Product & Planning
Product & planning agent skills structure the thinking side of building: specs, PRDs, user stories, roadmaps, and prioritization frameworks. Install one and your AI agent produces planning documents with the same rigor and format every time.
-
briiirussell Skill Security CommsTranslate technical security work into the language of non-security audiences — board, executives, engineering, customer success, customers, legal, procurement, sales. Covers incident communication, post-mortem narrative, audit-findings-for-stakeholders, risk justification, security spend justification, and customer-facing breach disclosure. Use when the user mentions 'security comms,' 'communicate this finding,' 'explain to my boss,' 'board update,' 'executive summary,' 'incident communication,' 'breach notification,' 'customer disclosure,' 'security memo,' 'post-mortem narrative,' 'risk justification,' 'why this matters to the business,' 'translate this finding,' 'stakeholder update,' or has technical security work that needs to land with a non-security audience.
-
useosint Bundle Find Exposed ServersFind internet-exposed hosts, ports, services and devices using third-party internet-scan data instead of touching the target. Covers Shodan and Censys query syntax, service banners, favicon-hash and TLS-certificate pivots, origin-IP discovery behind Cloudflare or a CDN, and exposed databases, dashboards, cameras and ICS devices. Use when asked what a company has exposed to the internet, to check open ports on an IP or netblock, or to write a Shodan filter query. Applies to external attack-surface management, third-party and vendor security review, M&A technical diligence, and pre-engagement reconnaissance. Reference at useosint.com/skills/find-exposed-servers.
-
useosint Bundle Find Hidden SubdomainsEnumerate an organisation's subdomains and sibling domains from Certificate Transparency logs and passive DNS, without sending traffic to the target. Covers crt.sh and CT log queries, certificate SAN fields, subfinder and amass, and newly issued TLS certificates. Use when looking for staging, dev, admin or VPN hosts, mapping the full hostname footprint of a domain, or spotting infrastructure a company forgot it had. Applies to attack-surface mapping, vendor and supply-chain security review, brand-infringement discovery, and M&A technical diligence. Reference at useosint.com/skills/find-hidden-subdomains.
-
qverisai Bundle Qveris CnQVeris is a capability discovery and tool calling engine. Use discover to find specialized API tools — real-time data, historical sequences, structured reports, web extraction, PDF workflows, media generation, OCR, TTS, translation, and more. Then call the selected tool. Discovery queries must be English API capability descriptions. Requires QVERIS_API_KEY.
-
qverisai Bundle Qveris OfficialQVeris is a capability discovery and tool calling engine. Use standardized capabilities/query for qveris_finance.* CAP workflows, or discover/call for generic specialized API tools such as real-time data, historical sequences, structured reports, web extraction, PDF workflows, media generation, OCR, TTS, translation, and more. Requires QVERIS_API_KEY.
-
tinyfish-io Skill Company Hiring IntelligenceReverse-engineer what a company is building by scraping their job postings, careers page, LinkedIn Jobs, and engineering blog using TinyFish web agents. Use whenever a user wants to understand a company's strategic direction from hiring signals, do competitive intelligence, figure out a tech stack from job descriptions, or evaluate whether a company is worth joining. Trigger on "what is [company] building", "what is [company] hiring for", "competitive intelligence", "[company] jobs", "should I join [company]", "hiring signals", "what teams are growing", "reverse engineer roadmap", or any request to understand a company's direction from public hiring activity. Always use this skill for company intelligence rather than guessing from memory. Also trigger when someone names a company and asks about strategy, tech stack, or org structure.
-
binjuhor Bundle Ck MCP ManagementManage MCP servers - discover, analyze, execute tools/prompts/resources. Use for MCP integrations, intelligent tool selection, multi-server management, context-efficient capability discovery.
