PR Review Provider
yansongda/pay
A skill your agent uses when reviewing PRs that add or modify a payment Provider in yansongda/pay - covers plugin pipeline, multi-tenant safety, signature verification, docs, and naming conventions.
MallBase 支付与退款回调安全规则;修改 backend/route/notify.php、PayNotifyController、NotifyService、WechatPaymentResultService、mbpaymentlog,或处理微信/其它渠道 webhook 的验签、解密、防重放、金额校验、幂等、事务与 HTTP 应答时使用。
$ npx skills add yyw-code/MallBase --skill payment-notify-idempotency -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install yyw-code/MallBase payment-notify-idempotency --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/yyw-code/MallBase.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/thinkPHP/payment-notify-idempotency .claude/skills/payment-notify-idempotency && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "payment-notify-idempotency" agent skill from https://github.com/yyw-code/MallBase/tree/main/.codex/skills/thinkPHP/payment-notify-idempotency into .claude/skills/payment-notify-idempotency/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "payment-notify-idempotency", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/yyw-code/MallBase/tree/main/.codex/skills/thinkPHP/payment-notify-idempotencyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add yyw-code/MallBase --skill payment-notify-idempotency -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install yyw-code/MallBase payment-notify-idempotency --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yyw-code/MallBase.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.codex/skills/thinkPHP/payment-notify-idempotency .agents/skills/payment-notify-idempotency && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "payment-notify-idempotency" agent skill from https://github.com/yyw-code/MallBase/tree/main/.codex/skills/thinkPHP/payment-notify-idempotency into .agents/skills/payment-notify-idempotency/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "payment-notify-idempotency", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yyw-code/MallBase --skill payment-notify-idempotency -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install yyw-code/MallBase payment-notify-idempotency --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yyw-code/MallBase.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.codex/skills/thinkPHP/payment-notify-idempotency .cursor/skills/payment-notify-idempotency && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "payment-notify-idempotency" agent skill from https://github.com/yyw-code/MallBase/tree/main/.codex/skills/thinkPHP/payment-notify-idempotency into .cursor/skills/payment-notify-idempotency/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "payment-notify-idempotency", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/yyw-code/MallBase.git --path .codex/skills/thinkPHP/payment-notify-idempotency--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add yyw-code/MallBase --skill payment-notify-idempotency -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install yyw-code/MallBase payment-notify-idempotency --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yyw-code/MallBase.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.codex/skills/thinkPHP/payment-notify-idempotency .gemini/skills/payment-notify-idempotency && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "payment-notify-idempotency" agent skill from https://github.com/yyw-code/MallBase/tree/main/.codex/skills/thinkPHP/payment-notify-idempotency into .gemini/skills/payment-notify-idempotency/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "payment-notify-idempotency", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install yyw-code/MallBase payment-notify-idempotencyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add yyw-code/MallBase --skill payment-notify-idempotency -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/yyw-code/MallBase.git skills-src && mkdir -p .github/skills && cp -r skills-src/.codex/skills/thinkPHP/payment-notify-idempotency .github/skills/payment-notify-idempotency && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "payment-notify-idempotency" agent skill from https://github.com/yyw-code/MallBase/tree/main/.codex/skills/thinkPHP/payment-notify-idempotency into .github/skills/payment-notify-idempotency/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "payment-notify-idempotency", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yyw-code/MallBase --skill payment-notify-idempotency -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install yyw-code/MallBase payment-notify-idempotency --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yyw-code/MallBase.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.codex/skills/thinkPHP/payment-notify-idempotency .opencode/skills/payment-notify-idempotency && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "payment-notify-idempotency" agent skill from https://github.com/yyw-code/MallBase/tree/main/.codex/skills/thinkPHP/payment-notify-idempotency into .opencode/skills/payment-notify-idempotency/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "payment-notify-idempotency", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
payment-notify-idempotencyMallBase 支付与退款回调安全规则;修改 backend/route/notify.php、PayNotifyController、NotifyService、WechatPaymentResultService、mbpaymentlog,或处理微信/其它渠道 webhook 的验签、解密、防重放、金额校验、幂等、事务与 HTTP 应答时使用。
Payment Notify Idempotency is an agent skill from yyw-code/MallBase. MallBase 支付与退款回调安全规则;修改 backend/route/notify.php、PayNotifyController、NotifyService、WechatPaymentResultService、mbpaymentlog,或处理微信/其它渠道 webhook 的验签、解密、防重放、金额校验、幂等、事务与 HTTP 应答时使用。
Its SKILL.md is about 500 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Webhooks. It works with PHP and MySQL. The repository describes itself as: MallBase 是一个基于 PHP 的商城型业务基础框架,围绕 用户、商品、订单、权限 四个最核心的商业模块,提供一套清晰、稳定、可扩展的业务结构基线。 它不是一个功能齐全的电商系统,也不是通用 Web 框架,而是一个专注于“商城核心模型”的业务底座,用于快速构建和演进各类商业应用。 The licence is MIT.
