety, signature verification, docs, and naming conventions.
PR Review Provider is an agent skill from yansongda/pay. Use when reviewing PRs that add or modify a payment Provider in yansongda/pay - covers plugin pipeline, multi-tenant safety, signature verification, docs, and naming conventions.
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Pull requests, Webhooks and Multi-tenancy. It works with PHP and WeChat. The repository describes itself as: 可能是我用过的最优雅的 Alipay/WeChat/Douyin/Unipay/江苏银行 的支付 SDK 扩展包了. The licence is MIT.
12 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 37cf0c1. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.xxx.comsandbox.api.xxx.comAlso links to:
wiki.php.netFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
PR Review Provider loads about 2.4k tokens when it runs. Until then it costs about 49 tokens; SKILL.md has 521 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from yansongda/pay at commit 37cf0c1, republished under its MIT licence (© yansongda). 521 words, ~2,436 tokens.
.claude/skills/pr-review-provider/SKILL.md (or your agent's skills folder).yansongda/pay 新增/修改 Provider 时的 Code Review 专用检查清单。基于 Airwallex PR #1140 review 经验沉淀。
绝对禁止:未经用户明确允许,不得使用 gh pr comment 或其他方式向 PR 提交任何评论。
正确流程:
在 review 报告的结论部分之后,必须添加以下信息:
---
*Review by {模型名称} | {YYYY-MM-DD} | 经人工审核确认*示例:
---
*Review by deepseek-v4-pro | 2026-05-07 | 经人工审核确认*按以下阶段顺序审查,确保覆盖完整:
对照以下清单逐项检查:
| # | 检查项 | 位置 | 说明 |
|---|---|---|---|
| 1 | 插件 | src/Plugin/{Provider}/V{n}/ | 按版本组织 |
| 2 | Provider 类 | src/Provider/{Provider}.php | 实现 ProviderInterface |
| 3 | 服务提供者 | src/Service/{Provider}ServiceProvider.php | 服务注册 |
| 4 | 快捷方式 | src/Shortcut/{Provider}/ | {Method}Shortcut.php |
| 5 | Trait 方法 | src/Traits/{Provider}Trait.php | get{Provider}Url、verify{Provider}WebhookSign 等 |
| 6 | Provider 注册 | src/Pay.php | 添加 {Provider}::class 和入口方法 |
| 7 | 异常常量 | src/Exception/Exception.php | PARAMS_{PROVIDER}_*、CONFIG_{PROVIDER}_* |
| 8 | 测试 | tests/ | 与源码结构对应 |
| 9 | 文档 | web/docs/v3/{provider}/ | VitePress 文档 |
| 10 | 侧边栏/CHANGELOG | web/.vitepress/sidebar/v3.js、CHANGELOG.md | 更新配置 |
注意:src/Functions.php 已不存在,URL/签名等方法已下沉到 src/Traits/*Trait.php。
| 检查项 | 要求 |
|---|---|
declare(strict_types=1) | 每个文件必须有 |
use 导入 | 除动态类名字符串/反射场景外,禁止直接写完整命名空间(如 \Yansongda\Pay\...) |
| 多行条件 | && / ` |
| 类型 | 格式 | 示例 |
|---|---|---|
| 插件 | {Action}Plugin.php | PayPlugin、RefundPlugin |
| 快捷方式 | {Method}Shortcut.php | WebShortcut、QueryShortcut |
| Provider | {ProviderName}.php | Paypal.php、Stripe.php |
| ServiceProvider | {ProviderName}ServiceProvider.php | PaypalServiceProvider.php |
| Trait | {Provider}Trait.php | WechatTrait、StripeTrait |
| 命名空间 | Yansongda\Pay\Plugin\{Provider}\V{n}\Pay\{Plugin} | 版本号与 API 版本一致 |
[Provider][V{n}][Category][Plugin],使用中文消息PARAMS_{PROVIDER}_*、CONFIG_{PROVIDER}_*高危:Artful::artful() 第二参数必须是 params(含 _config),不能是 payload。
// ❌ 错误 — payload 不含 _config,多租户必崩
