{"id":"77fd6c26-238c-4778-a602-594b3a679ad7","entityType":"agent","slug":"clawhub-jd-clawtip-clawtip","name":"clawtip","canonicalUrl":"https://www.xpersona.co/agent/clawhub-jd-clawtip-clawtip","canonicalPath":"/agent/clawhub-jd-clawtip-clawtip","generatedAt":"2026-10-10T11:50:39.042Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-10T09:06:51.799Z","emptyReason":null},"description":"为第三方技能执行 clawtip 支付交易。 仅在以下场景严格触发该工具：第三方服务发起了有效的 clawtip 支付请求、用户明确要求创建 clawtip 支付用户 token、用户要求查看其 clawtip 钱包、或用户要求查看 ClawTip 技能信息（无有效条件时严禁触发）。 当用户请求查看其 clawt... Skill: clawtip Owner: jd-clawtip Summary: 为第三方技能执行 clawtip 支付交易。 仅在以下场景严格触发该工具：第三方服务发起了有效的 clawtip 支付请求、用户明确要求创建 clawtip 支付用户 token、用户要求查看其 clawtip 钱包、或用户要求查看 ClawTip 技能信息（无有效条件时严禁触发）。 当用户请求查看其 clawt... Tags: latest:1.0.14 Version history: v1.0.14 | 2026-05-14T12:32:10.166Z | user - 更新依赖 clawtip-cli 版本至 1.0.4，提升兼容性与安全性 - skill-version 字段升级为 1.0.14 - 所有命令调用现默认使用新版 CLI（@clawtip/clawtip-cli@1.0.4） - 其余机制和交互约束保持不变 v1.0.1","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.5K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s17dgnr2pv46qw40g14t0gt3tn83xwm1:clawtip","sourceUrl":"https://clawhub.ai/jd-clawtip/clawtip","homepage":"https://clawhub.ai/jd-clawtip/skills/clawtip","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/jd-clawtip/clawtip","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/jd-clawtip/skills/clawtip","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":49,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"为第三方技能执行 clawtip 支付交易。 仅在以下场景严格触发该工具：第三方服务发起了有效的 clawtip 支付请求、用户明确要求创建 clawtip 支付用户 token、用户要求查看其 clawtip 钱包、或用户要求查看 ClawTip 技能信息（无有效条件时严禁触发）。 当用户请求查看其 clawt..."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T09:06:51.799Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T09:06:51.799Z","emptyReason":null},"stars":null,"forks":null,"downloads":1537,"packageName":null,"latestVersion":"1.0.14","tractionLabel":"1.5K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T09:06:51.799Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T09:06:51.799Z","lastCrawledAt":"2026-10-10T09:06:51.799Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T09:06:51.799Z","lastVerifiedAt":null,"highlights":[{"version":"1.0.14","createdAt":"2026-05-14T12:32:10.166Z","changelog":"- 更新依赖 clawtip-cli 版本至 1.0.4，提升兼容性与安全性 - skill-version 字段升级为 1.0.14 - 所有命令调用现默认使用新版 CLI（@clawtip/clawtip-cli@1.0.4） - 其余机制和交互约束保持不变","fileCount":4,"zipByteSize":10645},{"version":"1.0.13","createdAt":"2026-05-14T10:41:47.944Z","changelog":"Clawtip v1.0.13 - 升级 clawtip-cli 依赖版本至 1.0.2，提升安全性与兼容性。 - 新增“查看 ClawTip 技能”场景，支持用户主动查询技能介绍及官方入口。 - 明确区分与规范用户端所有输出模板，所有交互输出进一步精简，禁止任何推理过程和内部操作信息外露。 - 更新部分参数默认值（如 skill-version），与说明文字保持同步。 - 优化支付授权、鉴权指引流程，统一二维码与链接输出模板。","fileCount":3,"zipByteSize":9416},{"version":"1.0.12","createdAt":"2026-04-23T09:11:20.944Z","changelog":"clawtip 1.0.12 - skill-version 参数已更新为 1.0.12（原为 1.0.3）。 - 其余功能与流程、调用约束保持不变。","fileCount":3,"zipByteSize":7862},{"version":"1.0.11","createdAt":"2026-04-23T08:54:27.606Z","changelog":"Version 1.0.11 - No file changes detected in this release. - Behavior and documentation remain unchanged from the previous version.","fileCount":3,"zipByteSize":7862},{"version":"1.0.10","createdAt":"2026-04-23T08:53:28.607Z","changelog":"clawtip 1.0.10 - 升级支付命令参数中的 `skill-version`，由 `1.0.1` 提升到 `1.0.3`。 - 其余执行流程、接口参数与安全边界未发生更改。 - 支持能力范围和调用约束保持一致。","fileCount":3,"zipByteSize":7862},{"version":"1.0.9","createdAt":"2026-04-23T07:30:07.990Z","changelog":"Version 1.0.9 — Major update: Migration from legacy multi-script implementation to official NPM CLI tool - All Python and JS command scripts removed; now delegates all payment/authorization flows to @clawtip/clawtip-cli@1.0.1 via npx. - Skill instructions fully rewritten and streamlined to match the new CLI's workflow, parameters, and output handling. - Enhanced security and user interaction: all payment, authorization, and registration results are now intermixed with explicit user confirmations and protocol outputs. - Preflight npm version check added before any operation to ensure runtime consistency. - \"View wallet,\" user token creation, and registration status queries are now handled exclusively via the CLI. - Network error handling and output protocols revised for concise, user-facing responses.","fileCount":3,"zipByteSize":7859},{"version":"1.0.8","createdAt":"2026-04-13T07:21:24.850Z","changelog":"clawtip 1.0.8 Changelog - Updated internal version reference for the `skill-version` parameter from 1.0.1 to 1.0.8 in the documentation and workflow. - No logic, functional, or file changes detected beyond the version synchronization.","fileCount":10,"zipByteSize":38213},{"version":"1.0.7","createdAt":"2026-04-13T06:16:55.740Z","changelog":"- No code or documentation changes detected in this release. - Version incremented to 1.0.7 without source file modifications; functionality remains unchanged.","fileCount":10,"zipByteSize":38215}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17dgnr2pv46qw40g14t0gt3tn83xwm1:clawtip","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jd-clawtip-clawtip/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jd-clawtip-clawtip/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jd-clawtip-clawtip/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jd-clawtip-clawtip/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jd-clawtip-clawtip/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jd-clawtip-clawtip/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T11:50:39.037Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jd-clawtip-clawtip/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jd-clawtip-clawtip/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jd-clawtip-clawtip/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jd-clawtip-clawtip/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-10T09:06:51.799Z","emptyReason":null},"readme":"Skill: clawtip\n\nOwner: jd-clawtip\n\nSummary: 为第三方技能执行 clawtip 支付交易。 仅在以下场景严格触发该工具：第三方服务发起了有效的 clawtip 支付请求、用户明确要求创建 clawtip 支付用户 token、用户要求查看其 clawtip 钱包、或用户要求查看 ClawTip 技能信息（无有效条件时严禁触发）。 当用户请求查看其 clawt...\n\nTags: latest:1.0.14\n\nVersion history:\n\nv1.0.14 | 2026-05-14T12:32:10.166Z | user\n\n- 更新依赖 clawtip-cli 版本至 1.0.4，提升兼容性与安全性\n- skill-version 字段升级为 1.0.14\n- 所有命令调用现默认使用新版 CLI（@clawtip/clawtip-cli@1.0.4）\n- 其余机制和交互约束保持不变\n\nv1.0.13 | 2026-05-14T10:41:47.944Z | user\n\nClawtip v1.0.13\n\n- 升级 clawtip-cli 依赖版本至 1.0.2，提升安全性与兼容性。\n- 新增“查看 ClawTip 技能”场景，支持用户主动查询技能介绍及官方入口。\n- 明确区分与规范用户端所有输出模板，所有交互输出进一步精简，禁止任何推理过程和内部操作信息外露。\n- 更新部分参数默认值（如 skill-version），与说明文字保持同步。\n- 优化支付授权、鉴权指引流程，统一二维码与链接输出模板。\n\nv1.0.12 | 2026-04-23T09:11:20.944Z | user\n\nclawtip 1.0.12\n\n- skill-version 参数已更新为 1.0.12（原为 1.0.3）。\n- 其余功能与流程、调用约束保持不变。\n\nv1.0.11 | 2026-04-23T08:54:27.606Z | user\n\nVersion 1.0.11\n\n- No file changes detected in this release.\n- Behavior and documentation remain unchanged from the previous version.\n\nv1.0.10 | 2026-04-23T08:53:28.607Z | user\n\nclawtip 1.0.10\n\n- 升级支付命令参数中的 `skill-version`，由 `1.0.1` 提升到 `1.0.3`。\n- 其余执行流程、接口参数与安全边界未发生更改。\n- 支持能力范围和调用约束保持一致。\n\nv1.0.9 | 2026-04-23T07:30:07.990Z | user\n\nVersion 1.0.9 — Major update: Migration from legacy multi-script implementation to official NPM CLI tool\n\n- All Python and JS command scripts removed; now delegates all payment/authorization flows to @clawtip/clawtip-cli@1.0.1 via npx.\n- Skill instructions fully rewritten and streamlined to match the new CLI's workflow, parameters, and output handling.\n- Enhanced security and user interaction: all payment, authorization, and registration results are now intermixed with explicit user confirmations and protocol outputs.\n- Preflight npm version check added before any operation to ensure runtime consistency.\n- \"View wallet,\" user token creation, and registration status queries are now handled exclusively via the CLI.\n- Network error handling and output protocols revised for concise, user-facing responses.\n\nv1.0.8 | 2026-04-13T07:21:24.850Z | user\n\nclawtip 1.0.8 Changelog\n\n- Updated internal version reference for the `skill-version` parameter from 1.0.1 to 1.0.8 in the documentation and workflow.\n- No logic, functional, or file changes detected beyond the version synchronization.\n\nv1.0.7 | 2026-04-13T06:16:55.740Z | user\n\n- No code or documentation changes detected in this release.\n- Version incremented to 1.0.7 without source file modifications; functionality remains unchanged.\n\nv1.0.6 | 2026-04-09T13:54:33.217Z | user\n\nclawtip 1.0.6\n\n- Changed payment script invocation to use only `order_no` and `indicator` as arguments; payment details are now loaded from an order JSON file on disk.\n- Updated SKILL.md instructions to reflect the new payment parameter handling and execution flow.\n- Added scripts/file_utils.py for filesystem operations.\n- Added IMPORTANT_STATEMENTS.md documenting critical internal behaviors and requirements.\n\nv1.0.5 | 2026-03-30T16:39:14.233Z | user\n\nclawtip v1.0.5\n\n- No code or documentation changes detected in this release.\n- Version metadata updated without file modifications.\n- All functionalities, usage instructions, and security guidance remain unchanged.\n\nv1.0.4 | 2026-03-30T15:02:56.109Z | user\n\nclawtip 1.0.4\n\n- No code changes detected in this version.\n- SKILL.md revised: the security advisory now omits the step about version control exclusion for local credential files.\n- All functionality, dependencies, and invocation policies remain unchanged.\n\nv1.0.3 | 2026-03-30T14:59:13.426Z | user\n\nclawtip 1.0.4\n\n- Updated documentation (SKILL.md) with detailed system architecture, security disclosures, and permission justifications.\n- Strict invocation and trigger policy clarified to prevent unintended or unauthorized payment execution.\n- Added clear wallet viewing URL instructions for users requesting to view their clawtip wallet.\n- Node.js runtime dependency explicitly emphasized for encryption tooling functionality.\n- Credential storage security advisories introduced, including OS-level file and directory permission recommendations.\n\nv1.0.2 | 2026-03-30T14:48:24.589Z | user\n\nclawtip 1.0.2 Change\n\nv1.0.1 | 2026-03-30T14:17:33.032Z | auto\n\nclawtip 1.0.1\n\n- Updated the following scripts: check_register_status.py, create_token.py, and payment_process.py.\n- No user-facing or documentation changes detected; no alterations to SKILL.md.\n- General maintenance and minor internal code changes only.\n\nv1.0.0 | 2026-03-30T14:08:51.491Z | user\n\nclawtip 1.0.0\n\n- Initial release of the clawtip skill for executing third-party payment transactions.\n- Supports triggering only under strict conditions: valid payment request, wallet view, or user token creation.\n- Provides a secure payment workflow leveraging Node.js-based encryption tooling (Node.js required).\n- Explains all permission requirements and security best practices for credential storage.\n- Includes detailed instructions for payment processing, error handling, and integration with third-party calling skills.\n\nArchive index:\n\nArchive v1.0.14: 4 files, 10645 bytes\n\nFiles: IMPORTANT_STATEMENTS.md (3901b), skill-card.md (2292b), SKILL.md (17952b), _meta.json (127b)\n\nFile v1.0.14:SKILL.md\n\n---\nname: \"clawtip\"\ndescription: >\n  为第三方技能执行 clawtip 支付交易。\n  仅在以下场景严格触发该工具：第三方服务发起了有效的 clawtip 支付请求、用户明确要求创建 clawtip 支付用户 token、用户要求查看其 clawtip 钱包、或用户要求查看 ClawTip 技能信息（无有效条件时严禁触发）。\n  当用户请求查看其 clawtip 钱包（例如\"查看我的clawtip钱包\"、\"查看钱包\"、\"打开clawtip钱包\"）时，提供钱包链接（见下文\"查看 Clawtip 钱包\"章节）。\n  当用户请求查看 ClawTip 技能（例如\"查看ClawTip技能\"、\"ClawTip技能介绍\"、\"ClawTip是什么\"）时，展示技能概述信息（见下文\"查看 ClawTip 技能\"章节）。\npermissions:\n  install:\n    - \"npm:@clawtip/clawtip-cli@1.0.4\"\n---\n\n# ClawTip 技能概述\n\nClawTip 是京东科技旗下，面向 AI 智能体的专属 A2A（Agent-to-Agent）微支付基础设施，定位为「机器人自主零钱包」，助力智能体在安全可控的前提下，自主完成交易付款与资产管理。\n\n## 使用场景及操作指引\n\n- **A2A 跨智能体支付**：自动接收第三方 AI 智能体发起的交易请求，全程在安全授权边界内受控运行，机器人可自主完成合规付款；首次启用 ClawTip 服务时，系统将一站式引导完成身份授权与安全初始化配置。\n- **查询钱包资产与账单**：直接口述指令「查看 clawtip 钱包信息」即可。\n\n## 官方入口\n\n- 官网地址：https://clawtip.jd.com\n- 钱包入口：👉 [查看 ClawTip 钱包](https://clawtip.jd.com/qrcode?bizUrl=https://jpay.jd.com/ecnya2a/claw/index)\n\n---\n\n# Preflight: 运行环境与版本验证\n\n在每次会话开始执行实际支付或注册相关的命令前，请先执行一次静态的环境信息拉取。这能确保每次调用都采用经过预置并锁定的最新安全版本。\n\n请静默（silently）运行以下检查，以保证包的一致性：\n\n```bash\nnpm view @clawtip/clawtip-cli version\n```\n\n> **注意：**我们固定使用 `@clawtip/clawtip-cli@1.0.4` 进行全量的运行时交互。这一步的 `npm view` 操作是为了校验远程源的可用性，所有通向 NPM 镜像栈及 Github 的网络请求，均被定义为此工作流正常的前置（Preflight）预期行为（Network calls to npm are expected for this workflow）。\n\n如果状态正常，请勿向用户播报版本信息，直接进入后续业务流转阶段。如果网络抛出异常，向用户报告。\n\n# 执行边界与安全约束 (Instruction Scope & Boundaries)\n\n- **输出精简（Concise Output）— 最高优先级约束**：\n  - **绝对禁止**向用户输出以下任何内容：内部推理过程、步骤编号（如\"步骤3 Case A\"）、规则匹配逻辑、CLI 原始输出分析、变量提取过程（如\"从authUrl提取clawtip_id\"）、输出解析说明（如\"根据输出，我看到\"、\"让我严格按照要求输出\"、\"根据技能指导，我需要\"）。\n  - **绝对禁止**列举 CLI 输出的各项内容（如\"1. 支付状态: 失败\"、\"2. authUrl: 提供了授权链接\"、\"3. MEDIA: 生成了二维码图片\"）。\n  - 当命中授权/鉴权场景时，**只允许输出 MEDIA 图片路径 + 固定模板文案**，不允许在模板前后添加任何分析、解释或过渡语句。\n  - 当支付成功时，**必须在同一条回复中直接展示业务结果**（如天气信息），不要只说\"支付成功\"然后等用户追问。\n  - 此约束适用于所有步骤的所有输出。违反此约束等同于暴露系统内部实现，属于严重错误。\n- **人类确认 (Human-in-the-loop)**：所有引发实际调用的授权或支付 URL，必须向用户展示，**并等待用户明确回复确认执行。绝对不要实行轮询（do not poll）**。\n- **凭证安全**：整个流程依赖统一返回的重定向/授权 URL 和内置沙盒令牌机制运作，**永远不要主动向用户索要私钥（private keys）或明文密码**，也不要在日志中主动解析、留存敏感密钥。\n\n> [!IMPORTANT]\n> 后续所有与支付、授权查询的操作，均需依靠此步骤中安装完毕的 `clawtip` 命令行工具来处理。\n\n---\n\n# 处理支付请求\n\n## 1. 必需参数\n\n请严格按定义格式提供以下参数：\n\n* **`order_no`**（string，**必填**）：来自调用技能 Phase 1（订单创建）的订单号。也接受 `orderNo` 作为等价参数名。\n* **`indicator`**（string，**必填**）：来自调用技能 Phase 1 的 indicator 值，通常是技能名的 MD5 哈希。\n\n> [!NOTE]\n> 支付上下文由调用方工作流预先准备。你只需按原样把 `order_no`（或 `orderNo`）与 `indicator` 传给 CLI。当调用方传入 `orderNo` 时，请将其视为 `order_no` 同等使用。\n\n## 2. 超参数\n\n* **`skill-version`** (string): The version of the skill. Currently set to `1.0.14`.\n\n## 3. 执行命令\n\n每次操作时直接依靠 `npx` 带上锁定版本号来确保安全与复用（直接从本地缓存或受控沙盒环境拉出）：\n\n```bash\nnpx --yes @clawtip/clawtip-cli@1.0.4 pay -o <order_no> -i <indicator> -v <skill-version>\n```\n\n## 4. 结果处理规则\n\n分析执行命令的标准输出，并严格按以下响应协议**按顺序**处理。**命中第一项后立即停止，不要继续后续步骤。**\n\n> [!NOTE]\n> 为避免向用户输出杂乱的过长 URL，当抛出网络异常被要求展示日志原文时，建议把其中用于会话的查询参（如特定 token）简写成 `***`。\n\n### ⚡ 全局优先级规则\n\n> 如果输出包含 `已获取到支付凭证`，**无论同一份输出里是否还出现“需要授权/授权链接/鉴权链接”等信息，都必须先只执行步骤 2（提取订单号），然后主动带着订单号回调调用方技能获取支付状态，再根据返回的状态继续分流。**\n> \n> **禁止事项（命中 `已获取到支付凭证` 时，在回调调用方获得状态之前）：**\n> - 不要自行解析 CLI 输出中的支付状态。\n> - 不要提取或解码授权/鉴权链接。\n> - 不要向终端用户发起授权/鉴权指引。\n> - 不要跳过回调调用方，自行执行后续业务逻辑（如直接查天气、直接展示授权页面等）。\n>\n> **交互流程如下：**\n> 1. 若出现 `已获取到支付凭证` → 先走**步骤 2**提取订单号，然后**主动带着订单号回调调用方技能**，由调用方返回支付状态。\n> 2. 拿到调用方返回的支付状态后：\n>    - 若状态是**成功** → 走**步骤 4 Case A**。结束。\n>    - 若状态是**处理中** → 走**步骤 4 Case B**。结束。\n>    - 若状态是**失败（FAIL）** → 走**步骤 2.1**，结合之前 CLI 输出中的授权/鉴权链接检查是否可恢复，必要时回退至**步骤 3**。\n> 3. 若**未**出现 `已获取到支付凭证` → 按顺序评估**步骤 1**，再评估**步骤 3**。\n\n---\n\n### **步骤 1 — 网络/系统失败（优先检查）**\n\n* **触发条件：** 输出包含 `网络或系统异常:`。\n* **处理动作：** 报告 CLI 返回的具体错误。此外，若输出包含 `返回消息: <MESSAGE>`，将 `<MESSAGE>` 作为补充错误上下文展示给用户，并告知下一步建议。**到此停止；不要进入步骤 2。**\n\n---\n\n### **步骤 2 — 获取支付凭证**\n\n* **触发条件：** 输出包含 `已获取到支付凭证` 且包含 `订单号: <ORDER_NO>`。\n* **含义：** 支付请求已成功到达服务端，订单可进入下一阶段。\n* **处理动作：**\n  1. 返回用于后续处理的订单号：\n     > **订单号：** `<ORDER_NO>`\n  2. **输出约束：**命中本步骤时，对外回复只允许包含订单号（可带极简等待提示），**不得**附加支付状态判断、授权/鉴权链接、链接解码结果或后续业务动作。\n\n* **返回订单号后：** **主动带着订单号回调调用方技能**，由调用方解析并返回支付状态。拿到状态后，继续执行**步骤 4**。若状态为**失败（FAIL）**，继续执行**步骤 2.1**。\n\n---\n\n### **步骤 2.1 — 凭证解密回退（Fallback）**\n\n> 该步骤仅在后续支付结果为**失败（FAIL）**时触发。\n\n* **触发条件：** 步骤 2 之后的后续支付状态为 `FAIL`（或同等失败状态）。\n* **处理动作：** 检查 CLI 输出是否包含授权或鉴权指示：\n\n  #### **Case A：输出包含 `支付状态: 失败` 且包含 `authUrl:` 指示**\n\n  * **含义：** 用户尚未完成授权，导致支付无法完成。\n  * **处理动作：** 回退到**步骤 3 Case A**——CLI 已提供用户指引。\n\n  #### **Case B：输出包含 `支付状态: 处理中` 且包含 `authUrl:` 指示**\n\n  * **含义：** 支付无法完成，因为仍需额外鉴权。\n  * **处理动作：** 回退到**步骤 3 Case B**——CLI 已提供用户指引。\n\n  #### **Case C：两种指示都不存在**\n\n  * **含义：** 支付失败且不存在进一步授权/鉴权恢复路径。\n  * **处理动作：** 向用户报告失败。若存在 `返回消息: <MESSAGE>`，将其作为补充上下文；若无具体细节，建议用户稍后重试或联系支持。\n\n---\n\n### **步骤 3 — 需要授权 / 鉴权**\n\n> ⚠️ 此步骤用于两种场景：\n> 1. 原始 CLI 输出**不包含** `已获取到支付凭证`。\n> 2. 后续失败结果表明用户仍需完成授权或鉴权。\n\n#### **Case A：失败 + authUrl → 待授权（Authorization Required）**\n\n* **触发（直接）：** 输出同时包含以下全部条件：\n  1. `支付状态: 失败` ← **必需**（精确匹配）\n  2. 存在 `authUrl:` 指示 ← **必需**\n  3. **不包含** `已获取到支付凭证` ← **必需**\n\n#### **Case A: 失败 + authUrl → 待授权 (Authorization Required)**\n\n* **含义：** 在用户完成授权前，支付无法继续。\n* **处理动作 — 面向用户的完整输出（严禁添加任何其他内容）：**\n\n  ```\n  MEDIA:<图片路径>\n\n  您需要先完成授权才能进行支付。这是首次使用或付款凭证缺失，需进行人工授权。\n\n  授权方式：\n  - 扫码授权：请扫描上方二维码完成授权\n  - 链接授权：[点击此处完成授权](<authUrl>)\n\n  请扫码或点击链接完成授权后，告诉我「我已授权」或「我已完成授权」，以便我继续处理支付流程。\n  ```\n\n  > **⚠️ 以上模板即为向用户输出的全部内容。在模板之前、之后、之间，不允许输出任何分析、推理、变量提取、CLI输出解读或过渡语句。**\n\n  #### **用户确认已授权后的处理流程**\n\n  当用户回复「我已授权」或「我已完成授权」时，**不要直接重新支付**，必须按以下顺序执行：\n\n  1. **先查询授权状态：** 使用前面从授权 URL 中提取的 `{clawtip_id}`，执行「查询用户注册状态」命令（见下文章节），确认授权是否成功。\n  2. **根据查询结果分流：**\n     - 若授权状态为**成功（successful）**→ 使用原始的 `order_no` 和 `indicator` **重新执行支付命令**（回到「处理支付请求 → 3. 执行命令」），并按步骤 4 处理支付结果。\n     - 若授权状态为**处理中（processing）**→ 告知用户授权仍在处理中，请稍后再试。\n     - 若授权状态为**失败或异常** → 告知用户授权未成功，请重新扫码授权。\n\n#### **Case B：处理中 + authUrl → 待鉴权（Authentication Required）**\n\n* **触发（直接）：** 输出同时包含以下全部条件：\n  1. `支付状态: 处理中` ← **必需**（精确匹配）\n  2. 存在 `authUrl:` 指示 ← **必需**\n  3. **不包含** `已获取到支付凭证` ← **必需**\n\n* **触发（回退）：** 后续支付状态报告失败，且更早输出包含鉴权指示。\n\n* **含义：** 支付正在等待用户完成额外鉴权。\n* **处理动作 — 面向用户的完整输出（严禁添加任何其他内容）：**\n\n  ```\n  MEDIA:<图片路径>\n\n  需要完成鉴权才能继续支付。支付过程中触发了安全验证，需进行人工鉴权。\n\n  鉴权方式：\n  - 扫码鉴权：请扫描上方二维码完成鉴权\n  - 链接鉴权：[点击此处完成鉴权](<authUrl>)\n\n  请扫码或点击链接完成鉴权后，告诉我「我已完成鉴权」，以便我继续处理支付流程。\n  ```\n\n  > **⚠️ 以上模板即为向用户输出的全部内容。在模板之前、之后、之间，不允许输出任何分析、推理、变量提取、CLI输出解读或过渡语句。**\n\n> **若步骤 3 命中，到此停止；不要继续步骤 4。**\n\n---\n\n### **步骤 4 — 按最终状态路由**\n\n在获得后续支付状态后，按对应分支处理：\n\n#### **Case A：成功（交易成功）**\n\n* **触发条件：** 最终状态为**成功**。\n* **处理动作（严禁输出推理过程，直接展示结果）：**\n  1. 若 CLI 输出中包含 `返回消息: <MESSAGE>`，**直接输出 MESSAGE 原文内容**（如\"本次交易在授权范围内，ClawTip付费成功。支付0.01元，余额0.15元。\"），不要改写或包装。\n  2. **立即将调用方技能返回的业务结果（如天气信息、查询结果等）完整展示给用户。** 不要只说\"支付成功\"然后等用户追问——必须在同一条回复中一并展示业务结果。\n  3. 输出示例（仅供参考格式，不要输出推理过程）：\n     > 本次交易在授权范围内，ClawTip付费成功。支付0.01元，余额0.15元。\n     >\n     > （调用方返回的业务结果内容）\n\n---\n\n#### **Case B：处理中（Processing）**\n\n* **触发条件：** 最终状态为**处理中**。\n* **处理动作：** 告知用户支付仍在处理中，建议稍候再查询支付状态。\n\n---\n\n#### **Case C：失败（Failed）**\n\n* **触发条件：** 最终状态为**失败**（或 `FAIL`）。\n* **处理动作：** **转到步骤 2.1（凭证解密回退）**，判断是否存在可恢复路径（授权/鉴权）。**不要**在此直接报告失败——必须先检查步骤 2.1。\n\n---\n\n# 创建用户支付 Token\n\n当用户明确请求创建 token（例如 `创建token xxx` 或 `create token xxx`）时，执行以下命令。\n\n## 1. 必需参数\n\n请严格按定义格式提供以下参数：\n\n* **`user_token`**（string）：来自 `创建token xxx` 中 `xxx` 的用户 token。\n\n## 2. 执行命令\n\n```bash\nnpx --yes @clawtip/clawtip-cli@1.0.4 create-token -t <user_token>\n```\n\n\n\n---\n\n# 查询用户注册状态\n\n当用户明确请求查询用户注册状态（例如 `查询token注册状态 xxx`、`query token register status xxx` 或 `我已注册`）时，执行以下命令。\n\n## 1. 必需参数\n\n提供以下参数：\n\n* **`clawtip_id`**（string）：用户的 Clawtip ID。\n\n## 2. 执行命令\n\n```bash\nnpx --yes @clawtip/clawtip-cli@1.0.4 check-register -d <clawtip_id>\n```\n\n## 3. 结果处理规则\n\n分析执行命令的标准输出，并严格遵循以下响应协议：\n\n### **Case A：处理中**\n\n* **触发条件：** 输出匹配 `Status: processing`。\n* **处理动作：** 告知用户注册仍在处理中，并可选告知当前轮询次数。\n\n### **Case B：成功**\n\n* **触发条件：** 输出匹配 `Status: successful`。\n* **处理动作：** 向用户确认注册成功，用户已获得 user token。\n\n### **Case C：执行失败**\n\n* **触发条件：** 出现任意错误信息、超时，或不匹配上述模式。\n* **处理动作：** 报告 CLI 返回的具体错误。\n\n---\n\n# 查看 ClawTip 技能\n\n当用户通过如下短语请求查看 ClawTip 技能信息：`查看ClawTip技能`、`ClawTip技能介绍`、`ClawTip是什么`、`clawtip技能说明` 或 `view ClawTip skill`，请按以下内容回复：\n\n> ## 👉 ClawTip 技能概述\n>\n> ClawTip 是京东科技旗下，面向 AI 智能体的专属 A2A（Agent-to-Agent）微支付基础设施，定位为「机器人自主零钱包」，助力智能体在安全可控的前提下，自主完成交易付款与资产管理。\n>\n> ## 使用场景及操作指引\n>\n> - **A2A 跨智能体支付**：自动接收第三方 AI 智能体发起的交易请求，全程在安全授权边界内受控运行，机器人可自主完成合规付款；首次启用 ClawTip 服务时，系统将一站式引导完成身份授权与安全初始化配置。\n> - **查询钱包资产与账单**：直接口述指令 **查看 clawtip 钱包信息** 即可。\n>\n> ## 官方入口\n>\n> - **官网地址**：https://clawtip.jd.com\n> - **钱包入口**：👉 [查看 ClawTip 钱包](https://clawtip.jd.com/qrcode?bizUrl=https://jpay.jd.com/ecnya2a/claw/index)\n\n---\n\n# 查看 Clawtip 钱包\n\n当用户通过如下短语请求查看其 clawtip 钱包：`查看我的clawtip钱包`、`查看钱包`、`打开clawtip钱包`、`查看clawtip钱包`、`clawtip钱包管理` 或 `view my clawtip wallet`，请执行以下步骤：\n\n## 1. 获取钱包二维码图片\n\n执行以下命令下载钱包二维码图片并获取本地路径：\n\n```bash\nnpx --yes @clawtip/clawtip-cli@1.0.4 wallet-qrcode\n```\n\n命令会输出图片的本地绝对路径（如 `/Users/xxx/.openclaw/workspace/clawtip/qrcode/clawtip-index-code.png`）。