-
prisma-prisma-next Skill Record GotchasCapture surprises, workarounds, and rough edges hit while *consuming* the public surface of Prisma Next, Prisma Compute, or Prisma Postgres — anything a real user of these products would experience. Fires whenever an operator (or agent) writes a workaround, hits a surprising failure mode, or finds undocumented behaviour while using one of these three products from the outside (extension authoring, example apps, integration tests, customer reproductions, internal demos, manual repros). Does NOT fire on bugs in code the operator's own team maintains — those are normal product-backlog bugs. In product-team repos (e.g. `prisma-next-ws`), surfaces the gotcha and offers the operator three paths (capture-as-gotcha, file a normal bug, or note-and-move-on). Outside product-team repos (pet projects, hackathon entries, customer codebases), silent-captures into the project's gotchas log AND a Triage-state Linear ticket in the matching gotchas project — no operator escalation. Do not skip the recording step.
-
gohypergiant Bundle Constraints ExtractorExtract explicit and implicit constraints (compliance, security, hosting, tooling, stakeholder, scope, and external-dependency boundaries) from a project's documentation, then build or update a canonical CONSTRAINTS.md. Spawns one subagent per source document to flag externally-imposed boundaries with evidence citations and confidence ratings, then correlates, deduplicates, and organizes the results by category before writing them into CONSTRAINTS.md. Use this skill whenever a user mentions "CONSTRAINTS.md", "extract constraints", "find our constraints", "document constraints", "compliance constraints", "what limits this project", "synthesize constraints", or wants to capture externally-imposed boundaries (legal, security, compliance, stakeholder, vendor) that shape what a project can build and how. Always prefer this skill over ad-hoc constraint documentation.
-
gohypergiant Bundle Accelint Onboard AgentsOnboard a repository to agent-driven development by creating or refreshing a complete AGENTS.md or CLAUDE.md through behavior-focused discovery, structured interviewing, drift-aware updates, conflict-aware synthesis, proportional updates, and preview-before-write review. Use when the user wants to create, replace, refresh, import, restructure, append to, dry-run, or review AGENTS.md or CLAUDE.md guidance, mentions agent behavior, instructions, guardrails, workflow, Claude Code conventions, package-level agent files, or monorepo inheritance, or asks how to tell an AI coding agent how to behave in a project. Also use it when the user wants behavior rules kept separate from `openspec/config.yml` or `openspec/config.yaml` project DNA. Do not use it for OpenSpec config onboarding, architecture docs, or one-line AGENTS.md or CLAUDE.md edits that do not require discovery, synthesis, or section-level review.
-
wedsamuel1230 Bundle Arduino CLI SkillUse when users need Arduino CLI commands for board discovery, library installation, compilation, upload, or serial-port troubleshooting on Windows, macOS, or Linux. Use it as the CLI branch of a broader workflow when the project also involves Arduino IDE, PlatformIO, vendor tools, hardware, power, or deployment.
-
wedsamuel1230 Bundle Ota Deployment GuardianUse when users need safe over-the-air update workflows for ESP32-class boards or Arduino Uno R4 WiFi, including OTA sketch requirements, network port discovery failures, remote recovery planning, and rollout safety checks.
-
infisical Bundle Infisical PamGuide for Infisical Privileged Access Manager (PAM) — brokering human and AI-agent access to databases, servers, Kubernetes clusters, and cloud accounts without the connecting party ever seeing a credential, with full session recording and audit. Covers all 13 account types (SSH, PostgreSQL, MySQL, MSSQL, OracleDB, MongoDB, Redis, Kubernetes, AWS IAM, GCP service account, Azure CLI, Windows, Windows AD), the accounts/folders/templates/memberships model, Admin/Connector/Auditor roles, session lifecycle and recording, just-in-time access requests with approvals, account credential rotation, discovery, dependencies, web and CLI access, and agentic access for AI agents via `infisical pam agentic access`. Use this skill when someone asks about: Infisical PAM, privileged access, session recording, just-in-time database access, brokered SSH access, giving an AI agent database access safely, access requests and approvals for infrastructure, or 'how do I let someone into production without giving them the password'. F
-
infisical Bundle Infisical PkiGuide for Infisical Certificate Management (PKI) — issuing, renewing, revoking, and distributing X.509 certificates. Covers all 9 certificate authority types (internal root/intermediate CA, ACME including Let's Encrypt, AWS Private CA, AWS ACM Public CA, Microsoft ADCS, Azure ADCS, DigiCert, Venafi TPP, GoDaddy), Applications and Certificate Profiles, all 4 enrollment methods (API, ACME, EST, SCEP), all 12 PKI Syncs for pushing certs to AWS ACM / Azure Key Vault / Cloudflare / load balancers, certificate lifecycle and alerting, code signing with PKCS#11 and Windows KSP, certificate discovery, HSM connectors, CRL distribution, and post-quantum ML-DSA and SLH-DSA key algorithms. Use this skill when someone asks about: Infisical PKI, certificate authority, issuing a TLS certificate, mTLS certificates, ACME or Let's Encrypt with Infisical, EST or SCEP enrollment, certificate renewal, revocation, CRL, code signing certificates, or 'how do I manage certificates with Infisical'. For X.509/TLS certificates and code s
-
readdle Skill Spark Persona Project ManagerProject manager persona for Spark. Project thread tracking, stakeholder updates, action item extraction, and cross-team coordination.
