Agent skill

Payment Notify Idempotency

by yyw-code in yyw-code/MallBase

MallBase 支付与退款回调安全规则;修改 backend/route/notify.php、PayNotifyController、NotifyService、WechatPaymentResultService、mbpaymentlog,或处理微信/其它渠道 webhook 的验签、解密、防重放、金额校验、幂等、事务与 HTTP 应答时使用。

MITAuto-check passedBackend & APIs

Install Payment Notify Idempotency

skills CLI
$ npx skills add yyw-code/MallBase --skill payment-notify-idempotency -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yyw-code/MallBase payment-notify-idempotency --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yyw-code/MallBase.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/thinkPHP/payment-notify-idempotency .claude/skills/payment-notify-idempotency && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
payment-notify-idempotency
GitHub stars
106
Token cost
~495 tokens
SKILL.md length
119 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
MIT

At a glance

MallBase 支付与退款回调安全规则;修改 backend/route/notify.php、PayNotifyController、NotifyService、WechatPaymentResultService、mbpaymentlog,或处理微信/其它渠道 webhook 的验签、解密、防重放、金额校验、幂等、事务与 HTTP 应答时使用。

  • Works in 8 steps: 用原始 headers/body 构造 PSR-7 Request。 → 用 EasyWeChat Validator 验签,不自行实现微信签名算法。 → 通过 SDK Server 解密 resource,业务只使用解密后的… → …
  • Tasks that involve Webhooks
  • SKILL.md covers 当前入口, 支付处理顺序, 持久幂等 and 应答与副作用, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Payment Notify Idempotency is an agent skill from yyw-code/MallBase. MallBase 支付与退款回调安全规则;修改 backend/route/notify.php、PayNotifyController、NotifyService、WechatPaymentResultService、mbpaymentlog,或处理微信/其它渠道 webhook 的验签、解密、防重放、金额校验、幂等、事务与 HTTP 应答时使用。

Its SKILL.md is about 500 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Webhooks. It works with PHP and MySQL. The repository describes itself as: MallBase 是一个基于 PHP 的商城型业务基础框架,围绕 用户、商品、订单、权限 四个最核心的商业模块,提供一套清晰、稳定、可扩展的业务结构基线。 它不是一个功能齐全的电商系统,也不是通用 Web 框架,而是一个专注于“商城核心模型”的业务底座,用于快速构建和演进各类商业应用。 The licence is MIT.

When your agent uses it

  • Tasks that involve Webhooks

Example prompts

  • “/payment-notify-idempotency”

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. 用原始 headers/body 构造 PSR-7 Request。
  2. 用 EasyWeChat Validator 验签,不自行实现微信签名算法。
  3. 通过 SDK Server 解密 resource,业务只使用解密后的 attributes。
  4. 用微信 nonce 做 300 秒短窗口防重放。
  5. 校验 mchid、out_trade_no、transaction_id、trade_state 和整数分金额。
  6. 以活动 PREPAY 流水的 amount_cents 对比回调 amount.total,不使用浮点元金额。
  7. 在同一事务内追加 PAID 流水并通过订单 Service/状态机确认支付。
  8. 成功或已幂等处理返回微信 V3 JSON 成功应答;验签、重放和处理异常按当前协议返回失败状态。

What it can do on your machine

Read from SKILL.md and the folder at commit 3f10589. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are sql).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Payment Notify Idempotency loads about 495 tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 119 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~495

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from yyw-code/MallBase at commit 3f10589, republished under its MIT licence (© yyw-code). 119 words, ~495 tokens.

Download SKILL.mdSave it as .claude/skills/payment-notify-idempotency/SKILL.md (or your agent's skills folder).
name
payment-notify-idempotency
description
MallBase 支付与退款回调安全规则;修改 backend/route/notify.php、PayNotifyController、NotifyService、WechatPaymentResultService、mb_payment_log,或处理微信/其它渠道 webhook 的验签、解密、防重放、金额校验、幂等、事务与 HTTP 应答时使用。

支付回调验签与幂等

当前入口

  • 白名单路由:backend/route/notify.php
  • 支付:POST /api/notify/wechat/pay
  • 退款:POST /api/notify/wechat/refund
  • Controller:backend/app/controller/client/order/PayNotifyController.php
  • Service:NotifyService、WechatPaymentResultService

两个回调入口不挂 JWT/CSRF 中间件,支付与退款保持独立路由。网关必须透传 Wechatpay-Signature、Wechatpay-Serial、Wechatpay-Timestamp、Wechatpay-Nonce 和未经改写的原始请求体。

