Agent skill

Validate Then Transact

by yyw-code in yyw-code/MallBase

MallBase ThinkPHP 写操作与事务规则;实现或修改 create、update、delete、状态流转、多表写入、余额库存变更、行锁、条件更新或并发一致性校验时使用。

MITAuto-check passed

Install Validate Then Transact

skills CLI
$ npx skills add yyw-code/MallBase --skill validate-then-transact -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yyw-code/MallBase validate-then-transact --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yyw-code/MallBase.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/thinkPHP/validate-then-transact .claude/skills/validate-then-transact && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
validate-then-transact
GitHub stars
106
Token cost
~311 tokens
SKILL.md length
28 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
MIT

At a glance

MallBase ThinkPHP 写操作与事务规则;实现或修改 create、update、delete、状态流转、多表写入、余额库存变更、行锁、条件更新或并发一致性校验时使用。

  • Works in 4 steps: 在事务外完成参数格式、权限、静态业务规则和不依赖锁的存在性检查。 → 只在需要原子多表写入或并发一致性时开启事务。 → 在事务内保持查询和写入最少,完成后立即提交。 → …
  • SKILL.md covers 默认顺序, 并发校验例外, 禁止项 and 自检
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Validate Then Transact is an agent skill from yyw-code/MallBase. MallBase ThinkPHP 写操作与事务规则;实现或修改 create、update、delete、状态流转、多表写入、余额库存变更、行锁、条件更新或并发一致性校验时使用。

Its SKILL.md is about 310 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with PHP. The repository describes itself as: MallBase 是一个基于 PHP 的商城型业务基础框架,围绕 用户、商品、订单、权限 四个最核心的商业模块,提供一套清晰、稳定、可扩展的业务结构基线。 它不是一个功能齐全的电商系统,也不是通用 Web 框架,而是一个专注于“商城核心模型”的业务底座,用于快速构建和演进各类商业应用。 The licence is MIT.

Example prompts

  • “/validate-then-transact”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. 在事务外完成参数格式、权限、静态业务规则和不依赖锁的存在性检查。
  2. 只在需要原子多表写入或并发一致性时开启事务。
  3. 在事务内保持查询和写入最少,完成后立即提交。
  4. 把远程 API、短信、推送、文件处理等慢或不可回滚的外部 I/O 放到事务外;需要可靠副作用时使用提交后的事件或队列方案。

What it can do on your machine

Read from SKILL.md and the folder at commit 3f10589. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are php).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Validate Then Transact loads about 311 tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 28 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~28
When it runs · the whole SKILL.md, loaded when a task matches
~311

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from yyw-code/MallBase at commit 3f10589, republished under its MIT licence (© yyw-code). 28 words, ~311 tokens.

Download SKILL.mdSave it as .claude/skills/validate-then-transact/SKILL.md (or your agent's skills folder).
name
validate-then-transact
description
MallBase ThinkPHP 写操作与事务规则;实现或修改 create、update、delete、状态流转、多表写入、余额库存变更、行锁、条件更新或并发一致性校验时使用。

ThinkPHP 校验与事务边界

默认顺序

  1. 在事务外完成参数格式、权限、静态业务规则和不依赖锁的存在性检查。
  2. 只在需要原子多表写入或并发一致性时开启事务。
  3. 在事务内保持查询和写入最少,完成后立即提交。
  4. 把远程 API、短信、推送、文件处理等慢或不可回滚的外部 I/O 放到事务外;需要可靠副作用时使用提交后的事件或队列方案。
php
$this->validateBusiness($data);

return $this->transaction(function () use ($data): int {
    $model = $this->model();
    $model->save($data);
    return (int) $model->id;
});

并发校验例外

“先校验再事务”不等于禁止事务内校验。余额、库存、订单状态、退款额度等值可能在事务外检查后被并发修改,必须在事务内重新读取可信当前状态:

php
return $this->transaction(function () use ($id): bool {
    $row = $this->model()->where('id', $id)->lock(true)->find();
    if ($row === null) {
        throw new BusinessException('记录不存在');
    }
    if (!$this->canTransit((int) $row->status)) {
        throw new BusinessException('当前状态不允许操作');
    }
    return $row->save(['status' => 2]);
});

在热点计数或库存扣减中,优先使用带条件的原子 UPDATE,再根据受影响行数判断是否冲突。唯一约束、条件更新和行锁是并发下的最终防线,事务外预检不能替代它们。

禁止项

  • 不为单表单次写入机械地扩大事务范围。
  • 不在持锁事务内调用外部服务或执行可长时间阻塞的工作。
  • 不只依赖事务外读取做状态流转、余额或库存判断。
  • 不吞掉事务异常后返回成功。

自检

  • 可提前完成的校验已移到事务外。
  • 依赖锁内当前值的校验已在事务内重做。
  • 事务覆盖的写入具有同一原子目标。
  • 外部副作用不会因回滚而与数据库状态分叉。

© yyw-code, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .codex/skills/thinkPHP/validate-then-transact of yyw-code/MallBase.

