Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add theYahia/WWmcp --skill refund-requestgit clone --depth 1 https://github.com/theYahia/WWmcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/theyahia/wwmcp/refund-request)<a href="https://agentmods.dev/skills/theyahia/wwmcp/refund-request"><img src="https://agentmods.dev/badge/skills/theyahia/wwmcp/refund-request/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/theyahia/wwmcp/refund-request"><img src="https://agentmods.dev/badge/skills/theyahia/wwmcp/refund-request.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00021 | $0.00414 |
| Opus 5 | $0.00010 | $0.00207 |
| Sonnet 5 | $0.00004 | $0.00083 |
| Haiku 4.5 | $0.00002 | $0.00041 |
Grade A, and why
refund-request scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
/refund-request — Refund
Algorithm
- Locate the payment. If the user gave a payment_id, call
get_paymentwith it. If they gave an order reference, callsearch_paymentswith external_reference set to it. - Check the status. Only approved payments can be refunded. If it is pending, rejected or already refunded, stop and report that — do not attempt the refund.
- Check what is already refunded on the payment record. A second full refund on a partially refunded payment will fail or over-refund.
- Confirm the amount with the user. Omit amount for a full refund; pass a number for a partial one.
- Call
refund_paymentwith payment_id and, for a partial, amount. - Call
get_paymentagain to read back the resulting status and refunds list.
Response format
## MercadoPago refund
**Payment**: 1315432109 (ORDER-2026-0142)
**Original**: 17,000 ARS — approved
**Previously refunded**: 0
**This refund**: 8,500 ARS (partial)
**New status**: partially_refunded
Notes
- Refunds are irreversible. Always confirm the amount with the user before calling.
- MercadoPago's own fee is generally not returned on a refund — do not tell the user they get the full gross back unless the response says so.
- A charged_back payment is a dispute, not a refund. Refunding it on top of the chargeback double-pays; check status first.
Examples
/refund-request 1315432109
/refund-request ORDER-2026-0142 8500
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 48 lines · 21 tokens per session scan A a4923271a310
refund-request is a skill published in the GitHub repository theYahia/WWmcp (29 stars, last pushed 4d ago), licensed MIT. It adds 21 tokens to every session and 414 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-06.
Other skills, from other repositories
okx-cex-portfolio
This skill should be used when the user asks about 'account balance', 'how much USDT do I have', 'my funding account', 'show my positions', 'open positions', 'position P&L', 'unrealized PnL', 'closed positions', 'position history', 'realized PnL', 'account bills', 'transaction history', 'trading fees', 'fee tier'…
pdf-invoice-extractor
OCR a PDF invoice with mistralocr and extract structured line-item data (vendor, date, amounts, VAT) for accounting reconciliation. Use when the user provides an invoice PDF to process.
french-invoice-reminder
Rédige une relance de facture B2B en français avec un ton contrôlé (poli, ferme, ou final). À utiliser quand l'utilisateur demande une relance facture, un rappel de paiement, un mail de recouvrement, ou une dunning letter en français.
invompt-local-beta-invoice
Create or manage an Invompt invoice, quote, estimate, or pro forma from natural-language intent in any language, including short follow-ups that reuse earlier facts. Use for explicit billing-document requests across Latin, Cyrillic, RTL, Indic, CJK, and Southeast Asian scripts. Do not use for price or budgeting advice…
lemonsqueezy
Operate Lemon Squeezy — the Merchant of Record for digital products and SaaS — via its JSON:API REST endpoints. Covers stores, products, variants, checkouts, orders, subscriptions, customers, and license keys. Use when the user wants MoR billing (EU VAT, chargebacks, sales tax all handled for 5% + fees) instead of…
before-spend
Use this before any purchase, subscription, money transfer, or API credit top-up. Call sanctionauthorize first; never proceed when it returns false; if status is escalated, wait and follow handle-escalation.