支付处理顺序

  1. 用原始 headers/body 构造 PSR-7 Request。
  2. 用 EasyWeChat Validator 验签,不自行实现微信签名算法。
  3. 通过 SDK Server 解密 resource,业务只使用解密后的 attributes。
  4. 用微信 nonce 做 300 秒短窗口防重放。
  5. 校验 mchid、out_trade_no、transaction_id、trade_state 和整数分金额。
  6. 以活动 PREPAY 流水的 amount_cents 对比回调 amount.total,不使用浮点元金额。
  7. 在同一事务内追加 PAID 流水并通过订单 Service/状态机确认支付。
  8. 成功或已幂等处理返回微信 V3 JSON 成功应答;验签、重放和处理异常按当前协议返回失败状态。

WechatPaymentResultService::applyVerifiedSuccess() 同时供回调和主动查单复用。不要在另一条路径复制金额、商户号或订单状态校验。

持久幂等

mb_payment_log 使用合法的 MySQL 联合唯一索引:

sql
UNIQUE KEY `uk_txn_event` (`transaction_id`, `event_type`)

不要写 PostgreSQL 风格的 ... WHERE transaction_id IS NOT NULL 部分唯一索引。MySQL 唯一索引允许多行 NULL,同一非空交易号与事件类型仍会被唯一约束拦截。

应用层先查 (transaction_id, PAID),数据库唯一键处理并发竞争;命中重复键时按幂等结果处理,不重复推进业务。out_trade_no 的唯一约束继续保护预支付流水。

Redis nonce 是短期减压与重放告警层,数据库唯一键是持久防线。当前 Redis 异常采用可用性优先的放行策略;如要改为失败关闭,必须先评估支付回调可用性,不能顺手改变。

应答与副作用

  • 验签失败或重放:返回带 V3 JSON body 的 401。
  • 金额、商户、订单或落库处理失败:返回 5xx,让微信按协议重试。
  • trade_state 非 SUCCESS 且已完成审计处理:按当前实现返回成功,不推进订单。
  • 成功:返回 200 和 {"code":"SUCCESS","message":"成功"}。

事务内只做支付流水和订单状态的原子持久化,不调用短信、Webhook 等外部服务。当前支付告警监听器只落日志并预留运维通道;新增真实通知时放到事务外并做队列、限时和异常隔离。

自检

  • 路由无登录鉴权,支付与退款入口分离。
  • 验签、解密、重放、金额和幂等顺序未被打乱。
  • 金额以整数分和 PREPAY 流水为基准。
  • 唯一索引是目标 MySQL 可执行语法。
  • 重试不会重复写 PAID 流水或重复推进订单。
  • 外部通知不会进入数据库事务。

© yyw-code, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .codex/skills/thinkPHP/payment-notify-idempotency of yyw-code/MallBase.

Open the folder on GitHubat commit 3f10589

Compare with similar skills

Payment Notify Idempotency next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Payment Notify Idempotency compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Payment Notify Idempotency this skillyyw-code/MallBase106—~495Automated safety check: PassMIT
PR Review Provideryansongda/pay5.4k—~2.4kAutomated safety check: PassMIT
Discord Php Bot Securitydiscord-php/DiscordPHP1.1k—~1.2kAutomated safety check: NotesMIT
Sent Integration Starteraiskillstore/marketplace430—~2.2kAutomated safety check: PassNone
Alsacreations Guidelinesalsacreations/kiwipedia338—~900Automated safety check: PassNone
Deploy To Hostinghostinger/api-mcp-server159—~2.7kAutomated safety check: NotesMIT

Similar skills

  • PR Review Provider

    yansongda/pay

    A skill your agent uses when reviewing PRs that add or modify a payment Provider in yansongda/pay - covers plugin pipeline, multi-tenant safety, signature verification, docs, and naming conventions.

    5.4k GitHub stars~2.4k tokensUpdated 9 days ago
    Backend & APIsAuto-check passed
  • Discord Php Bot Security

    discord-php/DiscordPHP

    Audit checklist for DiscordPHP bots and API libraries — stop the bot token leaking to third-party APIs or logs, keep secrets out of customids and exception messages, use constant-time comparison and…

    1.1k GitHub stars~1.2k tokensUpdated 2 days ago
    Backend & APIsAuto-check: notes
  • Sent Integration Starter

    aiskillstore/marketplace

    Stands up a production-ready Sent v3 integration in an existing codebase — SDK selection and client construction, x-api-key configuration, idempotent sends, retry and rate-limit handling, the…

    430 GitHub stars~2.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Alsacreations Guidelines

    alsacreations/kiwipedia

    Guidelines techniques et conventions internes d'Alsacréations (Kiwipedia) — HTML, CSS, JavaScript, TypeScript, Vue.js, WordPress, PHP/MySQL, accessibilité, performance, SEO, RGPD, écoconception…

    338 GitHub stars~900 tokensUpdated 18 days ago
    DatabasesAuto-check passed
  • Deploy To Hosting

    hostinger/api-mcp-server

    Deploy an existing project to a website on Hostinger web hosting (Shared, Cloud or Agency plans) and keep it deployed: picks the right deploy for static sites, Node.js apps (Next.js, Nuxt, Express…

    159 GitHub stars~2.7k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Leaderboard System

    OpenLitterMap/openlittermap-web

    LeaderboardController, Redis sorted sets for all-time XP rankings, per-user metrics rows for time-filtered rankings, rewardXpToAdmin, and leaderboard privacy.