8 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 3f10589. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are sql).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Payment Notify Idempotency loads about 495 tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 119 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from yyw-code/MallBase at commit 3f10589, republished under its MIT licence (© yyw-code). 119 words, ~495 tokens.
.claude/skills/payment-notify-idempotency/SKILL.md (or your agent's skills folder).backend/route/notify.phpPOST /api/notify/wechat/payPOST /api/notify/wechat/refundbackend/app/controller/client/order/PayNotifyController.phpNotifyService、WechatPaymentResultService两个回调入口不挂 JWT/CSRF 中间件,支付与退款保持独立路由。网关必须透传 Wechatpay-Signature、Wechatpay-Serial、Wechatpay-Timestamp、Wechatpay-Nonce 和未经改写的原始请求体。
resource,业务只使用解密后的 attributes。mchid、out_trade_no、transaction_id、trade_state 和整数分金额。amount_cents 对比回调 amount.total,不使用浮点元金额。WechatPaymentResultService::applyVerifiedSuccess() 同时供回调和主动查单复用。不要在另一条路径复制金额、商户号或订单状态校验。
mb_payment_log 使用合法的 MySQL 联合唯一索引:
UNIQUE KEY `uk_txn_event` (`transaction_id`, `event_type`)不要写 PostgreSQL 风格的 ... WHERE transaction_id IS NOT NULL 部分唯一索引。MySQL 唯一索引允许多行 NULL,同一非空交易号与事件类型仍会被唯一约束拦截。
应用层先查 (transaction_id, PAID),数据库唯一键处理并发竞争;命中重复键时按幂等结果处理,不重复推进业务。out_trade_no 的唯一约束继续保护预支付流水。
Redis nonce 是短期减压与重放告警层,数据库唯一键是持久防线。当前 Redis 异常采用可用性优先的放行策略;如要改为失败关闭,必须先评估支付回调可用性,不能顺手改变。
trade_state 非 SUCCESS 且已完成审计处理:按当前实现返回成功,不推进订单。{"code":"SUCCESS","message":"成功"}。事务内只做支付流水和订单状态的原子持久化,不调用短信、Webhook 等外部服务。当前支付告警监听器只落日志并预留运维通道;新增真实通知时放到事务外并做队列、限时和异常隔离。
© yyw-code, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .codex/skills/thinkPHP/payment-notify-idempotency of yyw-code/MallBase.
Open the folder on GitHubat commit 3f10589
Payment Notify Idempotency next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Payment Notify Idempotency this skillyyw-code/MallBase | 106 | — | ~495 | Automated safety check: Pass | MIT | |
| PR Review Provideryansongda/pay | 5.4k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Discord Php Bot Securitydiscord-php/DiscordPHP | 1.1k | — | ~1.2k | Automated safety check: Notes | MIT | |
| Sent Integration Starteraiskillstore/marketplace | 430 | — | ~2.2k | Automated safety check: Pass | None | |
| Alsacreations Guidelinesalsacreations/kiwipedia | 338 | — | ~900 | Automated safety check: Pass | None | |
| Deploy To Hostinghostinger/api-mcp-server | 159 | — | ~2.7k | Automated safety check: Notes | MIT |
yansongda/pay
A skill your agent uses when reviewing PRs that add or modify a payment Provider in yansongda/pay - covers plugin pipeline, multi-tenant safety, signature verification, docs, and naming conventions.
