Agent skill

PR Review Provider

by yansongda in yansongda/pay

A skill your agent uses when reviewing PRs that add or modify a payment Provider in yansongda/pay - covers plugin pipeline, multi-tenant safety, signature verification, docs, and naming conventions.

MITAuto-check passedBackend & APIs

Install PR Review Provider

skills CLI
$ npx skills add yansongda/pay --skill pr-review-provider -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yansongda/pay pr-review-provider --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yansongda/pay.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/pr-review-provider .claude/skills/pr-review-provider && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pr-review-provider
GitHub stars
5.4k
Token cost
~2.4k tokens
SKILL.md length
521 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when reviewing PRs that add or modify a payment Provider in yansongda/pay - covers plugin pipeline, multi-tenant safety, signature verification, docs, and naming conventions.

  • Works in 12 steps: 提交评论前必须征求用户许可 → 报告末尾必须注明使用的模型及审核状态 → params vs payload 混淆 → …
  • Reviewing PRs that add
  • SKILL.md covers Review 规范(强制), Review 流程, Phase 1: Provider 结构完整性 and Phase 2: 代码规范检查, plus 8 more sections
  • Calls gh; reaches api.xxx.com and sandbox.api.xxx.com

What it does

PR Review Provider is an agent skill from yansongda/pay. Use when reviewing PRs that add or modify a payment Provider in yansongda/pay - covers plugin pipeline, multi-tenant safety, signature verification, docs, and naming conventions.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Pull requests, Webhooks and Multi-tenancy. It works with PHP and WeChat. The repository describes itself as: 可能是我用过的最优雅的 Alipay/WeChat/Douyin/Unipay/江苏银行 的支付 SDK 扩展包了. The licence is MIT.

When your agent uses it

  • Reviewing PRs that add
  • Modify a payment Provider in yansongda/pay - covers plugin pipeline
  • Multi-tenant safety
  • Signature verification

Example prompts

  • “/pr-review-provider”

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. 提交评论前必须征求用户许可
  2. 报告末尾必须注明使用的模型及审核状态
  3. params vs payload 混淆
  4. 空值处理
  5. Webhook 签名验证
  6. 数组回调的处理
  7. 加密资源解密(微信)
  8. 插件管道骨架
  9. mergeCommonPlugins 实现
  10. Trait 方法复用
  11. Provider 常量定义
  12. Event 调用

What it can do on your machine

Read from SKILL.md and the folder at commit 37cf0c1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.xxx.com
    • sandbox.api.xxx.com

    Also links to:

    • wiki.php.net

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

PR Review Provider loads about 2.4k tokens when it runs. Until then it costs about 49 tokens; SKILL.md has 521 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~49
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from yansongda/pay at commit 37cf0c1, republished under its MIT licence (© yansongda). 521 words, ~2,436 tokens.

Download SKILL.mdSave it as .claude/skills/pr-review-provider/SKILL.md (or your agent's skills folder).
name
pr-review-provider
description
Use when reviewing PRs that add or modify a payment Provider in yansongda/pay - covers plugin pipeline, multi-tenant safety, signature verification, docs, and naming conventions.

PR Review Checklist — Payment Provider

yansongda/pay 新增/修改 Provider 时的 Code Review 专用检查清单。基于 Airwallex PR #1140 review 经验沉淀。

Review 规范(强制)

1. 提交评论前必须征求用户许可

绝对禁止:未经用户明确允许,不得使用 gh pr comment 或其他方式向 PR 提交任何评论。

正确流程:

  1. 完成 review 分析
  2. 向用户展示 review 报告内容
  3. 询问用户:"是否需要我将此报告提交为 PR 评论?"
  4. 仅在用户明确确认后才执行提交
2. 报告末尾必须注明使用的模型及审核状态

在 review 报告的结论部分之后,必须添加以下信息:

markdown
---
*Review by {模型名称} | {YYYY-MM-DD} | 经人工审核确认*

示例:

markdown
---
*Review by deepseek-v4-pro | 2026-05-07 | 经人工审核确认*

Review 流程

按以下阶段顺序审查,确保覆盖完整:

  1. Phase 1: Provider 结构完整性
  2. Phase 2: 代码规范检查
  3. Phase 3: 安全性检查(签名验证、加密解密)
  4. Phase 4: 架构一致性(管道、Trait、Event)
  5. Phase 5: 官方文档对照
  6. Phase 6: 测试覆盖
  7. Phase 7: 文档完整性