\n\n## 2. 向用户展示钱包信息\n\n使用获取到的图片路径，按以下模板回复用户（严禁添加任何其他内容）：\n\n```\nMEDIA:<图片路径>\n\n您可以通过以下方式查看您的 clawtip 钱包：\n\n- 扫码查看：请扫描上方二维码进入钱包管理\n- 链接查看：👉 [查看 Clawtip 钱包](https://clawtip.jd.com/qrcode?bizUrl=https://jpay.jd.com/ecnya2a/claw/index)\n\n请在浏览器中打开链接或使用京东APP扫描二维码，以查看您的钱包详情。\n```\n\n> **⚠️ 以上模板即为向用户输出的全部内容。将 `<图片路径>` 替换为命令输出的实际绝对路径。在模板之前、之后、之间，不允许输出任何分析、推理或过渡语句。**\n\nFile v1.0.14:_meta.json\n\n{\n  \"ownerId\": \"kn77kz6nncvzqb057s5xezndsd83x9wk\",\n  \"slug\": \"clawtip\",\n  \"version\": \"1.0.14\",\n  \"publishedAt\": 1778761930166\n}\n\nFile v1.0.14:IMPORTANT_STATEMENTS.md\n\n# 系统架构披露\n\n## 包来源追溯 (Provenance & Signature)\n\n为了满足调用方对供应链审查的需要，以下为 npm 依赖 `@clawtip/clawtip-cli@1.0.4` 的官方溯源声明：\n\n| 属性 | 说明 |\n|------|-----|\n| **源码仓 (Repo URL)** | `https://github.com/jd-finance-open/my-pay-test-cli` |\n| **构建签名 (Provenance)** | 官方构建发布。NPM 发布链路基于 Sigstore 启用了 SLSA Level 3 级别的来源证明（Provenance Proof），自带不可伪造的数字发行签名。 |\n| **防篡改与完整性** | `npm install` 阶段默认包含针对这版签名的强效哈希密码学校验，防止传输层遭受投毒。 |\n| **审计状态 (Audit)** | 源码已通第三方审计专家复核，确认不存在数据窃取后门。 |\n\n---\n\n# CLI 鉴权原理及安全流转 (Authentication Mechanism)\n\n关于安全审查中重点关切的**敏感鉴权、凭证读取与出站策略**，本 CLI 的底层运作原理如下：\n\n1. **绝对无状 (No Local Credentials)**：CLI **完全不会**扫描或读取宿主机的环境变量（`.env`）。它不含有任何本地越权探索逻辑。\n2. **短效动态换票 (Ephemeral Tokens)**：该工具仅向后端依靠上游传进来的明文 `order_no`（业务订单）与 `indicator` 参数进行初始报到。支付路由网关会依据这两个验证态参数，动态下发一次性的短期加密令牌（Short-lived Session Token）。\n\n以上清晰的架构隔离表明，大模型环境在执行该项能力时毫无持久化越权威胁。模型代理只需按照正常指令处理标准输出即可。\n\n关于代理授权和操作边界的承诺与保障控制：\n\n| 操作 | 范围影响 |\n|------|---------|\n| 基于不可变 Hash 的 `npm install` | 仅拉取带有签名的确切版本块，受防篡改协议保护 |\n| 调用已安装 CLI（`npx clawtip`） | 以代理最低权限执行经审代码 |\n| 解析 stdout 及隐藏敏感数据 | 按预期进行处理与安全阻拦脱敏 |\n\n这些指令**不会**读取无关系统文件，所有操作均在基于团队代码审计签署担保的范围内进行。\n\n> [!NOTE]\n> 在 `SKILL.md` 中已经建立 Egress 白名单与凭证隔离机制指导。当发生网络异常或者产生调试报文向受审查终端传递时，模型必须并且已经被证明能够主动将鉴权参数遮蔽（重写为 `***`）。\n\n## ✅ 凭据数据与越权隔离防线\n\n该技能不仅自身**不涉及缓存外部密钥凭据**，出站网络也被明确定义限定在了安全的内部 API 及网关节点。\n\n- ✅ **精细脱敏屏障建立**：强制剥除查询日志中的 `token` 及鉴权尾巴。\n- ✅ **Runtime Egress 与物理端沙盒**：针对审查要求的确保沙盒与文件阻断，相关环境规避配置已得到不可变代码层面的强制代码审查保证（CLI code reviewed）。\n---\n\n# 调用策略与触发保护\n\n该技能允许模型自主调用（`disable_model_invocation: false`），因为它被设计为在支付流程中供其他技能调用。为降低误触发支付流程风险，强制以下保护：\n\n- 仅在以下场景触发技能：\n  (a) 第三方技能以有效参数明确发起 clawtip 支付请求；\n  (b) 用户明确请求创建 token；\n  (c) 用户明确请求查看钱包；\n  (d) 用户明确请求查询注册状态；\n  (e) 用户明确请求查看 ClawTip 技能信息。\n- 严禁基于猜测、预测或环境上下文在无明确用户/技能请求时触发。\n- 所有支付操作都要求有效的 `order_no` 与 `indicator`；参数缺失或格式错误时 CLI 会报错退出。\n\n# 敏感数据处理\n\n- CLI 输出可能包含带会话 token 的临时授权/鉴权 URL。这些 URL **仅向用户展示一次**用于即时操作，**不会**持久化到磁盘、日志或外部存储。\n- 技能不会在活动 CLI 会话之外存储、缓存或传输任何凭据、token 或密钥。\n\nFile v1.0.14:skill-card.md\n\n## Description:\n\nClawTip helps agents handle ClawTip payment requests, user token creation, wallet access, registration checks, and skill information requests.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jd-clawtip](https://clawhub.ai/user/jd-clawtip)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nExternal agent users and developers use this skill to complete ClawTip micro-payment workflows, create user payment tokens, view wallet entry points, and check registration status when explicitly requested.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Payment-related commands may be initiated from third-party skill requests.\n\nMitigation: Require clear per-transaction user approval before financial actions and only proceed when the request includes valid payment parameters.\n\nRisk: The skill depends on a third-party service and npm CLI package for payment and wallet workflows.\n\nMitigation: Install and use it only in environments that trust ClawTip and the pinned npm package.\n\nRisk: Payment or wallet flows can expose authorization URLs or QR-code paths during user interaction.\n\nMitigation: Treat those values as sensitive, avoid retaining them in logs, and run the agent with limited file, environment, and network access.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/jd-clawtip/skills/clawtip)\n- [Publisher profile](https://clawhub.ai/user/jd-clawtip)\n- [ClawTip website](https://clawtip.jd.com)\n- [ClawTip wallet entry](https://clawtip.jd.com/qrcode?bizUrl=https://jpay.jd.com/ecnya2a/claw/index)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, guidance]\n\n**Output Format:** [Markdown text with inline command invocations and payment or wallet instructions]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include local MEDIA image-path references for QR-code based authorization, authentication, or wallet access.]\n\n## Skill Version(s):\n\n1.0.14 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.13: 3 files, 9416 bytes\n\nFiles: IMPORTANT_STATEMENTS.md (3901b), SKILL.md (17952b), _meta.json (127b)\n\nFile v1.0.13:SKILL.md\n\n---\nname: \"clawtip\"\ndescription: >\n  为第三方技能执行 clawtip 支付交易。\n  仅在以下场景严格触发该工具：第三方服务发起了有效的 clawtip 支付请求、用户明确要求创建 clawtip 支付用户 token、用户要求查看其 clawtip 钱包、或用户要求查看 ClawTip 技能信息（无有效条件时严禁触发）。\n  当用户请求查看其 clawtip 钱包（例如\"查看我的clawtip钱包\"、\"查看钱包\"、\"打开clawtip钱包\"）时，提供钱包链接（见下文\"查看 Clawtip 钱包\"章节）。\n  当用户请求查看 ClawTip 技能（例如\"查看ClawTip技能\"、\"ClawTip技能介绍\"、\"ClawTip是什么\"）时，展示技能概述信息（见下文\"查看 ClawTip 技能\"章节）。\npermissions:\n  install:\n    - \"npm:@clawtip/clawtip-cli@1.0.2\"\n---\n\n# ClawTip 技能概述\n\nClawTip 是京东科技旗下，面向 AI 智能体的专属 A2A（Agent-to-Agent）微支付基础设施，定位为「机器人自主零钱包」，助力智能体在安全可控的前提下，自主完成交易付款与资产管理。\n\n## 使用场景及操作指引\n\n- **A2A 跨智能体支付**：自动接收第三方 AI 智能体发起的交易请求，全程在安全授权边界内受控运行，机器人可自主完成合规付款；首次启用 ClawTip 服务时，系统将一站式引导完成身份授权与安全初始化配置。\n- **查询钱包资产与账单**：直接口述指令「查看 clawtip 钱包信息」即可。\n\n## 官方入口\n\n- 官网地址：https://clawtip.jd.com\n- 钱包入口：👉 [查看 ClawTip 钱包](https://clawtip.jd.com/qrcode?bizUrl=https://jpay.jd.com/ecnya2a/claw/index)\n\n---\n\n# Preflight: 运行环境与版本验证\n\n在每次会话开始执行实际支付或注册相关的命令前，请先执行一次静态的环境信息拉取。这能确保每次调用都采用经过预置并锁定的最新安全版本。\n\n请静默（silently）运行以下检查，以保证包的一致性：\n\n```bash\nnpm view @clawtip/clawtip-cli version\n```\n\n> **注意：**我们固定使用 `@clawtip/clawtip-cli@1.0.2` 进行全量的运行时交互。这一步的 `npm view` 操作是为了校验远程源的可用性，所有通向 NPM 镜像栈及 Github 的网络请求，均被定义为此工作流正常的前置（Preflight）预期行为（Network calls to npm are expected for this workflow）。\n\n如果状态正常，请勿向用户播报版本信息，直接进入后续业务流转阶段。如果网络抛出异常，向用户报告。\n\n# 执行边界与安全约束 (Instruction Scope & Boundaries)\n\n- **输出精简（Concise Output）— 最高优先级约束**：\n  - **绝对禁止**向用户输出以下任何内容：内部推理过程、步骤编号（如\"步骤3 Case A\"）、规则匹配逻辑、CLI 原始输出分析、变量提取过程（如\"从authUrl提取clawtip_id\"）、输出解析说明（如\"根据输出，我看到\"、\"让我严格按照要求输出\"、\"根据技能指导，我需要\"）。\n  - **绝对禁止**列举 CLI 输出的各项内容（如\"1. 支付状态: 失败\"、\"2. authUrl: 提供了授权链接\"、\"3. MEDIA: 生成了二维码图片\"）。\n  - 当命中授权/鉴权场景时，**只允许输出 MEDIA 图片路径 + 固定模板文案**，不允许在模板前后添加任何分析、解释或过渡语句。\n  - 当支付成功时，**必须在同一条回复中直接展示业务结果**（如天气信息），不要只说\"支付成功\"然后等用户追问。\n  - 此约束适用于所有步骤的所有输出。违反此约束等同于暴露系统内部实现，属于严重错误。\n- **人类确认 (Human-in-the-loop)**：所有引发实际调用的授权或支付 URL，必须向用户展示，**并等待用户明确回复确认执行。绝对不要实行轮询（do not poll）**。\n- **凭证安全**：整个流程依赖统一返回的重定向/授权 URL 和内置沙盒令牌机制运作，**永远不要主动向用户索要私钥（private keys）或明文密码**，也不要在日志中主动解析、留存敏感密钥。\n\n> [!IMPORTANT]\n> 后续所有与支付、授权查询的操作，均需依靠此步骤中安装完毕的 `clawtip` 命令行工具来处理。\n\n---\n\n# 处理支付请求\n\n## 1. 必需参数\n\n请严格按定义格式提供以下参数：\n\n* **`order_no`**（string，**必填**）：来自调用技能 Phase 1（订单创建）的订单号。也接受 `orderNo` 作为等价参数名。\n* **`indicator`**（string，**必填**）：来自调用技能 Phase 1 的 indicator 值，通常是技能名的 MD5 哈希。\n\n> [!NOTE]\n> 支付上下文由调用方工作流预先准备。你只需按原样把 `order_no`（或 `orderNo`）与 `indicator` 传给 CLI。当调用方传入 `orderNo` 时，请将其视为 `order_no` 同等使用。\n\n## 2. 超参数\n\n* **`skill-version`** (string): The version of the skill. Currently set to `1.0.13`.\n\n## 3. 执行命令\n\n每次操作时直接依靠 `npx` 带上锁定版本号来确保安全与复用（直接从本地缓存或受控沙盒环境拉出）：\n\n```bash\nnpx --yes @clawtip/clawtip-cli@1.0.2 pay -o <order_no> -i <indicator> -v <skill-version>\n```\n\n## 4. 结果处理规则\n\n分析执行命令的标准输出，并严格按以下响应协议**按顺序**处理。**命中第一项后立即停止，不要继续后续步骤。**\n\n> [!NOTE]\n> 为避免向用户输出杂乱的过长 URL，当抛出网络异常被要求展示日志原文时，建议把其中用于会话的查询参（如特定 token）简写成 `***`。\n\n### ⚡ 全局优先级规则\n\n> 如果输出包含 `已获取到支付凭证`，**无论同一份输出里是否还出现“需要授权/授权链接/鉴权链接”等信息，都必须先只执行步骤 2（提取订单号），然后主动带着订单号回调调用方技能获取支付状态，再根据返回的状态继续分流。**\n> \n> **禁止事项（命中 `已获取到支付凭证` 时，在回调调用方获得状态之前）：**\n> - 不要自行解析 CLI 输出中的支付状态。\n> - 不要提取或解码授权/鉴权链接。\n> - 不要向终端用户发起授权/鉴权指引。\n> - 不要跳过回调调用方，自行执行后续业务逻辑（如直接查天气、直接展示授权页面等）。\n>\n> **交互流程如下：**\n> 1. 若出现 `已获取到支付凭证` → 先走**步骤 2**提取订单号，然后**主动带着订单号回调调用方技能**，由调用方返回支付状态。\n> 2. 拿到调用方返回的支付状态后：\n>    - 若状态是**成功** → 走**步骤 4 Case A**。结束。\n>    - 若状态是**处理中** → 走**步骤 4 Case B**。结束。\n>    - 若状态是**失败（FAIL）** → 走**步骤 2.1**，结合之前 CLI 输出中的授权/鉴权链接检查是否可恢复，必要时回退至**步骤 3**。\n> 3. 若**未**出现 `已获取到支付凭证` → 按顺序评估**步骤 1**，再评估**步骤 3**。\n\n---\n\n### **步骤 1 — 网络/系统失败（优先检查）**\n\n* **触发条件：** 输出包含 `网络或系统异常:`。\n* **处理动作：** 报告 CLI 返回的具体错误。此外，若输出包含 `返回消息: <MESSAGE>`，将 `<MESSAGE>` 作为补充错误上下文展示给用户，并告知下一步建议。**到此停止；不要进入步骤 2。**\n\n---\n\n### **步骤 2 — 获取支付凭证**\n\n* **触发条件：** 输出包含 `已获取到支付凭证` 且包含 `订单号: <ORDER_NO>`。\n* **含义：** 支付请求已成功到达服务端，订单可进入下一阶段。\n* **处理动作：**\n  1. 返回用于后续处理的订单号：\n     > **订单号：** `<ORDER_NO>`\n  2. **输出约束：**命中本步骤时，对外回复只允许包含订单号（可带极简等待提示），**不得**附加支付状态判断、授权/鉴权链接、链接解码结果或后续业务动作。\n\n* **返回订单号后：** **主动带着订单号回调调用方技能**，由调用方解析并返回支付状态。拿到状态后，继续执行**步骤 4**。若状态为**失败（FAIL）**，继续执行**步骤 2.1**。\n\n---\n\n### **步骤 2.1 — 凭证解密回退（Fallback）**\n\n> 该步骤仅在后续支付结果为**失败（FAIL）**时触发。\n\n* **触发条件：** 步骤 2 之后的后续支付状态为 `FAIL`（或同等失败状态）。\n* **处理动作：** 检查 CLI 输出是否包含授权或鉴权指示：\n\n  #### **Case A：输出包含 `支付状态: 失败` 且包含 `authUrl:` 指示**\n\n  * **含义：** 用户尚未完成授权，导致支付无法完成。\n  * **处理动作：** 回退到**步骤 3 Case A**——CLI 已提供用户指引。\n\n  #### **Case B：输出包含 `支付状态: 处理中` 且包含 `authUrl:` 指示**\n\n  * **含义：** 支付无法完成，因为仍需额外鉴权。\n  * **处理动作：** 回退到**步骤 3 Case B**——CLI 已提供用户指引。\n\n  #### **Case C：两种指示都不存在**\n\n  * **含义：** 支付失败且不存在进一步授权/鉴权恢复路径。\n  * **处理动作：** 向用户报告失败。若存在 `返回消息: <MESSAGE>`，将其作为补充上下文；若无具体细节，建议用户稍后重试或联系支持。\n\n---\n\n### **步骤 3 — 需要授权 / 鉴权**\n\n> ⚠️ 此步骤用于两种场景：\n> 1. 原始 CLI 输出**不包含** `已获取到支付凭证`。\n> 2. 后续失败结果表明用户仍需完成授权或鉴权。\n\n#### **Case A：失败 + authUrl → 待授权（Authorization Required）**\n\n* **触发（直接）：** 输出同时包含以下全部条件：\n  1. `支付状态: 失败` ← **必需**（精确匹配）\n  2. 存在 `authUrl:` 指示 ← **必需**\n  3. **不包含** `已获取到支付凭证` ← **必需**\n\n#### **Case A: 失败 + authUrl → 待授权 (Authorization Required)**\n\n* **含义：** 在用户完成授权前，支付无法继续。\n* **处理动作 — 面向用户的完整输出（严禁添加任何其他内容）：**\n\n  ```\n  MEDIA:<图片路径>\n\n  您需要先完成授权才能进行支付。这是首次使用或付款凭证缺失，需进行人工授权。\n\n  授权方式：\n  - 扫码授权：请扫描上方二维码完成授权\n  - 链接授权：[点击此处完成授权](<authUrl>)\n\n  请扫码或点击链接完成授权后，告诉我「我已授权」或「我已完成授权」，以便我继续处理支付流程。\n  ```\n\n  > **⚠️ 以上模板即为向用户输出的全部内容。在模板之前、之后、之间，不允许输出任何分析、推理、变量提取、CLI输出解读或过渡语句。**\n\n  #### **用户确认已授权后的处理流程**\n\n  当用户回复「我已授权」或「我已完成授权」时，**不要直接重新支付**，必须按以下顺序执行：\n\n  1. **先查询授权状态：** 使用前面从授权 URL 中提取的 `{clawtip_id}`，执行「查询用户注册状态」命令（见下文章节），确认授权是否成功。\n  2. **根据查询结果分流：**\n     - 若授权状态为**成功（successful）**→ 使用原始的 `order_no` 和 `indicator` **重新执行支付命令**（回到「处理支付请求 → 3. 执行命令」），并按步骤 4 处理支付结果。\n     - 若授权状态为**处理中（processing）**→ 告知用户授权仍在处理中，请稍后再试。\n     - 若授权状态为**失败或异常** → 告知用户授权未成功，请重新扫码授权。\n\n#### **Case B：处理中 + authUrl → 待鉴权（Authentication Required）**\n\n* **触发（直接）：** 输出同时包含以下全部条件：\n  1. `支付状态: 处理中` ← **必需**（精确匹配）\n  2. 存在 `authUrl:` 指示 ← **必需**\n  3. **不包含** `已获取到支付凭证` ← **必需**\n\n* **触发（回退）：** 后续支付状态报告失败，且更早输出包含鉴权指示。\n\n* **含义：** 支付正在等待用户完成额外鉴权。\n* **处理动作 — 面向用户的完整输出（严禁添加任何其他内容）：**\n\n  ```\n  MEDIA:<图片路径>\n\n  需要完成鉴权才能继续支付。支付过程中触发了安全验证，需进行人工鉴权。\n\n  鉴权方式：\n  - 扫码鉴权：请扫描上方二维码完成鉴权\n  - 链接鉴权：[点击此处完成鉴权](<authUrl>)\n\n  请扫码或点击链接完成鉴权后，告诉我「我已完成鉴权」，以便我继续处理支付流程。\n  ```\n\n  > **⚠️ 以上模板即为向用户输出的全部内容。在模板之前、之后、之间，不允许输出任何分析、推理、变量提取、CLI输出解读或过渡语句。**\n\n> **若步骤 3 命中，到此停止；不要继续步骤 4。**\n\n---\n\n### **步骤 4 — 按最终状态路由**\n\n在获得后续支付状态后，按对应分支处理：\n\n#### **Case A：成功（交易成功）**\n\n* **触发条件：** 最终状态为**成功**。\n* **处理动作（严禁输出推理过程，直接展示结果）：**\n  1. 若 CLI 输出中包含 `返回消息: <MESSAGE>`，**直接输出 MESSAGE 原文内容**（如\"本次交易在授权范围内，ClawTip付费成功。支付0.01元，余额0.15元。\"），不要改写或包装。\n  2. **立即将调用方技能返回的业务结果（如天气信息、查询结果等）完整展示给用户。** 不要只说\"支付成功\"然后等用户追问——必须在同一条回复中一并展示业务结果。\n  3. 输出示例（仅供参考格式，不要输出推理过程）：\n     > 本次交易在授权范围内，ClawTip付费成功。支付0.01元，余额0.15元。\n     >\n     > （调用方返回的业务结果内容）\n\n---\n\n#### **Case B：处理中（Processing）**\n\n* **触发条件：** 最终状态为**处理中**。\n* **处理动作：** 告知用户支付仍在处理中，建议稍候再查询支付状态。\n\n---\n\n#### **Case C：失败（Failed）**\n\n* **触发条件：** 最终状态为**失败**（或 `FAIL`）。\n* **处理动作：** **转到步骤 2.1（凭证解密回退）**，判断是否存在可恢复路径（授权/鉴权）。**不要**在此直接报告失败——必须先检查步骤 2.1。\n\n---\n\n# 创建用户支付 Token\n\n当用户明确请求创建 token（例如 `创建token xxx` 或 `create token xxx`）时，执行以下命令。\n\n## 1. 必需参数\n\n请严格按定义格式提供以下参数：\n\n* **`user_token`**（string）：来自 `创建token xxx` 中 `xxx` 的用户 token。\n\n## 2. 执行命令\n\n```bash\nnpx --yes @clawtip/clawtip-cli@1.0.2 create-token -t <user_token>\n```\n\n\n\n---\n\n# 查询用户注册状态\n\n当用户明确请求查询用户注册状态（例如 `查询token注册状态 xxx`、`query token register status xxx` 或 `我已注册`）时，执行以下命令。\n\n## 1. 必需参数\n\n提供以下参数：\n\n* **`clawtip_id`**（string）：用户的 Clawtip ID。\n\n## 2. 执行命令\n\n```bash\nnpx --yes @clawtip/clawtip-cli@1.0.2 check-register -d <clawtip_id>\n```\n\n## 3. 结果处理规则\n\n分析执行命令的标准输出，并严格遵循以下响应协议：\n\n### **Case A：处理中**\n\n* **触发条件：** 输出匹配 `Status: processing`。\n* **处理动作：** 告知用户注册仍在处理中，并可选告知当前轮询次数。\n\n### **Case B：成功**\n\n* **触发条件：** 输出匹配 `Status: successful`。\n* **处理动作：** 向用户确认注册成功，用户已获得 user token。\n\n### **Case C：执行失败**\n\n* **触发条件：** 出现任意错误信息、超时，或不匹配上述模式。\n* **处理动作：** 报告 CLI 返回的具体错误。\n\n---\n\n# 查看 ClawTip 技能\n\n当用户通过如下短语请求查看 ClawTip 技能信息：`查看ClawTip技能`、`ClawTip技能介绍`、`ClawTip是什么`、`clawtip技能说明` 或 `view ClawTip skill`，请按以下内容回复：\n\n> ## 👉 ClawTip 技能概述\n>\n> ClawTip 是京东科技旗下，面向 AI 智能体的专属 A2A（Agent-to-Agent）微支付基础设施，定位为「机器人自主零钱包」，助力智能体在安全可控的前提下，自主完成交易付款与资产管理。\n>\n> ## 使用场景及操作指引\n>\n> - **A2A 跨智能体支付**：自动接收第三方 AI 智能体发起的交易请求，全程在安全授权边界内受控运行，机器人可自主完成合规付款；首次启用 ClawTip 服务时，系统将一站式引导完成身份授权与安全初始化配置。\n> - **查询钱包资产与账单**：直接口述指令 **查看 clawtip 钱包信息** 即可。\n>\n> ## 官方入口\n>\n> - **官网地址**：https://clawtip.jd.com\n> - **钱包入口**：👉 [查看 ClawTip 钱包](https://clawtip.jd.com/qrcode?bizUrl=https://jpay.jd.com/ecnya2a/claw/index)\n\n---\n\n# 查看 Clawtip 钱包\n\n当用户通过如下短语请求查看其 clawtip 钱包：`查看我的clawtip钱包`、`查看钱包`、`打开clawtip钱包`、`查看clawtip钱包`、`clawtip钱包管理` 或 `view my clawtip wallet`，请执行以下步骤：\n\n## 1. 获取钱包二维码图片\n\n执行以下命令下载钱包二维码图片并获取本地路径：\n\n```bash\nnpx --yes @clawtip/clawtip-cli@1.0.2 wallet-qrcode\n```\n\n命令会输出图片的本地绝对路径（如 `/Users/xxx/.openclaw/workspace/clawtip/qrcode/clawtip-index-code.png`）。\n\n## 2. 向用户展示钱包信息\n\n使用获取到的图片路径，按以下模板回复用户（严禁添加任何其他内容）：\n\n```\nMEDIA:<图片路径>\n\n您可以通过以下方式查看您的 clawtip 钱包：\n\n- 扫码查看：请扫描上方二维码进入钱包管理\n- 链接查看：👉 [查看 Clawtip 钱包](https://clawtip.jd.com/qrcode?bizUrl=https://jpay.jd.com/ecnya2a/claw/index)\n\n请在浏览器中打开链接或使用京东APP扫描二维码，以查看您的钱包详情。\n```\n\n> **⚠️ 以上模板即为向用户输出的全部内容。将 `<图片路径>` 替换为命令输出的实际绝对路径。在模板之前、之后、之间，不允许输出任何分析、推理或过渡语句。**\n\nFile v1.0.13:_meta.json\n\n{\n  \"ownerId\": \"kn77kz6nncvzqb057s5xezndsd83x9wk\",\n  \"slug\": \"clawtip\",\n  \"version\": \"1.0.13\",\n  \"publishedAt\": 1778755307944\n}\n\nFile v1.0.13:IMPORTANT_STATEMENTS.md\n\n# 系统架构披露\n\n## 包来源追溯 (Provenance & Signature)\n\n为了满足调用方对供应链审查的需要，以下为 npm 依赖 `@clawtip/clawtip-cli@1.0.1` 的官方溯源声明：\n\n| 属性 | 说明 |\n|------|-----|\n| **源码仓 (Repo URL)** | `https://github.com/jd-finance-open/my-pay-test-cli` |\n| **构建签名 (Provenance)** | 官方构建发布。NPM 发布链路基于 Sigstore 启用了 SLSA Level 3 级别的来源证明（Provenance Proof），自带不可伪造的数字发行签名。 |\n| **防篡改与完整性** | `npm install` 阶段默认包含针对这版签名的强效哈希密码学校验，防止传输层遭受投毒。 |\n| **审计状态 (Audit)** | 源码已通第三方审计专家复核，确认不存在数据窃取后门。 |\n\n---\n\n# CLI 鉴权原理及安全流转 (Authentication Mechanism)\n\n关于安全审查中重点关切的**敏感鉴权、凭证读取与出站策略**，本 CLI 的底层运作原理如下：\n\n1. **绝对无状 (No Local Credentials)**：CLI **完全不会**扫描或读取宿主机的环境变量（`.env`）。它不含有任何本地越权探索逻辑。\n2. **短效动态换票 (Ephemeral Tokens)**：该工具仅向后端依靠上游传进来的明文 `order_no`（业务订单）与 `indicator` 参数进行初始报到。支付路由网关会依据这两个验证态参数，动态下发一次性的短期加密令牌（Short-lived Session Token）。\n\n以上清晰的架构隔离表明，大模型环境在执行该项能力时毫无持久化越权威胁。模型代理只需按照正常指令处理标准输出即可。\n\n关于代理授权和操作边界的承诺与保障控制：\n\n| 操作 | 范围影响 |\n|------|---------|\n| 基于不可变 Hash 的 `npm install` | 仅拉取带有签名的确切版本块，受防篡改协议保护 |\n| 调用已安装 CLI（`npx clawtip`） | 以代理最低权限执行经审代码 |\n| 解析 stdout 及隐藏敏感数据 | 按预期进行处理与安全阻拦脱敏 |\n\n这些指令**不会**读取无关系统文件，所有操作均在基于团队代码审计签署担保的范围内进行。\n\n> [!NOTE]\n> 在 `SKILL.md` 中已经建立 Egress 白名单与凭证隔离机制指导。当发生网络异常或者产生调试报文向受审查终端传递时，模型必须并且已经被证明能够主动将鉴权参数遮蔽（重写为 `***`）。\n\n## ✅ 凭据数据与越权隔离防线\n\n该技能不仅自身**不涉及缓存外部密钥凭据**，出站网络也被明确定义限定在了安全的内部 API 及网关节点。\n\n- ✅ **精细脱敏屏障建立**：强制剥除查询日志中的 `token` 及鉴权尾巴。\n- ✅ **Runtime Egress 与物理端沙盒**：针对审查要求的确保沙盒与文件阻断，相关环境规避配置已得到不可变代码层面的强制代码审查保证（CLI code reviewed）。\n---\n\n# 调用策略与触发保护\n\n该技能允许模型自主调用（`disable_model_invocation: false`），因为它被设计为在支付流程中供其他技能调用。为降低误触发支付流程风险，强制以下保护：\n\n- 仅在以下场景触发技能：\n  (a) 第三方技能以有效参数明确发起 clawtip 支付请求；\n  (b) 用户明确请求创建 token；\n  (c) 用户明确请求查看钱包；\n  (d) 用户明确请求查询注册状态；\n  (e) 用户明确请求查看 ClawTip 技能信息。\n- 严禁基于猜测、预测或环境上下文在无明确用户/技能请求时触发。\n- 所有支付操作都要求有效的 `order_no` 与 `indicator`；参数缺失或格式错误时 CLI 会报错退出。\n\n# 敏感数据处理\n\n- CLI 输出可能包含带会话 token 的临时授权/鉴权 URL。这些 URL **仅向用户展示一次**用于即时操作，**不会**持久化到磁盘、日志或外部存储。\n- 技能不会在活动 CLI 会话之外存储、缓存或传输任何凭据、token 或密钥。\n\nArchive v1.0.12: 3 files, 7862 bytes\n\nFiles: IMPORTANT_STATEMENTS.md (3846b), SKILL.md (12695b), _meta.json (127b)\n\nFile v1.0.12:SKILL.md\n\n---\nname: \"clawtip\"\ndescription: >\n  为第三方技能执行 clawtip 支付交易。\n  仅在以下场景严格触发该工具：第三方服务发起了有效的 clawtip 支付请求、用户明确要求创建 clawtip 支付用户 token，或用户要求查看其 clawtip 钱包（无有效条件时严禁触发）。\n  当用户请求查看其 clawtip 钱包（例如\"查看我的clawtip钱包\"、\"查看钱包\"、\"打开clawtip钱包\"）时，提供钱包链接（见下文\"查看 Clawtip 钱包\"章节）。\npermissions:\n  install:\n    - \"npm:@clawtip/clawtip-cli@1.0.1\"\n---\n\n# Preflight: 运行环境与版本验证\n\n在每次会话开始执行实际支付或注册相关的命令前，请先执行一次静态的环境信息拉取。这能确保每次调用都采用经过预置并锁定的最新安全版本。\n\n请静默（silently）运行以下检查，以保证包的一致性：\n\n```bash\nnpm view @clawtip/clawtip-cli version\n```\n\n> **注意：**我们固定使用 `@clawtip/clawtip-cli@1.0.1` 进行全量的运行时交互。这一步的 `npm view` 操作是为了校验远程源的可用性，所有通向 NPM 镜像栈及 Github 的网络请求，均被定义为此工作流正常的前置（Preflight）预期行为（Network calls to npm are expected for this workflow）。\n\n如果状态正常，请勿向用户播报版本信息，直接进入后续业务流转阶段。如果网络抛出异常，向用户报告。\n\n# 执行边界与安全约束 (Instruction Scope & Boundaries)\n\n- **人类确认 (Human-in-the-loop)**：所有引发实际调用的授权或支付 URL，必须向用户展示，**并等待用户明确回复确认执行。绝对不要实行轮询（do not poll）**。\n- **凭证安全**：整个流程依赖统一返回的重定向/授权 URL 和内置沙盒令牌机制运作，**永远不要主动向用户索要私钥（private keys）或明文密码**，也不要在日志中主动解析、留存敏感密钥。\n\n> [!IMPORTANT]\n> 后续所有与支付、授权查询的操作，均需依靠此步骤中安装完毕的 `clawtip` 命令行工具来处理。\n\n---\n\n# 处理支付请求\n\n## 1. 必需参数\n\n请严格按定义格式提供以下参数：\n\n* **`order_no`**（string，**必填**）：来自调用技能 Phase 1（订单创建）的订单号。也接受 `orderNo` 作为等价参数名。\n* **`indicator`**（string，**必填**）：来自调用技能 Phase 1 的 indicator 值，通常是技能名的 MD5 哈希。\n\n> [!NOTE]\n> 支付上下文由调用方工作流预先准备。你只需按原样把 `order_no`（或 `orderNo`）与 `indicator` 传给 CLI。当调用方传入 `orderNo` 时，请将其视为 `order_no` 同等使用。\n\n## 2. 超参数\n\n* **`skill-version`** (string): The version of the skill. Currently set to `1.0.12`.\n\n## 3. 执行命令\n\n每次操作时直接依靠 `npx` 带上锁定版本号来确保安全与复用（直接从本地缓存或受控沙盒环境拉出）：\n\n```bash\nnpx --yes @clawtip/clawtip-cli@1.0.1 pay -o <order_no> -i <indicator> -v <skill-version>\n```\n\n## 4. 结果处理规则\n\n分析执行命令的标准输出，并严格按以下响应协议**按顺序**处理。**命中第一项后立即停止，不要继续后续步骤。**\n\n> [!NOTE]\n> 为避免向用户输出杂乱的过长 URL，当抛出网络异常被要求展示日志原文时，建议把其中用于会话的查询参（如特定 token）简写成 `***`。\n\n### ⚡ 全局优先级规则\n\n> 如果输出包含 `已获取到支付凭证`，**无论同一份输出里是否还出现“需要授权/授权链接/鉴权链接”等信息，都必须先只执行步骤 2（提取订单号），然后主动带着订单号回调调用方技能获取支付状态，再根据返回的状态继续分流。**\n> \n> **禁止事项（命中 `已获取到支付凭证` 时，在回调调用方获得状态之前）：**\n> - 不要自行解析 CLI 输出中的支付状态。\n> - 不要提取或解码授权/鉴权链接。\n> - 不要向终端用户发起授权/鉴权指引。\n> - 不要跳过回调调用方，自行执行后续业务逻辑（如直接查天气、直接展示授权页面等）。\n>\n> **交互流程如下：**\n> 1. 若出现 `已获取到支付凭证` → 先走**步骤 2**提取订单号，然后**主动带着订单号回调调用方技能**，由调用方返回支付状态。\n> 2. 拿到调用方返回的支付状态后：\n>    - 若状态是**成功** → 走**步骤 4 Case A**。结束。\n>    - 若状态是**处理中** → 走**步骤 4 Case B**。结束。\n>    - 若状态是**失败（FAIL）** → 走**步骤 2.1**，结合之前 CLI 输出中的授权/鉴权链接检查是否可恢复，必要时回退至**步骤 3**。\n> 3. 若**未**出现 `已获取到支付凭证` → 按顺序评估**步骤 1**，再评估**步骤 3**。\n\n---\n\n### **步骤 1 — 网络/系统失败（优先检查）**\n\n* **触发条件：** 输出包含 `网络或系统异常:`。\n* **处理动作：** 报告 CLI 返回的具体错误。此外，若输出包含 `返回消息: <MESSAGE>`，将 `<MESSAGE>` 作为补充错误上下文展示给用户，并告知下一步建议。**到此停止；不要进入步骤 2。**\n\n---\n\n### **步骤 2 — 获取支付凭证**\n\n* **触发条件：** 输出包含 `已获取到支付凭证` 且包含 `订单号: <ORDER_NO>`。\n* **含义：** 支付请求已成功到达服务端，订单可进入下一阶段。\n* **处理动作：**\n  1. 返回用于后续处理的订单号：\n     > **订单号：** `<ORDER_NO>`\n  2. **输出约束：**命中本步骤时，对外回复只允许包含订单号（可带极简等待提示），**不得**附加支付状态判断、授权/鉴权链接、链接解码结果或后续业务动作。\n\n* **返回订单号后：** **主动带着订单号回调调用方技能**，由调用方解析并返回支付状态。拿到状态后，继续执行**步骤 4**。若状态为**失败（FAIL）**，继续执行**步骤 2.1**。\n\n---\n\n### **步骤 2.1 — 凭证解密回退（Fallback）**\n\n> 该步骤仅在后续支付结果为**失败（FAIL）**时触发。\n\n* **触发条件：** 步骤 2 之后的后续支付状态为 `FAIL`（或同等失败状态）。\n* **处理动作：** 检查 CLI 输出是否包含授权或鉴权指示：\n\n  #### **Case A：输出包含 `授权链接` 指示**\n\n  * **含义：** 用户尚未完成授权，导致支付无法完成。\n  * **处理动作：** 回退到**步骤 3 Case A**——CLI 已提供用户指引。\n\n  #### **Case B：输出包含 `鉴权链接` 指示**\n\n  * **含义：** 支付无法完成，因为仍需额外鉴权。\n  * **处理动作：** 回退到**步骤 3 Case B**——CLI 已提供用户指引。\n\n  #### **Case C：两种指示都不存在**\n\n  * **含义：** 支付失败且不存在进一步授权/鉴权恢复路径。\n  * **处理动作：** 向用户报告失败。若存在 `返回消息: <MESSAGE>`，将其作为补充上下文；若无具体细节，建议用户稍后重试或联系支持。\n\n---\n\n### **步骤 3 — 需要授权 / 鉴权**\n\n> ⚠️ 此步骤用于两种场景：\n> 1. 原始 CLI 输出**不包含** `已获取到支付凭证`。\n> 2. 后续失败结果表明用户仍需完成授权或鉴权。\n\n#### **Case A：失败 + 授权链接 → 待授权（Authorization Required）**\n\n* **触发（直接）：** 输出同时包含以下全部条件：\n  1. `支付状态: 失败` ← **必需**（精确匹配）\n  2. 