$result = Artful::artful([...], $confirmPayload);
// ✅ 正确 — params 含 _config 租户标识
$result = Artful::artful([...], $confirmParams);检查方法:搜索 Artful::artful( 调用,追踪第二参数来源。
检查最终发送的 body/query 是否包含不应出现的 null/空字段。
推荐方式:
filter_params() 函数(artful 库提供)array_filter()// ✅ 优先方式 — filter_params
$body = http_build_query(filter_params($payload)->toArray());
// ✅ 嵌套场景 — array_filter
$rocket->mergePayload(array_filter([
'application_context' => $payload->get('application_context'),
], static fn ($value) => !is_null($value)));检查位置:AddRadarPlugin::getBody()、getQueryString()、业务 Plugin 的 mergePayload()。
安全强制:所有 CallbackPlugin 必须验签。
| Provider | Trait 方法 | 必需配置字段 |
|---|---|---|
| Stripe | StripeTrait::verifyStripeWebhookSign() | webhook_secret |
| PayPal | PaypalTrait::verifyPaypalWebhookSign() | webhook_id + OAuth |
| 微信 | WechatTrait::verifyWechatSign() | mch_secret_cert、wechat_public_cert_path(可预置或运行时拉取) |
| 抖音 | —(在 CallbackPlugin::verifySign() 中实现) | mch_secret_token、mch_secret_salt |
| 银联 | UnipayTrait::verifyUnipaySign() | unipay_public_cert_path |
| 支付宝 | AlipayTrait::verifyAlipaySign() | alipay_public_cert_path |
检查点:
@see 链接)hash_equals 防时序攻击仅适用于 Stripe/Wechat/Paypal(构造 ServerRequest 并验签):
getCallbackParams() 处理逻辑:
| 输入类型 | 行为 |
|---|---|
['body' => ..., 'headers' => ...] | 构造带 headers 的 ServerRequest,会验签 |
| 纯数组(无 headers) | 构造无 headers 的 ServerRequest,验签时会抛 SIGN_EMPTY |
ServerRequestInterface | 直接使用,验签 |
null | 从 ServerRequest::fromGlobals() 获取 |
结论:数组回调只有提供完整 headers + body 才能通过验签;否则验签阶段抛异常。
Alipay/Douyin/Unipay 不同:
getCallbackParams() 返回 Collection(从 query/parsedBody 取值)ServerRequest微信回调的 resource 字段需解密:
$body['resource'] = self::decryptWechatResource($body['resource'] ?? [], $config);检查 CallbackPlugin 是否调用此方法。
通用骨架:
StartPlugin → [前置插件] → 业务插件 → [后置插件] → ParserPlugin各 Provider 差异:
| Provider | 前置插件 | 后置插件 |
|---|---|---|
| Stripe | 无 | AddRadarPlugin → ResponsePlugin |
| PayPal | ObtainAccessTokenPlugin | AddPayloadBodyPlugin → AddRadarPlugin → ResponsePlugin |
| 微信 | 无 | AddPayloadBodyPlugin → AddPayloadSignaturePlugin → AddRadarPlugin → VerifySignaturePlugin → ResponsePlugin |
| 支付宝 | 无 | FormatPayloadBizContentPlugin → AddPayloadSignaturePlugin → AddRadarPlugin → VerifySignaturePlugin → ResponsePlugin |
注意:不同 Provider 管道差异较大,不要按固定模板审查。
Provider 类必须实现此方法,返回完整管道:
public function mergeCommonPlugins(array $plugins): array
{
return array_merge(
[StartPlugin::class, /* 前置插件 */],
$plugins,
[/* 后置插件 */, ParserPlugin::class],
);
}新增 Provider 应复用 Trait 方法而非重新实现:
| 功能 | Trait 方法 |
|---|---|
| URL 构建 | get{Provider}Url() |
| 签名验证 | verify{Provider}WebhookSign() / verify{Provider}Sign() |
| 配置获取 | ProviderConfigTrait::getProviderConfig()、getTenant() |
| 加密解密 | WechatTrait::decryptWechatResource() |
必须定义 URL 常量:
public const URL = [
Pay::MODE_NORMAL => 'https://api.xxx.com/',
Pay::MODE_SANDBOX => 'https://sandbox.api.xxx.com/',
Pay::MODE_SERVICE => 'https://api.xxx.com/',
];特殊常量(如微信):
