Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Venkateshwar-Reddy-Jambula/razorpay-integration-plugin --skill go-livegit clone --depth 1 https://github.com/Venkateshwar-Reddy-Jambula/razorpay-integration-pluginWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/venkateshwar-reddy-jambula/razorpay-integration-plugin/go-live)<a href="https://agentmods.dev/skills/venkateshwar-reddy-jambula/razorpay-integration-plugin/go-live"><img src="https://agentmods.dev/badge/skills/venkateshwar-reddy-jambula/razorpay-integration-plugin/go-live/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/venkateshwar-reddy-jambula/razorpay-integration-plugin/go-live"><img src="https://agentmods.dev/badge/skills/venkateshwar-reddy-jambula/razorpay-integration-plugin/go-live.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00061 | $0.01981 |
| Opus 5 | $0.00030 | $0.00991 |
| Sonnet 5 | $0.00012 | $0.00396 |
| Haiku 4.5 | $0.00006 | $0.00198 |
Grade A, and why
go-live scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 224 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Go-Live Checklist & Production Hardening
Use this guide before launching a Razorpay integration to production, or to harden an existing live integration.
1. Pre-Launch Checklist
Complete every item before going live:
- CRITICAL: Auto-capture is ON — Dashboard → Settings → Payments → Set to "Auto-capture immediately". If off, payments stay
authorizedand webhookpayment.capturednever fires. Test mode hides this because it auto-captures regardless. - Switch to live API keys (
rzp_live_prefix) - Create live plans (separate from test plans — test plan IDs don't work in live mode)
- Register webhook with production URL (HTTPS required, port 443)
- Set live webhook secret (different from test)
- Enable all needed webhook events
- Test with a real Rs 1 payment end-to-end
- Verify refund flow works in live mode (refunds take 5-7 business days in live, instant in test)
- Remove all
console.logof sensitive data - Verify
.envis in.gitignore - Webhook route uses
runtime = "nodejs"NOT edge (crypto module required) - Set up error monitoring (Sentry, etc.)
- Set up reconciliation cron to catch missed webhooks (every 5-15 min)
- Add
processed_webhook_eventstable for idempotency
2. Security Hardening
a. Rate Limiting the Webhook Endpoint
// Razorpay sends from known IPs but rate limit anyway
// Simple in-memory rate limiter for webhook
const WINDOW_MS = 60_000; // 1 minute
const MAX_REQUESTS = 100;
const requestCounts = new Map<string, { count: number; resetAt: number }>();
function isRateLimited(ip: string): boolean {
const now = Date.now();
const entry = requestCounts.get(ip);
if (!entry || now > entry.resetAt) {
requestCounts.set(ip, { count: 1, resetAt: now + WINDOW_MS });
return false;
}
entry.count++;
return entry.count > MAX_REQUESTS;
}
// In your webhook handler:
export async function POST(req: Request) {
const ip = req.headers.get("x-forwarded-for") ?? "unknown";
if (isRateLimited(ip)) {
return new Response("Too Many Requests", { status: 429 });
}
// ... signature verification and processing
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 224 lines · 61 tokens per session scan A dbaf63f2392c
go-live is a skill published in the GitHub repository Venkateshwar-Reddy-Jambula/razorpay-integration-plugin (6 stars, last pushed 6mo ago), licensed MIT. It adds 61 tokens to every session and 1,981 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
sector-rotation
An analysis framework for comparing industries in the Chinese A-share stock market, using business conditions, price momentum, valuation, and money flows. It produces rankings and higher- or lower-allocation suggestions.
strategy-pivot-designer
Detect backtest iteration stagnation and generate structurally different strategy pivot proposals when parameter tuning reaches a local optimum.
twitter-reader
Read Twitter/X for financial research using opencli (read-only). Use this skill whenever the user wants to read their Twitter feed, search for financial tweets, view bookmarks, look up user profiles, or gather market sentiment from Twitter/X. Triggers include: "check my feed", "search Twitter for", "show my…
chenhao-limit-up
A framework for judging Chinese A-share stocks that have reached the daily price-rise limit, using market mood, sector leadership, and trading momentum.
trading-risk-gate
Unified pre-trade safety gate: Ruin check (Law #1), ergodicity audit, and win-rate dominance validation. Absorbs: ergodicity-check, law-of-ruin, win-rate-dominance.
furusato
A Japanese hometown-tax donation manager for furusato nozei, a system where donations to municipalities can qualify for an income-tax or local-tax deduction. It reads donation receipts, stores donation records, and calculates deduction limits.