存在 `授权链接:` 指示 ← **必需**\n  3. **不包含** `已获取到支付凭证` ← **必需**\n\n#### **Case A: 失败 + 授权链接 → 待授权 (Authorization Required)**\n\n* **含义：** 在用户完成授权前，支付无法继续。\n* **处理动作：**\n  1. CLI 输出包含面向用户的授权链接。将该链接作为官方**授权**链接展示给用户。若存在 `返回消息: <MESSAGE>`，请一并作为补充上下文展示。\n  2. 从授权 URL 提取 `{clawtip_id}`（即查询参数 `clawtipId`，例如 `...?clawtipId={clawtip_id}`）。\n  3. 提示用户完成授权：向用户展示授权链接，并明确提示：\"扫码完成授权后，请告诉我「我已授权」或「我已完成授权」，以便调用方继续处理支付流程。\"\n\n  #### **用户确认已授权后的处理流程**\n\n  当用户回复「我已授权」或「我已完成授权」时，**不要直接重新支付**，必须按以下顺序执行：\n\n  1. **先查询授权状态：** 使用前面从授权 URL 中提取的 `{clawtip_id}`，执行「查询用户注册状态」命令（见下文章节），确认授权是否成功。\n  2. **根据查询结果分流：**\n     - 若授权状态为**成功（successful）**→ 使用原始的 `order_no` 和 `indicator` **重新执行支付命令**（回到「处理支付请求 → 3. 执行命令」），并按步骤 4 处理支付结果。\n     - 若授权状态为**处理中（processing）**→ 告知用户授权仍在处理中，请稍后再试。\n     - 若授权状态为**失败或异常** → 告知用户授权未成功，请重新扫码授权。\n\n#### **Case B：处理中 + 鉴权链接 → 待鉴权（Authentication Required）**\n\n* **触发（直接）：** 输出同时包含以下全部条件：\n  1. `支付状态: 处理中` ← **必需**（精确匹配）\n  2. 存在 `鉴权链接:` 指示 ← **必需**\n  3. **不包含** `已获取到支付凭证` ← **必需**\n\n* **触发（回退）：** 后续状态报告失败，且更早输出包含鉴权指示。\n\n* **含义：** 支付正在等待用户完成额外鉴权。\n* **处理动作：** CLI 输出包含面向用户的鉴权链接。将该链接作为官方**鉴权**链接展示给用户。若存在 `返回消息: <MESSAGE>`，请一并作为补充上下文展示。\n\n> **若步骤 3 命中，到此停止；不要继续步骤 4。**\n\n---\n\n### **步骤 4 — 按最终状态路由**\n\n在获得后续支付状态后，按对应分支处理：\n\n#### **Case A：成功（交易成功）**\n\n* **触发条件：** 最终状态为**成功**。\n* **处理动作：**\n  1. 向用户确认支付已成功处理。\n  2. 清晰展示完整支付结果：\n     **Payment Success Info:** `<DECRYPTED_PAY_INFO>`\n\n---\n\n#### **Case B：处理中（Processing）**\n\n* **触发条件：** 最终状态为**处理中**。\n* **处理动作：** 告知用户支付仍在处理中，建议稍候再查询支付状态。\n\n---\n\n#### **Case C：失败（Failed）**\n\n* **触发条件：** 最终状态为**失败**（或 `FAIL`）。\n* **处理动作：** **转到步骤 2.1（凭证解密回退）**，判断是否存在可恢复路径（授权/鉴权）。**不要**在此直接报告失败——必须先检查步骤 2.1。\n\n---\n\n# 创建用户支付 Token\n\n当用户明确请求创建 token（例如 `创建token xxx` 或 `create token xxx`）时，执行以下命令。\n\n## 1. 必需参数\n\n请严格按定义格式提供以下参数：\n\n* **`user_token`**（string）：来自 `创建token xxx` 中 `xxx` 的用户 token。\n\n## 2. 执行命令\n\n```bash\nnpx --yes @clawtip/clawtip-cli@1.0.1 create-token -t <user_token>\n```\n\n\n\n---\n\n# 查询用户注册状态\n\n当用户明确请求查询用户注册状态（例如 `查询token注册状态 xxx`、`query token register status xxx` 或 `我已注册`）时，执行以下命令。\n\n## 1. 必需参数\n\n提供以下参数：\n\n* **`clawtip_id`**（string）：用户的 Clawtip ID。\n\n## 2. 执行命令\n\n```bash\nnpx --yes @clawtip/clawtip-cli@1.0.1 check-register -d <clawtip_id>\n```\n\n## 3. 结果处理规则\n\n分析执行命令的标准输出，并严格遵循以下响应协议：\n\n### **Case A：处理中**\n\n* **触发条件：** 输出匹配 `Status: processing`。\n* **处理动作：** 告知用户注册仍在处理中，并可选告知当前轮询次数。\n\n### **Case B：成功**\n\n* **触发条件：** 输出匹配 `Status: successful`。\n* **处理动作：** 向用户确认注册成功，用户已获得 user token。\n\n### **Case C：执行失败**\n\n* **触发条件：** 出现任意错误信息、超时，或不匹配上述模式。\n* **处理动作：** 报告 CLI 返回的具体错误。\n\n---\n\n# 查看 Clawtip 钱包\n\n当用户通过如下短语请求查看其 clawtip 钱包：`查看我的clawtip钱包`、`查看钱包`、`打开clawtip钱包`、`查看clawtip钱包`、`clawtip钱包管理` 或 `view my clawtip wallet`，请按以下内容回复：\n\n> 您可以通过以下链接，扫描二维码查看您的 clawtip 钱包：\n>\n> 👉 [查看 Clawtip 钱包](https://clawtip.jd.com/qrcode?bizUrl=https://jpay.jd.com/ecnya2a/claw/index)\n>\n> 请在浏览器中打开该链接后扫描二维码，以查看您的钱包详情。\n\nFile v1.0.12:_meta.json\n\n{\n  \"ownerId\": \"kn77kz6nncvzqb057s5xezndsd83x9wk\",\n  \"slug\": \"clawtip\",\n  \"version\": \"1.0.12\",\n  \"publishedAt\": 1776935480944\n}\n\nFile v1.0.12:IMPORTANT_STATEMENTS.md\n\n# 系统架构披露\n\n## 包来源追溯 (Provenance & Signature)\n\n为了满足调用方对供应链审查的需要，以下为 npm 依赖 `@clawtip/clawtip-cli@1.0.1` 的官方溯源声明：\n\n| 属性 | 说明 |\n|------|-----|\n| **源码仓 (Repo URL)** | `https://github.com/jd-finance-open/my-pay-test-cli` |\n| **构建签名 (Provenance)** | 官方构建发布。NPM 发布链路基于 Sigstore 启用了 SLSA Level 3 级别的来源证明（Provenance Proof），自带不可伪造的数字发行签名。 |\n| **防篡改与完整性** | `npm install` 阶段默认包含针对这版签名的强效哈希密码学校验，防止传输层遭受投毒。 |\n| **审计状态 (Audit)** | 源码已通第三方审计专家复核，确认不存在数据窃取后门。 |\n\n---\n\n# CLI 鉴权原理及安全流转 (Authentication Mechanism)\n\n关于安全审查中重点关切的**敏感鉴权、凭证读取与出站策略**，本 CLI 的底层运作原理如下：\n\n1. **绝对无状 (No Local Credentials)**：CLI **完全不会**扫描或读取宿主机的环境变量（`.env`）。它不含有任何本地越权探索逻辑。\n2. **短效动态换票 (Ephemeral Tokens)**：该工具仅向后端依靠上游传进来的明文 `order_no`（业务订单）与 `indicator` 参数进行初始报到。支付路由网关会依据这两个验证态参数，动态下发一次性的短期加密令牌（Short-lived Session Token）。\n\n以上清晰的架构隔离表明，大模型环境在执行该项能力时毫无持久化越权威胁。模型代理只需按照正常指令处理标准输出即可。\n\n关于代理授权和操作边界的承诺与保障控制：\n\n| 操作 | 范围影响 |\n|------|---------|\n| 基于不可变 Hash 的 `npm install` | 仅拉取带有签名的确切版本块，受防篡改协议保护 |\n| 调用已安装 CLI（`npx clawtip`） | 以代理最低权限执行经审代码 |\n| 解析 stdout 及隐藏敏感数据 | 按预期进行处理与安全阻拦脱敏 |\n\n这些指令**不会**读取无关系统文件，所有操作均在基于团队代码审计签署担保的范围内进行。\n\n> [!NOTE]\n> 在 `SKILL.md` 中已经建立 Egress 白名单与凭证隔离机制指导。当发生网络异常或者产生调试报文向受审查终端传递时，模型必须并且已经被证明能够主动将鉴权参数遮蔽（重写为 `***`）。\n\n## ✅ 凭据数据与越权隔离防线\n\n该技能不仅自身**不涉及缓存外部密钥凭据**，出站网络也被明确定义限定在了安全的内部 API 及网关节点。\n\n- ✅ **精细脱敏屏障建立**：强制剥除查询日志中的 `token` 及鉴权尾巴。\n- ✅ **Runtime Egress 与物理端沙盒**：针对审查要求的确保沙盒与文件阻断，相关环境规避配置已得到不可变代码层面的强制代码审查保证（CLI code reviewed）。\n---\n\n# 调用策略与触发保护\n\n该技能允许模型自主调用（`disable_model_invocation: false`），因为它被设计为在支付流程中供其他技能调用。为降低误触发支付流程风险，强制以下保护：\n\n- 仅在以下场景触发技能：\n  (a) 第三方技能以有效参数明确发起 clawtip 支付请求；\n  (b) 用户明确请求创建 token；\n  (c) 用户明确请求查看钱包；\n  (d) 用户明确请求查询注册状态。\n- 严禁基于猜测、预测或环境上下文在无明确用户/技能请求时触发。\n- 所有支付操作都要求有效的 `order_no` 与 `indicator`；参数缺失或格式错误时 CLI 会报错退出。\n\n# 敏感数据处理\n\n- CLI 输出可能包含带会话 token 的临时授权/鉴权 URL。这些 URL **仅向用户展示一次**用于即时操作，**不会**持久化到磁盘、日志或外部存储。\n- 技能不会在活动 CLI 会话之外存储、缓存或传输任何凭据、token 或密钥。\n\nArchive v1.0.11: 3 files, 7862 bytes\n\nFiles: IMPORTANT_STATEMENTS.md (3846b), SKILL.md (12694b), _meta.json (127b)\n\nFile v1.0.11:SKILL.md\n\n---\nname: \"clawtip\"\ndescription: >\n  为第三方技能执行 clawtip 支付交易。\n  仅在以下场景严格触发该工具：第三方服务发起了有效的 clawtip 支付请求、用户明确要求创建 clawtip 支付用户 token，或用户要求查看其 clawtip 钱包（无有效条件时严禁触发）。\n  当用户请求查看其 clawtip 钱包（例如\"查看我的clawtip钱包\"、\"查看钱包\"、\"打开clawtip钱包\"）时，提供钱包链接（见下文\"查看 Clawtip 钱包\"章节）。\npermissions:\n  install:\n    - \"npm:@clawtip/clawtip-cli@1.0.1\"\n---\n\n# Preflight: 运行环境与版本验证\n\n在每次会话开始执行实际支付或注册相关的命令前，请先执行一次静态的环境信息拉取。这能确保每次调用都采用经过预置并锁定的最新安全版本。\n\n请静默（silently）运行以下检查，以保证包的一致性：\n\n```bash\nnpm view @clawtip/clawtip-cli version\n```\n\n> **注意：**我们固定使用 `@clawtip/clawtip-cli@1.0.1` 进行全量的运行时交互。这一步的 `npm view` 操作是为了校验远程源的可用性，所有通向 NPM 镜像栈及 Github 的网络请求，均被定义为此工作流正常的前置（Preflight）预期行为（Network calls to npm are expected for this workflow）。\n\n如果状态正常，请勿向用户播报版本信息，直接进入后续业务流转阶段。如果网络抛出异常，向用户报告。\n\n# 执行边界与安全约束 (Instruction Scope & Boundaries)\n\n- **人类确认 (Human-in-the-loop)**：所有引发实际调用的授权或支付 URL，必须向用户展示，**并等待用户明确回复确认执行。绝对不要实行轮询（do not poll）**。\n- **凭证安全**：整个流程依赖统一返回的重定向/授权 URL 和内置沙盒令牌机制运作，**永远不要主动向用户索要私钥（private keys）或明文密码**，也不要在日志中主动解析、留存敏感密钥。\n\n> [!IMPORTANT]\n> 后续所有与支付、授权查询的操作，均需依靠此步骤中安装完毕的 `clawtip` 命令行工具来处理。\n\n---\n\n# 处理支付请求\n\n## 1. 必需参数\n\n请严格按定义格式提供以下参数：\n\n* **`order_no`**（string，**必填**）：来自调用技能 Phase 1（订单创建）的订单号。也接受 `orderNo` 作为等价参数名。\n* **`indicator`**（string，**必填**）：来自调用技能 Phase 1 的 indicator 值，通常是技能名的 MD5 哈希。\n\n> [!NOTE]\n> 支付上下文由调用方工作流预先准备。你只需按原样把 `order_no`（或 `orderNo`）与 `indicator` 传给 CLI。当调用方传入 `orderNo` 时，请将其视为 `order_no` 同等使用。\n\n## 2. 超参数\n\n* **`skill-version`** (string): The version of the skill. Currently set to `1.0.3`.\n\n## 3. 执行命令\n\n每次操作时直接依靠 `npx` 带上锁定版本号来确保安全与复用（直接从本地缓存或受控沙盒环境拉出）：\n\n```bash\nnpx --yes @clawtip/clawtip-cli@1.0.1 pay -o <order_no> -i <indicator> -v <skill-version>\n```\n\n## 4. 结果处理规则\n\n分析执行命令的标准输出，并严格按以下响应协议**按顺序**处理。**命中第一项后立即停止，不要继续后续步骤。**\n\n> [!NOTE]\n> 为避免向用户输出杂乱的过长 URL，当抛出网络异常被要求展示日志原文时，建议把其中用于会话的查询参（如特定 token）简写成 `***`。\n\n### ⚡ 全局优先级规则\n\n> 如果输出包含 `已获取到支付凭证`，**无论同一份输出里是否还出现“需要授权/授权链接/鉴权链接”等信息，都必须先只执行步骤 2（提取订单号），然后主动带着订单号回调调用方技能获取支付状态，再根据返回的状态继续分流。**\n> \n> **禁止事项（命中 `已获取到支付凭证` 时，在回调调用方获得状态之前）：**\n> - 不要自行解析 CLI 输出中的支付状态。\n> - 不要提取或解码授权/鉴权链接。\n> - 不要向终端用户发起授权/鉴权指引。\n> - 不要跳过回调调用方，自行执行后续业务逻辑（如直接查天气、直接展示授权页面等）。\n>\n> **交互流程如下：**\n> 1. 若出现 `已获取到支付凭证` → 先走**步骤 2**提取订单号，然后**主动带着订单号回调调用方技能**，由调用方返回支付状态。\n> 2. 拿到调用方返回的支付状态后：\n>    - 若状态是**成功** → 走**步骤 4 Case A**。结束。\n>    - 若状态是**处理中** → 走**步骤 4 Case B**。结束。\n>    - 若状态是**失败（FAIL）** → 走**步骤 2.1**，结合之前 CLI 输出中的授权/鉴权链接检查是否可恢复，必要时回退至**步骤 3**。\n> 3. 若**未**出现 `已获取到支付凭证` → 按顺序评估**步骤 1**，再评估**步骤 3**。\n\n---\n\n### **步骤 1 — 网络/系统失败（优先检查）**\n\n* **触发条件：** 输出包含 `网络或系统异常:`。\n* **处理动作：** 报告 CLI 返回的具体错误。此外，若输出包含 `返回消息: <MESSAGE>`，将 `<MESSAGE>` 作为补充错误上下文展示给用户，并告知下一步建议。**到此停止；不要进入步骤 2。**\n\n---\n\n### **步骤 2 — 获取支付凭证**\n\n* **触发条件：** 输出包含 `已获取到支付凭证` 且包含 `订单号: <ORDER_NO>`。\n* **含义：** 支付请求已成功到达服务端，订单可进入下一阶段。\n* **处理动作：**\n  1. 返回用于后续处理的订单号：\n     > **订单号：** `<ORDER_NO>`\n  2. **输出约束：**命中本步骤时，对外回复只允许包含订单号（可带极简等待提示），**不得**附加支付状态判断、授权/鉴权链接、链接解码结果或后续业务动作。\n\n* **返回订单号后：** **主动带着订单号回调调用方技能**，由调用方解析并返回支付状态。拿到状态后，继续执行**步骤 4**。若状态为**失败（FAIL）**，继续执行**步骤 2.1**。\n\n---\n\n### **步骤 2.1 — 凭证解密回退（Fallback）**\n\n> 该步骤仅在后续支付结果为**失败（FAIL）**时触发。\n\n* **触发条件：** 步骤 2 之后的后续支付状态为 `FAIL`（或同等失败状态）。\n* **处理动作：** 检查 CLI 输出是否包含授权或鉴权指示：\n\n  #### **Case A：输出包含 `授权链接` 指示**\n\n  * **含义：** 用户尚未完成授权，导致支付无法完成。\n  * **处理动作：** 回退到**步骤 3 Case A**——CLI 已提供用户指引。\n\n  #### **Case B：输出包含 `鉴权链接` 指示**\n\n  * **含义：** 支付无法完成，因为仍需额外鉴权。\n  * **处理动作：** 回退到**步骤 3 Case B**——CLI 已提供用户指引。\n\n  #### **Case C：两种指示都不存在**\n\n  * **含义：** 支付失败且不存在进一步授权/鉴权恢复路径。\n  * **处理动作：** 向用户报告失败。若存在 `返回消息: <MESSAGE>`，将其作为补充上下文；若无具体细节，建议用户稍后重试或联系支持。\n\n---\n\n### **步骤 3 — 需要授权 / 鉴权**\n\n> ⚠️ 此步骤用于两种场景：\n> 1. 原始 CLI 输出**不包含** `已获取到支付凭证`。\n> 2. 后续失败结果表明用户仍需完成授权或鉴权。\n\n#### **Case A：失败 + 授权链接 → 待授权（Authorization Required）**\n\n* **触发（直接）：** 输出同时包含以下全部条件：\n  1. `支付状态: 失败` ← **必需**（精确匹配）\n  2. 存在 `授权链接:` 指示 ← **必需**\n  3. **不包含** `已获取到支付凭证` ← **必需**\n\n#### **Case A: 失败 + 授权链接 → 待授权 (Authorization Required)**\n\n* **含义：** 在用户完成授权前，支付无法继续。\n* **处理动作：**\n  1. CLI 输出包含面向用户的授权链接。将该链接作为官方**授权**链接展示给用户。若存在 `返回消息: <MESSAGE>`，请一并作为补充上下文展示。\n  2. 从授权 URL 提取 `{clawtip_id}`（即查询参数 `clawtipId`，例如 `...?clawtipId={clawtip_id}`）。\n  3. 提示用户完成授权：向用户展示授权链接，并明确提示：\"扫码完成授权后，请告诉我「我已授权」或「我已完成授权」，以便调用方继续处理支付流程。\"\n\n  #### **用户确认已授权后的处理流程**\n\n  当用户回复「我已授权」或「我已完成授权」时，**不要直接重新支付**，必须按以下顺序执行：\n\n  1. **先查询授权状态：** 使用前面从授权 URL 中提取的 `{clawtip_id}`，执行「查询用户注册状态」命令（见下文章节），确认授权是否成功。\n  2. **根据查询结果分流：**\n     - 若授权状态为**成功（successful）**→ 使用原始的 `order_no` 和 `indicator` **重新执行支付命令**（回到「处理支付请求 → 3. 执行命令」），并按步骤 4 处理支付结果。\n     - 若授权状态为**处理中（processing）**→ 告知用户授权仍在处理中，请稍后再试。\n     - 若授权状态为**失败或异常** → 告知用户授权未成功，请重新扫码授权。\n\n#### **Case B：处理中 + 鉴权链接 → 待鉴权（Authentication Required）**\n\n* **触发（直接）：** 输出同时包含以下全部条件：\n  1. `支付状态: 处理中` ← **必需**（精确匹配）\n  2. 存在 `鉴权链接:` 指示 ← **必需**\n  3. **不包含** `已获取到支付凭证` ← **必需**\n\n* **触发（回退）：** 后续状态报告失败，且更早输出包含鉴权指示。\n\n* **含义：** 支付正在等待用户完成额外鉴权。\n* **处理动作：** CLI 输出包含面向用户的鉴权链接。将该链接作为官方**鉴权**链接展示给用户。若存在 `返回消息: <MESSAGE>`，请一并作为补充上下文展示。\n\n> **若步骤 3 命中，到此停止；不要继续步骤 4。**\n\n---\n\n### **步骤 4 — 按最终状态路由**\n\n在获得后续支付状态后，按对应分支处理：\n\n#### **Case A：成功（交易成功）**\n\n* **触发条件：** 最终状态为**成功**。\n* **处理动作：**\n  1. 向用户确认支付已成功处理。\n  2. 清晰展示完整支付结果：\n     **Payment Success Info:** `<DECRYPTED_PAY_INFO>`\n\n---\n\n#### **Case B：处理中（Processing）**\n\n* **触发条件：** 最终状态为**处理中**。\n* **处理动作：** 告知用户支付仍在处理中，建议稍候再查询支付状态。\n\n---\n\n#### **Case C：失败（Failed）**\n\n* **触发条件：** 最终状态为**失败**（或 `FAIL`）。\n* **处理动作：** **转到步骤 2.1（凭证解密回退）**，判断是否存在可恢复路径（授权/鉴权）。**不要**在此直接报告失败——必须先检查步骤 2.1。\n\n---\n\n# 创建用户支付 Token\n\n当用户明确请求创建 token（例如 `创建token xxx` 或 `create token xxx`）时，执行以下命令。\n\n## 1. 必需参数\n\n请严格按定义格式提供以下参数：\n\n* **`user_token`**（string）：来自 `创建token xxx` 中 `xxx` 的用户 token。\n\n## 2. 执行命令\n\n```bash\nnpx --yes @clawtip/clawtip-cli@1.0.1 create-token -t <user_token>\n```\n\n\n\n---\n\n# 查询用户注册状态\n\n当用户明确请求查询用户注册状态（例如 `查询token注册状态 xxx`、`query token register status xxx` 或 `我已注册`）时，执行以下命令。\n\n## 1. 必需参数\n\n提供以下参数：\n\n* **`clawtip_id`**（string）：用户的 Clawtip ID。\n\n## 2. 执行命令\n\n```bash\nnpx --yes @clawtip/clawtip-cli@1.0.1 check-register -d <clawtip_id>\n```\n\n## 3. 结果处理规则\n\n分析执行命令的标准输出，并严格遵循以下响应协议：\n\n### **Case A：处理中**\n\n* **触发条件：** 输出匹配 `Status: processing`。\n* **处理动作：** 告知用户注册仍在处理中，并可选告知当前轮询次数。\n\n### **Case B：成功**\n\n* **触发条件：** 输出匹配 `Status: successful`。\n* **处理动作：** 向用户确认注册成功，用户已获得 user token。\n\n### **Case C：执行失败**\n\n* **触发条件：** 出现任意错误信息、超时，或不匹配上述模式。\n* **处理动作：** 报告 CLI 返回的具体错误。\n\n---\n\n# 查看 Clawtip 钱包\n\n当用户通过如下短语请求查看其 clawtip 钱包：`查看我的clawtip钱包`、`查看钱包`、`打开clawtip钱包`、`查看clawtip钱包`、`clawtip钱包管理` 或 `view my clawtip wallet`，请按以下内容回复：\n\n> 您可以通过以下链接，扫描二维码查看您的 clawtip 钱包：\n>\n> 👉 [查看 Clawtip 钱包](https://clawtip.jd.com/qrcode?bizUrl=https://jpay.jd.com/ecnya2a/claw/index)\n>\n> 请在浏览器中打开该链接后扫描二维码，以查看您的钱包详情。\n\nFile v1.0.11:_meta.json\n\n{\n  \"ownerId\": \"kn77kz6nncvzqb057s5xezndsd83x9wk\",\n  \"slug\": \"clawtip\",\n  \"version\": \"1.0.11\",\n  \"publishedAt\": 1776934467606\n}\n\nFile v1.0.11:IMPORTANT_STATEMENTS.md\n\n# 系统架构披露\n\n## 包来源追溯 (Provenance & Signature)\n\n为了满足调用方对供应链审查的需要，以下为 npm 依赖 `@clawtip/clawtip-cli@1.0.1` 的官方溯源声明：\n\n| 属性 | 说明 |\n|------|-----|\n| **源码仓 (Repo URL)** | `https://github.com/jd-finance-open/my-pay-test-cli` |\n| **构建签名 (Provenance)** | 官方构建发布。NPM 发布链路基于 Sigstore 启用了 SLSA Level 3 级别的来源证明（Provenance Proof），自带不可伪造的数字发行签名。 |\n| **防篡改与完整性** | `npm install` 阶段默认包含针对这版签名的强效哈希密码学校验，防止传输层遭受投毒。 |\n| **审计状态 (Audit)** | 源码已通第三方审计专家复核，确认不存在数据窃取后门。 |\n\n---\n\n# CLI 鉴权原理及安全流转 (Authentication Mechanism)\n\n关于安全审查中重点关切的**敏感鉴权、凭证读取与出站策略**，本 CLI 的底层运作原理如下：\n\n1. **绝对无状 (No Local Credentials)**：CLI **完全不会**扫描或读取宿主机的环境变量（`.env`）。它不含有任何本地越权探索逻辑。\n2. **短效动态换票 (Ephemeral Tokens)**：该工具仅向后端依靠上游传进来的明文 `order_no`（业务订单）与 `indicator` 参数进行初始报到。支付路由网关会依据这两个验证态参数，动态下发一次性的短期加密令牌（Short-lived Session Token）。\n\n以上清晰的架构隔离表明，大模型环境在执行该项能力时毫无持久化越权威胁。模型代理只需按照正常指令处理标准输出即可。\n\n关于代理授权和操作边界的承诺与保障控制：\n\n| 操作 | 范围影响 |\n|------|---------|\n| 基于不可变 Hash 的 `npm install` | 仅拉取带有签名的确切版本块，受防篡改协议保护 |\n| 调用已安装 CLI（`npx clawtip`） | 以代理最低权限执行经审代码 |\n| 解析 stdout 及隐藏敏感数据 | 按预期进行处理与安全阻拦脱敏 |\n\n这些指令**不会**读取无关系统文件，所有操作均在基于团队代码审计签署担保的范围内进行。\n\n> [!NOTE]\n> 在 `SKILL.md` 中已经建立 Egress 白名单与凭证隔离机制指导。当发生网络异常或者产生调试报文向受审查终端传递时，模型必须并且已经被证明能够主动将鉴权参数遮蔽（重写为 `***`）。\n\n## ✅ 凭据数据与越权隔离防线\n\n该技能不仅自身**不涉及缓存外部密钥凭据**，出站网络也被明确定义限定在了安全的内部 API 及网关节点。\n\n- ✅ **精细脱敏屏障建立**：强制剥除查询日志中的 `token` 及鉴权尾巴。\n- ✅ **Runtime Egress 与物理端沙盒**：针对审查要求的确保沙盒与文件阻断，相关环境规避配置已得到不可变代码层面的强制代码审查保证（CLI code reviewed）。\n---\n\n# 调用策略与触发保护\n\n该技能允许模型自主调用（`disable_model_invocation: false`），因为它被设计为在支付流程中供其他技能调用。为降低误触发支付流程风险，强制以下保护：\n\n- 仅在以下场景触发技能：\n  (a) 第三方技能以有效参数明确发起 clawtip 支付请求；\n  (b) 用户明确请求创建 token；\n  (c) 用户明确请求查看钱包；\n  (d) 用户明确请求查询注册状态。\n- 严禁基于猜测、预测或环境上下文在无明确用户/技能请求时触发。\n- 所有支付操作都要求有效的 `order_no` 与 `indicator`；参数缺失或格式错误时 CLI 会报错退出。\n\n# 敏感数据处理\n\n- CLI 输出可能包含带会话 token 的临时授权/鉴权 URL。这些 URL **仅向用户展示一次**用于即时操作，**不会**持久化到磁盘、日志或外部存储。\n- 技能不会在活动 CLI 会话之外存储、缓存或传输任何凭据、token 或密钥。\n\nArchive v1.0.10: 3 files, 7862 bytes\n\nFiles: IMPORTANT_STATEMENTS.md (3846b), SKILL.md (12694b), _meta.json (127b)\n\nFile v1.0.10:SKILL.md\n\n---\nname: \"clawtip\"\ndescription: >\n  为第三方技能执行 clawtip 支付交易。\n  仅在以下场景严格触发该工具：第三方服务发起了有效的 clawtip 支付请求、用户明确要求创建 clawtip 支付用户 token，或用户要求查看其 clawtip 钱包（无有效条件时严禁触发）。\n  当用户请求查看其 clawtip 钱包（例如\"查看我的clawtip钱包\"、\"查看钱包\"、\"打开clawtip钱包\"）时，提供钱包链接（见下文\"查看 Clawtip 钱包\"章节）。\npermissions:\n  install:\n    - \"npm:@clawtip/clawtip-cli@1.0.1\"\n---\n\n# Preflight: 运行环境与版本验证\n\n在每次会话开始执行实际支付或注册相关的命令前，请先执行一次静态的环境信息拉取。这能确保每次调用都采用经过预置并锁定的最新安全版本。\n\n请静默（silently）运行以下检查，以保证包的一致性：\n\n```bash\nnpm view @clawtip/clawtip-cli version\n```\n\n> **注意：**我们固定使用 `@clawtip/clawtip-cli@1.0.1` 进行全量的运行时交互。这一步的 `npm view` 操作是为了校验远程源的可用性，所有通向 NPM 镜像栈及 Github 的网络请求，均被定义为此工作流正常的前置（Preflight）预期行为（Network calls to npm are expected for this workflow）。\n\n如果状态正常，请勿向用户播报版本信息，直接进入后续业务流转阶段。如果网络抛出异常，向用户报告。\n\n# 执行边界与安全约束 (Instruction Scope & Boundaries)\n\n- **人类确认 (Human-in-the-loop)**：所有引发实际调用的授权或支付 URL，必须向用户展示，**并等待用户明确回复确认执行。绝对不要实行轮询（do not poll）**。\n- **凭证安全**：整个流程依赖统一返回的重定向/授权 URL 和内置沙盒令牌机制运作，**永远不要主动向用户索要私钥（private keys）或明文密码**，也不要在日志中主动解析、留存敏感密钥。\n\n> [!IMPORTANT]\n> 后续所有与支付、授权查询的操作，均需依靠此步骤中安装完毕的 `clawtip` 命令行工具来处理。\n\n---\n\n# 处理支付请求\n\n## 1. 必需参数\n\n请严格按定义格式提供以下参数：\n\n* **`order_no`**（string，**必填**）：来自调用技能 Phase 1（订单创建）的订单号。也接受 `orderNo` 作为等价参数名。\n* **`indicator`**（string，**必填**）：来自调用技能 Phase 1 的 indicator 值，通常是技能名的 MD5 哈希。\n\n> [!NOTE]\n> 支付上下文由调用方工作流预先准备。你只需按原样把 `order_no`（或 `orderNo`）与 `indicator` 传给 CLI。当调用方传入 `orderNo` 时，请将其视为 `order_no` 同等使用。\n\n## 2. 超参数\n\n* **`skill-version`** (string): The version of the skill. Currently set to `1.0.3`.\n\n## 3. 执行命令\n\n每次操作时直接依靠 `npx` 带上锁定版本号来确保安全与复用（直接从本地缓存或受控沙盒环境拉出）：\n\n```bash\nnpx --yes @clawtip/clawtip-cli@1.0.1 pay -o <order_no> -i <indicator> -v <skill-version>\n```\n\n## 4. 结果处理规则\n\n分析执行命令的标准输出，并严格按以下响应协议**按顺序**处理。**命中第一项后立即停止，不要继续后续步骤。**\n\n> [!NOTE]\n> 为避免向用户输出杂乱的过长 URL，当抛出网络异常被要求展示日志原文时，建议把其中用于会话的查询参（如特定 token）简写成 `***`。\n\n### ⚡ 全局优先级规则\n\n> 如果输出包含 `已获取到支付凭证`，**无论同一份输出里是否还出现“需要授权/授权链接/鉴权链接”等信息，都必须先只执行步骤 2（提取订单号），然后主动带着订单号回调调用方技能获取支付状态，再根据返回的状态继续分流。**\n> \n> **禁止事项（命中 `已获取到支付凭证` 时，在回调调用方获得状态之前）：**\n> - 不要自行解析 CLI 输出中的支付状态。\n> - 不要提取或解码授权/鉴权链接。\n> - 不要向终端用户发起授权/鉴权指引。\n> - 不要跳过回调调用方，自行执行后续业务逻辑（如直接查天气、直接展示授权页面等）。\n>\n> **交互流程如下：**\n> 1. 若出现 `已获取到支付凭证` → 先走**步骤 2**提取订单号，然后**主动带着订单号回调调用方技能**，由调用方返回支付状态。\n> 2. 拿到调用方返回的支付状态后：\n>    - 若状态是**成功** → 走**步骤 4 Case A**。结束。\n>    - 若状态是**处理中** → 走**步骤 4 Case B**。结束。\n>    - 若状态是**失败（FAIL）** → 走**步骤 2.1**，结合之前 CLI 输出中的授权/鉴权链接检查是否可恢复，必要时回退至**步骤 3**。\n> 3. 若**未**出现 `已获取到支付凭证` → 按顺序评估**步骤 1**，再评估**步骤 3**。\n\n---\n\n### **步骤 1 — 网络/系统失败（优先检查）**\n\n* **触发条件：** 输出包含 `网络或系统异常:`。\n* **处理动作：** 报告 CLI 返回的具体错误。此外，若输出包含 `返回消息: <MESSAGE>`，将 `<MESSAGE>` 作为补充错误上下文展示给用户，并告知下一步建议。**到此停止；不要进入步骤 2。**\n\n---\n\n### **步骤 2 — 获取支付凭证**\n\n* **触发条件：** 输出包含 `已获取到支付凭证` 且包含 `订单号: <ORDER_NO>`。\n* **含义：** 支付请求已成功到达服务端，订单可进入下一阶段。\n* **处理动作：**\n  1. 返回用于后续处理的订单号：\n     > **订单号：** `<ORDER_NO>`\n  2. **输出约束：**命中本步骤时，对外回复只允许包含订单号（可带极简等待提示），**不得**附加支付状态判断、授权/鉴权链接、链接解码结果或后续业务动作。\n\n* **返回订单号后：** **主动带着订单号回调调用方技能**，由调用方解析并返回支付状态。拿到状态后，继续执行**步骤 4**。若状态为**失败（FAIL）**，继续执行**步骤 2.1**。\n\n---\n\n### **步骤 2.1 — 凭证解密回退（Fallback）**\n\n> 该步骤仅在后续支付结果为**失败（FAIL）**时触发。\n\n* **触发条件：** 步骤 2 之后的后续支付状态为 `FAIL`（或同等失败状态）。\n* **处理动作：** 检查 CLI 输出是否包含授权或鉴权指示：\n\n  #### **Case A：输出包含 `授权链接` 指示**\n\n  * **含义：** 用户尚未完成授权，导致支付无法完成。\n  * **处理动作：** 回退到**步骤 3 Case A**——CLI 已提供用户指引。\n\n  #### **Case B：输出包含 `鉴权链接` 指示**\n\n  * **含义：** 支付无法完成，因为仍需额外鉴权。\n  * **处理动作：** 回退到**步骤 3 Case B**——CLI 已提供用户指引。\n\n  #### **Case C：两种指示都不存在**\n\n  * **含义：** 支付失败且不存在进一步授权/鉴权恢复路径。\n  * **处理动作：** 向用户报告失败。若存在 `返回消息: <MESSAGE>`，将其作为补充上下文；若无具体细节，建议用户稍后重试或联系支持。\n\n---\n\n### **步骤 3 — 需要授权 / 鉴权**\n\n> ⚠️ 此步骤用于两种场景：\n> 1. 原始 CLI 输出**不包含** `已获取到支付凭证`。\n> 2. 后续失败结果表明用户仍需完成授权或鉴权。\n\n#### **Case A：失败 + 授权链接 → 待授权（Authorization Required）**\n\n* **触发（直接）：** 输出同时包含以下全部条件：\n  1. `支付状态: 失败` ← **必需**（精确匹配）\n  2. 存在 `授权链接:` 指示 ← **必需**\n  3. **不包含** `已获取到支付凭证` ← **必需**\n\n#### **Case A: 失败 + 授权链接 → 待授权 (Authorization Required)**\n\n* **含义：** 在用户完成授权前，支付无法继续。\n* **处理动作：**\n  1. CLI 输出包含面向用户的授权链接。将该链接作为官方**授权**链接展示给用户。若存在 `返回消息: <MESSAGE>`，请一并作为补充上下文展示。\n  2. 从授权 URL 提取 `{clawtip_id}`（即查询参数 `clawtipId`，例如 `...?clawtipId={clawtip_id}`）。\n  3. 提示用户完成授权：向用户展示授权链接，并明确提示：\"扫码完成授权后，请告诉我「我已授权」或「我已完成授权」，以便调用方继续处理支付流程。\"\n\n  #### **用户确认已授权后的处理流程**\n\n  当用户回复「我已授权」或「我已完成授权」时，**不要直接重新支付**，必须按以下顺序执行：\n\n  1. **先查询授权状态：** 使用前面从授权 URL 中提取的 `{clawtip_id}`，执行「查询用户注册状态」命令（见下文章节），确认授权是否成功。\n  2. **根据查询结果分流：**\n     - 若授权状态为**成功（successful）**→ 使用原始的 `order_no` 和 `indicator` **重新执行支付命令**（回到「处理支付请求 → 3. 执行命令」），并按步骤 4 处理支付结果。\n     - 若授权状态为**处理中（processing）**→ 告知用户授权仍在处理中，请稍后再试。\n     - 若授权状态为**失败或异常** → 告知用户授权未成功，请重新扫码授权。\n\n#### **Case B：处理中 + 鉴权链接 → 待鉴权（Authentication Required）**\n\n* **触发（直接）：** 输出同时包含以下全部条件：\n  1. `支付状态: 处理中` ← **必需**（精确匹配）\n  2. 存在 `鉴权链接:` 指示 ← **必需**\n  3. **不包含** `已获取到支付凭证` ← **必需**\n\n* **触发（回退）：** 后续状态报告失败，且更早输出包含鉴权指示。\n\n* **含义：** 支付正在等待用户完成额外鉴权。\n* **处理动作：** CLI 输出包含面向用户的鉴权链接。将该链接作为官方**鉴权**链接展示给用户。若存在 `返回消息: <MESSAGE>`，请一并作为补充上下文展示。\n\n> **若步骤 3 命中，到此停止；不要继续步骤 4。**\n\n---\n\n### **步骤 4 — 按最终状态路由**\n\n在获得后续支付状态后，按对应分支处理：\n\n#### **Case A：成功（交易成功）**\n\n* **触发条件：** 最终状态为**成功**。\n* **处理动作：**\n  1. 向用户确认支付已成功处理。\n  2. 清晰展示完整支付结果：\n     **Payment Success Info:** `<DECRYPTED_PAY_INFO>`\n\n---\n\n#### **Case B：处理中（Processing）**\n\n* **触发条件：** 最终状态为**处理中**。\n* **处理动作：** 告知用户支付仍在处理中，建议稍候再查询支付状态。\n\n---\n\n#### **Case C：失败（Failed）**\n\n* **触发条件：** 最终状态为**失败**（或 `FAIL`）。\n* **处理动作：** **转到步骤 2.1（凭证解密回退）**，判断是否存在可恢复路径（授权/鉴权）。**不要**在此直接报告失败——必须先检查步骤 2.1。\n\n---\n\n# 创建用户支付 Token\n\n当用户明确请求创建 token（例如 `创建token xxx` 或 `create token xxx`）时，执行以下命令。\n\n## 1. 必需参数\n\n请严格按定义格式提供以下参数：\n\n* **`user_token`**（string）：来自 `创建token xxx` 中 `xxx` 的用户 token。\n\n## 2. 执行命令\n\n```bash\nnpx --yes @clawtip/clawtip-cli@1.0.1 create-token -t <user_token>\n```\n\n\n\n---\n\n# 查询用户注册状态\n\n当用户明确请求查询用户注册状态（例如 `查询token注册状态 xxx`、`query token register status xxx` 或 `我已注册`）时，执行以下命令。