Real Skill packageSource verifiedClawHub registry

ZL-ClawPay

支付技能:支持免密支付、订单查询、交易流水等功能。 触发词:我要支付、帮我付款、确认买单、查询支付订单、查询订单状态、查询交易流水、查询交易记录、查询账单、绑定子钱包、验证钱包凭据、解绑子钱包、撤销钱包绑定。 不适用于:非支付场景、历史数据导出、批量操作、余额查询、收款码生成。 基于 Node.js 实现,使用 SM2/SM3/SM4 国密算法加密通信。

Identity and source

Publisher attributionzlpayregistry owner unverified by skillvetai
Functional categoryAwaiting category reviewreview pending · 0% rule confidence
Package forminstruction with code20 recorded files
Canonical sourceClawHub registryclawhub:kevindagege:zl-clawpay
Open canonical source ↗

Platform declarations

These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.

OpenClawnative officialProvenance: registry distribution

Independent structural checks

These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.

Claude Codeissues found
Checker 0.1.0 · agent-skills-2026-08-13+claude-code-docs-2026-08-13 · 9/16/2026.claude/skills/ZL-ClawPay
1 structural issue
  • error: name must contain lowercase ASCII letters, numbers and single hyphens only. SKILL.md

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenAI Codexissues found
Checker 0.1.0 · agent-skills-2026-08-13+codex-docs-2026-08-13 · 9/16/2026.agents/skills/ZL-ClawPay
1 structural issue
  • error: name must contain lowercase ASCII letters, numbers and single hyphens only. SKILL.md

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenClawissues found
Checker 0.1.0 · agent-skills-2026-08-13+openclaw-docs-2026-08-13 · 9/16/2026skills/ZL-ClawPay
1 structural issue
  • error: name must contain lowercase ASCII letters, numbers and single hyphens only. SKILL.md

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

Installation and inspection

This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.

clawhub install @kevindagege/zl-clawpay
clawhub inspect @kevindagege/zl-clawpay --version 1.0.8

Security evidence

SkillVetAI static result: high signal

This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.

Status
completed
Coverage
full text content
Files
20 / 20 inspected as text
Checked
9/16/2026, 4:52:07 AM
Scanner
0.1.3
Policy
1.0.3
1 automated finding
highPackage contains a path commonly used for secretsconfig/.env · confidence 88%/.env
1 High/Critical review queue entry
STATIC_SENSITIVE_FILE_IN_PACKAGEpending
Open human review queue →
4 inferred permission indicators
  • network access — automatically inferred
  • filesystem read — automatically inferred
  • filesystem write — automatically inferred
  • credential access — automatically inferred
5 dependency and API indicators
  • npm: axios ^1.16.0
  • npm: dotenv ^16.6.1
  • npm: sm-crypto ^0.3.14
  • api: clawhub.ai
  • api: gatewaytest.zqpay.com
External clawhub result: suspicious

This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.

Evidence checked
6/1/2026, 3:57:03 AM
Release binding
Matches this record
  • vt: clean
  • skillspector: suspicious
  • llm: suspicious

Recorded files

The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.

Package content hashsha256:249bd885b19ef8eef7d926b37ac8dabc92e08c421edca8a127284fd67cfdc084
Show up to 20 recorded paths
  • assets/request-examples.md
  • config/.env
  • package.json
  • references/api-spec.md
  • references/credential-setup-guide.md
  • references/dependency-guide.md
  • references/troubleshooting.md
  • scripts/config.js
  • scripts/constants.js
  • scripts/context/memory.js
  • scripts/context/state-store.js
  • scripts/crypto/gm-strategy.js
  • scripts/crypto/sm2.js
  • scripts/crypto/sm3.js
  • scripts/crypto/sm4.js
  • scripts/secure-client.js
  • scripts/services.js
  • scripts/skill.js
  • skill-card.md
  • SKILL.md

Source changelog

**Major update: Local encrypted credential storage, wallet binding/management, and new command interfaces.** - Credentials (`apiKey`, `subWalletId`) are now stored locally in an encrypted file (`~/.zl-claw-pay/state.json`) instead of environment variables. - Added interfaces: C00003 (bind wallet), L00001 (query wallet), and L00002 (unbind wallet locally). - Removed obsolete files and environment variable requirements for credentials. - Improved trigger policy: operations are now restricted to explicit user actions, preventing speculative commands. - Skill documentation updated for new workflows, usage instructions, and security practices.