npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

alipay-subscription-skill

v1.12.6

Published

面向商家的支付宝订阅、自动续费、单笔支付与企业支付 B2B 接入 Skill,支持 Claude Code 和 Codex

Readme

alipay-subscription-skill

Claude Code / Codex Skill —— 支付宝订阅、自动续购、单笔支付与企业支付 B2B 商家接入指南。

安装器可将 skill 放入 Claude Code 或 Codex 的 skills 目录,无需手动拷贝。重启对应客户端后, 当你询问支付宝订阅、自动续费、团体席位订阅、试用期/优惠券、企业支付聚合收银、银行转账、OpenMQ、账单对账或退款等问题时, 该 skill 会被自动触发加载。

skill 内容包括:

  • SKILL.md —— 场景判定、对外安全边界、核心契约与参考路由
  • references/ —— 订阅与企业支付 API、示例代码、数据模型、OpenMQ、测试推进和排障等参考材料
  • assets/ —— 企业支付无 SDK Go 经典网关协议资产和验收 manifest 示例
  • scripts/validate_b2b_integration_manifest.py —— 企业支付接入证据检查器

安装

一条命令将最新版 Skill 自动覆盖安装到 Claude Code 和 Codex:

npx alipay-subscription-skill

裸命令与 npx alipay-subscription-skill@latest 效果一致:如果 npm 优先命中了项目本地或全局安装的 旧版本,入口会自动转交给 latest;显式固定版本的 npm exec --package=... 仍保持原语义。

首次安装会默认启用自动更新:macOS 登录后及每 12 小时检查一次 npm stable 标签,发现新版本后 使用临时目录和原子替换更新 Skill。当前会话不被强制重启,新版本在下次会话或重启客户端后生效。 不希望注册自动更新时使用:

npx alipay-subscription-skill@latest --no-auto-update

运行诊断默认统计成功安装次数和 Skill 调用次数;安装事件区分首次安装与升级,升级时携带上一版本号。调用意图由业务类型(周期续费、自动续购、单笔支付、企业支付)和阶段(商户接入、开发接入、问题排查)用下划线拼接为单一枚举,例如 subscription_merchant_onboarding、auto_purchase_api_integration、enterprise_payment_troubleshooting。计数事件只发送随机安装标识、随机调用标识、Skill/客户端版本和调用意图枚举;不记录完成、失败或耗时。原始计数事件最长保留 90 天。

调用事件还支持一句经过本地模板校验和脱敏的问题摘要,格式为 [模型名+IP] 产品域:用户希望……。前缀包含本次调用的模型标识和运行 Skill 的机器本地网卡 IP(优先 IPv4),取不到时分别标为 unknown-model、unknown-ip;不会查询公网 IP 服务。新安装和升级默认保留该开关,诊断未关闭时使用发布包内置写入 Key 上报,无需另行配置。含前缀的摘要最多 512 UTF-8 字节,摘要最长保留 30 天。可分别关闭诊断或摘要:

npx alipay-subscription-skill@latest --no-telemetry
npx alipay-subscription-skill@latest --no-telemetry-question-summary
# 重新开启已关闭的摘要开关
npx alipay-subscription-skill@latest --telemetry-question-summary
# 或在运行时设置
export ALIPAY_SUBSCRIPTION_TELEMETRY=0
export ALIPAY_SUBSCRIPTION_TELEMETRY_QUESTION_SUMMARY=0

发布包内置的公开写入 Token 同时用于不含用户原文的安装/调用计数和经本地脱敏的问题摘要。发布包内容可被检查,该 Token 不能作为服务端安全边界;服务端必须通过 Skill/事件/属性白名单、限流和异常检测防止伪造与滥用。ALIPAY_SUBSCRIPTION_TELEMETRY_WRITE_KEY 仅用于紧急轮换或环境覆盖;诊断接收地址只允许 Watchtower 预发/生产 HTTPS 域名,另仅为本机测试地址允许 HTTP。

Skill 调用事件使用 node <skill-dir>/runtime/telemetry.mjs skill_invoked --intent <枚举> --report-json 上报;宿主已明确本次模型标识时追加 --model <模型标识>,也支持宿主设置 ALIPAY_SUBSCRIPTION_TELEMETRY_MODEL(参数优先),不可根据客户端名称猜测模型。摘要通过 --memo-stdin 或 --memo-file <绝对路径> 传入(二选一),只写摘要正文,前缀由运行时生成。stdin 需由宿主在同次调用中传入,等待上限 500ms;不能同次传 stdin 的工具应先用 mktemp 创建私有临时文件,再用文件工具写入脱敏摘要。文件必须属于当前用户、权限 600、非符号链接且不超过 4096 字节,调用后由调用方清理。摘要正文不得放入 shell 字符串、argv 或环境变量;最终 memo 仅位于 skill_invoked 顶层,不会混入 properties。运行时也继续兼容安装器使用的 JSON 属性参数。

