Php Thinkphp Audit
0xShe/PHP-Code-Audit-Skill
ThinkPHP 框架特效安全审计工具。针对 ThinkPHP 常见的鉴权/CSRF/模板转义/ORM 写入(Mass Assignment)/调试与配置暴露等机制进行白盒静态审计,并映射到通用漏洞类型体系(AUTH/CSRF/TPL/XSS/LOGIC/CFG/SESS/SQL 等)。
MallBase ThinkPHP 后端规则导航;仅在后端任务涉及多个场景、需要查找项目规则,或无法确定应读取哪个更具体的 ThinkPHP skill 时使用。
$ npx skills add yyw-code/MallBase --skill thinkphp -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install yyw-code/MallBase thinkphp --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/yyw-code/MallBase.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/thinkPHP .claude/skills/thinkphp && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "thinkphp" agent skill from https://github.com/yyw-code/MallBase/tree/main/.codex/skills/thinkPHP into .claude/skills/thinkphp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "thinkphp", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/yyw-code/MallBase/tree/main/.codex/skills/thinkPHPType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add yyw-code/MallBase --skill thinkphp -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install yyw-code/MallBase thinkphp --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yyw-code/MallBase.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.codex/skills/thinkPHP .agents/skills/thinkphp && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "thinkphp" agent skill from https://github.com/yyw-code/MallBase/tree/main/.codex/skills/thinkPHP into .agents/skills/thinkphp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "thinkphp", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yyw-code/MallBase --skill thinkphp -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install yyw-code/MallBase thinkphp --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yyw-code/MallBase.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.codex/skills/thinkPHP .cursor/skills/thinkphp && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "thinkphp" agent skill from https://github.com/yyw-code/MallBase/tree/main/.codex/skills/thinkPHP into .cursor/skills/thinkphp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "thinkphp", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/yyw-code/MallBase.git --path .codex/skills/thinkPHP--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add yyw-code/MallBase --skill thinkphp -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install yyw-code/MallBase thinkphp --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yyw-code/MallBase.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.codex/skills/thinkPHP .gemini/skills/thinkphp && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "thinkphp" agent skill from https://github.com/yyw-code/MallBase/tree/main/.codex/skills/thinkPHP into .gemini/skills/thinkphp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "thinkphp", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install yyw-code/MallBase thinkphpInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add yyw-code/MallBase --skill thinkphp -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/yyw-code/MallBase.git skills-src && mkdir -p .github/skills && cp -r skills-src/.codex/skills/thinkPHP .github/skills/thinkphp && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "thinkphp" agent skill from https://github.com/yyw-code/MallBase/tree/main/.codex/skills/thinkPHP into .github/skills/thinkphp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "thinkphp", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yyw-code/MallBase --skill thinkphp -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install yyw-code/MallBase thinkphp --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yyw-code/MallBase.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.codex/skills/thinkPHP .opencode/skills/thinkphp && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "thinkphp" agent skill from https://github.com/yyw-code/MallBase/tree/main/.codex/skills/thinkPHP into .opencode/skills/thinkphp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "thinkphp", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
thinkphpMallBase ThinkPHP 后端规则导航;仅在后端任务涉及多个场景、需要查找项目规则,或无法确定应读取哪个更具体的 ThinkPHP skill 时使用。
Thinkphp is an agent skill from yyw-code/MallBase. MallBase ThinkPHP 后端规则导航;仅在后端任务涉及多个场景、需要查找项目规则,或无法确定应读取哪个更具体的 ThinkPHP skill 时使用。
Its SKILL.md is about 190 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: MallBase 是一个基于 PHP 的商城型业务基础框架,围绕 用户、商品、订单、权限 四个最核心的商业模块,提供一套清晰、稳定、可扩展的业务结构基线。 它不是一个功能齐全的电商系统,也不是通用 Web 框架,而是一个专注于“商城核心模型”的业务底座,用于快速构建和演进各类商业应用。 The licence is MIT.
Read from SKILL.md and the folder at commit 3f10589. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
rgFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Thinkphp loads about 185 tokens when it runs. Until then it costs about 23 tokens; SKILL.md has 36 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from yyw-code/MallBase at commit 3f10589, republished under its MIT licence (© yyw-code). 36 words, ~185 tokens.
.claude/skills/thinkphp/SKILL.md (or your agent's skills folder).优先读取与任务直接匹配的具体 skill,不要把本文件当成后端规则全集。
architecture-layering。validate-then-transact。{total, list} 返回时,读取 list-query-sync。route-permission-system。dev-schema-upgrade-sql。支付、商品媒体、SKU、地区快照和 backend/mall_base/ 边界都有独立 skill。先根据 frontmatter 的 description 选择,不要只套通用规则。
需要查看当前可用规则时,从项目根目录执行:
rg -n '^description:' .codex/skills/thinkPHP/*/SKILL.md任务同时命中多个场景时,读取所有直接相关的 skill,并以更具体、风险更高的规则为准。
© yyw-code, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .codex/skills/thinkPHP of yyw-code/MallBase.