Phase 1: Provider 结构完整性

对照以下清单逐项检查:

#检查项位置说明
1插件src/Plugin/{Provider}/V{n}/按版本组织
2Provider 类src/Provider/{Provider}.php实现 ProviderInterface
3服务提供者src/Service/{Provider}ServiceProvider.php服务注册
4快捷方式src/Shortcut/{Provider}/{Method}Shortcut.php
5Trait 方法src/Traits/{Provider}Trait.phpget{Provider}Url、verify{Provider}WebhookSign 等
6Provider 注册src/Pay.php添加 {Provider}::class 和入口方法
7异常常量src/Exception/Exception.phpPARAMS_{PROVIDER}_*、CONFIG_{PROVIDER}_*
8测试tests/与源码结构对应
9文档web/docs/v3/{provider}/VitePress 文档
10侧边栏/CHANGELOGweb/.vitepress/sidebar/v3.js、CHANGELOG.md更新配置

注意:src/Functions.php 已不存在,URL/签名等方法已下沉到 src/Traits/*Trait.php。


Phase 2: 代码规范检查

基本规范
检查项要求
declare(strict_types=1)每个文件必须有
use 导入除动态类名字符串/反射场景外,禁止直接写完整命名空间(如 \Yansongda\Pay\...)
多行条件&& / `
命名规范
类型格式示例
插件{Action}Plugin.phpPayPlugin、RefundPlugin
快捷方式{Method}Shortcut.phpWebShortcut、QueryShortcut
Provider{ProviderName}.phpPaypal.php、Stripe.php
ServiceProvider{ProviderName}ServiceProvider.phpPaypalServiceProvider.php
Trait{Provider}Trait.phpWechatTrait、StripeTrait
命名空间Yansongda\Pay\Plugin\{Provider}\V{n}\Pay\{Plugin}版本号与 API 版本一致
日志与异常
  • 日志格式:[Provider][V{n}][Category][Plugin],使用中文消息
  • 异常常量:PARAMS_{PROVIDER}_*、CONFIG_{PROVIDER}_*
  • 异常消息:中文,附带上下文参数

Phase 3: 安全性检查

1. params vs payload 混淆

高危:Artful::artful() 第二参数必须是 params(含 _config),不能是 payload。

php
// ❌ 错误 — payload 不含 _config,多租户必崩
$result = Artful::artful([...], $confirmPayload);

// ✅ 正确 — params 含 _config 租户标识
$result = Artful::artful([...], $confirmParams);

检查方法:搜索 Artful::artful( 调用,追踪第二参数来源。

2. 空值处理

检查最终发送的 body/query 是否包含不应出现的 null/空字段。

推荐方式:

  • 优先使用 filter_params() 函数(artful 库提供)
  • 嵌套数组场景补充 array_filter()
php
// ✅ 优先方式 — filter_params
$body = http_build_query(filter_params($payload)->toArray());

// ✅ 嵌套场景 — array_filter
$rocket->mergePayload(array_filter([
    'application_context' => $payload->get('application_context'),
], static fn ($value) => !is_null($value)));

检查位置:AddRadarPlugin::getBody()、getQueryString()、业务 Plugin 的 mergePayload()。

3. Webhook 签名验证

安全强制:所有 CallbackPlugin 必须验签。

ProviderTrait 方法必需配置字段
StripeStripeTrait::verifyStripeWebhookSign()webhook_secret
PayPalPaypalTrait::verifyPaypalWebhookSign()webhook_id + OAuth
微信WechatTrait::verifyWechatSign()mch_secret_cert、wechat_public_cert_path(可预置或运行时拉取)
抖音—(在 CallbackPlugin::verifySign() 中实现)mch_secret_token、mch_secret_salt
银联UnipayTrait::verifyUnipaySign()unipay_public_cert_path
支付宝AlipayTrait::verifyAlipaySign()alipay_public_cert_path

检查点:

  • CallbackPlugin 是否调用 Trait 提供或 Plugin 自身实现的签名验证方法
  • 签名算法是否与官方文档一致(对照 @see 链接)
  • 配置缺失时抛异常
  • 签名为空时抛异常
  • 使用 hash_equals 防时序攻击
4. 数组回调的处理

仅适用于 Stripe/Wechat/Paypal(构造 ServerRequest 并验签):

getCallbackParams() 处理逻辑:

输入类型行为
['body' => ..., 'headers' => ...]构造带 headers 的 ServerRequest,会验签
纯数组(无 headers)构造无 headers 的 ServerRequest,验签时会抛 SIGN_EMPTY
ServerRequestInterface直接使用,验签
null从 ServerRequest::fromGlobals() 获取

结论:数组回调只有提供完整 headers + body 才能通过验签;否则验签阶段抛异常。

Alipay/Douyin/Unipay 不同:

  • getCallbackParams() 返回 Collection(从 query/parsedBody 取值)
  • 直接 merge 到 params,不构造 ServerRequest
  • CallbackPlugin 从 params 中取值验签
Show full SKILL.md (211 more words)Show less
5. 加密资源解密(微信)

微信回调的 resource 字段需解密:

php
$body['resource'] = self::decryptWechatResource($body['resource'] ?? [], $config);

检查 CallbackPlugin 是否调用此方法。


Phase 4: 架构一致性

1. 插件管道骨架

通用骨架:

StartPlugin → [前置插件] → 业务插件 → [后置插件] → ParserPlugin

各 Provider 差异:

Provider前置插件后置插件
Stripe无AddRadarPlugin → ResponsePlugin
PayPalObtainAccessTokenPluginAddPayloadBodyPlugin → AddRadarPlugin → ResponsePlugin
微信无AddPayloadBodyPlugin → AddPayloadSignaturePlugin → AddRadarPlugin → VerifySignaturePlugin → ResponsePlugin
支付宝无FormatPayloadBizContentPlugin → AddPayloadSignaturePlugin → AddRadarPlugin → VerifySignaturePlugin → ResponsePlugin

注意:不同 Provider 管道差异较大,不要按固定模板审查。

2. mergeCommonPlugins 实现

Provider 类必须实现此方法,返回完整管道:

php
public function mergeCommonPlugins(array $plugins): array
{
    return array_merge(
        [StartPlugin::class, /* 前置插件 */],
        $plugins,
        [/* 后置插件 */, ParserPlugin::class],
    );
}
3. Trait 方法复用

新增 Provider 应复用 Trait 方法而非重新实现:

功能Trait 方法
URL 构建get{Provider}Url()
签名验证verify{Provider}WebhookSign() / verify{Provider}Sign()
配置获取ProviderConfigTrait::getProviderConfig()、getTenant()
加密解密WechatTrait::decryptWechatResource()
4. Provider 常量定义

必须定义 URL 常量:

php
public const URL = [
    Pay::MODE_NORMAL => 'https://api.xxx.com/',
    Pay::MODE_SANDBOX => 'https://sandbox.api.xxx.com/',
    Pay::MODE_SERVICE => 'https://api.xxx.com/',
];

特殊常量(如微信):

  • AUTH_TAG_LENGTH_BYTE
  • MCH_SECRET_KEY_LENGTH_BYTE
5. Event 调用

callback 方法必须触发事件:

php
// Stripe/Wechat/Paypal(ServerRequestInterface)
Event::dispatch(new CallbackReceived('provider', clone $request, $params, null));

// Alipay/Douyin/Unipay/Jsb(Collection)
Event::dispatch(new CallbackReceived('provider', $request->all(), $params, null));

其他方法触发:

php
Event::dispatch(new MethodCalled('provider', __METHOD__, $order, null));
6. PHPStan ignore 注释

Trait 静态方法调用需添加注释:

php
/* @phpstan-ignore-next-line */
self::verifyWechatSign(...);

这是 PHPStan 对 Trait 静态调用的已知限制,非代码质量问题。


Phase 5: 官方文档对照

结合代码中的 @see 链接验证:

#检查点
1API 端点 URL 是否与官方一致
2HTTP 方法(GET/POST)是否正确
3认证 Header 名称、格式是否正确
4请求/响应字段(必填/可选)是否正确
5签名算法、拼接顺序是否与官方完全一致
6Base URL(production/sandbox)是否正确

Phase 6: 测试覆盖

#检查项
1每个 Plugin 有对应测试
2必填参数缺失的异常测试
3可选参数缺失的边界测试
4多租户场景(_config 参数)
5HTTP client mock,禁止真实 API 调用
6Callback 签名验证的正向/反向测试

Phase 7: 文档完整性

#检查项
1官方链接可访问且指向正确端点
2示例代码使用原生 PHP,框架无关
3侧边栏已更新
4CHANGELOG 已更新

常见误报

null-safe 操作符
php
$payload?->get('a', $payload->get('b'))