AUTH_TAG_LENGTH_BYTEMCH_SECRET_KEY_LENGTH_BYTEcallback 方法必须触发事件:
// Stripe/Wechat/Paypal(ServerRequestInterface)
Event::dispatch(new CallbackReceived('provider', clone $request, $params, null));
// Alipay/Douyin/Unipay/Jsb(Collection)
Event::dispatch(new CallbackReceived('provider', $request->all(), $params, null));其他方法触发:
Event::dispatch(new MethodCalled('provider', __METHOD__, $order, null));Trait 静态方法调用需添加注释:
/* @phpstan-ignore-next-line */
self::verifyWechatSign(...);这是 PHPStan 对 Trait 静态调用的已知限制,非代码质量问题。
结合代码中的 @see 链接验证:
| # | 检查点 |
|---|---|
| 1 | API 端点 URL 是否与官方一致 |
| 2 | HTTP 方法(GET/POST)是否正确 |
| 3 | 认证 Header 名称、格式是否正确 |
| 4 | 请求/响应字段(必填/可选)是否正确 |
| 5 | 签名算法、拼接顺序是否与官方完全一致 |
| 6 | Base URL(production/sandbox)是否正确 |
| # | 检查项 |
|---|---|
| 1 | 每个 Plugin 有对应测试 |
| 2 | 必填参数缺失的异常测试 |
| 3 | 可选参数缺失的边界测试 |
| 4 | 多租户场景(_config 参数) |
| 5 | HTTP client mock,禁止真实 API 调用 |
| 6 | Callback 签名验证的正向/反向测试 |
| # | 检查项 |
|---|---|
| 1 | 官方链接可访问且指向正确端点 |
| 2 | 示例代码使用原生 PHP,框架无关 |
| 3 | 侧边栏已更新 |
| 4 | CHANGELOG 已更新 |
$payload?->get('a', $payload->get('b'))PHP 8.0 的 null-safe 实现了 full short-circuiting:当 $payload 为 null 时,右侧参数不会被求值。这不是 bug。
检查新增功能是否在 yansongda/supports 或 yansongda/artful 中已有实现:
| 功能 | 已有实现 |
|---|---|
| UUID 生成 | Str::uuidV4() |
| 字符串处理 | Str::* |
| 集合操作 | Collection::* |
| 空值过滤 | filter_params() (artful) |
| HTTP 方法获取 | get_radar_method() (artful) |
| Body 获取 | get_radar_body() (artful) |
以下为提交 review 时的标准报告格式:
# PR #{number} Code Review — {Provider} Provider
## 一、总览
| 维度 | 内容 |
|------|------|
| PR | #{number} — {title} |
| 涉及文件 | {n} 个 |
| Review 范围 | 全量代码 + 文档 + 测试 |
| 方法 | 逐文件审查 + 官方文档对照 + 跨 Provider 一致性比对 |
## 二、已确认 Bug(含证据链)
### BUG-{n}: {简要描述}
**严重级别**:{高/中高/中/低}
**位置**:`{file_path}` L{line}
**问题**:
{详细描述问题本质}
**证据链**:
1. 代码现状:`{相关代码片段}`
2. 预期行为:{应该怎样}
3. 实际行为:{实际会怎样}
4. 影响范围:{哪些场景会触发}
**修复建议**:
```php
// 修复方案
```
---
(重复以上格式,每个 Bug 单独一节)
## 三、已排除的误报
### {误报描述}
**结论**:非 Bug
**原因**:{详细解释,附 RFC/文档链接}
## 四、风险项
| # | 风险 | 严重级别 | 文件 | 说明 |
|---|------|----------|------|------|
| RISK-{n} | {风险名} | {级别} | `{file}` | {说明} |
## 五、改进建议
| # | 建议 | 优先级 | 文件 | 说明 |
|---|------|--------|------|------|
| SUG-{n} | {建议名} | {级别} | `{file}` | {说明} |
## 六、官方文档对照验证
| 功能 | 代码中的 URL/算法 | 官方文档 | 是否一致 |
|------|-------------------|----------|----------|
| {功能名} | `{代码实现}` | [官方文档]({url}) | ✅/❌ |
## 七、代码规范检查
| 检查项 | 状态 | 备注 |
|--------|------|------|
| `declare(strict_types=1)` | ✅/❌ | |
| `use` 导入(无内联命名空间) | ✅/❌ | |
| 日志格式 `[Provider][V{n}][Category][Plugin]` | ✅/❌ | |
| 异常常量命名 | ✅/❌ | |
| Plugin/Shortcut 命名规范 | ✅/❌ | |
| 测试覆盖 | ✅/❌ | |
## 八、汇总
| 类别 | 数量 | 详情 |
|------|------|------|
| 已确认 Bug | {n} | {简要列举} |
| 已排除误报 | {n} | {简要列举} |
| 风险项 | {n} | {简要列举} |
| 改进建议 | {n} | {简要列举} |
## 九、结论
{总体评价:代码质量、架构一致性、安全性等。明确给出 Approve / Request Changes 建议及原因。}
---
*Review by {模型名称} | {YYYY-MM-DD} | 经人工审核确认*© yansongda, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/pr-review-provider of yansongda/pay.