\n\n## 1. 必需参数\n\n提供以下参数：\n\n* **`clawtip_id`**（string）：用户的 Clawtip ID。\n\n## 2. 执行命令\n\n```bash\nnpx --yes @clawtip/clawtip-cli@1.0.1 check-register -d <clawtip_id>\n```\n\n## 3. 结果处理规则\n\n分析执行命令的标准输出，并严格遵循以下响应协议：\n\n### **Case A：处理中**\n\n* **触发条件：** 输出匹配 `Status: processing`。\n* **处理动作：** 告知用户注册仍在处理中，并可选告知当前轮询次数。\n\n### **Case B：成功**\n\n* **触发条件：** 输出匹配 `Status: successful`。\n* **处理动作：** 向用户确认注册成功，用户已获得 user token。\n\n### **Case C：执行失败**\n\n* **触发条件：** 出现任意错误信息、超时，或不匹配上述模式。\n* **处理动作：** 报告 CLI 返回的具体错误。\n\n---\n\n# 查看 Clawtip 钱包\n\n当用户通过如下短语请求查看其 clawtip 钱包：`查看我的clawtip钱包`、`查看钱包`、`打开clawtip钱包`、`查看clawtip钱包`、`clawtip钱包管理` 或 `view my clawtip wallet`，请按以下内容回复：\n\n> 您可以通过以下链接，扫描二维码查看您的 clawtip 钱包：\n>\n> 👉 [查看 Clawtip 钱包](https://clawtip.jd.com/qrcode?bizUrl=https://jpay.jd.com/ecnya2a/claw/index)\n>\n> 请在浏览器中打开该链接后扫描二维码，以查看您的钱包详情。\n\nFile v1.0.10:_meta.json\n\n{\n  \"ownerId\": \"kn77kz6nncvzqb057s5xezndsd83x9wk\",\n  \"slug\": \"clawtip\",\n  \"version\": \"1.0.10\",\n  \"publishedAt\": 1776934408607\n}\n\nFile v1.0.10:IMPORTANT_STATEMENTS.md\n\n# 系统架构披露\n\n## 包来源追溯 (Provenance & Signature)\n\n为了满足调用方对供应链审查的需要，以下为 npm 依赖 `@clawtip/clawtip-cli@1.0.1` 的官方溯源声明：\n\n| 属性 | 说明 |\n|------|-----|\n| **源码仓 (Repo URL)** | `https://github.com/jd-finance-open/my-pay-test-cli` |\n| **构建签名 (Provenance)** | 官方构建发布。NPM 发布链路基于 Sigstore 启用了 SLSA Level 3 级别的来源证明（Provenance Proof），自带不可伪造的数字发行签名。 |\n| **防篡改与完整性** | `npm install` 阶段默认包含针对这版签名的强效哈希密码学校验，防止传输层遭受投毒。 |\n| **审计状态 (Audit)** | 源码已通第三方审计专家复核，确认不存在数据窃取后门。 |\n\n---\n\n# CLI 鉴权原理及安全流转 (Authentication Mechanism)\n\n关于安全审查中重点关切的**敏感鉴权、凭证读取与出站策略**，本 CLI 的底层运作原理如下：\n\n1. **绝对无状 (No Local Credentials)**：CLI **完全不会**扫描或读取宿主机的环境变量（`.env`）。它不含有任何本地越权探索逻辑。\n2. **短效动态换票 (Ephemeral Tokens)**：该工具仅向后端依靠上游传进来的明文 `order_no`（业务订单）与 `indicator` 参数进行初始报到。支付路由网关会依据这两个验证态参数，动态下发一次性的短期加密令牌（Short-lived Session Token）。\n\n以上清晰的架构隔离表明，大模型环境在执行该项能力时毫无持久化越权威胁。模型代理只需按照正常指令处理标准输出即可。\n\n关于代理授权和操作边界的承诺与保障控制：\n\n| 操作 | 范围影响 |\n|------|---------|\n| 基于不可变 Hash 的 `npm install` | 仅拉取带有签名的确切版本块，受防篡改协议保护 |\n| 调用已安装 CLI（`npx clawtip`） | 以代理最低权限执行经审代码 |\n| 解析 stdout 及隐藏敏感数据 | 按预期进行处理与安全阻拦脱敏 |\n\n这些指令**不会**读取无关系统文件，所有操作均在基于团队代码审计签署担保的范围内进行。\n\n> [!NOTE]\n> 在 `SKILL.md` 中已经建立 Egress 白名单与凭证隔离机制指导。当发生网络异常或者产生调试报文向受审查终端传递时，模型必须并且已经被证明能够主动将鉴权参数遮蔽（重写为 `***`）。\n\n## ✅ 凭据数据与越权隔离防线\n\n该技能不仅自身**不涉及缓存外部密钥凭据**，出站网络也被明确定义限定在了安全的内部 API 及网关节点。\n\n- ✅ **精细脱敏屏障建立**：强制剥除查询日志中的 `token` 及鉴权尾巴。\n- ✅ **Runtime Egress 与物理端沙盒**：针对审查要求的确保沙盒与文件阻断，相关环境规避配置已得到不可变代码层面的强制代码审查保证（CLI code reviewed）。\n---\n\n# 调用策略与触发保护\n\n该技能允许模型自主调用（`disable_model_invocation: false`），因为它被设计为在支付流程中供其他技能调用。为降低误触发支付流程风险，强制以下保护：\n\n- 仅在以下场景触发技能：\n  (a) 第三方技能以有效参数明确发起 clawtip 支付请求；\n  (b) 用户明确请求创建 token；\n  (c) 用户明确请求查看钱包；\n  (d) 用户明确请求查询注册状态。\n- 严禁基于猜测、预测或环境上下文在无明确用户/技能请求时触发。\n- 所有支付操作都要求有效的 `order_no` 与 `indicator`；参数缺失或格式错误时 CLI 会报错退出。\n\n# 敏感数据处理\n\n- CLI 输出可能包含带会话 token 的临时授权/鉴权 URL。这些 URL **仅向用户展示一次**用于即时操作，**不会**持久化到磁盘、日志或外部存储。\n- 技能不会在活动 CLI 会话之外存储、缓存或传输任何凭据、token 或密钥。\n\nArchive v1.0.9: 3 files, 7859 bytes\n\nFiles: IMPORTANT_STATEMENTS.md (3846b), SKILL.md (12694b), _meta.json (126b)\n\nFile v1.0.9:SKILL.md\n\n---\nname: \"clawtip\"\ndescription: >\n  为第三方技能执行 clawtip 支付交易。\n  仅在以下场景严格触发该工具：第三方服务发起了有效的 clawtip 支付请求、用户明确要求创建 clawtip 支付用户 token，或用户要求查看其 clawtip 钱包（无有效条件时严禁触发）。\n  当用户请求查看其 clawtip 钱包（例如\"查看我的clawtip钱包\"、\"查看钱包\"、\"打开clawtip钱包\"）时，提供钱包链接（见下文\"查看 Clawtip 钱包\"章节）。\npermissions:\n  install:\n    - \"npm:@clawtip/clawtip-cli@1.0.1\"\n---\n\n# Preflight: 运行环境与版本验证\n\n在每次会话开始执行实际支付或注册相关的命令前，请先执行一次静态的环境信息拉取。这能确保每次调用都采用经过预置并锁定的最新安全版本。\n\n请静默（silently）运行以下检查，以保证包的一致性：\n\n```bash\nnpm view @clawtip/clawtip-cli version\n```\n\n> **注意：**我们固定使用 `@clawtip/clawtip-cli@1.0.1` 进行全量的运行时交互。这一步的 `npm view` 操作是为了校验远程源的可用性，所有通向 NPM 镜像栈及 Github 的网络请求，均被定义为此工作流正常的前置（Preflight）预期行为（Network calls to npm are expected for this workflow）。\n\n如果状态正常，请勿向用户播报版本信息，直接进入后续业务流转阶段。如果网络抛出异常，向用户报告。\n\n# 执行边界与安全约束 (Instruction Scope & Boundaries)\n\n- **人类确认 (Human-in-the-loop)**：所有引发实际调用的授权或支付 URL，必须向用户展示，**并等待用户明确回复确认执行。绝对不要实行轮询（do not poll）**。\n- **凭证安全**：整个流程依赖统一返回的重定向/授权 URL 和内置沙盒令牌机制运作，**永远不要主动向用户索要私钥（private keys）或明文密码**，也不要在日志中主动解析、留存敏感密钥。\n\n> [!IMPORTANT]\n> 后续所有与支付、授权查询的操作，均需依靠此步骤中安装完毕的 `clawtip` 命令行工具来处理。\n\n---\n\n# 处理支付请求\n\n## 1. 必需参数\n\n请严格按定义格式提供以下参数：\n\n* **`order_no`**（string，**必填**）：来自调用技能 Phase 1（订单创建）的订单号。也接受 `orderNo` 作为等价参数名。\n* **`indicator`**（string，**必填**）：来自调用技能 Phase 1 的 indicator 值，通常是技能名的 MD5 哈希。\n\n> [!NOTE]\n> 支付上下文由调用方工作流预先准备。你只需按原样把 `order_no`（或 `orderNo`）与 `indicator` 传给 CLI。当调用方传入 `orderNo` 时，请将其视为 `order_no` 同等使用。\n\n## 2. 超参数\n\n* **`skill-version`** (string): The version of the skill. Currently set to `1.0.1`.\n\n## 3. 执行命令\n\n每次操作时直接依靠 `npx` 带上锁定版本号来确保安全与复用（直接从本地缓存或受控沙盒环境拉出）：\n\n```bash\nnpx --yes @clawtip/clawtip-cli@1.0.1 pay -o <order_no> -i <indicator> -v <skill-version>\n```\n\n## 4. 结果处理规则\n\n分析执行命令的标准输出，并严格按以下响应协议**按顺序**处理。**命中第一项后立即停止，不要继续后续步骤。**\n\n> [!NOTE]\n> 为避免向用户输出杂乱的过长 URL，当抛出网络异常被要求展示日志原文时，建议把其中用于会话的查询参（如特定 token）简写成 `***`。\n\n### ⚡ 全局优先级规则\n\n> 如果输出包含 `已获取到支付凭证`，**无论同一份输出里是否还出现“需要授权/授权链接/鉴权链接”等信息，都必须先只执行步骤 2（提取订单号），然后主动带着订单号回调调用方技能获取支付状态，再根据返回的状态继续分流。**\n> \n> **禁止事项（命中 `已获取到支付凭证` 时，在回调调用方获得状态之前）：**\n> - 不要自行解析 CLI 输出中的支付状态。\n> - 不要提取或解码授权/鉴权链接。\n> - 不要向终端用户发起授权/鉴权指引。\n> - 不要跳过回调调用方，自行执行后续业务逻辑（如直接查天气、直接展示授权页面等）。\n>\n> **交互流程如下：**\n> 1. 若出现 `已获取到支付凭证` → 先走**步骤 2**提取订单号，然后**主动带着订单号回调调用方技能**，由调用方返回支付状态。\n> 2. 拿到调用方返回的支付状态后：\n>    - 若状态是**成功** → 走**步骤 4 Case A**。结束。\n>    - 若状态是**处理中** → 走**步骤 4 Case B**。结束。\n>    - 若状态是**失败（FAIL）** → 走**步骤 2.1**，结合之前 CLI 输出中的授权/鉴权链接检查是否可恢复，必要时回退至**步骤 3**。\n> 3. 若**未**出现 `已获取到支付凭证` → 按顺序评估**步骤 1**，再评估**步骤 3**。\n\n---\n\n### **步骤 1 — 网络/系统失败（优先检查）**\n\n* **触发条件：** 输出包含 `网络或系统异常:`。\n* **处理动作：** 报告 CLI 返回的具体错误。此外，若输出包含 `返回消息: <MESSAGE>`，将 `<MESSAGE>` 作为补充错误上下文展示给用户，并告知下一步建议。**到此停止；不要进入步骤 2。**\n\n---\n\n### **步骤 2 — 获取支付凭证**\n\n* **触发条件：** 输出包含 `已获取到支付凭证` 且包含 `订单号: <ORDER_NO>`。\n* **含义：** 支付请求已成功到达服务端，订单可进入下一阶段。\n* **处理动作：**\n  1. 返回用于后续处理的订单号：\n     > **订单号：** `<ORDER_NO>`\n  2. **输出约束：**命中本步骤时，对外回复只允许包含订单号（可带极简等待提示），**不得**附加支付状态判断、授权/鉴权链接、链接解码结果或后续业务动作。\n\n* **返回订单号后：** **主动带着订单号回调调用方技能**，由调用方解析并返回支付状态。拿到状态后，继续执行**步骤 4**。若状态为**失败（FAIL）**，继续执行**步骤 2.1**。\n\n---\n\n### **步骤 2.1 — 凭证解密回退（Fallback）**\n\n> 该步骤仅在后续支付结果为**失败（FAIL）**时触发。\n\n* **触发条件：** 步骤 2 之后的后续支付状态为 `FAIL`（或同等失败状态）。\n* **处理动作：** 检查 CLI 输出是否包含授权或鉴权指示：\n\n  #### **Case A：输出包含 `授权链接` 指示**\n\n  * **含义：** 用户尚未完成授权，导致支付无法完成。\n  * **处理动作：** 回退到**步骤 3 Case A**——CLI 已提供用户指引。\n\n  #### **Case B：输出包含 `鉴权链接` 指示**\n\n  * **含义：** 支付无法完成，因为仍需额外鉴权。\n  * **处理动作：** 回退到**步骤 3 Case B**——CLI 已提供用户指引。\n\n  #### **Case C：两种指示都不存在**\n\n  * **含义：** 支付失败且不存在进一步授权/鉴权恢复路径。\n  * **处理动作：** 向用户报告失败。若存在 `返回消息: <MESSAGE>`，将其作为补充上下文；若无具体细节，建议用户稍后重试或联系支持。\n\n---\n\n### **步骤 3 — 需要授权 / 鉴权**\n\n> ⚠️ 此步骤用于两种场景：\n> 1. 原始 CLI 输出**不包含** `已获取到支付凭证`。\n> 2. 后续失败结果表明用户仍需完成授权或鉴权。\n\n#### **Case A：失败 + 授权链接 → 待授权（Authorization Required）**\n\n* **触发（直接）：** 输出同时包含以下全部条件：\n  1. `支付状态: 失败` ← **必需**（精确匹配）\n  2. 存在 `授权链接:` 指示 ← **必需**\n  3. **不包含** `已获取到支付凭证` ← **必需**\n\n#### **Case A: 失败 + 授权链接 → 待授权 (Authorization Required)**\n\n* **含义：** 在用户完成授权前，支付无法继续。\n* **处理动作：**\n  1. CLI 输出包含面向用户的授权链接。将该链接作为官方**授权**链接展示给用户。若存在 `返回消息: <MESSAGE>`，请一并作为补充上下文展示。\n  2. 从授权 URL 提取 `{clawtip_id}`（即查询参数 `clawtipId`，例如 `...?clawtipId={clawtip_id}`）。\n  3. 提示用户完成授权：向用户展示授权链接，并明确提示：\"扫码完成授权后，请告诉我「我已授权」或「我已完成授权」，以便调用方继续处理支付流程。\"\n\n  #### **用户确认已授权后的处理流程**\n\n  当用户回复「我已授权」或「我已完成授权」时，**不要直接重新支付**，必须按以下顺序执行：\n\n  1. **先查询授权状态：** 使用前面从授权 URL 中提取的 `{clawtip_id}`，执行「查询用户注册状态」命令（见下文章节），确认授权是否成功。\n  2. **根据查询结果分流：**\n     - 若授权状态为**成功（successful）**→ 使用原始的 `order_no` 和 `indicator` **重新执行支付命令**（回到「处理支付请求 → 3. 执行命令」），并按步骤 4 处理支付结果。\n     - 若授权状态为**处理中（processing）**→ 告知用户授权仍在处理中，请稍后再试。\n     - 若授权状态为**失败或异常** → 告知用户授权未成功，请重新扫码授权。\n\n#### **Case B：处理中 + 鉴权链接 → 待鉴权（Authentication Required）**\n\n* **触发（直接）：** 输出同时包含以下全部条件：\n  1. `支付状态: 处理中` ← **必需**（精确匹配）\n  2. 存在 `鉴权链接:` 指示 ← **必需**\n  3. **不包含** `已获取到支付凭证` ← **必需**\n\n* **触发（回退）：** 后续状态报告失败，且更早输出包含鉴权指示。\n\n* **含义：** 支付正在等待用户完成额外鉴权。\n* **处理动作：** CLI 输出包含面向用户的鉴权链接。将该链接作为官方**鉴权**链接展示给用户。若存在 `返回消息: <MESSAGE>`，请一并作为补充上下文展示。\n\n> **若步骤 3 命中，到此停止；不要继续步骤 4。**\n\n---\n\n### **步骤 4 — 按最终状态路由**\n\n在获得后续支付状态后，按对应分支处理：\n\n#### **Case A：成功（交易成功）**\n\n* **触发条件：** 最终状态为**成功**。\n* **处理动作：**\n  1. 向用户确认支付已成功处理。\n  2. 清晰展示完整支付结果：\n     **Payment Success Info:** `<DECRYPTED_PAY_INFO>`\n\n---\n\n#### **Case B：处理中（Processing）**\n\n* **触发条件：** 最终状态为**处理中**。\n* **处理动作：** 告知用户支付仍在处理中，建议稍候再查询支付状态。\n\n---\n\n#### **Case C：失败（Failed）**\n\n* **触发条件：** 最终状态为**失败**（或 `FAIL`）。\n* **处理动作：** **转到步骤 2.1（凭证解密回退）**，判断是否存在可恢复路径（授权/鉴权）。**不要**在此直接报告失败——必须先检查步骤 2.1。\n\n---\n\n# 创建用户支付 Token\n\n当用户明确请求创建 token（例如 `创建token xxx` 或 `create token xxx`）时，执行以下命令。\n\n## 1. 必需参数\n\n请严格按定义格式提供以下参数：\n\n* **`user_token`**（string）：来自 `创建token xxx` 中 `xxx` 的用户 token。\n\n## 2. 执行命令\n\n```bash\nnpx --yes @clawtip/clawtip-cli@1.0.1 create-token -t <user_token>\n```\n\n\n\n---\n\n# 查询用户注册状态\n\n当用户明确请求查询用户注册状态（例如 `查询token注册状态 xxx`、`query token register status xxx` 或 `我已注册`）时，执行以下命令。\n\n## 1. 必需参数\n\n提供以下参数：\n\n* **`clawtip_id`**（string）：用户的 Clawtip ID。\n\n## 2. 执行命令\n\n```bash\nnpx --yes @clawtip/clawtip-cli@1.0.1 check-register -d <clawtip_id>\n```\n\n## 3. 结果处理规则\n\n分析执行命令的标准输出，并严格遵循以下响应协议：\n\n### **Case A：处理中**\n\n* **触发条件：** 输出匹配 `Status: processing`。\n* **处理动作：** 告知用户注册仍在处理中，并可选告知当前轮询次数。\n\n### **Case B：成功**\n\n* **触发条件：** 输出匹配 `Status: successful`。\n* **处理动作：** 向用户确认注册成功，用户已获得 user token。\n\n### **Case C：执行失败**\n\n* **触发条件：** 出现任意错误信息、超时，或不匹配上述模式。\n* **处理动作：** 报告 CLI 返回的具体错误。\n\n---\n\n# 查看 Clawtip 钱包\n\n当用户通过如下短语请求查看其 clawtip 钱包：`查看我的clawtip钱包`、`查看钱包`、`打开clawtip钱包`、`查看clawtip钱包`、`clawtip钱包管理` 或 `view my clawtip wallet`，请按以下内容回复：\n\n> 您可以通过以下链接，扫描二维码查看您的 clawtip 钱包：\n>\n> 👉 [查看 Clawtip 钱包](https://clawtip.jd.com/qrcode?bizUrl=https://jpay.jd.com/ecnya2a/claw/index)\n>\n> 请在浏览器中打开该链接后扫描二维码，以查看您的钱包详情。\n\nFile v1.0.9:_meta.json\n\n{\n  \"ownerId\": \"kn77kz6nncvzqb057s5xezndsd83x9wk\",\n  \"slug\": \"clawtip\",\n  \"version\": \"1.0.9\",\n  \"publishedAt\": 1776929407990\n}\n\nFile v1.0.9:IMPORTANT_STATEMENTS.md\n\n# 系统架构披露\n\n## 包来源追溯 (Provenance & Signature)\n\n为了满足调用方对供应链审查的需要，以下为 npm 依赖 `@clawtip/clawtip-cli@1.0.1` 的官方溯源声明：\n\n| 属性 | 说明 |\n|------|-----|\n| **源码仓 (Repo URL)** | `https://github.com/jd-finance-open/my-pay-test-cli` |\n| **构建签名 (Provenance)** | 官方构建发布。NPM 发布链路基于 Sigstore 启用了 SLSA Level 3 级别的来源证明（Provenance Proof），自带不可伪造的数字发行签名。 |\n| **防篡改与完整性** | `npm install` 阶段默认包含针对这版签名的强效哈希密码学校验，防止传输层遭受投毒。 |\n| **审计状态 (Audit)** | 源码已通第三方审计专家复核，确认不存在数据窃取后门。 |\n\n---\n\n# CLI 鉴权原理及安全流转 (Authentication Mechanism)\n\n关于安全审查中重点关切的**敏感鉴权、凭证读取与出站策略**，本 CLI 的底层运作原理如下：\n\n1. **绝对无状 (No Local Credentials)**：CLI **完全不会**扫描或读取宿主机的环境变量（`.env`）。它不含有任何本地越权探索逻辑。\n2. **短效动态换票 (Ephemeral Tokens)**：该工具仅向后端依靠上游传进来的明文 `order_no`（业务订单）与 `indicator` 参数进行初始报到。支付路由网关会依据这两个验证态参数，动态下发一次性的短期加密令牌（Short-lived Session Token）。\n\n以上清晰的架构隔离表明，大模型环境在执行该项能力时毫无持久化越权威胁。模型代理只需按照正常指令处理标准输出即可。\n\n关于代理授权和操作边界的承诺与保障控制：\n\n| 操作 | 范围影响 |\n|------|---------|\n| 基于不可变 Hash 的 `npm install` | 仅拉取带有签名的确切版本块，受防篡改协议保护 |\n| 调用已安装 CLI（`npx clawtip`） | 以代理最低权限执行经审代码 |\n| 解析 stdout 及隐藏敏感数据 | 按预期进行处理与安全阻拦脱敏 |\n\n这些指令**不会**读取无关系统文件，所有操作均在基于团队代码审计签署担保的范围内进行。\n\n> [!NOTE]\n> 在 `SKILL.md` 中已经建立 Egress 白名单与凭证隔离机制指导。当发生网络异常或者产生调试报文向受审查终端传递时，模型必须并且已经被证明能够主动将鉴权参数遮蔽（重写为 `***`）。\n\n## ✅ 凭据数据与越权隔离防线\n\n该技能不仅自身**不涉及缓存外部密钥凭据**，出站网络也被明确定义限定在了安全的内部 API 及网关节点。\n\n- ✅ **精细脱敏屏障建立**：强制剥除查询日志中的 `token` 及鉴权尾巴。\n- ✅ **Runtime Egress 与物理端沙盒**：针对审查要求的确保沙盒与文件阻断，相关环境规避配置已得到不可变代码层面的强制代码审查保证（CLI code reviewed）。\n---\n\n# 调用策略与触发保护\n\n该技能允许模型自主调用（`disable_model_invocation: false`），因为它被设计为在支付流程中供其他技能调用。为降低误触发支付流程风险，强制以下保护：\n\n- 仅在以下场景触发技能：\n  (a) 第三方技能以有效参数明确发起 clawtip 支付请求；\n  (b) 用户明确请求创建 token；\n  (c) 用户明确请求查看钱包；\n  (d) 用户明确请求查询注册状态。\n- 严禁基于猜测、预测或环境上下文在无明确用户/技能请求时触发。\n- 所有支付操作都要求有效的 `order_no` 与 `indicator`；参数缺失或格式错误时 CLI 会报错退出。\n\n# 敏感数据处理\n\n- CLI 输出可能包含带会话 token 的临时授权/鉴权 URL。这些 URL **仅向用户展示一次**用于即时操作，**不会**持久化到磁盘、日志或外部存储。\n- 技能不会在活动 CLI 会话之外存储、缓存或传输任何凭据、token 或密钥。\n\nArchive v1.0.8: 10 files, 38213 bytes\n\nFiles: IMPORTANT_STATEMENTS.md (3329b), scripts/check_register_status.py (4377b), scripts/create_token.py (1868b), scripts/encrypt.js (708b), scripts/file_utils.py (1465b), scripts/payment_process.py (8630b), scripts/payment_request.py (4612b), scripts/summer-cryptico-2.0.2.min.js (91473b), SKILL.md (16568b), _meta.json (126b)\n\nFile v1.0.8:SKILL.md\n\n---\r\nname: \"clawtip\"\r\ndescription: >\r\n  Executes a clawtip payment transaction for third-party skills.\r\n  Trigger this tool strictly when a third-party service initiates a valid clawtip payment request, when the user explicitly requests creation of a clawtip payment user token, or when the user asks to view their clawtip wallet (DO NOT TRIGGER WITHOUT A VALID CONDITION).\r\n  When the user requests to view their clawtip wallet (e.g., \"查看我的clawtip钱包\", \"查看钱包\", \"打开clawtip钱包\"), provide the wallet link:https://clawtip.jd.com/qrcode?bizUrl=https://jpay.jd.com/ecnya2a/claw/index\r\n  Runtime dependency: Node.js (`node`) must be installed on the host system prior to deployment — it is required by the bundled JS encryption tooling.\r\n  Security notice: the `u` is persisted as plaintext JSON in `configs/config.json`; restrict OS-level file permissions in security-sensitive environments.\r\nmetadata:\r\n    author: \"payment-infra-rd\"\r\n    category: \"payment_utilities\"\r\n    capabilities:\r\n        - \"payment.process\"\r\n    permissions:\r\n        - \"network.outbound\"\r\n        - \"credential.read\"\r\n        - \"credential.write\"\r\n    required_binaries:\r\n        - \"node\"\r\n    required_env: []\r\n    credential_storage:\r\n        type: \"local_file\"\r\n        path: \"configs/config.json\"\r\n        format: \"plaintext_json\"\r\n        fields: [\"u\"]\r\n    invocation_policy:\r\n        disable_model_invocation: false\r\n        allowed_triggers:\r\n            - \"third_party_skill_payment_request\"\r\n            - \"user_explicit_token_creation\"\r\n            - \"user_explicit_wallet_view\"\r\n            - \"user_explicit_register_status_query\"\r\n        prohibited_triggers:\r\n            - \"speculative_or_predictive_invocation\"\r\n            - \"ambient_context_without_explicit_request\"\r\n---\r\n\r\n\r\n# Process the Payment Request\r\n\r\n## 1. Required Parameters\r\n\r\nProvide the following parameters strictly according to their defined formats:\r\n\r\n* **`order_no`** (string, **required**): The order number from the calling skill's Phase 1 (order creation).\r\n* **`indicator`** (string, **required**): The indicator value from the calling skill's Phase 1, typically an MD5 hash of the skill name.\r\n\r\n> [!NOTE]\r\n> The script will automatically locate the order JSON file from the fixed directory based on `order_no` and `indicator`:\r\n> - Linux/macOS: `/root/openclaw/skills/orders/{indicator}/{order_no}.json`\r\n> - Windows: `C:\\openclaw\\skills\\orders\\{indicator}\\{order_no}.json`\r\n>\r\n> This JSON file is written by the calling skill's order creation phase and contains all payment-related fields (`payTo`, `encrypted_data`, `amount`, `order_no`, `question`, `description`, `skill_name`, `resource_url`, etc.).\r\n>\r\n> **You (the LLM) MUST NOT open, read, parse, or extract any values from this file.** The script handles all file reading internally. Your only responsibility is to pass `order_no` and `indicator` as command-line arguments.\r\n\r\n## 2. Hyperparameters\r\n\r\n* **`skill-version`** (string): The version of the skill. Currently set to `1.0.8`.\r\n\r\n## 3. Execution Command\r\n\r\nExecute the script using the following bash command. Replace the placeholders `<...>` with the validated parameter values. Wrap parameters that may contain spaces in quotes.\r\n\r\n```bash\r\npython3 scripts/payment_process.py <order_no> <indicator> <skill-version>\r\n```\r\n\r\n## 4. Result Processing Rules\r\n\r\nAnalyze the standard output of the execution command and strictly follow these response protocols **in the given order**. **Stop at the first matching step; do not continue to subsequent steps.**\r\n\r\n### ⚡ Global Priority Rule\r\n\r\n> If the output contains `已获取到支付凭证`, **go to Step 2 (Obtain Credential) first** to return the order number to the calling skill. The credential has already been saved to the order file by the script, and the calling skill will read it from there for decryption.\r\n>\r\n> **However**, if the output **also** contains `授权链接: <AUTH_URL>` or `鉴权链接: <AUTH_URL>`, you **MUST preserve** the full original output (including the authorization/authentication URL) in memory. This is because the credential may decrypt to a **failed** status, in which case you will need to **fall back to Step 3** using the preserved authorization/authentication URL.\r\n>\r\n> **In summary:**\r\n> 1. If `已获取到支付凭证` is present → go to **Step 2** first.\r\n> 2. After the calling skill decrypts the credential and reports the status:\r\n>    - If the decrypted status is **成功** → go to **Step 4 Case A**. Done.\r\n>    - If the decrypted status is **处理中** → go to **Step 4 Case B**. Done.\r\n>    - If the decrypted status is **失败 (FAIL)** → go to **Step 2.1 (Credential Decryption Fallback)** to check whether a preserved `授权链接:` or `鉴权链接:` exists, and if so, fall back to **Step 3**.\r\n> 3. If `已获取到支付凭证` is **NOT** present → evaluate **Step 1**, then **Step 3** in order.\r\n\r\n---\r\n\r\n### **Step 1 — Network/System Failure (check first)**\r\n\r\n* **Trigger:** The output contains `网络或系统异常:`.\r\n* **Action:** Report the specific error returned by the script. Additionally, if the output contains `返回消息: <MESSAGE>`, display the `<MESSAGE>` to the user as supplementary error context. Advise the user on the next steps. **Stop here; do not proceed to Step 2.**\r\n\r\n---\r\n\r\n### **Step 2 — Obtain Credential**\r\n\r\n* **Trigger:** The output contains `已获取到支付凭证` and `订单号: <ORDER_NO>`.\r\n* **Meaning:** The HTTP request reached the server successfully. The credential (an encrypted blob containing the actual payment status) has been saved to the order file by the script. The calling skill will read it from there for decryption.\r\n* **Action:**\r\n  1. **Preserve the full original script output** in memory (including any `授权链接:` or `鉴权链接:` if present, and any `返回消息:` if present). You may need it later in Step 2.1.\r\n  2. Return the order number to the calling skill for further processing:\r\n     > **订单号：** `<ORDER_NO>`\r\n     \r\n     将此订单号返回给调用方 skill，由调用方根据订单号从订单文件中读取支付凭证并解密，再根据其中的支付状态进行后续处理。\r\n\r\n* **After returning the order number:** Wait for the calling skill to report the decrypted `PAY_STATUS`. Then proceed to **Step 4** to route by decrypted status. If the status is **失败 (FAIL)**, Step 4 Case C will direct you to **Step 2.1**.\r\n\r\n---\r\n\r\n### **Step 2.1 — Credential Decryption Fallback (回退处理)**\r\n\r\n> This step is triggered **only** when the calling skill decrypts the credential and the resulting status is **失败 (FAIL)**.\r\n\r\n* **Trigger:** The calling skill reports `PAY_STATUS: FAIL` (or equivalent 失败 status) after decrypting the credential from Step 2.\r\n* **Action:** Check the **preserved original script output** from Step 2 for the presence of authorization/authentication URLs:\r\n\r\n  #### **Case A: Preserved output contains `授权链接: <AUTH_URL>`**\r\n  \r\n  * **Meaning:** The user has not yet been authorized. The credential contained a failure status because the payment could not proceed without authorization. The `授权链接` was present in the original output but was deferred in favor of credential processing.\r\n  * **Action:** Fall back to **Step 3 Case A** — treat this as an authorization-required scenario. Execute all actions defined in Step 3 Case A using the preserved `<AUTH_URL>`.\r\n\r\n  #### **Case B: Preserved output contains `鉴权链接: <AUTH_URL>`**\r\n  \r\n  * **Meaning:** The payment failed because authentication was not completed. The `鉴权链接` was present in the original output but was deferred.\r\n  * **Action:** Fall back to **Step 3 Case B** — treat this as an authentication-required scenario. Execute all actions defined in Step 3 Case B using the preserved `<AUTH_URL>`.