PHP 8.0 的 null-safe 实现了 full short-circuiting:当 $payload 为 null 时,右侧参数不会被求值。这不是 bug。

参考:PHP RFC nullsafe_operator


避免重复造轮子

检查新增功能是否在 yansongda/supports 或 yansongda/artful 中已有实现:

功能已有实现
UUID 生成Str::uuidV4()
字符串处理Str::*
集合操作Collection::*
空值过滤filter_params() (artful)
HTTP 方法获取get_radar_method() (artful)
Body 获取get_radar_body() (artful)

Review 报告模板

以下为提交 review 时的标准报告格式:

markdown
# PR #{number} Code Review — {Provider} Provider

## 一、总览

| 维度 | 内容 |
|------|------|
| PR | #{number} — {title} |
| 涉及文件 | {n} 个 |
| Review 范围 | 全量代码 + 文档 + 测试 |
| 方法 | 逐文件审查 + 官方文档对照 + 跨 Provider 一致性比对 |

## 二、已确认 Bug(含证据链)

### BUG-{n}: {简要描述}

**严重级别**:{高/中高/中/低}

**位置**:`{file_path}` L{line}

**问题**:
{详细描述问题本质}

**证据链**:
1. 代码现状:`{相关代码片段}`
2. 预期行为:{应该怎样}
3. 实际行为:{实际会怎样}
4. 影响范围:{哪些场景会触发}

**修复建议**:
```php
// 修复方案
```

---

(重复以上格式,每个 Bug 单独一节)

## 三、已排除的误报

### {误报描述}

**结论**:非 Bug

**原因**:{详细解释,附 RFC/文档链接}

## 四、风险项

| # | 风险 | 严重级别 | 文件 | 说明 |
|---|------|----------|------|------|
| RISK-{n} | {风险名} | {级别} | `{file}` | {说明} |

## 五、改进建议

| # | 建议 | 优先级 | 文件 | 说明 |
|---|------|--------|------|------|
| SUG-{n} | {建议名} | {级别} | `{file}` | {说明} |

## 六、官方文档对照验证

| 功能 | 代码中的 URL/算法 | 官方文档 | 是否一致 |
|------|-------------------|----------|----------|
| {功能名} | `{代码实现}` | [官方文档]({url}) | ✅/❌ |

## 七、代码规范检查

| 检查项 | 状态 | 备注 |
|--------|------|------|
| `declare(strict_types=1)` | ✅/❌ | |
| `use` 导入(无内联命名空间) | ✅/❌ | |
| 日志格式 `[Provider][V{n}][Category][Plugin]` | ✅/❌ | |
| 异常常量命名 | ✅/❌ | |
| Plugin/Shortcut 命名规范 | ✅/❌ | |
| 测试覆盖 | ✅/❌ | |

## 八、汇总

| 类别 | 数量 | 详情 |
|------|------|------|
| 已确认 Bug | {n} | {简要列举} |
| 已排除误报 | {n} | {简要列举} |
| 风险项 | {n} | {简要列举} |
| 改进建议 | {n} | {简要列举} |

## 九、结论

{总体评价:代码质量、架构一致性、安全性等。明确给出 Approve / Request Changes 建议及原因。}

---
*Review by {模型名称} | {YYYY-MM-DD} | 经人工审核确认*

© yansongda, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/pr-review-provider of yansongda/pay.

Open the folder on GitHubat commit 37cf0c1

Compare with similar skills

PR Review Provider next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

PR Review Provider compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
PR Review Provider this skillyansongda/pay5.4k—~2.4kAutomated safety check: PassMIT
B24phpsdk Maintainerbitrix24/b24phpsdk102—~10kAutomated safety check: NotesMIT
Stewardbomzheg/Shvatka144—~574Automated safety check: PassMIT
00 Async Devai-driven-dev/framework513—~2.4kAutomated safety check: PassMIT
Forgejo CLImagnus919/agent-skills115—~645Automated safety check: PassMIT
Bktavivsinai/bitbucket-cli2341 repos~1kAutomated safety check: PassMIT

Similar skills

  • B24phpsdk Maintainer

    bitrix24/b24phpsdk

    A skill your agent uses whenever working with GitHub issues in the bitrix24/b24phpsdk repository: creating new issues, reading existing ones, planning implementation from an issue, referencing an…

    102 GitHub stars~10k tokensUpdated 11 days ago
    Backend & APIsAuto-check: notes
  • Steward

    bomzheg/Shvatka

    How an agent watches a pull request in this repository — webhooks only, no scheduled check-ins.

