paw-testing-layer

paw-testing-layer is a skill for Codex from keodubo/PAW-Wiki. It costs 53 tokens per session (1,473 once invoked), scanned A, original, MIT.

A testing guide for the PAW Forkd application, covering backend services, databases, web pages, security, APIs, and front-end code. It explains which test type fits each behavior.

In plain words
What is it for?
Create or repair black-box tests, Maven verification gates, HSQLDB database tests, JPA persistence tests, MVC and security tests, REST API tests, and front-end tests.
Why use it?
It helps developers test the layer where a defect can occur and avoid tests that pass without checking the real contract.

Skill for Codex

Written for Codex: agents/openai.yaml present.

Good fit Create or repair black-box tests, Maven verification gates, HSQLDB database tests, JPA persistence tests, MVC and security tests, REST API tests, and front-end tests.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/keodubo/paw-wiki/paw-testing-layer
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add keodubo/PAW-Wiki --skill paw-testing-layer
Clone the repo
git clone --depth 1 https://github.com/keodubo/PAW-Wiki

Made for: Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for paw-testing-layer

README.md
[![agentmods](https://agentmods.dev/badge/skills/keodubo/paw-wiki/paw-testing-layer/github.svg)](https://agentmods.dev/skills/keodubo/paw-wiki/paw-testing-layer)
Your own site
<a href="https://agentmods.dev/skills/keodubo/paw-wiki/paw-testing-layer"><img src="https://agentmods.dev/badge/skills/keodubo/paw-wiki/paw-testing-layer/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for paw-testing-layer

Your own site · 80×15
<a href="https://agentmods.dev/skills/keodubo/paw-wiki/paw-testing-layer"><img src="https://agentmods.dev/badge/skills/keodubo/paw-wiki/paw-testing-layer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 53 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,473 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00053 $0.01473
Opus 5 $0.00026 $0.00737
Sonnet 5 $0.00011 $0.00295
Haiku 4.5 $0.00005 $0.00147

Measured 9d ago against content hash 2e37bcaaa042, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-09, from the pricing page.

Security

Grade A, and why

paw-testing-layer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/paw-testing-layer/SKILL.md · 93 lines

How it starts

The opening of the file, as written. The whole thing — 93 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Paw Testing Layer

Overview

Use this as the transversal testing skill for PAW/Forkd. It encodes the PAW-Wiki testing rules and the repo-specific Maven/test habits needed to avoid false confidence.

Read references/testing-rules.md before writing, repairing, or judging tests.

Test Selection

Choose the test type from the behavior under test:

  • Business rule or state transition: service test.
  • SQL, row mapping, constraints, ordering, pagination, or schema behavior: DAO/persistence test against HSQLDB.
  • TP2 JPA mapping, fetch, cascade, dirty checking, or generated SQL behavior: persistence/context test plus SQL/log inspection where useful.
  • Route, binding, validation error, security rule, redirect, or JSP model contract: webapp MVC/security test.
  • TP final REST resource status/body/header/error contract: API/MVC/JAX-RS resource test.
  • SPA stores/composables, routes, forms, errors, and i18n behavior: frontend test if the repo has a frontend test runner; otherwise document the gap and manual/contract verification.
  • API cache/static hosting behavior: cache/smoke test for ETag, If-None-Match, 304, and asset cache headers.
  • TP final WAR contents and route split: packaging/smoke check.
  • JSP escaping, scriptlets, i18n bundle symmetry, or rendered-template contract: template/i18n test.
  • Runtime wiring, AOP proxy, scheduler, or app startup behavior: context/integration test or Jetty smoke.

Core Rules

  • Tests are blackbox: assert externally observable behavior or final state, not internal calls.
  • One test covers one scenario and one action. If the name needs "and", split it.
  • Never use Mockito.verify, never, verifyNoInteractions, spy, or hand-rolled equivalents that count whether a dependency method was called.
  • Never test private methods, reflection paths, or Class.forName seams. Exercise private logic only through public behavior.
  • DAO tests use HSQLDB, shared schema bootstrap, SQL fixtures/direct setup, @Rollback, and DB state assertions.
  • Service tests mock DAOs but assert returned state, thrown exceptions, state transitions, or recorded side effects.
  • Do not test services that are pure pass-through wrappers; move/test real business behavior where it belongs.
  • MVC tests verify status, redirects, model/binding errors, security, and preserved GET state.
  • API contract tests verify status, DTO body, Problem Details, media types, auth errors, and headers such as Location, Link, ETag, and CORS-exposed headers.
  • API 404 tests must prove /api/* returns JSON/Problem Details, while SPA deep links fall back to index.html.
  • Cache tests prove both validator flow (ETag -> If-None-Match -> 304) and static cache policy when cache is implemented.
  • Frontend tests cover stores/composables/routes/forms/i18n at the public UI/state contract level, not component internals.
  • Frontend tests must not assert component internals, exact CSS classes, source snippets, exact DOM shape, implementation-specific store calls, or framework internals as the target.
  • Do not use the object under test to set its own preconditions.
  • Cover happy, unhappy, and edge paths as separate tests.
  • A green build is not proof of wiki compliance; inspect test style and coverage against the rules.

Read the full file on GitHub · 93 lines

Files

What ships with it

2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 9d ago First seen · 93 lines · 53 tokens per session scan A 2e37bcaaa042

Subscribe to this mod's changes

paw-testing-layer is a skill published in the GitHub repository keodubo/PAW-Wiki (10 stars, last pushed 1mo ago), licensed MIT. It adds 53 tokens to every session and 1,473 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

research-engineer

An uncompromising Academic Research Engineer. Operates with absolute scientific rigor, objective criticism, and zero flair. Focuses on theoretical correctness, formal verification, and optimal implementation across any required technology.

davila7/claude-code-templates · 43 tokens

tika-eval-compare

Compare extracts from two Tika builds over a corpus to detect regressions in content, encoding, exceptions, and embedded-document handling. Use for "compare before/after extracts", "eval this change against the corpus".

apache/tika · 50 tokens

neuron-evaluation-engineer

Create and run AI evaluations with datasets, assertions, and output drivers in Neuron AI. Use this skill whenever the user mentions evaluation, testing AI systems, creating evaluators, dataset-driven testing, assertion-based validation, or wants to measure AI system performance. Also trigger for tasks involving…

neuron-core/neuron-ai · 77 tokens

jetson-validate-image

Use after jetson-flash-image to run static BSP checks, on-target smoke/regression tests on a flashed DUT, or both. Not for build or flash steps. Triggers: validate bsp, on-target validation.

NVIDIA/skills · 50 tokens

atmos-validation

Validate Atmos projects, components, arbitrary JSON Schema inputs, EditorConfig, and GitHub Actions; use affected-file selection and native CI annotations.

cloudposse/atmos · 31 tokens

skill-benchmark

Benchmark AI skill effectiveness by measuring implementation quality against legacy constraints.

HoangNguyen0403/agent-skills-standard · 16 tokens