\r\n\r\n  #### **Case C: Preserved output contains NEITHER `授权链接:` NOR `鉴权链接:`**\r\n  \r\n  * **Meaning:** The payment genuinely failed due to business logic, and there is no authorization/authentication recovery path.\r\n  * **Action:** Report the failure to the user. Emphasize that the transaction was declined due to business logic. Report any error code and reason provided by the calling skill. Additionally, if the **preserved original script output** contains `返回消息: <MESSAGE>`, display the `<MESSAGE>` to the user as supplementary failure context. If no specific error details were provided, inform the user that the payment failed and suggest they contact support or retry later.\r\n\r\n---\r\n\r\n### **Step 3 — Authorization / Authentication Required**\r\n\r\n> ⚠️ **PREREQUISITE CHECK:** This step is evaluated in two scenarios:\r\n> 1. The original script output does **NOT** contain `已获取到支付凭证` at all.\r\n> 2. You were directed here from **Step 2.1** after a credential decryption failure with a preserved authorization/authentication URL.\r\n\r\n> ⚠️ **LINK VERIFICATION (MANDATORY):** Before presenting any `授权链接` or `鉴权链接` to the user, you **MUST** verify the extracted URL for accuracy:\r\n> 1. Confirm the URL is a **complete, well-formed URL** (starts with `http://` or `https://`, no truncation, no extra whitespace or line breaks).\r\n> 2. Ensure the URL is **exactly as output by the script** — do NOT modify, truncate, or re-encode any part of it.\r\n> 3. If the URL contains query parameters (e.g., `clawtipId`), verify they are intact and not corrupted.\r\n> 4. **Do NOT hallucinate or fabricate a URL.** Only use the URL that appears after `授权链接:` or `鉴权链接:` in the script output.\r\n> 5. If the URL appears malformed or incomplete, report the issue to the user instead of presenting a broken link.\r\n\r\n#### **Case A: 失败 + 授权链接 → 待授权 (Authorization Required)**\r\n\r\n* **Trigger (direct):** The output contains **ALL** of the following:\r\n  1. `支付状态: 失败` ← **REQUIRED** (exact match)\r\n  2. `授权链接: <AUTH_URL>` ← **REQUIRED**\r\n  3. Does **NOT** contain `已获取到支付凭证` ← **REQUIRED**\r\n\r\n* **Trigger (fallback from Step 2.1 Case A):** The calling skill reported `PAY_STATUS: FAIL` after credential decryption, and the preserved original output contains `授权链接: <AUTH_URL>`.\r\n\r\n* **Meaning:** The user has not yet been authorized. The payment cannot proceed until the user completes authorization via the provided link.\r\n* **Action:**\r\n  1. Provide the extracted `<AUTH_URL>` to the user as the official **authorization** link. Additionally, if the output (or preserved output) contains `返回消息: <MESSAGE>`, display the `<MESSAGE>` to the user as supplementary context.\r\n  2. Extract `{clawtip_id}` from the authorization URL (the `clawtipId` query parameter, e.g., `...?clawtipId={clawtip_id}`).\r\n  3. Create a `scheduled task` to query the user's registration status:\r\n      * **Query Phrase:** Use a phrase like `查询token注册状态 {clawtip_id}` or `query token register status {clawtip_id}`.\r\n      * **Frequency & Duration:** Execute once per minute for the next 5 executions (after complete, you should notice user in the main session).\r\n      * **Crucial Note:** **Check the registration status, NOT the payment result.**\r\n      * **Execution Limit:** If it exceeds 5 times, cancel the scheduled task (`clawtip-payment user token register status {clawtip_id}`).\r\n      * **Conflict Handling:** Cancel any currently running scheduled tasks related to `查询token注册状态` before starting the new one.\r\n      * **Task Name:** `clawtip-payment user token register status {clawtip_id}`。当用户需要授权，并创建了授权任务后，需要显示提示用户可以说当用户扫码完成授权后，可以说`我已授权`或`我已完成授权`以继续之前的流程\r\n\r\n#### **Case B: 处理中 + 鉴权链接 → 待鉴权 (Authentication Required)**\r\n\r\n* **Trigger (direct):** The output contains **ALL** of the following:\r\n  1. `支付状态: 处理中` ← **REQUIRED** (exact match)\r\n  2. `鉴权链接: <AUTH_URL>` ← **REQUIRED**\r\n  3. Does **NOT** contain `已获取到支付凭证` ← **REQUIRED**\r\n\r\n* **Trigger (fallback from Step 2.1 Case B):** The calling skill reported `PAY_STATUS: FAIL` after credential decryption, and the preserved original output contains `鉴权链接: <AUTH_URL>`.\r\n\r\n* **Meaning:** The payment is pending authentication. The user must complete authentication before the transaction can proceed.\r\n* **Action:** Provide the extracted `<AUTH_URL>` to the user as the official **authentication** link. Additionally, if the output (or preserved output) contains `返回消息: <MESSAGE>`, display the `<MESSAGE>` to the user as supplementary context.\r\n\r\n> **Stop here if Step 3 matched; do not proceed to Step 4.**\r\n\r\n---\r\n\r\n### **Step 4 — Route by Decrypted Status**\r\n\r\nAfter the calling skill decrypts the credential and reports the status, follow the corresponding case:\r\n\r\n#### **Case A: 成功 (Transaction Success)**\r\n\r\n* **Trigger:** The decrypted status is **成功**.\r\n* **Action:**\r\n  1. Confirm to the user that the payment has been processed successfully.\r\n  2. Display the full decrypted payment info clearly:\r\n     **Payment Success Info:** `<DECRYPTED_PAY_INFO>`\r\n\r\n---\r\n\r\n#### **Case B: 处理中 (Processing)**\r\n\r\n* **Trigger:** The decrypted status is **处理中**.\r\n* **Action:** Inform the user that the payment is still being processed. Suggest they wait a moment and then check the payment status again.\r\n\r\n---\r\n\r\n#### **Case C: 失败 (Failed)**\r\n\r\n* **Trigger:** The decrypted status is **失败** (or `FAIL`).\r\n* **Action:** **Go to Step 2.1 (Credential Decryption Fallback)** to determine whether a recovery path (authorization/authentication) is available from the preserved original output. Do **NOT** simply report the failure here — always check Step 2.1 first.\r\n\r\n---\r\n\r\n# Create User Payment Token\r\n\r\nWhen the user explicitly requests to create a token with a phrase like `创建token xxx` or `create token xxx`, execute the following command.\r\n\r\n## 1. Required Parameters\r\n\r\nProvide the following parameters strictly according to their defined formats:\r\n\r\n* **`user_token`** (string): the user's token provided by `xxx` of `创建token xxx`.\r\n\r\n## 2. Execution Command\r\n\r\n```bash\r\npython3 scripts/create_token.py <user_token>\r\n```\r\n\r\n## 3. Other Actions\r\n\r\nYou should check and cancel the running scheduled task about `查询token注册状态` if it is running (named `clawtip-payment user token register status ${device_id}`). The `device_id` is a flexible value.\r\n\r\n---\r\n\r\n# Query the User Register Status\r\n\r\nWhen the user explicitly requests to query the user register status with a phrase like `查询token注册状态 xxx` or `query token register status xxx`, or `我已注册`, execute the following command.\r\n\r\n## 1. Required Parameters\r\n\r\nProvide the following parameter:\r\n\r\n* **`device_id`** (string): The user's device ID.\r\n\r\n## 2. Execution Command\r\n\r\n```bash\r\npython3 scripts/check_register_status.py <device_id>\r\n```\r\n\r\n## 3. Result Processing Rules\r\n\r\nAnalyze the standard output of the execution command and strictly follow these response protocols:\r\n\r\n### **Case A: Processing**\r\n\r\n* **Trigger:** The output matches the pattern `Status: processing`.\r\n* **Action:** Inform the user that the registration is still processing, and optionally tell them the current count.\r\n\r\n### **Case B: Successful**\r\n\r\n* **Trigger:** The output matches the pattern `Status: successful`.\r\n* **Action:** Confirm to the user that the registration is successful, and they have obtained the user token. You should check and cancel the running scheduled task about `查询token注册状态` if it is running (named `clawtip-payment user token register status ${device_id}`). The `device_id` is a flexible value.\r\n\r\n### **Case C: Execution Failure**\r\n\r\n* **Trigger:** Any error message, timeout, or failure to match the patterns above.\r\n* **Action:** Report the specific error returned by the script.\r\n\r\n---\r\n\r\n# View Clawtip Wallet\r\n\r\nWhen the user requests to view their clawtip wallet with phrases like `查看我的clawtip钱包`, `查看钱包`, `打开clawtip钱包`, `查看clawtip钱包`, `clawtip钱包管理` or `view my clawtip wallet`, respond with the following:\r\n\r\n> 您可以通过以下链接，扫描二维码查看您的 clawtip 钱包：\r\n>\r\n> 👉 [查看 Clawtip 钱包](https://clawtip.jd.com/qrcode?bizUrl=https://jpay.jd.com/ecnya2a/claw/index)\r\n>\r\n> 请在浏览器中打开此链接然后扫描二维码以查看您的钱包详情。\n\nFile v1.0.8:_meta.json\n\n{\n  \"ownerId\": \"kn77kz6nncvzqb057s5xezndsd83x9wk\",\n  \"slug\": \"clawtip\",\n  \"version\": \"1.0.8\",\n  \"publishedAt\": 1776064884850\n}\n\nFile v1.0.8:IMPORTANT_STATEMENTS.md\n\n# System Architecture & Security Disclosures\n\nTo clarify the scope of the scripts and justify the requested permissions (`credential.read`, `credential.write`, `network.outbound`), the following underlying operations are declared:\n\n1. **Local State Persistence (Credentials):** The `credential.read` and `credential.write` permissions are granted solely to read and write the `u` field inside the local file `configs/config.json`. No environment variables, system keychain entries, or any other credential stores are accessed.\n\n   **Why persist the token?** The `u` (user token) is obtained through a multi-step authorization flow (QR code scan → registration polling → token issuance). Persisting it locally avoids requiring the user to re-authorize on every single payment request, which would be impractical. The token is written once during authorization and read on subsequent payment calls.\n\n   > ⚠️ **Security Advisory — Credential Hardening:**\n   >\n   > The `u` is stored in local. Operators deploying this skill in security-sensitive environments **must** apply the following protections:\n   >\n   > 1. **File permissions:** `chmod 600 configs/config.json` — restrict to owner-only read/write.\n   > 2. **Directory permissions:** `chmod 700 configs/` — prevent directory listing by other users.\n   > 3. **Disk encryption:** On shared or multi-tenant hosts, enable full-disk encryption (e.g., FileVault on macOS, LUKS on Linux).\n   >\n   > The skill does **not** use OS keychains, environment variables, or any other credential stores — `configs/config.json` is the sole persistence point.\n\n2. **External Network Calls:** The scripts actively call out to external JD endpoints (e.g., `ms.jr.jd.com`) over the network to process transactions, fetch authorization/authentication links, and verify token registration status. This justifies the `network.outbound` permission. No other external domains are contacted.\n\n3. **Bundled Encryption Tooling:** To securely handle payment payloads and credentials, the Python scripts locally invoke a bundled Node.js encryption tool (`scripts/encrypt.js` + `scripts/summer-cryptico-2.0.2.min.js`). **Node.js (`node`) is a required runtime dependency** — it must be present on the host system before the skill is deployed. This requirement is declared in both the `required_binaries` field of the registry metadata above and in this section.\n\n4. **Invocation Policy & Trigger Safeguards:** This skill allows autonomous model invocation (`disable_model_invocation: false`) because it is designed to be called by other skills during payment workflows. To mitigate the risk of mis-triggered payment flows, the following safeguards are enforced:\n   - The skill **must only** be triggered when: (a) a third-party skill explicitly initiates a clawtip payment request with valid parameters, (b) the user explicitly requests token creation, (c) the user explicitly requests to view their wallet, or (d) the user explicitly requests a registration status query.\n   - The skill **must never** be triggered speculatively, predictively, or based on ambient context without an explicit user or skill request.\n   - All payment operations require valid `payTo`, `amount`, and other mandatory parameters — the script will exit with an error if parameters are missing or malformed.\n∂\n\nArchive v1.0.7: 10 files, 38215 bytes\n\nFiles: IMPORTANT_STATEMENTS.md (3329b), scripts/check_register_status.py (4377b), scripts/create_token.py (1868b), scripts/encrypt.js (708b), scripts/file_utils.py (1465b), scripts/payment_process.py (8632b), scripts/payment_request.py (4612b), scripts/summer-cryptico-2.0.2.min.js (91473b), SKILL.md (16568b), _meta.json (126b)\n\nFile v1.0.7:SKILL.md\n\n---\r\nname: \"clawtip\"\r\ndescription: >\r\n  Executes a clawtip payment transaction for third-party skills.\r\n  Trigger this tool strictly when a third-party service initiates a valid clawtip payment request, when the user explicitly requests creation of a clawtip payment user token, or when the user asks to view their clawtip wallet (DO NOT TRIGGER WITHOUT A VALID CONDITION).\r\n  When the user requests to view their clawtip wallet (e.g., \"查看我的clawtip钱包\", \"查看钱包\", \"打开clawtip钱包\"), provide the wallet link:https://clawtip.jd.com/qrcode?bizUrl=https://jpay.jd.com/ecnya2a/claw/index\r\n  Runtime dependency: Node.js (`node`) must be installed on the host system prior to deployment — it is required by the bundled JS encryption tooling.\r\n  Security notice: the `u` is persisted as plaintext JSON in `configs/config.json`; restrict OS-level file permissions in security-sensitive environments.\r\nmetadata:\r\n    author: \"payment-infra-rd\"\r\n    category: \"payment_utilities\"\r\n    capabilities:\r\n        - \"payment.process\"\r\n    permissions:\r\n        - \"network.outbound\"\r\n        - \"credential.read\"\r\n        - \"credential.write\"\r\n    required_binaries:\r\n        - \"node\"\r\n    required_env: []\r\n    credential_storage:\r\n        type: \"local_file\"\r\n        path: \"configs/config.json\"\r\n        format: \"plaintext_json\"\r\n        fields: [\"u\"]\r\n    invocation_policy:\r\n        disable_model_invocation: false\r\n        allowed_triggers:\r\n            - \"third_party_skill_payment_request\"\r\n            - \"user_explicit_token_creation\"\r\n            - \"user_explicit_wallet_view\"\r\n            - \"user_explicit_register_status_query\"\r\n        prohibited_triggers:\r\n            - \"speculative_or_predictive_invocation\"\r\n            - \"ambient_context_without_explicit_request\"\r\n---\r\n\r\n\r\n# Process the Payment Request\r\n\r\n## 1. Required Parameters\r\n\r\nProvide the following parameters strictly according to their defined formats:\r\n\r\n* **`order_no`** (string, **required**): The order number from the calling skill's Phase 1 (order creation).\r\n* **`indicator`** (string, **required**): The indicator value from the calling skill's Phase 1, typically an MD5 hash of the skill name.\r\n\r\n> [!NOTE]\r\n> The script will automatically locate the order JSON file from the fixed directory based on `order_no` and `indicator`:\r\n> - Linux/macOS: `/root/openclaw/skills/orders/{indicator}/{order_no}.json`\r\n> - Windows: `C:\\openclaw\\skills\\orders\\{indicator}\\{order_no}.json`\r\n>\r\n> This JSON file is written by the calling skill's order creation phase and contains all payment-related fields (`payTo`, `encrypted_data`, `amount`, `order_no`, `question`, `description`, `skill_name`, `resource_url`, etc.).\r\n>\r\n> **You (the LLM) MUST NOT open, read, parse, or extract any values from this file.** The script handles all file reading internally. Your only responsibility is to pass `order_no` and `indicator` as command-line arguments.\r\n\r\n## 2. Hyperparameters\r\n\r\n* **`skill-version`** (string): The version of the skill. Currently set to `1.0.1`.\r\n\r\n## 3. Execution Command\r\n\r\nExecute the script using the following bash command. Replace the placeholders `<...>` with the validated parameter values. Wrap parameters that may contain spaces in quotes.\r\n\r\n```bash\r\npython3 scripts/payment_process.py <order_no> <indicator> <skill-version>\r\n```\r\n\r\n## 4. Result Processing Rules\r\n\r\nAnalyze the standard output of the execution command and strictly follow these response protocols **in the given order**. **Stop at the first matching step; do not continue to subsequent steps.**\r\n\r\n### ⚡ Global Priority Rule\r\n\r\n> If the output contains `已获取到支付凭证`, **go to Step 2 (Obtain Credential) first** to return the order number to the calling skill. The credential has already been saved to the order file by the script, and the calling skill will read it from there for decryption.\r\n>\r\n> **However**, if the output **also** contains `授权链接: <AUTH_URL>` or `鉴权链接: <AUTH_URL>`, you **MUST preserve** the full original output (including the authorization/authentication URL) in memory. This is because the credential may decrypt to a **failed** status, in which case you will need to **fall back to Step 3** using the preserved authorization/authentication URL.\r\n>\r\n> **In summary:**\r\n> 1. If `已获取到支付凭证` is present → go to **Step 2** first.\r\n> 2. After the calling skill decrypts the credential and reports the status:\r\n>    - If the decrypted status is **成功** → go to **Step 4 Case A**. Done.\r\n>    - If the decrypted status is **处理中** → go to **Step 4 Case B**. Done.\r\n>    - If the decrypted status is **失败 (FAIL)** → go to **Step 2.1 (Credential Decryption Fallback)** to check whether a preserved `授权链接:` or `鉴权链接:` exists, and if so, fall back to **Step 3**.\r\n> 3. If `已获取到支付凭证` is **NOT** present → evaluate **Step 1**, then **Step 3** in order.\r\n\r\n---\r\n\r\n### **Step 1 — Network/System Failure (check first)**\r\n\r\n* **Trigger:** The output contains `网络或系统异常:`.\r\n* **Action:** Report the specific error returned by the script. Additionally, if the output contains `返回消息: <MESSAGE>`, display the `<MESSAGE>` to the user as supplementary error context. Advise the user on the next steps. **Stop here; do not proceed to Step 2.**\r\n\r\n---\r\n\r\n### **Step 2 — Obtain Credential**\r\n\r\n* **Trigger:** The output contains `已获取到支付凭证` and `订单号: <ORDER_NO>`.\r\n* **Meaning:** The HTTP request reached the server successfully. The credential (an encrypted blob containing the actual payment status) has been saved to the order file by the script. The calling skill will read it from there for decryption.\r\n* **Action:**\r\n  1. **Preserve the full original script output** in memory (including any `授权链接:` or `鉴权链接:` if present, and any `返回消息:` if present). You may need it later in Step 2.1.\r\n  2. Return the order number to the calling skill for further processing:\r\n     > **订单号：** `<ORDER_NO>`\r\n     \r\n     将此订单号返回给调用方 skill，由调用方根据订单号从订单文件中读取支付凭证并解密，再根据其中的支付状态进行后续处理。\r\n\r\n* **After returning the order number:** Wait for the calling skill to report the decrypted `PAY_STATUS`. Then proceed to **Step 4** to route by decrypted status. If the status is **失败 (FAIL)**, Step 4 Case C will direct you to **Step 2.1**.\r\n\r\n---\r\n\r\n### **Step 2.1 — Credential Decryption Fallback (回退处理)**\r\n\r\n> This step is triggered **only** when the calling skill decrypts the credential and the resulting status is **失败 (FAIL)**.\r\n\r\n* **Trigger:** The calling skill reports `PAY_STATUS: FAIL` (or equivalent 失败 status) after decrypting the credential from Step 2.\r\n* **Action:** Check the **preserved original script output** from Step 2 for the presence of authorization/authentication URLs:\r\n\r\n  #### **Case A: Preserved output contains `授权链接: <AUTH_URL>`**\r\n  \r\n  * **Meaning:** The user has not yet been authorized. The credential contained a failure status because the payment could not proceed without authorization. The `授权链接` was present in the original output but was deferred in favor of credential processing.\r\n  * **Action:** Fall back to **Step 3 Case A** — treat this as an authorization-required scenario. Execute all actions defined in Step 3 Case A using the preserved `<AUTH_URL>`.\r\n\r\n  #### **Case B: Preserved output contains `鉴权链接: <AUTH_URL>`**\r\n  \r\n  * **Meaning:** The payment failed because authentication was not completed. The `鉴权链接` was present in the original output but was deferred.\r\n  * **Action:** Fall back to **Step 3 Case B** — treat this as an authentication-required scenario. Execute all actions defined in Step 3 Case B using the preserved `<AUTH_URL>`.