    144 GitHub stars~574 tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • 00 Async Dev

    ai-driven-dev/framework

    Drive the async-dev pipeline from one entry point, whether setup, run, or review.

    513 GitHub stars~2.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Forgejo CLI

    magnus919/agent-skills

    A skill your agent uses when managing a Forgejo or Gitea server from the terminal: issues, pull requests, repositories, file contents, labels, milestones, releases, webhooks, user settings, or any…

    115 GitHub stars~645 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Bkt

    avivsinai/bitbucket-cli

    Operate Bitbucket Cloud or Data Center repositories, pull requests, branches, issues, pipelines, permissions, and webhooks with bkt.

    234 GitHub starsUsed in 1 repo~1k tokens
    DevelopmentAuto-check passed
  • Discord Php Bot Security

    discord-php/DiscordPHP

    Audit checklist for DiscordPHP bots and API libraries — stop the bot token leaking to third-party APIs or logs, keep secrets out of customids and exception messages, use constant-time comparison and…

    1.1k GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check: notes

More from yansongda/pay

  • Container Dev

    yansongda/pay

    A skill your agent uses when local PHP environment is unavailable.

    5.4k GitHub stars~968 tokensUpdated 3 days ago
    Auto-check passed
  • A skill your agent uses when preparing to publish a new version of a PHP Composer package and need to write or update CHANGELOG, upgrade guides, and documentation before tagging and releasing

    5.4k GitHub stars~1.6k tokensUpdated 3 days ago
    Auto-check passed
  • Dev Guide

    yansongda/pay

    A skill your agent uses when developing, testing, or adding new providers to yansongda/pay project.

    5.4k GitHub stars~378 tokensUpdated 3 days ago
    Auto-check passed

Works with

Questions about PR Review Provider

What does PR Review Provider do?

A skill your agent uses when reviewing PRs that add or modify a payment Provider in yansongda/pay - covers plugin pipeline, multi-tenant safety, signature verification, docs, and naming conventions. PR Review Provider is an agent skill from yansongda/pay. Use when reviewing PRs that add or modify a payment Provider in yansongda/pay - covers plugin pipeline, multi-tenant safety, signature verification, docs, and naming conventions.

When should I use PR Review Provider?

PR Review Provider fits situations like: reviewing PRs that add; modify a payment Provider in yansongda/pay - covers plugin pipeline; multi-tenant safety; signature verification.

How do I install PR Review Provider in Claude Code?

Run `npx skills add yansongda/pay --skill pr-review-provider -a claude-code`. Or copy the skill folder (.agents/skills/pr-review-provider in yansongda/pay) into .claude/skills/pr-review-provider in your project. Claude Code loads it when a task matches its description.

How do I install PR Review Provider in Codex?

Run `npx skills add yansongda/pay --skill pr-review-provider -a codex`. Or copy the skill folder (.agents/skills/pr-review-provider in yansongda/pay) into .agents/skills/pr-review-provider in your project. Codex loads it when a task matches its description.

Can I use PR Review Provider in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yansongda/pay --skill pr-review-provider -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pr-review-provider, .gemini/skills/pr-review-provider, .github/skills/pr-review-provider and .opencode/skills/pr-review-provider in your project.

What does PR Review Provider need to run?

Going by SKILL.md and its folder, PR Review Provider needs the command-line tools its instructions call (gh).

Does PR Review Provider access the network?

SKILL.md names 3 domains. In commands or code: api.xxx.com and sandbox.api.xxx.com; the agent is likely to contact these when it follows the instructions. As links in the text: wiki.php.net. This is read from the text; nothing was executed.

Is PR Review Provider safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does PR Review Provider use?

PR Review Provider is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does PR Review Provider use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to PR Review Provider?

Skills that share tags, products or a category with PR Review Provider: B24phpsdk Maintainer (bitrix24/b24phpsdk, 102 stars), Steward (bomzheg/Shvatka, 144 stars), 00 Async Dev (ai-driven-dev/framework, 513 stars) and Forgejo CLI (magnus919/agent-skills, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains PR Review Provider?

yansongda (a GitHub user) maintains it in yansongda/pay, which has 5,370 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 8, 2026.

Source: yansongda/pay on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.