Open the folder on GitHubat commit 3f10589
Thinkphp next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Thinkphp this skillyyw-code/MallBase | 106 | — | ~185 | Automated safety check: Pass | MIT | |
| Php Thinkphp Audit0xShe/PHP-Code-Audit-Skill | 402 | 1 repos | ~779 | Automated safety check: Pass | None | |
| Repo Scanaffaan-m/ECC | 274k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Lark DocPinvou/pinvou-agent | 2.4k | — | ~738 | Automated safety check: Pass | MIT | |
| Template CraftMaaAssistantArknights/MaaAssistantArknights | 24k | — | ~1.7k | Automated safety check: Pass | AGPL-3.0 | |
| Dbs Updatedontbesilent2025/dbskill | 10k | — | ~285 | Automated safety check: Pass | Custom licence |
0xShe/PHP-Code-Audit-Skill
ThinkPHP 框架特效安全审计工具。针对 ThinkPHP 常见的鉴权/CSRF/模板转义/ORM 写入(Mass Assignment)/调试与配置暴露等机制进行白盒静态审计,并映射到通用漏洞类型体系(AUTH/CSRF/TPL/XSS/LOGIC/CFG/SESS/SQL 等)。
affaan-m/ECC
用于从固定且可审查的提交安装外部 repo-scan 技能的引导指针。在运行跨栈源代码资产审计前需要安装 repo-scan 时使用;此 ECC 指针本身不执行审计。
Pinvou/pinvou-agent
【何时用:仅当用户明确指向飞书/Lark(发到飞书、飞书文档等)时使用;泛指做个文档或PPT或表格或方案默认走本地工具,不要误用飞书】飞书云文档(Docx/Wiki)与思维笔记内容操作:读取、创建、编辑文档,插入或下载图片附件,查询或回滚历史版本。用户给出文档 URL/token(含 doubao.com 的 /docx/、/wiki/)时使用,按 URL 路径/token…
MaaAssistantArknights/MaaAssistantArknights
制作与调整 MAA 任务的识别资源:截模板图/抠模板、定位 roi/定坐标/量坐标、取色生成 ColorMatch 参数、调 maskRange/maskranges/掩码范围。用户提到截模板/裁模板/模板图、roi 坐标、取色、ColorMatch、给新活动或新界面做图像适配,或点名 ImageCropper/MaskRangeTool 时使用,即使用户没有明确说出工具名。
dontbesilent2025/dbskill
更新官方 dbskill,并保留其他 Skill 与用户存档。用户要求更新、升级、检查 dbskill 版本,或在更新提醒后回复 1 时使用。
dontbesilent2025/dbskill
面向创作者的内容发布风险检查。逐句检查自媒体、社交媒体和内容平台的标题、正文、图片文字、字幕、口播、评论、账号资料及视频画面,分别判断平台机器可能识别什么、内容本身存在什么实质问题,并给出具体位置和最小修改动作;需要明确视频语境边界时,额外生成真实准确的三行贴片小字。用户询问「检查敏感词」「发布前排雷」「这篇内容哪里可能违规」「这条小红书能不能发」「视频上放什么声明」时使用。保留强观点、情绪张力…
yyw-code/MallBase
MallBase 支付与退款回调安全规则;修改 backend/route/notify.php、PayNotifyController、NotifyService、WechatPaymentResultService、mbpaymentlog,或处理微信/其它渠道 webhook 的验签、解密、防重放、金额校验、幂等、事务与 HTTP 应答时使用。
yyw-code/MallBase
MallBase ThinkPHP 后台路由与权限元数据规则;新增或调整 backend/route/api/admin 路由、System 权限码、菜单元数据、/:id 路径参数、共享 permission 或 sync:permissions 同步时使用。
yyw-code/MallBase
MallBase Vben Admin 上传组件与字段契约规则;实现图片、视频或文件上传,以及处理 FileInfo 回填和提交值时使用。
yyw-code/MallBase
MallBase ThinkPHP 后端分层、Swoole Service 无状态与 IDE 泛型规则;开发或重构 backend/app 下的 Controller、Service、Model,调整 BaseController/BaseService、service()/model() 调用、构造注入或协程安全状态时使用。
yyw-code/MallBase
MallBase Vben Admin 局部格式化与真实后端 E2E 收口规则;修改、测试或回归 web-antd 代码时使用。
yyw-code/MallBase
MallBase ThinkPHP 列表查询与分页返回规则;实现或调整 Service 的 buildListQuery、分页 list/total、动态筛选、关联查询、统计、导出或 compact('total', 'list') 返回时使用。
MallBase ThinkPHP 后端规则导航;仅在后端任务涉及多个场景、需要查找项目规则,或无法确定应读取哪个更具体的 ThinkPHP skill 时使用。. Thinkphp is an agent skill from yyw-code/MallBase.
Run `npx skills add yyw-code/MallBase --skill thinkphp -a claude-code`. Or copy the skill folder (.codex/skills/thinkPHP in yyw-code/MallBase) into .claude/skills/thinkphp in your project. Claude Code loads it when a task matches its description.
Run `npx skills add yyw-code/MallBase --skill thinkphp -a codex`. Or copy the skill folder (.codex/skills/thinkPHP in yyw-code/MallBase) into .agents/skills/thinkphp in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yyw-code/MallBase --skill thinkphp -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/thinkphp, .gemini/skills/thinkphp, .github/skills/thinkphp and .opencode/skills/thinkphp in your project.
Going by SKILL.md and its folder, Thinkphp needs the command-line tools its instructions call (rg).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Thinkphp is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 185 tokens (SKILL.md is roughly 740 characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Thinkphp: Php Thinkphp Audit (0xShe/PHP-Code-Audit-Skill, 402 stars), Repo Scan (affaan-m/ECC, 274k stars), Lark Doc (Pinvou/pinvou-agent, 2.4k stars) and Template Craft (MaaAssistantArknights/MaaAssistantArknights, 24k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
yyw-code (a GitHub user) maintains it in yyw-code/MallBase, which has 106 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on August 3, 2026.
Source: yyw-code/MallBase on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.