discord-php/DiscordPHP
Audit checklist for DiscordPHP bots and API libraries — stop the bot token leaking to third-party APIs or logs, keep secrets out of customids and exception messages, use constant-time comparison and…
aiskillstore/marketplace
Stands up a production-ready Sent v3 integration in an existing codebase — SDK selection and client construction, x-api-key configuration, idempotent sends, retry and rate-limit handling, the…
alsacreations/kiwipedia
Guidelines techniques et conventions internes d'Alsacréations (Kiwipedia) — HTML, CSS, JavaScript, TypeScript, Vue.js, WordPress, PHP/MySQL, accessibilité, performance, SEO, RGPD, écoconception…
hostinger/api-mcp-server
Deploy an existing project to a website on Hostinger web hosting (Shared, Cloud or Agency plans) and keep it deployed: picks the right deploy for static sites, Node.js apps (Next.js, Nuxt, Express…
OpenLitterMap/openlittermap-web
LeaderboardController, Redis sorted sets for all-time XP rankings, per-user metrics rows for time-filtered rankings, rewardXpToAdmin, and leaderboard privacy.
yyw-code/MallBase
MallBase ThinkPHP 后台路由与权限元数据规则;新增或调整 backend/route/api/admin 路由、System 权限码、菜单元数据、/:id 路径参数、共享 permission 或 sync:permissions 同步时使用。
yyw-code/MallBase
MallBase Vben Admin 上传组件与字段契约规则;实现图片、视频或文件上传,以及处理 FileInfo 回填和提交值时使用。
yyw-code/MallBase
MallBase ThinkPHP 后端分层、Swoole Service 无状态与 IDE 泛型规则;开发或重构 backend/app 下的 Controller、Service、Model,调整 BaseController/BaseService、service()/model() 调用、构造注入或协程安全状态时使用。
yyw-code/MallBase
MallBase Vben Admin 局部格式化与真实后端 E2E 收口规则;修改、测试或回归 web-antd 代码时使用。
yyw-code/MallBase
MallBase ThinkPHP 列表查询与分页返回规则;实现或调整 Service 的 buildListQuery、分页 list/total、动态筛选、关联查询、统计、导出或 compact('total', 'list') 返回时使用。
yyw-code/MallBase
MallBase ThinkPHP 后端规则导航;仅在后端任务涉及多个场景、需要查找项目规则,或无法确定应读取哪个更具体的 ThinkPHP skill 时使用。
Categories
MallBase 支付与退款回调安全规则;修改 backend/route/notify.php、PayNotifyController、NotifyService、WechatPaymentResultService、mbpaymentlog,或处理微信/其它渠道 webhook 的验签、解密、防重放、金额校验、幂等、事务与 HTTP 应答时使用。. Payment Notify Idempotency is an agent skill from yyw-code/MallBase.
Payment Notify Idempotency fits situations like: tasks that involve Webhooks.
Run `npx skills add yyw-code/MallBase --skill payment-notify-idempotency -a claude-code`. Or copy the skill folder (.codex/skills/thinkPHP/payment-notify-idempotency in yyw-code/MallBase) into .claude/skills/payment-notify-idempotency in your project. Claude Code loads it when a task matches its description.
Run `npx skills add yyw-code/MallBase --skill payment-notify-idempotency -a codex`. Or copy the skill folder (.codex/skills/thinkPHP/payment-notify-idempotency in yyw-code/MallBase) into .agents/skills/payment-notify-idempotency in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yyw-code/MallBase --skill payment-notify-idempotency -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/payment-notify-idempotency, .gemini/skills/payment-notify-idempotency, .github/skills/payment-notify-idempotency and .opencode/skills/payment-notify-idempotency in your project.
SKILL.md names no scripts, command-line tools or credentials: Payment Notify Idempotency is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Payment Notify Idempotency is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 495 tokens (SKILL.md is roughly 2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Payment Notify Idempotency: PR Review Provider (yansongda/pay, 5.4k stars), Discord Php Bot Security (discord-php/DiscordPHP, 1.1k stars), Sent Integration Starter (aiskillstore/marketplace, 430 stars) and Alsacreations Guidelines (alsacreations/kiwipedia, 338 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
yyw-code (a GitHub user) maintains it in yyw-code/MallBase, which has 106 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on August 3, 2026.
Source: yyw-code/MallBase on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.