Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add keodubo/PAW-Wiki --skill paw-webapp-layergit clone --depth 1 https://github.com/keodubo/PAW-WikiWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/keodubo/paw-wiki/paw-webapp-layer)<a href="https://agentmods.dev/skills/keodubo/paw-wiki/paw-webapp-layer"><img src="https://agentmods.dev/badge/skills/keodubo/paw-wiki/paw-webapp-layer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/keodubo/paw-wiki/paw-webapp-layer"><img src="https://agentmods.dev/badge/skills/keodubo/paw-wiki/paw-webapp-layer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00082 | $0.01159 |
| Opus 5 | $0.00041 | $0.00580 |
| Sonnet 5 | $0.00016 | $0.00232 |
| Haiku 4.5 | $0.00008 | $0.00116 |
Grade A, and why
paw-webapp-layer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 55 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Paw Webapp Layer
Overview
Use this for webapp/: TP1 controllers, forms, validation, JSP/JSTL, i18n, Spring Security, filters, webapp CSS/JS, and MVC tests. In TP final, use it for REST resources, API error mapping, auth/web security, CORS, SPA static hosting, and WAR asset integration after $paw-tp-final-migration sets the plan. Use $paw-frontend-layer for SPA source under frontend/.
Read references/layer-rules.md before editing webapp.
Workflow
- Inspect
CLAUDE.md, affected controller/form/JSP/tests, andDESIGN.mdfor UI changes; for TP final also readresumen-final-paw-2026andchecklist-tp-final-rest-spa. - Resolve stage: TP1 uses MVC/JSP; TP final may use REST resources plus SPA assets.
- Keep controllers/resources thin: bind/deserialize, validate, delegate once, return view/redirect or HTTP response/status/header/body.
- Put validation in form annotations/custom JSR380 validators for MVC; keep REST input validation and API errors explicit for final.
- Keep authorization declarative in
WebAuthConfigplusAccessHelperexpressions; update JSP visibility with Spring Security taglib when JSP remains. - Render JSP safely with
<c:out>,<c:url>,<spring:message>, and private views underWEB-INF. - Preserve GET state and inline validation behavior already expected by MVC flows.
- For TP final migration, work only inside the current vertical slice from
$paw-tp-final-migration: REST contract, SPA route/static hosting, tests, and rollback state must match that slice. - Route SPA source code, API client, router, stores/composables, frontend i18n, and frontend tests to
$paw-frontend-layer. - Test routes, bindings, security, redirects/status codes, i18n, template safety, or API contracts as applicable.
Web Rules
- No SQL,
java.sql, business orchestration, or domain ownership decisions in controllers. - No scriptlets or Java code in JSPs.
- No raw
${...}for dynamic user content; use<c:out>or escaping helpers. - No free redirects; use
SafeRedirectPathValidator. - Do not mix
@PreAuthorizewith URL rules unless the existing flow already chose that pattern. - Use shared JSP fragments/tags and
forkd.cssbefore adding local markup or inline styles. - For visual work, read
DESIGN.mdfirst. - For TP final SPA/API work, use
$paw-tp-final-migrationfirst; do not graft a frontend build or JWT flow into TP1 by accident. - For SPA source work under
frontend/, use$paw-frontend-layer; webapp owns hosting/integration, not component/store/router implementation. - TP final JAX-RS resources live under
/api/*, expose DTOs/forms only, and buildLocation, relation links,Link, andETagwith request-aware URI helpers. - API errors are JSON Problem Details (
type,title,status,detail,instance);/api/*404 stays JSON, while SPA fallback servesindex.htmlonly for non-API deep links. - If the SPA reads
Location,Link,ETag,X-Access-Token, orX-Refresh-Token, expose them explicitly through CORS. - Cache dynamic API responses with validators (
ETag/If-None-Match/304) only when semantically valid. Cache only hashed static assets as long-livedimmutable; keepindex.html/root revalidated or short-lived. - TP final packaging must keep one WAR with API,
index.html, hashed JS/CSS/assets, and backend classes; Maven must build frontend beforewebapp. - Do not remove the old JSP route for a migrated flow until the slice has green API/resource tests, SPA route verification, and package/static-hosting checks or an explicit rollback decision.
- Admin and owner restaurant forms share
WEB-INF/views/shared/restaurant-form-body.jspf; keep them aligned. - Upload errors go through
MultipartRequestSizeFilterandErrorHandlingAdvice.
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 55 lines · 82 tokens per session scan A 4b709aa507ea
paw-webapp-layer is a skill published in the GitHub repository keodubo/PAW-Wiki (10 stars, last pushed 1mo ago), licensed MIT. It adds 82 tokens to every session and 1,159 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
copilotkit-upgrade
Use when migrating a CopilotKit v1 application to v2 -- updating package imports, replacing deprecated hooks and components, switching from GraphQL runtime to AG-UI protocol runtime, and resolving breaking API changes.
nextjs-pages-router
Set up tRPC in Next.js Pages Router with createNextApiHandler, createTRPCNext, withTRPC HOC, SSR via ssr option and ssrPrepass, SSG via createServerSideHelpers with getStaticProps, and server-side helpers for getServerSideProps prefetching.
with-tanstack-query
Compose Angular Query with signal-owned Table filtering, sorting, and pagination state using reactive query options, manual row-model boundaries, direct query data, server counts, and valid injection context.
auth-web-cloudbase
CloudBase Web Authentication Quick Guide for frontend integration after auth-tool has already been checked. Provides concise and practical Web authentication solutions with multiple login methods and complete user management.
service-digital-engagement-channel-configure
Configures and deploys enhanced chat Messaging Channels for Messaging for In-App and Web (MIAW). Use when the user needs to create, deploy, and activate a messaging channel configured with Omni-Channel Flow, Omni-Channel Queue, User, or Agentforce Service Agent routing. Generates MessagingChannel metadata, deploys it…
om-system-extension
Extend installed Open Mercato modules through UMES enrichers, interceptors, mutation guards, widgets, menus, entity extensions, events, component/page replacements, and overrides. Use for "extend core", "add field/column/action", "hide page", "intercept API", "UMES", or "rozszerz moduł".