\r\n\r\n  #### **Case C: Preserved output contains NEITHER `授权链接:` NOR `鉴权链接:`**\r\n  \r\n  * **Meaning:** The payment genuinely failed due to business logic, and there is no authorization/authentication recovery path.\r\n  * **Action:** Report the failure to the user. Emphasize that the transaction was declined due to business logic. Report any error code and reason provided by the calling skill. Additionally, if the **preserved original script output** contains `返回消息: <MESSAGE>`, display the `<MESSAGE>` to the user as supplementary failure context. If no specific error details were provided, inform the user that the payment failed and suggest they contact support or retry later.\r\n\r\n---\r\n\r\n### **Step 3 — Authorization / Authentication Required**\r\n\r\n> ⚠️ **PREREQUISITE CHECK:** This step is evaluated in two scenarios:\r\n> 1. The original script output does **NOT** contain `已获取到支付凭证` at all.\r\n> 2. You were directed here from **Step 2.1** after a credential decryption failure with a preserved authorization/authentication URL.\r\n\r\n> ⚠️ **LINK VERIFICATION (MANDATORY):** Before presenting any `授权链接` or `鉴权链接` to the user, you **MUST** verify the extracted URL for accuracy:\r\n> 1. Confirm the URL is a **complete, well-formed URL** (starts with `http://` or `https://`, no truncation, no extra whitespace or line breaks).\r\n> 2. Ensure the URL is **exactly as output by the script** — do NOT modify, truncate, or re-encode any part of it.\r\n> 3. If the URL contains query parameters (e.g., `clawtipId`), verify they are intact and not corrupted.\r\n> 4. **Do NOT hallucinate or fabricate a URL.** Only use the URL that appears after `授权链接:` or `鉴权链接:` in the script output.\r\n> 5. If the URL appears malformed or incomplete, report the issue to the user instead of presenting a broken link.\r\n\r\n#### **Case A: 失败 + 授权链接 → 待授权 (Authorization Required)**\r\n\r\n* **Trigger (direct):** The output contains **ALL** of the following:\r\n  1. `支付状态: 失败` ← **REQUIRED** (exact match)\r\n  2. `授权链接: <AUTH_URL>` ← **REQUIRED**\r\n  3. Does **NOT** contain `已获取到支付凭证` ← **REQUIRED**\r\n\r\n* **Trigger (fallback from Step 2.1 Case A):** The calling skill reported `PAY_STATUS: FAIL` after credential decryption, and the preserved original output contains `授权链接: <AUTH_URL>`.\r\n\r\n* **Meaning:** The user has not yet been authorized. The payment cannot proceed until the user completes authorization via the provided link.\r\n* **Action:**\r\n  1. Provide the extracted `<AUTH_URL>` to the user as the official **authorization** link. Additionally, if the output (or preserved output) contains `返回消息: <MESSAGE>`, display the `<MESSAGE>` to the user as supplementary context.\r\n  2. Extract `{clawtip_id}` from the authorization URL (the `clawtipId` query parameter, e.g., `...?clawtipId={clawtip_id}`).\r\n  3. Create a `scheduled task` to query the user's registration status:\r\n      * **Query Phrase:** Use a phrase like `查询token注册状态 {clawtip_id}` or `query token register status {clawtip_id}`.\r\n      * **Frequency & Duration:** Execute once per minute for the next 5 executions (after complete, you should notice user in the main session).\r\n      * **Crucial Note:** **Check the registration status, NOT the payment result.**\r\n      * **Execution Limit:** If it exceeds 5 times, cancel the scheduled task (`clawtip-payment user token register status {clawtip_id}`).\r\n      * **Conflict Handling:** Cancel any currently running scheduled tasks related to `查询token注册状态` before starting the new one.\r\n      * **Task Name:** `clawtip-payment user token register status {clawtip_id}`。当用户需要授权，并创建了授权任务后，需要显示提示用户可以说当用户扫码完成授权后，可以说`我已授权`或`我已完成授权`以继续之前的流程\r\n\r\n#### **Case B: 处理中 + 鉴权链接 → 待鉴权 (Authentication Required)**\r\n\r\n* **Trigger (direct):** The output contains **ALL** of the following:\r\n  1. `支付状态: 处理中` ← **REQUIRED** (exact match)\r\n  2. `鉴权链接: <AUTH_URL>` ← **REQUIRED**\r\n  3. Does **NOT** contain `已获取到支付凭证` ← **REQUIRED**\r\n\r\n* **Trigger (fallback from Step 2.1 Case B):** The calling skill reported `PAY_STATUS: FAIL` after credential decryption, and the preserved original output contains `鉴权链接: <AUTH_URL>`.\r\n\r\n* **Meaning:** The payment is pending authentication. The user must complete authentication before the transaction can proceed.\r\n* **Action:** Provide the extracted `<AUTH_URL>` to the user as the official **authentication** link. Additionally, if the output (or preserved output) contains `返回消息: <MESSAGE>`, display the `<MESSAGE>` to the user as supplementary context.\r\n\r\n> **Stop here if Step 3 matched; do not proceed to Step 4.**\r\n\r\n---\r\n\r\n### **Step 4 — Route by Decrypted Status**\r\n\r\nAfter the calling skill decrypts the credential and reports the status, follow the corresponding case:\r\n\r\n#### **Case A: 成功 (Transaction Success)**\r\n\r\n* **Trigger:** The decrypted status is **成功**.\r\n* **Action:**\r\n  1. Confirm to the user that the payment has been processed successfully.\r\n  2. Display the full decrypted payment info clearly:\r\n     **Payment Success Info:** `<DECRYPTED_PAY_INFO>`\r\n\r\n---\r\n\r\n#### **Case B: 处理中 (Processing)**\r\n\r\n* **Trigger:** The decrypted status is **处理中**.\r\n* **Action:** Inform the user that the payment is still being processed. Suggest they wait a moment and then check the payment status again.\r\n\r\n---\r\n\r\n#### **Case C: 失败 (Failed)**\r\n\r\n* **Trigger:** The decrypted status is **失败** (or `FAIL`).\r\n* **Action:** **Go to Step 2.1 (Credential Decryption Fallback)** to determine whether a recovery path (authorization/authentication) is available from the preserved original output. Do **NOT** simply report the failure here — always check Step 2.1 first.\r\n\r\n---\r\n\r\n# Create User Payment Token\r\n\r\nWhen the user explicitly requests to create a token with a phrase like `创建token xxx` or `create token xxx`, execute the following command.\r\n\r\n## 1. Required Parameters\r\n\r\nProvide the following parameters strictly according to their defined formats:\r\n\r\n* **`user_token`** (string): the user's token provided by `xxx` of `创建token xxx`.\r\n\r\n## 2. Execution Command\r\n\r\n```bash\r\npython3 scripts/create_token.py <user_token>\r\n```\r\n\r\n## 3. Other Actions\r\n\r\nYou should check and cancel the running scheduled task about `查询token注册状态` if it is running (named `clawtip-payment user token register status ${device_id}`). The `device_id` is a flexible value.\r\n\r\n---\r\n\r\n# Query the User Register Status\r\n\r\nWhen the user explicitly requests to query the user register status with a phrase like `查询token注册状态 xxx` or `query token register status xxx`, or `我已注册`, execute the following command.\r\n\r\n## 1. Required Parameters\r\n\r\nProvide the following parameter:\r\n\r\n* **`device_id`** (string): The user's device ID.\r\n\r\n## 2. Execution Command\r\n\r\n```bash\r\npython3 scripts/check_register_status.py <device_id>\r\n```\r\n\r\n## 3. Result Processing Rules\r\n\r\nAnalyze the standard output of the execution command and strictly follow these response protocols:\r\n\r\n### **Case A: Processing**\r\n\r\n* **Trigger:** The output matches the pattern `Status: processing`.\r\n* **Action:** Inform the user that the registration is still processing, and optionally tell them the current count.\r\n\r\n### **Case B: Successful**\r\n\r\n* **Trigger:** The output matches the pattern `Status: successful`.\r\n* **Action:** Confirm to the user that the registration is successful, and they have obtained the user token. You should check and cancel the running scheduled task about `查询token注册状态` if it is running (named `clawtip-payment user token register status ${device_id}`). The `device_id` is a flexible value.\r\n\r\n### **Case C: Execution Failure**\r\n\r\n* **Trigger:** Any error message, timeout, or failure to match the patterns above.\r\n* **Action:** Report the specific error returned by the script.\r\n\r\n---\r\n\r\n# View Clawtip Wallet\r\n\r\nWhen the user requests to view their clawtip wallet with phrases like `查看我的clawtip钱包`, `查看钱包`, `打开clawtip钱包`, `查看clawtip钱包`, `clawtip钱包管理` or `view my clawtip wallet`, respond with the following:\r\n\r\n> 您可以通过以下链接，扫描二维码查看您的 clawtip 钱包：\r\n>\r\n> 👉 [查看 Clawtip 钱包](https://clawtip.jd.com/qrcode?bizUrl=https://jpay.jd.com/ecnya2a/claw/index)\r\n>\r\n> 请在浏览器中打开此链接然后扫描二维码以查看您的钱包详情。\n\nFile v1.0.7:_meta.json\n\n{\n  \"ownerId\": \"kn77kz6nncvzqb057s5xezndsd83x9wk\",\n  \"slug\": \"clawtip\",\n  \"version\": \"1.0.7\",\n  \"publishedAt\": 1776061015740\n}\n\nFile v1.0.7:IMPORTANT_STATEMENTS.md\n\n# System Architecture & Security Disclosures\n\nTo clarify the scope of the scripts and justify the requested permissions (`credential.read`, `credential.write`, `network.outbound`), the following underlying operations are declared:\n\n1. **Local State Persistence (Credentials):** The `credential.read` and `credential.write` permissions are granted solely to read and write the `u` field inside the local file `configs/config.json`. No environment variables, system keychain entries, or any other credential stores are accessed.\n\n   **Why persist the token?** The `u` (user token) is obtained through a multi-step authorization flow (QR code scan → registration polling → token issuance). Persisting it locally avoids requiring the user to re-authorize on every single payment request, which would be impractical. The token is written once during authorization and read on subsequent payment calls.\n\n   > ⚠️ **Security Advisory — Credential Hardening:**\n   >\n   > The `u` is stored in local. Operators deploying this skill in security-sensitive environments **must** apply the following protections:\n   >\n   > 1. **File permissions:** `chmod 600 configs/config.json` — restrict to owner-only read/write.\n   > 2. **Directory permissions:** `chmod 700 configs/` — prevent directory listing by other users.\n   > 3. **Disk encryption:** On shared or multi-tenant hosts, enable full-disk encryption (e.g., FileVault on macOS, LUKS on Linux).\n   >\n   > The skill does **not** use OS keychains, environment variables, or any other credential stores — `configs/config.json` is the sole persistence point.\n\n2. **External Network Calls:** The scripts actively call out to external JD endpoints (e.g., `ms.jr.jd.com`) over the network to process transactions, fetch authorization/authentication links, and verify token registration status. This justifies the `network.outbound` permission. No other external domains are contacted.\n\n3. **Bundled Encryption Tooling:** To securely handle payment payloads and credentials, the Python scripts locally invoke a bundled Node.js encryption tool (`scripts/encrypt.js` + `scripts/summer-cryptico-2.0.2.min.js`). **Node.js (`node`) is a required runtime dependency** — it must be present on the host system before the skill is deployed. This requirement is declared in both the `required_binaries` field of the registry metadata above and in this section.\n\n4. **Invocation Policy & Trigger Safeguards:** This skill allows autonomous model invocation (`disable_model_invocation: false`) because it is designed to be called by other skills during payment workflows. To mitigate the risk of mis-triggered payment flows, the following safeguards are enforced:\n   - The skill **must only** be triggered when: (a) a third-party skill explicitly initiates a clawtip payment request with valid parameters, (b) the user explicitly requests token creation, (c) the user explicitly requests to view their wallet, or (d) the user explicitly requests a registration status query.\n   - The skill **must never** be triggered speculatively, predictively, or based on ambient context without an explicit user or skill request.\n   - All payment operations require valid `payTo`, `amount`, and other mandatory parameters — the script will exit with an error if parameters are missing or malformed.\n∂\n\nArchive v1.0.6: 10 files, 38218 bytes\n\nFiles: IMPORTANT_STATEMENTS.md (3329b), scripts/check_register_status.py (4383b), scripts/create_token.py (1868b), scripts/encrypt.js (708b), scripts/file_utils.py (1465b), scripts/payment_process.py (8636b), scripts/payment_request.py (4612b), scripts/summer-cryptico-2.0.2.min.js (91473b), SKILL.md (16568b), _meta.json (126b)\n\nFile v1.0.6:SKILL.md\n\n---\r\nname: \"clawtip\"\r\ndescription: >\r\n  Executes a clawtip payment transaction for third-party skills.\r\n  Trigger this tool strictly when a third-party service initiates a valid clawtip payment request, when the user explicitly requests creation of a clawtip payment user token, or when the user asks to view their clawtip wallet (DO NOT TRIGGER WITHOUT A VALID CONDITION).\r\n  When the user requests to view their clawtip wallet (e.g., \"查看我的clawtip钱包\", \"查看钱包\", \"打开clawtip钱包\"), provide the wallet link:https://clawtip.jd.com/qrcode?bizUrl=https://jpay.jd.com/ecnya2a/claw/index\r\n  Runtime dependency: Node.js (`node`) must be installed on the host system prior to deployment — it is required by the bundled JS encryption tooling.\r\n  Security notice: the `u` is persisted as plaintext JSON in `configs/config.json`; restrict OS-level file permissions in security-sensitive environments.\r\nmetadata:\r\n    author: \"payment-infra-rd\"\r\n    category: \"payment_utilities\"\r\n    capabilities:\r\n        - \"payment.process\"\r\n    permissions:\r\n        - \"network.outbound\"\r\n        - \"credential.read\"\r\n        - \"credential.write\"\r\n    required_binaries:\r\n        - \"node\"\r\n    required_env: []\r\n    credential_storage:\r\n        type: \"local_file\"\r\n        path: \"configs/config.json\"\r\n        format: \"plaintext_json\"\r\n        fields: [\"u\"]\r\n    invocation_policy:\r\n        disable_model_invocation: false\r\n        allowed_triggers:\r\n            - \"third_party_skill_payment_request\"\r\n            - \"user_explicit_token_creation\"\r\n            - \"user_explicit_wallet_view\"\r\n            - \"user_explicit_register_status_query\"\r\n        prohibited_triggers:\r\n            - \"speculative_or_predictive_invocation\"\r\n            - \"ambient_context_without_explicit_request\"\r\n---\r\n\r\n\r\n# Process the Payment Request\r\n\r\n## 1. Required Parameters\r\n\r\nProvide the following parameters strictly according to their defined formats:\r\n\r\n* **`order_no`** (string, **required**): The order number from the calling skill's Phase 1 (order creation).\r\n* **`indicator`** (string, **required**): The indicator value from the calling skill's Phase 1, typically an MD5 hash of the skill name.\r\n\r\n> [!NOTE]\r\n> The script will automatically locate the order JSON file from the fixed directory based on `order_no` and `indicator`:\r\n> - Linux/macOS: `/root/openclaw/skills/orders/{indicator}/{order_no}.json`\r\n> - Windows: `C:\\openclaw\\skills\\orders\\{indicator}\\{order_no}.json`\r\n>\r\n> This JSON file is written by the calling skill's order creation phase and contains all payment-related fields (`payTo`, `encrypted_data`, `amount`, `order_no`, `question`, `description`, `skill_name`, `resource_url`, etc.).\r\n>\r\n> **You (the LLM) MUST NOT open, read, parse, or extract any values from this file.** The script handles all file reading internally. Your only responsibility is to pass `order_no` and `indicator` as command-line arguments.\r\n\r\n## 2. Hyperparameters\r\n\r\n* **`skill-version`** (string): The version of the skill. Currently set to `1.0.1`.\r\n\r\n## 3. Execution Command\r\n\r\nExecute the script using the following bash command. Replace the placeholders `<...>` with the validated parameter values. Wrap parameters that may contain spaces in quotes.\r\n\r\n```bash\r\npython3 scripts/payment_process.py <order_no> <indicator> <skill-version>\r\n```\r\n\r\n## 4. Result Processing Rules\r\n\r\nAnalyze the standard output of the execution command and strictly follow these response protocols **in the given order**. **Stop at the first matching step; do not continue to subsequent steps.**\r\n\r\n### ⚡ Global Priority Rule\r\n\r\n> If the output contains `已获取到支付凭证`, **go to Step 2 (Obtain Credential) first** to return the order number to the calling skill. The credential has already been saved to the order file by the script, and the calling skill will read it from there for decryption.\r\n>\r\n> **However**, if the output **also** contains `授权链接: <AUTH_URL>` or `鉴权链接: <AUTH_URL>`, you **MUST preserve** the full original output (including the authorization/authentication URL) in memory. This is because the credential may decrypt to a **failed** status, in which case you will need to **fall back to Step 3** using the preserved authorization/authentication URL.\r\n>\r\n> **In summary:**\r\n> 1. If `已获取到支付凭证` is present → go to **Step 2** first.\r\n> 2. After the calling skill decrypts the credential and reports the status:\r\n>    - If the decrypted status is **成功** → go to **Step 4 Case A**. Done.\r\n>    - If the decrypted status is **处理中** → go to **Step 4 Case B**. Done.\r\n>    - If the decrypted status is **失败 (FAIL)** → go to **Step 2.1 (Credential Decryption Fallback)** to check whether a preserved `授权链接:` or `鉴权链接:` exists, and if so, fall back to **Step 3**.\r\n> 3. If `已获取到支付凭证` is **NOT** present → evaluate **Step 1**, then **Step 3** in order.\r\n\r\n---\r\n\r\n### **Step 1 — Network/System Failure (check first)**\r\n\r\n* **Trigger:** The output contains `网络或系统异常:`.\r\n* **Action:** Report the specific error returned by the script. Additionally, if the output contains `返回消息: <MESSAGE>`, display the `<MESSAGE>` to the user as supplementary error context. Advise the user on the next steps. **Stop here; do not proceed to Step 2.**\r\n\r\n---\r\n\r\n### **Step 2 — Obtain Credential**\r\n\r\n* **Trigger:** The output contains `已获取到支付凭证` and `订单号: <ORDER_NO>`.\r\n* **Meaning:** The HTTP request reached the server successfully. The credential (an encrypted blob containing the actual payment status) has been saved to the order file by the script. The calling skill will read it from there for decryption.\r\n* **Action:**\r\n  1. **Preserve the full original script output** in memory (including any `授权链接:` or `鉴权链接:` if present, and any `返回消息:` if present). You may need it later in Step 2.1.\r\n  2. Return the order number to the calling skill for further processing:\r\n     > **订单号：** `<ORDER_NO>`\r\n     \r\n     将此订单号返回给调用方 skill，由调用方根据订单号从订单文件中读取支付凭证并解密，再根据其中的支付状态进行后续处理。\r\n\r\n* **After returning the order number:** Wait for the calling skill to report the decrypted `PAY_STATUS`. Then proceed to **Step 4** to route by decrypted status. If the status is **失败 (FAIL)**, Step 4 Case C will direct you to **Step 2.1**.\r\n\r\n---\r\n\r\n### **Step 2.1 — Credential Decryption Fallback (回退处理)**\r\n\r\n> This step is triggered **only** when the calling skill decrypts the credential and the resulting status is **失败 (FAIL)**.\r\n\r\n* **Trigger:** The calling skill reports `PAY_STATUS: FAIL` (or equivalent 失败 status) after decrypting the credential from Step 2.\r\n* **Action:** Check the **preserved original script output** from Step 2 for the presence of authorization/authentication URLs:\r\n\r\n  #### **Case A: Preserved output contains `授权链接: <AUTH_URL>`**\r\n  \r\n  * **Meaning:** The user has not yet been authorized. The credential contained a failure status because the payment could not proceed without authorization. The `授权链接` was present in the original output but was deferred in favor of credential processing.\r\n  * **Action:** Fall back to **Step 3 Case A** — treat this as an authorization-required scenario. Execute all actions defined in Step 3 Case A using the preserved `<AUTH_URL>`.\r\n\r\n  #### **Case B: Preserved output contains `鉴权链接: <AUTH_URL>`**\r\n  \r\n  * **Meaning:** The payment failed because authentication was not completed. The `鉴权链接` was present in the original output but was deferred.\r\n  * **Action:** Fall back to **Step 3 Case B** — treat this as an authentication-required scenario. Execute all actions defined in Step 3 Case B using the preserved `<AUTH_URL>`.