安装完成与统计接收是两个结果:安装器会显示接收成功的 eventId,失败时显示原因及 HTTP 状态,不影响 Skill 安装。运行 node <skill-dir>/runtime/telemetry.mjs status 可只读查看版本、开关、Key 格式是否有效及接收地址,不发送事件、不显示 Key。调用时增加 --report-json 获取回执:只有 accepted=true 才表示服务端确认;memoStatus=included 表示携带摘要,missing_input 表示调用方漏传,empty_or_rejected 表示摘要为空或被本地拒绝。回执不含 Key、摘要正文或服务端原始响应。发送失败返回非零退出码;诊断关闭返回 skipped。

单个事件发送总预算为 6 秒,网络错误和 5xx 最多重试一次并复用 eventId;不会跟随重定向,也不会重试 4xx。默认接收地址为 Watchtower 生产环境,排障时在后台选择 PROD;切换环境时必须使用对应环境的 Key。没有服务端回执不能把进程退出当成上报成功。

命令执行后无需选择目标:

  • Claude Code → ~/.claude/skills/alipay-subscription/
  • Codex → ~/.codex/skills/alipay-subscription/
  • 把 SKILL.md、references/、runtime/、assets/ 和企业支付验收器覆盖写入两个目录,并写入安装归属与内容摘要标记。

目标中存在同名目录时,安装器默认使用当前包内容覆盖,无论目录是否带安装标记或是否被手工修改。替换失败时会尝试自动恢复旧目录;替换成功后通常会清理旧目录,若清理失败则保留隐藏备份并提示路径。请提前备份需要保留的本地修改。

重启对应客户端(Claude Code / Codex)后即可使用。

只安装一个客户端

npx alipay-subscription-skill@latest --claude  # 只装 Claude Code
npx alipay-subscription-skill@latest --codex   # 只装 Codex

也可先执行 npm i -g alipay-subscription-skill,再运行 alipay-subscription-skill。npx 模式不会强制写入全局 npm 目录。

npm 会优先使用项目本地依赖。若机器上仍有不支持自动转发的历史全局版本,请先执行 npm uninstall -g alipay-subscription-skill,或将其升级到最新版本;新代码无法在启动前拦截这些旧版本。需要严格固定版本时,使用 npm exec --yes --package=alipay-subscription-skill@<版本> -- alipay-subscription-skill,不要依赖可能命中全局 bin 的简写。

自定义 skills 目录

若你的 skills 目录不在默认位置,用环境变量指定:

CLAUDE_SKILLS_DIR=/path/to/claude/skills \
CODEX_SKILLS_DIR=/path/to/codex/skills \
  npx alipay-subscription-skill@latest

升级

npx alipay-subscription-skill@latest

新版本默认覆盖同名 Skill 目录,包括旧版无标记目录和本地修改过的目录。覆盖过程使用临时目录与失败回滚;正常情况下成功后会清理旧目录,清理失败时会保留隐藏备份并提示路径。

自动更新只处理带有本包有效安装标记且安装后未被修改的目录;检测到本地修改时会安全跳过。 可查看状态、立即检查或开关自动更新:

npx alipay-subscription-skill@latest update status
npx alipay-subscription-skill@latest update now
npx alipay-subscription-skill@latest update enable
npx alipay-subscription-skill@latest update disable

自动更新器和日志位于 ~/.alipay-subscription-skill/。当前系统定时任务支持 macOS LaunchAgent; Linux 和 Windows 会保存配置,但暂不注册系统定时任务,可继续手动运行升级命令。

卸载

npx alipay-subscription-skill@latest --uninstall
# 也可用 --claude 或 --codex 只移除一个目标

卸载只移除带有本包有效安装标记且安装后未被修改的目录。用户手工创建、其他渠道安装或本地修改过的同名目录会保留。若使用全局安装,npm uninstall -g alipay-subscription-skill 也执行相同的安全检查。 当最后一个受管理目标被卸载时,会同时移除自动更新配置和 macOS LaunchAgent。

License

MIT