    134 GitHub stars~2k tokensUpdated 23 days ago
    DatabasesAuto-check passed

More from yyw-code/MallBase

All 12 skills in this repo
  • Route Permission System

    yyw-code/MallBase

    MallBase ThinkPHP 后台路由与权限元数据规则;新增或调整 backend/route/api/admin 路由、System 权限码、菜单元数据、/:id 路径参数、共享 permission 或 sync:permissions 同步时使用。

    106 GitHub stars~499 tokensUpdated 2 mo ago
    Auto-check passed
  • Upload Component First

    yyw-code/MallBase

    MallBase Vben Admin 上传组件与字段契约规则;实现图片、视频或文件上传,以及处理 FileInfo 回填和提交值时使用。

    106 GitHub stars~553 tokensUpdated 2 mo ago
    Auto-check passed
  • Architecture Layering

    yyw-code/MallBase

    MallBase ThinkPHP 后端分层、Swoole Service 无状态与 IDE 泛型规则;开发或重构 backend/app 下的 Controller、Service、Model,调整 BaseController/BaseService、service()/model() 调用、构造注入或协程安全状态时使用。

    106 GitHub stars~391 tokensUpdated 2 mo ago
    Auto-check passed
  • E2E Webantd Realapi

    yyw-code/MallBase

    MallBase Vben Admin 局部格式化与真实后端 E2E 收口规则;修改、测试或回归 web-antd 代码时使用。

    106 GitHub stars~308 tokensUpdated 2 mo ago
    Auto-check passed
  • List Query Sync

    yyw-code/MallBase

    MallBase ThinkPHP 列表查询与分页返回规则;实现或调整 Service 的 buildListQuery、分页 list/total、动态筛选、关联查询、统计、导出或 compact('total', 'list') 返回时使用。

    106 GitHub stars~395 tokensUpdated 2 mo ago
    Auto-check passed
  • Thinkphp

    yyw-code/MallBase

    MallBase ThinkPHP 后端规则导航;仅在后端任务涉及多个场景、需要查找项目规则,或无法确定应读取哪个更具体的 ThinkPHP skill 时使用。

    106 GitHub stars~185 tokensUpdated 2 mo ago
    Auto-check passed

Works with

Categories

Questions about Payment Notify Idempotency

What does Payment Notify Idempotency do?

MallBase 支付与退款回调安全规则;修改 backend/route/notify.php、PayNotifyController、NotifyService、WechatPaymentResultService、mbpaymentlog,或处理微信/其它渠道 webhook 的验签、解密、防重放、金额校验、幂等、事务与 HTTP 应答时使用。. Payment Notify Idempotency is an agent skill from yyw-code/MallBase.

When should I use Payment Notify Idempotency?

Payment Notify Idempotency fits situations like: tasks that involve Webhooks.

How do I install Payment Notify Idempotency in Claude Code?

Run `npx skills add yyw-code/MallBase --skill payment-notify-idempotency -a claude-code`. Or copy the skill folder (.codex/skills/thinkPHP/payment-notify-idempotency in yyw-code/MallBase) into .claude/skills/payment-notify-idempotency in your project. Claude Code loads it when a task matches its description.

How do I install Payment Notify Idempotency in Codex?

Run `npx skills add yyw-code/MallBase --skill payment-notify-idempotency -a codex`. Or copy the skill folder (.codex/skills/thinkPHP/payment-notify-idempotency in yyw-code/MallBase) into .agents/skills/payment-notify-idempotency in your project. Codex loads it when a task matches its description.

Can I use Payment Notify Idempotency in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yyw-code/MallBase --skill payment-notify-idempotency -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/payment-notify-idempotency, .gemini/skills/payment-notify-idempotency, .github/skills/payment-notify-idempotency and .opencode/skills/payment-notify-idempotency in your project.

What does Payment Notify Idempotency need to run?

SKILL.md names no scripts, command-line tools or credentials: Payment Notify Idempotency is instructions for the agent only.

Does Payment Notify Idempotency access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Payment Notify Idempotency safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Payment Notify Idempotency use?

Payment Notify Idempotency is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Payment Notify Idempotency use?

About 495 tokens (SKILL.md is roughly 2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Payment Notify Idempotency?

Skills that share tags, products or a category with Payment Notify Idempotency: PR Review Provider (yansongda/pay, 5.4k stars), Discord Php Bot Security (discord-php/DiscordPHP, 1.1k stars), Sent Integration Starter (aiskillstore/marketplace, 430 stars) and Alsacreations Guidelines (alsacreations/kiwipedia, 338 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Payment Notify Idempotency?

yyw-code (a GitHub user) maintains it in yyw-code/MallBase, which has 106 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on August 3, 2026.

Source: yyw-code/MallBase on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.