{"id":19184,"plugin_id":"plugins_6a9319929b74819193f3f276f98627c4","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:15:20.959Z","digest":"19bef345730e95634b22e5877958c4234cfe295522f0e7dc59d1d685db744b9b","against":null,"payload":{"description":"Use as lead for fintech Go diff/PR review: money, payments, settlement, payment data, and audit. Do not use for general work.","included_files":[{"relative_path":"agents/openai.yaml","size_in_bytes":259},{"relative_path":"evals.json","size_in_bytes":16159},{"relative_path":"references/financial-finding-standard.md","size_in_bytes":825},{"relative_path":"skill.json","size_in_bytes":2293}],"name":"review-go-fintech-change","skill_md_contents":"---\nname: review-go-fintech-change\ndescription: \"Use as lead for fintech Go diff/PR review: money, payments, settlement, payment data, and audit. Do not use for general work.\"\nlicense: Apache-2.0\ncompatibility: \"Go 1.24 or newer; product, provider, rail, and compliance contracts control the review.\"\n---\n\n# Review a Go fintech change\n\nTreat any path that can invent, duplicate, lose, misstate, or conceal money as financial-integrity sensitive.\n\n## Trace the financial effect\n\nFollow authenticated command, money representation, idempotency identity, state transition, provider attempt, ledger posting, event, settlement evidence, reconciliation, response, and audit record. Identify exact transaction boundaries and unknown-outcome windows.\n\nFor every caller, payment, provider, or replay identity, verify its authority scope and canonical payload binding. State all three behaviors explicitly: equivalent input replays the same outcome; different input is rejected before a new effect or prior-result disclosure; wrong authority learns nothing. Saying an identity is “bound to a fingerprint” is not an enforceable finding unless the mismatch path is defined.\n\nTreat product, provider, rail, report, and repository semantics already supplied by the task as the review contract. Choose the narrowest focused skill that owns the dominant financial effect: `go-money-and-ledgers` for arithmetic or journal invariants, `go-payment-lifecycles` for provider states, `go-financial-idempotency` for financial replay identity, `go-clearing-settlement-reconciliation` for post-capture evidence, or `go-fintech-security-compliance` for regulated data and audit controls. Do not load adjacent skills merely because the diff mentions their topic.\n\nFor report ingestion, payout, settlement, or reconciliation code, read `go-clearing-settlement-reconciliation` before findings even when business contracts are supplied. Source completeness, source and parser provenance, exclusive match-group membership, currency-preserving equations, and completion evidence are correctness invariants rather than optional background. Load another focused or cross-collection skill only when an unresolved invariant directly changes the financial finding; stop once it is resolved.\n\n## Critical schedules\n\n- concurrent same-key and different-payload requests;\n- timeout after provider or database may have committed;\n- duplicate, delayed, and out-of-order webhooks;\n- partial capture/refund and cumulative amount races;\n- rounding residual across allocations and currencies;\n- unbalanced or mutable journal history;\n- report re-ingestion and duplicate adjustment;\n- late chargeback or settlement event after local terminal state;\n- cross-tenant replay, excessive privilege, or sensitive data in telemetry;\n- mixed versions during schema and state-machine rollout.\n\n## Findings\n\nZero tolerance: silent precision loss, unbalanced committed entries, duplicate financial effects, illegal state transitions presented as success, missing reconciliation evidence, or sensitive authentication data leakage. Tie every finding to a reachable schedule and authoritative invariant. State the exact identity, amount, currency, evidence state, authority, known/failed/ambiguous outcome, durable consequence, smallest repair, and required backfill or reconciliation. Do not treat provider documentation as universal across rails.\n\nRead [references/financial-finding-standard.md](references/financial-finding-standard.md) only when the task requires a formal audit format or a finding still lacks one of those dispositions.\n\n## Output contract\n\nLead with critical financial-integrity findings, then security/compliance and operational risks. State when scheme, legal, or compliance interpretation requires a qualified owner; never infer certification.\n\nAudit the final prose against every applicable financial-effect boundary. Do not rely on naming idempotency, reconciliation, or an adjustment to imply payload mismatch handling, evidence lineage, replay safety, exact arithmetic, or immutable correction.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}