Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Protegge dati di pagamento e abbonamenti quando un sito/app gestisce checkout, carte, subscription o fatturazione. Copre integrazione sicura Stripe/PayPal, verifica firma webhook, PCI-DSS, GDPR, minimizzazione dati e ciclo di vita degli abbonamenti. Trigger - "pagamenti", "checkout", "abbonamento", "subscription", "Stripe", "PayPal", "carta di credito", "fatturazione", "privacy dei pagamenti".
.claude/skills/ccplugins-privacy-pagamenti/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 49% | 0% |
| case-09 | ✗→✓ | ▲ Improved | 7% | 0% |
| case-17 | ✗→✓ | ▲ Improved | 19% | 0% |
| case-22 | ✗→✓ | ▲ Improved | 13% | 0% |
| case-03 | ✓→✓ | = Same ✓ | -8% | 0% |
Quando un sito/app gestisce pagamenti o abbonamenti, applicare queste regole.
cus_...), ID abbonamento, stato, ultime 4 cifre e brand se forniti dal provider.sk_..., client secret) vivono solo in variabili d'ambiente lato server. Nel frontend solo chiavi pubblicabili.Lo stato di pagamenti/abbonamenti si aggiorna SOLO da webhook verificati, mai dal redirect del browser (falsificabile).
js// Stripe (Express) — il body deve essere RAW app.post('/webhook', express.raw({type: 'application/json'}), (req, res) => { let event; try { event = stripe.webhooks.constructEvent( req.body, req.headers['stripe-signature'], process.env.STRIPE_WEBHOOK_SECRET ); } catch (err) { return res.status(400).send('Firma non valida'); } // gestire event.type: checkout.session.completed, invoice.paid, // invoice.payment_failed, customer.subscription.deleted ... res.json({received: true}); });
Per PayPal usare l'API di verifica firma webhook. Rendere i gestori idempotenti (stesso evento ricevuto due volte = nessun doppio effetto): salvare gli event.id processati.
Chiavi in env, webhook con firma verificata e idempotente, nessun dato carta nel DB/log, portale di gestione abbonamento, privacy policy, flusso di cancellazione, gestione pagamento fallito.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→pass | 23,904 | 26,880 | +12% | 1 | 1 | 0% | 4,125 | 6,145 | +49% | 0 | 0 | — |
case-02 | fail→fail | 24,889 | 24,779 | -0% | 1 | 1 | 0% | 3,896 | 4,856 | +25% | 0 | 0 | — |
case-03 | pass→pass | 18,497 | 13,321 | -28% | 1 | 1 | 0% | 2,913 | 2,678 | -8% | 0 | 0 | — |
case-04 | pass→pass | 17,803 | 16,672 | -6% | 1 | 1 | 0% | 2,665 | 3,323 | +25% | 0 | 0 | — |
case-05 | pass→pass | 13,831 | 13,852 | +0% | 1 | 1 | 0% | 2,361 | 3,130 | +33% | 0 | 0 | — |
case-06 | pass→pass | 15,433 | 14,645 | -5% | 1 | 1 | 0% | 2,354 | 3,112 | +32% | 0 | 0 | — |
case-07 | pass→pass | 14,980 | 13,718 | -8% | 1 | 1 | 0% | 2,538 | 2,885 | +14% | 0 | 0 | — |
case-08 | pass→pass | 14,591 | 12,413 | -15% | 1 | 1 | 0% | 2,209 | 2,621 | +19% | 0 | 0 | — |
case-09 | fail→pass | 14,105 | 10,335 | -27% | 1 | 1 | 0% | 2,146 | 2,289 | +7% | 0 | 0 | — |
case-10 | pass→pass | 17,505 | 16,301 | -7% | 1 | 1 | 0% | 2,917 | 3,504 | +20% | 0 | 0 | — |
case-11 | pass→pass | 11,685 | 12,178 | +4% | 1 | 1 | 0% | 1,843 | 2,774 | +51% | 0 | 0 | — |
case-12 | pass→pass | 19,979 | 18,225 | -9% | 1 | 1 | 0% | 2,971 | 3,387 | +14% | 0 | 0 | — |
case-13 | pass→pass | 11,673 | 11,483 | -2% | 1 | 1 | 0% | 1,787 | 2,439 | +36% | 0 | 0 | — |
case-14 | pass→pass | 16,631 | 15,940 | -4% | 1 | 1 | 0% | 2,389 | 3,220 | +35% | 0 | 0 | — |
case-15 | pass→pass | 18,877 | 15,188 | -20% | 1 | 1 | 0% | 2,687 | 3,064 | +14% | 0 | 0 | — |
case-16 | pass→pass | 18,163 | 17,182 | -5% | 1 | 1 | 0% | 2,725 | 3,102 | +14% | 0 | 0 | — |
case-17 | fail→pass | 19,408 | 18,942 | -2% | 1 | 1 | 0% | 3,032 | 3,595 | +19% | 0 | 0 | — |
case-18 | pass→pass | 19,569 | 18,752 | -4% | 1 | 1 | 0% | 3,050 | 3,742 | +23% | 0 | 0 | — |
case-19 | pass→pass | 20,949 | 17,431 | -17% | 1 | 1 | 0% | 3,150 | 3,360 | +7% | 0 | 0 | — |
case-20 | pass→pass | 14,576 | 13,668 | -6% | 1 | 1 | 0% | 2,554 | 3,041 | +19% | 0 | 0 | — |
case-21 | pass→pass | 16,761 | 16,302 | -3% | 1 | 1 | 0% | 2,657 | 3,602 | +36% | 0 | 0 | — |
case-22 | fail→pass | 16,970 | 14,383 | -15% | 1 | 1 | 0% | 2,765 | 3,130 | +13% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +18 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.