Open the folder on GitHubat commit 3f10589

Compare with similar skills

Validate Then Transact next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Validate Then Transact compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Validate Then Transact this skillyyw-code/MallBase106—~311Automated safety check: PassMIT
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
Tailwindcss Developmentanonaddy/anonaddy4.9k10 repos~865Automated safety check: PassMIT
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
MCP Developmentcoollabsio/coolify63k1 repos~949Automated safety check: PassMIT
WooCommerce Code Reviewwoocommerce/woocommerce11k3 repos~1.1kAutomated safety check: PassCustom licence

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Tailwindcss Development

    anonaddy/anonaddy

    Always invoke when the user's message includes 'tailwind' in any form.

    4.9k GitHub starsUsed in 10 repos~865 tokens
    Frontend & DesignAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • MCP Development

    coollabsio/coolify

    A skill your agent uses for Laravel MCP development. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 1 repo~949 tokens
    Frontend & DesignAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Sync Translations

    symfony/symfony

    Synchronize translation catalogs across maintained Symfony branches: find messages that newer branches added to the English catalogs but that are still missing from the oldest maintained branch…

    31k GitHub stars~1.9k tokensUpdated today
    Writing & ContentAuto-check passed

More from yyw-code/MallBase

All 12 skills in this repo
  • MallBase 支付与退款回调安全规则;修改 backend/route/notify.php、PayNotifyController、NotifyService、WechatPaymentResultService、mbpaymentlog,或处理微信/其它渠道 webhook 的验签、解密、防重放、金额校验、幂等、事务与 HTTP 应答时使用。

    106 GitHub stars~495 tokensUpdated 2 mo ago
    Auto-check passed
  • Route Permission System

    yyw-code/MallBase

    MallBase ThinkPHP 后台路由与权限元数据规则;新增或调整 backend/route/api/admin 路由、System 权限码、菜单元数据、/:id 路径参数、共享 permission 或 sync:permissions 同步时使用。

    106 GitHub stars~499 tokensUpdated 2 mo ago
    Auto-check passed
  • Upload Component First

    yyw-code/MallBase

    MallBase Vben Admin 上传组件与字段契约规则;实现图片、视频或文件上传,以及处理 FileInfo 回填和提交值时使用。

    106 GitHub stars~553 tokensUpdated 2 mo ago
    Auto-check passed
  • Architecture Layering

    yyw-code/MallBase

    MallBase ThinkPHP 后端分层、Swoole Service 无状态与 IDE 泛型规则;开发或重构 backend/app 下的 Controller、Service、Model,调整 BaseController/BaseService、service()/model() 调用、构造注入或协程安全状态时使用。

    106 GitHub stars~391 tokensUpdated 2 mo ago
    Auto-check passed
  • E2E Webantd Realapi

    yyw-code/MallBase

    MallBase Vben Admin 局部格式化与真实后端 E2E 收口规则;修改、测试或回归 web-antd 代码时使用。

    106 GitHub stars~308 tokensUpdated 2 mo ago
    Auto-check passed
  • List Query Sync

    yyw-code/MallBase

    MallBase ThinkPHP 列表查询与分页返回规则;实现或调整 Service 的 buildListQuery、分页 list/total、动态筛选、关联查询、统计、导出或 compact('total', 'list') 返回时使用。

    106 GitHub stars~395 tokensUpdated 2 mo ago
    Auto-check passed

Works with

Questions about Validate Then Transact

What does Validate Then Transact do?

MallBase ThinkPHP 写操作与事务规则;实现或修改 create、update、delete、状态流转、多表写入、余额库存变更、行锁、条件更新或并发一致性校验时使用。. Validate Then Transact is an agent skill from yyw-code/MallBase.

How do I install Validate Then Transact in Claude Code?

Run `npx skills add yyw-code/MallBase --skill validate-then-transact -a claude-code`. Or copy the skill folder (.codex/skills/thinkPHP/validate-then-transact in yyw-code/MallBase) into .claude/skills/validate-then-transact in your project. Claude Code loads it when a task matches its description.

How do I install Validate Then Transact in Codex?

Run `npx skills add yyw-code/MallBase --skill validate-then-transact -a codex`. Or copy the skill folder (.codex/skills/thinkPHP/validate-then-transact in yyw-code/MallBase) into .agents/skills/validate-then-transact in your project. Codex loads it when a task matches its description.

Can I use Validate Then Transact in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yyw-code/MallBase --skill validate-then-transact -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/validate-then-transact, .gemini/skills/validate-then-transact, .github/skills/validate-then-transact and .opencode/skills/validate-then-transact in your project.

What does Validate Then Transact need to run?

SKILL.md names no scripts, command-line tools or credentials: Validate Then Transact is instructions for the agent only.

Does Validate Then Transact access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Validate Then Transact safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Validate Then Transact use?

Validate Then Transact is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Validate Then Transact use?

About 311 tokens (SKILL.md is roughly 1.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Validate Then Transact?

Skills that share tags, products or a category with Validate Then Transact: Configuring Horizon (coollabsio/coolify, 63k stars), Tailwindcss Development (anonaddy/anonaddy, 4.9k stars), Fortify Development (coollabsio/coolify, 63k stars) and MCP Development (coollabsio/coolify, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Validate Then Transact?

yyw-code (a GitHub user) maintains it in yyw-code/MallBase, which has 106 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on August 3, 2026.

Source: yyw-code/MallBase on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.