Open the folder on GitHubat commit 37cf0c1
PR Review Provider next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| PR Review Provider this skillyansongda/pay | 5.4k | — | ~2.4k | Automated safety check: Pass | MIT | |
| B24phpsdk Maintainerbitrix24/b24phpsdk | 102 | — | ~10k | Automated safety check: Notes | MIT | |
| Stewardbomzheg/Shvatka | 144 | — | ~574 | Automated safety check: Pass | MIT | |
| 00 Async Devai-driven-dev/framework | 513 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Forgejo CLImagnus919/agent-skills | 115 | — | ~645 | Automated safety check: Pass | MIT | |
| Bktavivsinai/bitbucket-cli | 234 | 1 repos | ~1k | Automated safety check: Pass | MIT |
bitrix24/b24phpsdk
A skill your agent uses whenever working with GitHub issues in the bitrix24/b24phpsdk repository: creating new issues, reading existing ones, planning implementation from an issue, referencing an…
bomzheg/Shvatka
How an agent watches a pull request in this repository — webhooks only, no scheduled check-ins.
ai-driven-dev/framework
Drive the async-dev pipeline from one entry point, whether setup, run, or review.
magnus919/agent-skills
A skill your agent uses when managing a Forgejo or Gitea server from the terminal: issues, pull requests, repositories, file contents, labels, milestones, releases, webhooks, user settings, or any…
avivsinai/bitbucket-cli
Operate Bitbucket Cloud or Data Center repositories, pull requests, branches, issues, pipelines, permissions, and webhooks with bkt.
discord-php/DiscordPHP
Audit checklist for DiscordPHP bots and API libraries — stop the bot token leaking to third-party APIs or logs, keep secrets out of customids and exception messages, use constant-time comparison and…
yansongda/pay
A skill your agent uses when local PHP environment is unavailable.
yansongda/pay
A skill your agent uses when preparing to publish a new version of a PHP Composer package and need to write or update CHANGELOG, upgrade guides, and documentation before tagging and releasing
yansongda/pay
A skill your agent uses when developing, testing, or adding new providers to yansongda/pay project.
Categories
A skill your agent uses when reviewing PRs that add or modify a payment Provider in yansongda/pay - covers plugin pipeline, multi-tenant safety, signature verification, docs, and naming conventions. PR Review Provider is an agent skill from yansongda/pay. Use when reviewing PRs that add or modify a payment Provider in yansongda/pay - covers plugin pipeline, multi-tenant safety, signature verification, docs, and naming conventions.
PR Review Provider fits situations like: reviewing PRs that add; modify a payment Provider in yansongda/pay - covers plugin pipeline; multi-tenant safety; signature verification.
Run `npx skills add yansongda/pay --skill pr-review-provider -a claude-code`. Or copy the skill folder (.agents/skills/pr-review-provider in yansongda/pay) into .claude/skills/pr-review-provider in your project. Claude Code loads it when a task matches its description.
Run `npx skills add yansongda/pay --skill pr-review-provider -a codex`. Or copy the skill folder (.agents/skills/pr-review-provider in yansongda/pay) into .agents/skills/pr-review-provider in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yansongda/pay --skill pr-review-provider -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pr-review-provider, .gemini/skills/pr-review-provider, .github/skills/pr-review-provider and .opencode/skills/pr-review-provider in your project.
Going by SKILL.md and its folder, PR Review Provider needs the command-line tools its instructions call (gh).
SKILL.md names 3 domains. In commands or code: api.xxx.com and sandbox.api.xxx.com; the agent is likely to contact these when it follows the instructions. As links in the text: wiki.php.net. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
PR Review Provider is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with PR Review Provider: B24phpsdk Maintainer (bitrix24/b24phpsdk, 102 stars), Steward (bomzheg/Shvatka, 144 stars), 00 Async Dev (ai-driven-dev/framework, 513 stars) and Forgejo CLI (magnus919/agent-skills, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
yansongda (a GitHub user) maintains it in yansongda/pay, which has 5,370 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 8, 2026.
Source: yansongda/pay on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.