Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add keodubo/PAW-Wiki --skill paw-testing-layergit clone --depth 1 https://github.com/keodubo/PAW-WikiWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/keodubo/paw-wiki/paw-testing-layer)<a href="https://agentmods.dev/skills/keodubo/paw-wiki/paw-testing-layer"><img src="https://agentmods.dev/badge/skills/keodubo/paw-wiki/paw-testing-layer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/keodubo/paw-wiki/paw-testing-layer"><img src="https://agentmods.dev/badge/skills/keodubo/paw-wiki/paw-testing-layer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00053 | $0.01473 |
| Opus 5 | $0.00026 | $0.00737 |
| Sonnet 5 | $0.00011 | $0.00295 |
| Haiku 4.5 | $0.00005 | $0.00147 |
Grade A, and why
paw-testing-layer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 93 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Paw Testing Layer
Overview
Use this as the transversal testing skill for PAW/Forkd. It encodes the PAW-Wiki testing rules and the repo-specific Maven/test habits needed to avoid false confidence.
Read references/testing-rules.md before writing, repairing, or judging tests.
Test Selection
Choose the test type from the behavior under test:
- Business rule or state transition: service test.
- SQL, row mapping, constraints, ordering, pagination, or schema behavior: DAO/persistence test against HSQLDB.
- TP2 JPA mapping, fetch, cascade, dirty checking, or generated SQL behavior: persistence/context test plus SQL/log inspection where useful.
- Route, binding, validation error, security rule, redirect, or JSP model contract: webapp MVC/security test.
- TP final REST resource status/body/header/error contract: API/MVC/JAX-RS resource test.
- SPA stores/composables, routes, forms, errors, and i18n behavior: frontend test if the repo has a frontend test runner; otherwise document the gap and manual/contract verification.
- API cache/static hosting behavior: cache/smoke test for
ETag,If-None-Match,304, and asset cache headers. - TP final WAR contents and route split: packaging/smoke check.
- JSP escaping, scriptlets, i18n bundle symmetry, or rendered-template contract: template/i18n test.
- Runtime wiring, AOP proxy, scheduler, or app startup behavior: context/integration test or Jetty smoke.
Core Rules
- Tests are blackbox: assert externally observable behavior or final state, not internal calls.
- One test covers one scenario and one action. If the name needs "and", split it.
- Never use
Mockito.verify,never,verifyNoInteractions,spy, or hand-rolled equivalents that count whether a dependency method was called. - Never test private methods, reflection paths, or
Class.forNameseams. Exercise private logic only through public behavior. - DAO tests use HSQLDB, shared schema bootstrap, SQL fixtures/direct setup,
@Rollback, and DB state assertions. - Service tests mock DAOs but assert returned state, thrown exceptions, state transitions, or recorded side effects.
- Do not test services that are pure pass-through wrappers; move/test real business behavior where it belongs.
- MVC tests verify status, redirects, model/binding errors, security, and preserved GET state.
- API contract tests verify status, DTO body, Problem Details, media types, auth errors, and headers such as
Location,Link,ETag, and CORS-exposed headers. - API 404 tests must prove
/api/*returns JSON/Problem Details, while SPA deep links fall back toindex.html. - Cache tests prove both validator flow (
ETag->If-None-Match->304) and static cache policy when cache is implemented. - Frontend tests cover stores/composables/routes/forms/i18n at the public UI/state contract level, not component internals.
- Frontend tests must not assert component internals, exact CSS classes, source snippets, exact DOM shape, implementation-specific store calls, or framework internals as the target.
- Do not use the object under test to set its own preconditions.
- Cover happy, unhappy, and edge paths as separate tests.
- A green build is not proof of wiki compliance; inspect test style and coverage against the rules.
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 93 lines · 53 tokens per session scan A 2e37bcaaa042
paw-testing-layer is a skill published in the GitHub repository keodubo/PAW-Wiki (10 stars, last pushed 1mo ago), licensed MIT. It adds 53 tokens to every session and 1,473 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
research-engineer
An uncompromising Academic Research Engineer. Operates with absolute scientific rigor, objective criticism, and zero flair. Focuses on theoretical correctness, formal verification, and optimal implementation across any required technology.
tika-eval-compare
Compare extracts from two Tika builds over a corpus to detect regressions in content, encoding, exceptions, and embedded-document handling. Use for "compare before/after extracts", "eval this change against the corpus".
neuron-evaluation-engineer
Create and run AI evaluations with datasets, assertions, and output drivers in Neuron AI. Use this skill whenever the user mentions evaluation, testing AI systems, creating evaluators, dataset-driven testing, assertion-based validation, or wants to measure AI system performance. Also trigger for tasks involving…
jetson-validate-image
Use after jetson-flash-image to run static BSP checks, on-target smoke/regression tests on a flashed DUT, or both. Not for build or flash steps. Triggers: validate bsp, on-target validation.
atmos-validation
Validate Atmos projects, components, arbitrary JSON Schema inputs, EditorConfig, and GitHub Actions; use affected-file selection and native CI annotations.
skill-benchmark
Benchmark AI skill effectiveness by measuring implementation quality against legacy constraints.