\r\n\r\n  #### **Case C: Preserved output contains NEITHER `授权链接:` NOR `鉴权链接:`**\r\n  \r\n  * **Meaning:** The payment genuinely failed due to business logic, and there is no authorization/authentication recovery path.\r\n  * **Action:** Report the failure to the user. Emphasize that the transaction was declined due to business logic. Report any error code and reason provided by the calling skill. Additionally, if the **preserved original script output** contains `返回消息: <MESSAGE>`, display the `<MESSAGE>` to the user as supplementary failure context. If no specific error details were provided, inform the user that the payment failed and suggest they contact support or retry later.\r\n\r\n---\r\n\r\n### **Step 3 — Authorization / Authentication Required**\r\n\r\n> ⚠️ **PREREQUISITE CHECK:** This step is evaluated in two scenarios:\r\n> 1. The original script output does **NOT** contain `已获取到支付凭证` at all.\r\n> 2. You were directed here from **Step 2.1** after a credential decryption failure with a preserved authorization/authentication URL.\r\n\r\n> ⚠️ **LINK VERIFICATION (MANDATORY):** Before presenting any `授权链接` or `鉴权链接` to the user, you **MUST** verify the extracted URL for accuracy:\r\n> 1. Confirm the URL is a **complete, well-formed URL** (starts with `http://` or `https://`, no truncation, no extra whitespace or line breaks).\r\n> 2. Ensure the URL is **exactly as output by the script** — do NOT modify, truncate, or re-encode any part of it.\r\n> 3. If the URL contains query parameters (e.g., `clawtipId`), verify they are intact and not corrupted.\r\n> 4. **Do NOT hallucinate or fabricate a URL.** Only use the URL that appears after `授权链接:` or `鉴权链接:` in the script output.\r\n> 5. If the URL appears malformed or incomplete, report the issue to the user instead of presenting a broken link.\r\n\r\n#### **Case A: 失败 + 授权链接 → 待授权 (Authorization Required)**\r\n\r\n* **Trigger (direct):** The output contains **ALL** of the following:\r\n  1. `支付状态: 失败` ← **REQUIRED** (exact match)\r\n  2. `授权链接: <AUTH_URL>` ← **REQUIRED**\r\n  3. Does **NOT** contain `已获取到支付凭证` ← **REQUIRED**\r\n\r\n* **Trigger (fallback from Step 2.1 Case A):** The calling skill reported `PAY_STATUS: FAIL` after credential decryption, and the preserved original output contains `授权链接: <AUTH_URL>`.\r\n\r\n* **Meaning:** The user has not yet been authorized. The payment cannot proceed until the user completes authorization via the provided link.\r\n* **Action:**\r\n  1. Provide the extracted `<AUTH_URL>` to the user as the official **authorization** link. Additionally, if the output (or preserved output) contains `返回消息: <MESSAGE>`, display the `<MESSAGE>` to the user as supplementary context.\r\n  2. Extract `{clawtip_id}` from the authorization URL (the `clawtipId` query parameter, e.g., `...?clawtipId={clawtip_id}`).\r\n  3. Create a `scheduled task` to query the user's registration status:\r\n      * **Query Phrase:** Use a phrase like `查询token注册状态 {clawtip_id}` or `query token register status {clawtip_id}`.\r\n      * **Frequency & Duration:** Execute once per minute for the next 5 executions (after complete, you should notice user in the main session).\r\n      * **Crucial Note:** **Check the registration status, NOT the payment result.**\r\n      * **Execution Limit:** If it exceeds 5 times, cancel the scheduled task (`clawtip-payment user token register status {clawtip_id}`).\r\n      * **Conflict Handling:** Cancel any currently running scheduled tasks related to `查询token注册状态` before starting the new one.\r\n      * **Task Name:** `clawtip-payment user token register status {clawtip_id}`。当用户需要授权，并创建了授权任务后，需要显示提示用户可以说当用户扫码完成授权后，可以说`我已授权`或`我已完成授权`以继续之前的流程\r\n\r\n#### **Case B: 处理中 + 鉴权链接 → 待鉴权 (Authentication Required)**\r\n\r\n* **Trigger (direct):** The output contains **ALL** of the following:\r\n  1. `支付状态: 处理中` ← **REQUIRED** (exact match)\r\n  2. `鉴权链接: <AUTH_URL>` ← **REQUIRED**\r\n  3. Does **NOT** contain `已获取到支付凭证` ← **REQUIRED**\r\n\r\n* **Trigger (fallback from Step 2.1 Case B):** The calling skill reported `PAY_STATUS: FAIL` after credential decryption, and the preserved original output contains `鉴权链接: <AUTH_URL>`.\r\n\r\n* **Meaning:** The payment is pending authentication. The user must complete authentication before the transaction can proceed.\r\n* **Action:** Provide the extracted `<AUTH_URL>` to the user as the official **authentication** link. Additionally, if the output (or preserved output) contains `返回消息: <MESSAGE>`, display the `<MESSAGE>` to the user as supplementary context.\r\n\r\n> **Stop here if Step 3 matched; do not proceed to Step 4.**\r\n\r\n---\r\n\r\n### **Step 4 — Route by Decrypted Status**\r\n\r\nAfter the calling skill decrypts the credential and reports the status, follow the corresponding case:\r\n\r\n#### **Case A: 成功 (Transaction Success)**\r\n\r\n* **Trigger:** The decrypted status is **成功**.\r\n* **Action:**\r\n  1. Confirm to the user that the payment has been processed successfully.\r\n  2. Display the full decrypted payment info clearly:\r\n     **Payment Success Info:** `<DECRYPTED_PAY_INFO>`\r\n\r\n---\r\n\r\n#### **Case B: 处理中 (Processing)**\r\n\r\n* **Trigger:** The decrypted status is **处理中**.\r\n* **Action:** Inform the user that the payment is still being processed. Suggest they wait a moment and then check the payment status again.\r\n\r\n---\r\n\r\n#### **Case C: 失败 (Failed)**\r\n\r\n* **Trigger:** The decrypted status is **失败** (or `FAIL`).\r\n* **Action:** **Go to Step 2.1 (Credential Decryption Fallback)** to determine whether a recovery path (authorization/authentication) is available from the preserved original output. Do **NOT** simply report the failure here — always check Step 2.1 first.\r\n\r\n---\r\n\r\n# Create User Payment Token\r\n\r\nWhen the user explicitly requests to create a token with a phrase like `创建token xxx` or `create token xxx`, execute the following command.\r\n\r\n## 1. Required Parameters\r\n\r\nProvide the following parameters strictly according to their defined formats:\r\n\r\n* **`user_token`** (string): the user's token provided by `xxx` of `创建token xxx`.\r\n\r\n## 2. Execution Command\r\n\r\n```bash\r\npython3 scripts/create_token.py <user_token>\r\n```\r\n\r\n## 3. Other Actions\r\n\r\nYou should check and cancel the running scheduled task about `查询token注册状态` if it is running (named `clawtip-payment user token register status ${device_id}`). The `device_id` is a flexible value.\r\n\r\n---\r\n\r\n# Query the User Register Status\r\n\r\nWhen the user explicitly requests to query the user register status with a phrase like `查询token注册状态 xxx` or `query token register status xxx`, or `我已注册`, execute the following command.\r\n\r\n## 1. Required Parameters\r\n\r\nProvide the following parameter:\r\n\r\n* **`device_id`** (string): The user's device ID.\r\n\r\n## 2. Execution Command\r\n\r\n```bash\r\npython3 scripts/check_register_status.py <device_id>\r\n```\r\n\r\n## 3. Result Processing Rules\r\n\r\nAnalyze the standard output of the execution command and strictly follow these response protocols:\r\n\r\n### **Case A: Processing**\r\n\r\n* **Trigger:** The output matches the pattern `Status: processing`.\r\n* **Action:** Inform the user that the registration is still processing, and optionally tell them the current count.\r\n\r\n### **Case B: Successful**\r\n\r\n* **Trigger:** The output matches the pattern `Status: successful`.\r\n* **Action:** Confirm to the user that the registration is successful, and they have obtained the user token. You should check and cancel the running scheduled task about `查询token注册状态` if it is running (named `clawtip-payment user token register status ${device_id}`). The `device_id` is a flexible value.\r\n\r\n### **Case C: Execution Failure**\r\n\r\n* **Trigger:** Any error message, timeout, or failure to match the patterns above.\r\n* **Action:** Report the specific error returned by the script.\r\n\r\n---\r\n\r\n# View Clawtip Wallet\r\n\r\nWhen the user requests to view their clawtip wallet with phrases like `查看我的clawtip钱包`, `查看钱包`, `打开clawtip钱包`, `查看clawtip钱包`, `clawtip钱包管理` or `view my clawtip wallet`, respond with the following:\r\n\r\n> 您可以通过以下链接，扫描二维码查看您的 clawtip 钱包：\r\n>\r\n> 👉 [查看 Clawtip 钱包](https://clawtip.jd.com/qrcode?bizUrl=https://jpay.jd.com/ecnya2a/claw/index)\r\n>\r\n> 请在浏览器中打开此链接然后扫描二维码以查看您的钱包详情。\n\nFile v1.0.6:_meta.json\n\n{\n  \"ownerId\": \"kn77kz6nncvzqb057s5xezndsd83x9wk\",\n  \"slug\": \"clawtip\",\n  \"version\": \"1.0.6\",\n  \"publishedAt\": 1775742873217\n}\n\nFile v1.0.6:IMPORTANT_STATEMENTS.md\n\n# System Architecture & Security Disclosures\n\nTo clarify the scope of the scripts and justify the requested permissions (`credential.read`, `credential.write`, `network.outbound`), the following underlying operations are declared:\n\n1. **Local State Persistence (Credentials):** The `credential.read` and `credential.write` permissions are granted solely to read and write the `u` field inside the local file `configs/config.json`. No environment variables, system keychain entries, or any other credential stores are accessed.\n\n   **Why persist the token?** The `u` (user token) is obtained through a multi-step authorization flow (QR code scan → registration polling → token issuance). Persisting it locally avoids requiring the user to re-authorize on every single payment request, which would be impractical. The token is written once during authorization and read on subsequent payment calls.\n\n   > ⚠️ **Security Advisory — Credential Hardening:**\n   >\n   > The `u` is stored in local. Operators deploying this skill in security-sensitive environments **must** apply the following protections:\n   >\n   > 1. **File permissions:** `chmod 600 configs/config.json` — restrict to owner-only read/write.\n   > 2. **Directory permissions:** `chmod 700 configs/` — prevent directory listing by other users.\n   > 3. **Disk encryption:** On shared or multi-tenant hosts, enable full-disk encryption (e.g., FileVault on macOS, LUKS on Linux).\n   >\n   > The skill does **not** use OS keychains, environment variables, or any other credential stores — `configs/config.json` is the sole persistence point.\n\n2. **External Network Calls:** The scripts actively call out to external JD endpoints (e.g., `ms.jr.jd.com`) over the network to process transactions, fetch authorization/authentication links, and verify token registration status. This justifies the `network.outbound` permission. No other external domains are contacted.\n\n3. **Bundled Encryption Tooling:** To securely handle payment payloads and credentials, the Python scripts locally invoke a bundled Node.js encryption tool (`scripts/encrypt.js` + `scripts/summer-cryptico-2.0.2.min.js`). **Node.js (`node`) is a required runtime dependency** — it must be present on the host system before the skill is deployed. This requirement is declared in both the `required_binaries` field of the registry metadata above and in this section.\n\n4. **Invocation Policy & Trigger Safeguards:** This skill allows autonomous model invocation (`disable_model_invocation: false`) because it is designed to be called by other skills during payment workflows. To mitigate the risk of mis-triggered payment flows, the following safeguards are enforced:\n   - The skill **must only** be triggered when: (a) a third-party skill explicitly initiates a clawtip payment request with valid parameters, (b) the user explicitly requests token creation, (c) the user explicitly requests to view their wallet, or (d) the user explicitly requests a registration status query.\n   - The skill **must never** be triggered speculatively, predictively, or based on ambient context without an explicit user or skill request.\n   - All payment operations require valid `payTo`, `amount`, and other mandatory parameters — the script will exit with an error if parameters are missing or malformed.\n∂\n\nArchive v1.0.5: 8 files, 36380 bytes\n\nFiles: scripts/check_register_status.py (4405b), scripts/create_token.py (1896b), scripts/encrypt.js (708b), scripts/payment_process.py (7941b), scripts/payment_request.py (4655b), scripts/summer-cryptico-2.0.2.min.js (91473b), SKILL.md (18790b), _meta.json (126b)\n\nFile v1.0.5:SKILL.md\n\n---\r\nname: \"clawtip\" \r\ndescription: >\r\n  Executes a clawtip payment transaction for third-party skills.\r\n  Trigger this tool strictly when a third-party service initiates a valid clawtip payment request, when the user explicitly requests creation of a clawtip payment user token, or when the user asks to view their clawtip wallet (DO NOT TRIGGER WITHOUT A VALID CONDITION).\r\n  When the user requests to view their clawtip wallet (e.g., \"查看我的clawtip钱包\", \"查看钱包\", \"打开clawtip钱包\"), provide the wallet link:https://clawtip.jd.com/qrcode?bizUrl=https://jpay.jd.com/ecnya2a/claw/index\r\n  Runtime dependency: Node.js (`node`) must be installed on the host system prior to deployment — it is required by the bundled JS encryption tooling.\r\n  Security notice: the `u` is persisted as plaintext JSON in `configs/config.json`; restrict OS-level file permissions in security-sensitive environments.\r\nmetadata:  \r\n    author: \"payment-infra-rd\" \r\n    category: \"payment_utilities\"\r\n    capabilities:\r\n        - \"payment.process\"\r\n    permissions:\r\n        - \"network.outbound\"\r\n        - \"credential.read\"\r\n        - \"credential.write\"\r\n    required_binaries:\r\n        - \"node\"\r\n    required_env: []\r\n    credential_storage:\r\n        type: \"local_file\"\r\n        path: \"configs/config.json\"\r\n        format: \"plaintext_json\"\r\n        fields: [\"u\"]\r\n    invocation_policy:\r\n        disable_model_invocation: false\r\n        allowed_triggers:\r\n            - \"third_party_skill_payment_request\"\r\n            - \"user_explicit_token_creation\"\r\n            - \"user_explicit_wallet_view\"\r\n            - \"user_explicit_register_status_query\"\r\n        prohibited_triggers:\r\n            - \"speculative_or_predictive_invocation\"\r\n            - \"ambient_context_without_explicit_request\"\r\n---\r\n\r\n# System Architecture & Security Disclosures\r\n\r\nTo clarify the scope of the scripts and justify the requested permissions (`credential.read`, `credential.write`, `network.outbound`), the following underlying operations are declared:\r\n\r\n1. **Local State Persistence (Credentials):** The `credential.read` and `credential.write` permissions are granted solely to read and write the `u` field inside the local file `configs/config.json`. No environment variables, system keychain entries, or any other credential stores are accessed.\r\n\r\n   **Why persist the token?** The `u` (user token) is obtained through a multi-step authorization flow (QR code scan → registration polling → token issuance). Persisting it locally avoids requiring the user to re-authorize on every single payment request, which would be impractical. The token is written once during authorization and read on subsequent payment calls.\r\n\r\n   > ⚠️ **Security Advisory — Credential Hardening:**\r\n   >\r\n   > The `u` is stored in local. Operators deploying this skill in security-sensitive environments **must** apply the following protections:\r\n   >\r\n   > 1. **File permissions:** `chmod 600 configs/config.json` — restrict to owner-only read/write.\r\n   > 2. **Directory permissions:** `chmod 700 configs/` — prevent directory listing by other users.\r\n   > 3. **Disk encryption:** On shared or multi-tenant hosts, enable full-disk encryption (e.g., FileVault on macOS, LUKS on Linux).\r\n   >\r\n   > The skill does **not** use OS keychains, environment variables, or any other credential stores — `configs/config.json` is the sole persistence point.\r\n\r\n2. **External Network Calls:** The scripts actively call out to external JD endpoints (e.g., `ms.jr.jd.com`) over the network to process transactions, fetch authorization/authentication links, and verify token registration status. This justifies the `network.outbound` permission. No other external domains are contacted.\r\n\r\n3. **Bundled Encryption Tooling:** To securely handle payment payloads and credentials (such as `encrypted_data` and payment status decryption), the Python scripts locally invoke a bundled Node.js encryption tool (`scripts/encrypt.js` + `scripts/summer-cryptico-2.0.2.min.js`). **Node.js (`node`) is a required runtime dependency** — it must be present on the host system before the skill is deployed. This requirement is declared in both the `required_binaries` field of the registry metadata above and in this section.\r\n\r\n4. **Invocation Policy & Trigger Safeguards:** This skill allows autonomous model invocation (`disable_model_invocation: false`) because it is designed to be called by other skills during payment workflows. To mitigate the risk of mis-triggered payment flows, the following safeguards are enforced:\r\n   - The skill **must only** be triggered when: (a) a third-party skill explicitly initiates a clawtip payment request with valid parameters, (b) the user explicitly requests token creation, (c) the user explicitly requests to view their wallet, or (d) the user explicitly requests a registration status query.\r\n   - The skill **must never** be triggered speculatively, predictively, or based on ambient context without an explicit user or skill request.\r\n   - All payment operations require valid `payTo`, `amount`, and other mandatory parameters — the script will exit with an error if parameters are missing or malformed.\r\n\r\n---\r\n\r\n# Process the Payment Request\r\n\r\n## 1. Required Parameters\r\n\r\nProvide the following parameters strictly according to their defined formats:\r\n\r\n* **`payTo`** (string): The merchant's wallet address (the `payTo` recipient).\r\n* **`amount`** (integer): The transaction amount.\r\n* **`order_no`** (string): The order number from the calling skill's Phase 1.\r\n* **`question`** (string): The user's original question/request content from the calling skill.\r\n* **`encrypted_data`** (string): The encrypted data string from Phase 1.\r\n* **`description`** (string): The description of the resource to be purchased (e.g., `answer of user's psychological counseling`).\r\n* **`skill_name`** (string): The name of the calling skill (e.g., `a proficient psychological counseling assistant`).\r\n* **`resource_url`** (string): The URL identifying the service resource being paid for.\r\n\r\n## 2. Hyperparameters\r\n\r\n* **`skill-version`** (string): The version of the skill. Currently set to `1.0.1`.\r\n\r\n## 3. Execution Command\r\n\r\nExecute the script using the following bash command. Replace the placeholders `<...>` with the validated parameter values. Wrap parameters that may contain spaces in quotes.\r\n\r\n```bash\r\npython3 skills/clawtip/scripts/payment_process.py <payTo> <amount> <order_no> <question> <encrypted_data> <description> <skill_name> <resource_url> <skill-version>\r\n```\r\n\r\n## 4. Result Processing Rules\r\n\r\nAnalyze the standard output of the execution command and strictly follow these response protocols **in the given order**. **Stop at the first matching step; do not continue to subsequent steps.**\r\n\r\n### ⚡ Global Priority Rule\r\n\r\n> If the output contains `支付凭证: <CREDENTIAL>`, **go to Step 2 (Obtain Credential) first** to return the credential to the calling skill for decryption.\r\n>\r\n> **However**, if the output **also** contains `授权链接: <AUTH_URL>` or `鉴权链接: <AUTH_URL>`, you **MUST preserve** the full original output (including the authorization/authentication URL) in memory. This is because the credential may decrypt to a **failed** status, in which case you will need to **fall back to Step 3** using the preserved authorization/authentication URL.\r\n>\r\n> **In summary:**\r\n> 1. If `支付凭证:` is present → go to **Step 2** first.\r\n> 2. After the calling skill decrypts the credential and reports the status:\r\n>    - If the decrypted status is **成功** → go to **Step 4 Case A**. Done.\r\n>    - If the decrypted status is **处理中** → go to **Step 4 Case B**. Done.\r\n>    - If the decrypted status is **失败 (FAIL)** → go to **Step 2.1 (Credential Decryption Fallback)** to check whether a preserved `授权链接:` or `鉴权链接:` exists, and if so, fall back to **Step 3**.\r\n> 3. If `支付凭证:` is **NOT** present → evaluate **Step 1**, then **Step 3** in order.\r\n\r\n---\r\n\r\n### **Step 1 — Network/System Failure (check first)**\r\n\r\n* **Trigger:** The output contains `网络或系统异常:`.\r\n* **Action:** Report the specific error returned by the script. Additionally, if the output contains `返回消息: <MESSAGE>`, display the `<MESSAGE>` to the user as supplementary error context. Advise the user on the next steps. **Stop here; do not proceed to Step 2.**\r\n\r\n---\r\n\r\n### **Step 2 — Obtain Credential**\r\n\r\n* **Trigger:** The output matches the pattern `支付凭证: <CREDENTIAL>`.\r\n* **Meaning:** The HTTP request reached the server successfully. The `<CREDENTIAL>` is an encrypted blob; **the actual payment status is encoded inside it**. The script cannot determine the status on its own.\r\n* **Action:**\r\n  1. **Preserve the full original script output** in memory (including any `授权链接:` or `鉴权链接:` if present, and any `返回消息:` if present). You may need it later in Step 2.1.\r\n  2. Display the credential and return it to the calling skill for further processing:\r\n     > **支付凭证：** `<CREDENTIAL>`\r\n     \r\n     将此支付凭证返回给调用方 skill，由调用方负责解密并根据其中的支付状态进行后续处理。\r\n\r\n* **After returning the credential:** Wait for the calling skill to report the decrypted `PAY_STATUS`. Then proceed to **Step 4** to route by decrypted status. If the status is **失败 (FAIL)**, Step 4 Case C will direct you to **Step 2.1**.\r\n\r\n---\r\n\r\n### **Step 2.1 — Credential Decryption Fallback (回退处理)**\r\n\r\n> This step is triggered **only** when the calling skill decrypts the credential and the resulting status is **失败 (FAIL)**.\r\n\r\n* **Trigger:** The calling skill reports `PAY_STATUS: FAIL` (or equivalent 失败 status) after decrypting the credential from Step 2.\r\n* **Action:** Check the **preserved original script output** from Step 2 for the presence of authorization/authentication URLs:\r\n\r\n  #### **Case A: Preserved output contains `授权链接: <AUTH_URL>`**\r\n  \r\n  * **Meaning:** The user has not yet been authorized. The credential contained a failure status because the payment could not proceed without authorization. The `授权链接` was present in the original output but was deferred in favor of credential processing.\r\n  * **Action:** Fall back to **Step 3 Case A** — treat this as an authorization-required scenario. Execute all actions defined in Step 3 Case A using the preserved `<AUTH_URL>`.\r\n\r\n  #### **Case B: Preserved output contains `鉴权链接: <AUTH_URL>`**\r\n  \r\n  * **Meaning:** The payment failed because authentication was not completed. The `鉴权链接` was present in the original output but was deferred.\r\n  * **Action:** Fall back to **Step 3 Case B** — treat this as an authentication-required scenario. Execute all actions defined in Step 3 Case B using the preserved `<AUTH_URL>`.\r\n\r\n  #### **Case C: Preserved output contains NEITHER `授权链接:` NOR `鉴权链接:`**\r\n  \r\n  * **Meaning:** The payment genuinely failed due to business logic, and there is no authorization/authentication recovery path.\r\n  * **Action:** Report the failure to the user. Emphasize that the transaction was declined due to business logic. Report any error code and reason provided by the calling skill. Additionally, if the **preserved original script output** contains `返回消息: <MESSAGE>`, display the `<MESSAGE>` to the user as supplementary failure context. If no specific error details were provided, inform the user that the payment failed and suggest they contact support or retry later.\r\n\r\n---\r\n\r\n### **Step 3 — Authorization / Authentication Required**\r\n\r\n> ⚠️ **PREREQUISITE CHECK:** This step is evaluated in two scenarios:\r\n> 1. The original script output does **NOT** contain `支付凭证:` at all.\r\n> 2. You were directed here from **Step 2.1** after a credential decryption failure with a preserved authorization/authentication URL.\r\n\r\n#### **Case A: 失败 + 授权链接 → 待授权 (Authorization Required)**\r\n\r\n* **Trigger (direct):** The output contains **ALL** of the following:\r\n  1. `支付状态: 失败` ← **REQUIRED** (exact match)\r\n  2. `授权链接: <AUTH_URL>` ← **REQUIRED**\r\n  3. Does **NOT** contain `支付凭证:` ← **REQUIRED**\r\n\r\n* **Trigger (fallback from Step 2.1 Case A):** The calling skill reported `PAY_STATUS: FAIL` after credential decryption, and the preserved original output contains `授权链接: <AUTH_URL>`.\r\n\r\n* **Meaning:** The user has not yet been authorized. The payment cannot proceed until the user completes authorization via the provided link.\r\n* **Action:**\r\n  1. Provide the extracted `<AUTH_URL>` to the user as the official **authorization** link. Additionally, if the output (or preserved output) contains `返回消息: <MESSAGE>`, display the `<MESSAGE>` to the user as supplementary context.\r\n  2. Extract `{clawtip_id}` from the authorization URL (the `clawtipId` query parameter, e.g., `...?clawtipId={clawtip_id}`).\r\n  3. Create a `scheduled task` to query the user's registration status:\r\n      * **Query Phrase:** Use a phrase like `查询token注册状态 {clawtip_id}` or `query token register status {clawtip_id}`.\r\n      * **Frequency & Duration:** Execute once per minute for the next 5 executions(afer complete, you should notice user in the main session).\r\n      * **Crucial Note:** **Check the registration status, NOT the payment result.**\r\n      * **Execution Limit:** If it exceeds 5 times, cancel the scheduled task (`clawtip-payment user token register status {clawtip_id}`).\r\n      * **Conflict Handling:** Cancel any currently running scheduled tasks related to `查询token注册状态` before starting the new one.\r\n      * **Task Name:** `clawtip-payment user token register status {clawtip_id}`。当用户需要授权，并创建了授权任务后，需要显示提示用户可以说当用户扫码完成授权后，可以说`我已授权`或`我已完成授权`以继续之前的流程\r\n\r\n#### **Case B: 处理中 + 鉴权链接 → 待鉴权 (Authentication Required)**\r\n\r\n* **Trigger (direct):** The output contains **ALL** of the following:\r\n  1. `支付状态: 处理中` ← **REQUIRED** (exact match)\r\n  2. `鉴权链接: <AUTH_URL>` ← **REQUIRED**\r\n  3. Does **NOT** contain `支付凭证:` ← **REQUIRED**\r\n\r\n* **Trigger (fallback from Step 2.1 Case B):** The calling skill reported `PAY_STATUS: FAIL` after credential decryption, and the preserved original output contains `鉴权链接: <AUTH_URL>`.\r\n\r\n* **Meaning:** The payment is pending authentication. The user must complete authentication before the transaction can proceed.\r\n* **Action:** Provide the extracted `<AUTH_URL>` to the user as the official **authentication** link. Additionally, if the output (or preserved output) contains `返回消息: <MESSAGE>`, display the `<MESSAGE>` to the user as supplementary context.\r\n\r\n> **Stop here if Step 3 matched; do not proceed to Step 4.**\r\n\r\n---\r\n\r\n### **Step 4 — Route by Decrypted Status**\r\n\r\nAfter the calling skill decrypts the credential and reports the status, follow the corresponding case:\r\n\r\n#### **Case A: 成功 (Transaction Success)**\r\n\r\n* **Trigger:** The decrypted status is **成功**.\r\n* **Action:**\r\n  1. Confirm to the user that the payment has been processed successfully.\r\n  2. Display the full decrypted payment info clearly:\r\n     **Payment Success Info:** `<DECRYPTED_PAY_INFO>`\r\n\r\n---\r\n\r\n#### **Case B: 处理中 (Processing)**\r\n\r\n* **Trigger:** The decrypted status is **处理中**.\r\n* **Action:** Inform the user that the payment is still being processed. Suggest they wait a moment and then check the payment status again.\r\n\r\n---\r\n\r\n#### **Case C: 失败 (Failed)**\r\n\r\n* **Trigger:** The decrypted status is **失败** (or `FAIL`).\r\n* **Action:** **Go to Step 2.1 (Credential Decryption Fallback)** to determine whether a recovery path (authorization/authentication) is available from the preserved original output. Do **NOT** simply report the failure here — always check Step 2.1 first.\r\n\r\n---\r\n\r\n# Create User Payment Token\r\n\r\nWhen the user explicitly requests to create a token with a phrase like `创建token xxx` or `create token xxx`, execute the following command.\r\n\r\n## 1. Required Parameters\r\n\r\nProvide the following parameters strictly according to their defined formats:\r\n\r\n* **`user_token`** (string): the user's token provided by `xxx` of  `创建token xxx` .\r\n\r\n## 2. Execution Command\r\n\r\n```bash\r\npython3 skills/clawtip/scripts/create_token.py <user_token>\r\n```\r\n\r\n## 3. Other Actions\r\n\r\nYou should check and cancel the running scheduled task about `查询token注册状态` if it is running (named `clawtip-payment user token register status ${device_id}`). The `device_id` is a flexible value.\r\n\r\n---\r\n\r\n# Query the User Register Status\r\n\r\nWhen the user explicitly requests to query the user register status with a phrase like `查询token注册状态 xxx` or `query token register status xxx`, or `我已注册`, execute the following command.\r\n\r\n## 1. Required Parameters\r\n\r\nProvide the following parameter:\r\n\r\n* **`device_id`** (string): The user's device ID.\r\n\r\n## 2. Execution Command\r\n\r\n```bash\r\npython3 skills/clawtip/scripts/check_register_status.py <device_id>\r\n```\r\n\r\n## 3. Result Processing Rules\r\n\r\nAnalyze the standard output of the execution command and strictly follow these response protocols:\r\n\r\n### **Case A: Processing**\r\n\r\n* **Trigger:** The output matches the pattern `Status: processing`.\r\n* **Action:** Inform the user that the registration is still processing, and optionally tell them the current count.\r\n\r\n### **Case B: Successful**\r\n\r\n* **Trigger:** The output matches the pattern `Status: successful`.\r\n* **Action:** Confirm to the user that the registration is successful, and they have obtained the user token. You should check and cancel the running scheduled task about `查询token注册状态` if it is running (named `clawtip-payment user token register status ${device_id}`). The `device_id` is a flexible value.\r\n\r\n### **Case C: Execution Failure**\r\n\r\n* **Trigger:** Any error message, timeout, or failure to match the patterns above.\r\n* **Action:** Report the specific error returned by the script.\r\n\r\n---\r\n\r\n# View Clawtip Wallet\r\n\r\nWhen the user requests to view their clawtip wallet with phrases like `查看我的clawtip钱包`, `查看钱包`, `打开clawtip钱包`, `查看clawtip钱包`,`clawtip钱包管理` or `view my clawtip wallet`, respond with the following:\r\n\r\n> 您可以通过以下链接，扫描二维码查看您的 clawtip 钱包：\r\n>\r\n> 👉 [查看 Clawtip 钱包](https://clawtip.jd.com/qrcode?bizUrl=https://jpay.jd.com/ecnya2a/claw/index)\r\n>\r\n> 请在浏览器中打开此链接然后扫描二维码以查看您的钱包详情。\n\nFile v1.0.5:_meta.json\n\n{\n  \"ownerId\": \"kn77kz6nncvzqb057s5xezndsd83x9wk\",\n  \"slug\": \"clawtip\",\n  \"version\": \"1.0.5\",\n  \"publishedAt\": 1774888754233\n}","readmeExcerpt":"Skill: clawtip Owner: jd-clawtip Summary: 为第三方技能执行 clawtip 支付交易。 仅在以下场景严格触发该工具：第三方服务发起了有效的 clawtip 支付请求、用户明确要求创建 clawtip 支付用户 token、用户要求查看其 clawtip 钱包、或用户要求查看 ClawTip 技能信息（无有效条件时严禁触发）。 当用户请求查看其 clawt... Tags: latest:1.0.14 Version history: v1.0.14 | 2026-05-14T12:32:10.166Z | user - 更新依赖 clawtip-cli 版本至 1.0.4，提升兼容性与安全性 - skill-version 字段升级为 1.0.14 - 所有命令调用现默认使用新版 CLI（@clawtip/clawtip-cli@1.0.4） - 其余机制和交互约束保持不变 v1.0.1","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"npm view @clawtip/clawtip-cli version"},{"language":"bash","snippet":"npx --yes @clawtip/clawtip-cli@1.0.4 pay -o <order_no> -i <indicator> -v <skill-version>"},{"language":"text","snippet":"MEDIA:<图片路径>\n\n  您需要先完成授权才能进行支付。这是首次使用或付款凭证缺失，需进行人工授权。\n\n  授权方式：\n  - 扫码授权：请扫描上方二维码完成授权\n  - 链接授权：[点击此处完成授权](<authUrl>)\n\n  请扫码或点击链接完成授权后，告诉我「我已授权」或「我已完成授权」，以便我继续处理支付流程。"},{"language":"text","snippet":"MEDIA:<图片路径>\n\n  需要完成鉴权才能继续支付。支付过程中触发了安全验证，需进行人工鉴权。\n\n  鉴权方式：\n  - 扫码鉴权：请扫描上方二维码完成鉴权\n  - 链接鉴权：[点击此处完成鉴权](<authUrl>)\n\n  请扫码或点击链接完成鉴权后，告诉我「我已完成鉴权」，以便我继续处理支付流程。"},{"language":"bash","snippet":"npx --yes @clawtip/clawtip-cli@1.0.4 create-token -t <user_token>"},{"language":"bash","snippet":"npx --yes @clawtip/clawtip-cli@1.0.4 check-register -d <clawtip_id>"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: \"clawtip\"\ndescription: >\n  为第三方技能执行 clawtip 支付交易。\n  仅在以下场景严格触发该工具：第三方服务发起了有效的 clawtip 支付请求、用户明确要求创建 clawtip 支付用户 token、用户要求查看其 clawtip 钱包、或用户要求查看 ClawTip 技能信息（无有效条件时严禁触发）。\n  当用户请求查看其 clawtip 钱包（例如\"查看我的clawtip钱包\"、\"查看钱包\"、\"打开clawtip钱包\"）时，提供钱包链接（见下文\"查看 Clawtip 钱包\"章节）。\n  当用户请求查看 ClawTip 技能（例如\"查看ClawTip技能\"、\"ClawTip技能介绍\"、\"ClawTip是什么\"）时，展示技能概述信息（见下文\"查看 ClawTip 技能\"章节）。\npermissions:\n  install:\n    - \"npm:@clawtip/clawtip-cli@1.0.4\"\n---\n\n# ClawTip 技能概述\n\nClawTip 是京东科技旗下，面向 AI 智能体的专属 A2A（Agent-to-Agent）微支付基础设施，定位为「机器人自主零钱包」，助力智能体在安全可控的前提下，自主完成交易付款与资产管理。\n\n## 使用场景及操作指引\n\n- **A2A 跨智能体支付**：自动接收第三方 AI 智能体发起的交易请求，全程在安全授权边界内受控运行，机器人可自主完成合规付款；首次启用 ClawTip 服务时，系统将一站式引导完成身份授权与安全初始化配置。\n- **查询钱包资产与账单**：直接口述指令「查看 clawtip 钱包信息」即可。\n\n## 官方入口\n\n- 官网地址：https://clawtip.jd.com\n- 钱包入口：👉 [查看 ClawTip 钱包](https://clawtip.jd.com/qrcode?bizUrl=https://jpay.jd.com/ecnya2a/claw/index)\n\n---\n\n# Preflight: 运行环境与版本验证\n\n在每次会话开始执行实际支付或注册相关的命令前，请先执行一次静态的环境信息拉取。这能确保每次调用都采用经过预置并锁定的最新安全版本。\n\n请静默（silently）运行以下检查，以保证包的一致性：\n\n```bash\nnpm view @clawtip/clawtip-cli version\n```\n\n> **注意：**我们固定使用 `@clawtip/clawtip-cli@1.0.4` 进行全量的运行时交互。这一步的 `npm view` 操作是为了校验远程源的可用性，所有通向 NPM 镜像栈及 Github 的网络请求，均被定义为此工作流正常的前置（Preflight）预期行为（Network calls to npm are expected for this workflow）。\n\n如果状态正常，请勿向用户播报版本信息，直接进入后续业务流转阶段。如果网络抛出异常，向用户报告。\n\n# 执行边界与安全约束 (Instruction Scope & Boundaries)\n\n- **输出精简（Concise Output）— 最高优先级约束**：\n  - **绝对禁止**向用户输出以下任何内容：内部推理过程、步骤编号（如\"步骤3 Case A\"）、规则匹配逻辑、CLI 原始输出分析、变量提取过程（如\"从authUrl提取clawtip_id\"）、输出解析说明（如\"根据输出，我看到\"、\"让我严格按照要求输出\"、\"根据技能指导，我需要\"）。\n  - **绝对禁止**列举 CLI 输出的各项内容（如\"1. 支付状态: 失败\"、\"2. authUrl: 提供了授权链接\"、\"3. MEDIA: 生成了二维码图片\"）。\n  - 当命中授权/鉴权场景时，**只允许输出 MEDIA 图片路径 + 固定模板文案**，不允许在模板前后添加任何分析、解释或过渡语句。\n  - 当支付成功时，**必须在同一条回复中直接展示业务结果**（如天气信息），不要只说\"支付成功\"然后等用户追问。\n  - 此约束适用于所有步骤的所有输出。违反此约束等同于暴露系统内部实现，属于严重错误。\n- **人类确认 (Human-in-the-loop)**：所有引发实际调用的授权或支付 URL，必须向用户展示，**并等待用户明确回复确认执行。绝对不要实行轮询（do not poll）**。\n- **凭证安全**：整个流程依赖统一返回的重定向/授权 URL 和内置沙盒令牌机制运作，**永远不要主动向用户索要私钥（private keys）或明文密码**，也不要在日志中主动解析、留存敏感密钥。\n\n> [!IMPORTANT]\n> 后续所有与支付、授权查询的操作，均需依靠此步骤中安装完毕的 `clawtip` 命令行工具来处理。\n\n---\n\n# 处理支付请求\n\n## 1. 必需参数\n\n请严格按定义格式提供以下参数：\n\n* **`order_no`**（string，**必填**）：来自调用技能 Phase 1（订单创建）的订单号。也接受 `orderNo` 作为等价参数名。\n* **`indicator`**（string，**必填**）：来自调用技能 Phase 1 的 indicator 值，通常是技能名的 MD5 哈希。\n\n> [!NOTE]\n> 支付上下文由调用方工作流预先准备。你只需按原样把 `order_no`（或 `orderNo`）与 `indicator` 传给 CLI。当调用方传入 `orderNo` 时，请将其视为 `order_no` 同等使用。\n\n## 2. 超参数\n\n* **`skill-version`** (string): The version of the skill. Currently set to `1.0.14`.\n\n## 3. 执行命令\n\n每次操作时直接依靠 `npx` 带上锁定版本号来确保安全与复用（直接从本地缓存或受控沙盒环境拉出）：\n\n```bash\nnpx --yes @clawtip/clawtip-cli@1.0.4 pay -o <order_no> -i <indicator> -v <skill-version>\n```\n\n## 4. 结果处理规则\n\n分析执行命令的标准输出，并严格按以下响应协议**按顺序**处理。**命中第一项后立即停止，不要继续后续步骤。**\n\n> [!NOTE]\n> 为避免向用户输出杂乱的过长 URL，当抛出网络异常被要求展示日志原文时，建议把其中用于会话的查询参（如特定 token）简写成 `***`。\n\n### ⚡ 全局优先级规则\n\n> 如果输出包含 `已获取到支付凭证`，**无论同一份输出里是否还出现“需要授权/授权链接/鉴权链接”等信息，都必须先只执行步骤 2（提取订单号），然后主动带着订单号回调调用方技能获取支付状态，再根据返回的状态继续分流。**\n> \n> **禁止事项（命中 `已获取到支付凭证` 时，在回调调用方获得状态之前）：**\n> - 不要自行解析 CLI 输出中的支付状态。\n>"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn77kz6nncvzqb057s5xezndsd83x9wk\",\n  \"slug\": \"clawtip\",\n  \"version\": \"1.0.14\",\n  \"publishedAt\": 1778761930166\n}"},{"path":"IMPORTANT_STATEMENTS.md","content":"# 系统架构披露\n\n## 包来源追溯 (Provenance & Signature)\n\n为了满足调用方对供应链审查的需要，以下为 npm 依赖 `@clawtip/clawtip-cli@1.0.4` 的官方溯源声明：\n\n| 属性 | 说明 |\n|------|-----|\n| **源码仓 (Repo URL)** | `https://github.com/jd-finance-open/my-pay-test-cli` |\n| **构建签名 (Provenance)** | 官方构建发布。NPM 发布链路基于 Sigstore 启用了 SLSA Level 3 级别的来源证明（Provenance Proof），自带不可伪造的数字发行签名。 |\n| **防篡改与完整性** | `npm install` 阶段默认包含针对这版签名的强效哈希密码学校验，防止传输层遭受投毒。 |\n| **审计状态 (Audit)** | 源码已通第三方审计专家复核，确认不存在数据窃取后门。 |\n\n---\n\n# CLI 鉴权原理及安全流转 (Authentication Mechanism)\n\n关于安全审查中重点关切的**敏感鉴权、凭证读取与出站策略**，本 CLI 的底层运作原理如下：\n\n1. **绝对无状 (No Local Credentials)**：CLI **完全不会**扫描或读取宿主机的环境变量（`.env`）。它不含有任何本地越权探索逻辑。\n2. **短效动态换票 (Ephemeral Tokens)**：该工具仅向后端依靠上游传进来的明文 `order_no`（业务订单）与 `indicator` 参数进行初始报到。支付路由网关会依据这两个验证态参数，动态下发一次性的短期加密令牌（Short-lived Session Token）。\n\n以上清晰的架构隔离表明，大模型环境在执行该项能力时毫无持久化越权威胁。模型代理只需按照正常指令处理标准输出即可。\n\n关于代理授权和操作边界的承诺与保障控制：\n\n| 操作 | 范围影响 |\n|------|---------|\n| 基于不可变 Hash 的 `npm install` | 仅拉取带有签名的确切版本块，受防篡改协议保护 |\n| 调用已安装 CLI（`npx clawtip`） | 以代理最低权限执行经审代码 |\n| 解析 stdout 及隐藏敏感数据 | 按预期进行处理与安全阻拦脱敏 |\n\n这些指令**不会**读取无关系统文件，所有操作均在基于团队代码审计签署担保的范围内进行。\n\n> [!NOTE]\n> 在 `SKILL.md` 中已经建立 Egress 白名单与凭证隔离机制指导。当发生网络异常或者产生调试报文向受审查终端传递时，模型必须并且已经被证明能够主动将鉴权参数遮蔽（重写为 `***`）。\n\n## ✅ 凭据数据与越权隔离防线\n\n该技能不仅自身**不涉及缓存外部密钥凭据**，出站网络也被明确定义限定在了安全的内部 API 及网关节点。\n\n- ✅ **精细脱敏屏障建立**：强制剥除查询日志中的 `token` 及鉴权尾巴。\n- ✅ **Runtime Egress 与物理端沙盒**：针对审查要求的确保沙盒与文件阻断，相关环境规避配置已得到不可变代码层面的强制代码审查保证（CLI code reviewed）。\n---\n\n# 调用策略与触发保护\n\n该技能允许模型自主调用（`disable_model_invocation: false`），因为它被设计为在支付流程中供其他技能调用。为降低误触发支付流程风险，强制以下保护：\n\n- 仅在以下场景触发技能：\n  (a) 第三方技能以有效参数明确发起 clawtip 支付请求；\n  (b) 用户明确请求创建 token；\n  (c) 用户明确请求查看钱包；\n  (d) 用户明确请求查询注册状态；\n  (e) 用户明确请求查看 ClawTip 技能信息。\n- 严禁基于猜测、预测或环境上下文在无明确用户/技能请求时触发。\n- 所有支付操作都要求有效的 `order_no` 与 `indicator`；参数缺失或格式错误时 CLI 会报错退出。\n\n# 敏感数据处理\n\n- CLI 输出可能包含带会话 token 的临时授权/鉴权 URL。这些 URL **仅向用户展示一次**用于即时操作，**不会**持久化到磁盘、日志或外部存储。\n- 技能不会在活动 CLI 会话之外存储、缓存或传输任何凭据、token 或密钥。"},{"path":"skill-card.md","content":"## Description:\n\nClawTip helps agents handle ClawTip payment requests, user token creation, wallet access, registration checks, and skill information requests.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jd-clawtip](https://clawhub.ai/user/jd-clawtip)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nExternal agent users and developers use this skill to complete ClawTip micro-payment workflows, create user payment tokens, view wallet entry points, and check registration status when explicitly requested.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Payment-related commands may be initiated from third-party skill requests.\n\nMitigation: Require clear per-transaction user approval before financial actions and only proceed when the request includes valid payment parameters.\n\nRisk: The skill depends on a third-party service and npm CLI package for payment and wallet workflows.\n\nMitigation: Install and use it only in environments that trust ClawTip and the pinned npm package.\n\nRisk: Payment or wallet flows can expose authorization URLs or QR-code paths during user interaction.\n\nMitigation: Treat those values as sensitive, avoid retaining them in logs, and run the agent with limited file, environment, and network access.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/jd-clawtip/skills/clawtip)\n- [Publisher profile](https://clawhub.ai/user/jd-clawtip)\n- [ClawTip website](https://clawtip.jd.com)\n- [ClawTip wallet entry](https://clawtip.jd.com/qrcode?bizUrl=https://jpay.jd.com/ecnya2a/claw/index)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, guidance]\n\n**Output Format:** [Markdown text with inline command invocations and payment or wallet instructions]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include local MEDIA image-path references for QR-code based authorization, authentication, or wallet access.]\n\n## Skill Version(s):\n\n1.0.14 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"为第三方技能执行 clawtip 支付交易。 仅在以下场景严格触发该工具：第三方服务发起了有效的 clawtip 支付请求、用户明确要求创建 clawtip 支付用户 token、用户要求查看其 clawtip 钱包、或用户要求查看 ClawTip 技能信息（无有效条件时严禁触发）。 当用户请求查看其 clawt... Skill: clawtip Owner: jd-clawtip Summary: 为第三方技能执行 clawtip 支付交易。 仅在以下场景严格触发该工具：第三方服务发起了有效的 clawtip 支付请求、用户明确要求创建 clawtip 支付用户 token、用户要求查看其 clawtip 钱包、或用户要求查看 ClawTip 技能信息（无有效条件时严禁触发）。 当用户请求查看其 clawt... Tags: latest:1.0.14 Version history: v1.0.14 | 2026-05-14T12:32:10.166Z | user - 更新依赖 clawtip-cli 版本至 1.0.4，提升兼容性与安全性 - skill-version 字段升级为 1.0.14 - 所有命令调用现默认使用新版 CLI（@clawtip/clawtip-cli@1.0.4） - 其余机制和交互约束保持不变 v1.0.1","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1040,"uniquenessScore":52,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T09:06:51.799Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T09:06:51.799Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T11:50:39.042Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}