-
readdle Skill Spark Recipe Vacation CatchupProcess a large email backlog after time away: assess by category, batch-archive noise, and surface what needs attention.
-
readdle Skill Spark Recipe Stakeholder BriefBuild a comprehensive dossier on a person by pulling all meetings they attended and email threads with them into a single relationship brief.
-
haowjy Skill Character SimSpeak as a specified character from their current knowledge, voice, and emotional state. Use for skill-only workflows that need in-character conversation, voice discovery, or relationship pressure tests.
-
janjaszczak Skill Task Planning ShrimpPlan and split work with Shrimp Task Manager MCP when backlog must persist across sessions and tasks have explicit dependencies. Skip for same-session planning (use Plan Mode). Requires shrimp-task-manager MCP + Docker volume.
-
wwwzhouhui Bundle Github Readme GeneratorGenerate professional GitHub project README.md with standard structure including project intro, features, installation, usage, documentation, FAQ, contact info, donation, statistics, roadmap, and license. Auto-detects project type and tech stack.
-
yunshu0909 Skill Auto Task复杂长程任务的自主执行流程。当用户有一个复杂或模糊的任务("帮我搞清楚 X / 帮我评估 Y / 帮我把这堆东西整理出来 / 帮我对比 N 个方案 / 帮我跑一次调研"),希望 AI 自己拆解、自己执行、自己校验、只在关键时刻找用户的场景。通过"任务确认 → 任务队列 → 分批执行 → 周期校验队列 → 触发式汇报"实现 1-2 小时无人值守的自主执行。当用户说"帮我搞清楚 / 评估一下 / 整理一下 / 对比一下 / 跑一次调研 / 你自己跑别打扰我 / 长程任务 / 自主跑"时触发。**不适用于**:UI 设计(用 design-exploration)、待办优先级(用 priority-judge)、文章写作(用 writing-assistant)、需求池管理(用 backlog-manager)、终局发散(用 vision-exploration)、起名(用 product-naming)、有明确 spec 的实现编码任务(直接编码)。
-
yunshu0909 Skill UI DesignUI 样式修改协作流程(已有界面的视觉层微调)。触发硬条件:页面已经在代码里跑着,改的只是它的视觉表现——布局、间距、颜色、字号、圆角、组件搭配。通过"读代码 + ASCII 画出现状让用户确认 → 给 2-3 个 ASCII 方案 → 用户选定 → 最小改动 → 微调"的流程,减少沟通偏差、避免浪费 token。产出:只动样式的代码 diff。硬边界:不动业务逻辑、不动数据流、不改交互行为、不顺手重构。不适用于:界面还不存在、要从零探索长什么样(用 design-exploration)、改的是功能或交互逻辑而不只是视觉(用 req-change-workflow)、照着设计图/截图复刻整页(用 design-replica)、给还没实现的需求画线框(用 design-exploration 或 prd-test-writer)。
-
yunshu0909 Bundle Case Radar案例雷达。给一个新东西(新工具/新概念/新生态),扫一遍生态找好玩的真实案例,重点是抓"真物"(截图/源码/演示)而不是 GitHub 主页,输出可浏览的 HTML 案例集。当用户说"看看大家用 X 做了什么"、"扫一下 X 生态"、"市面上 X 有什么新玩法"、"给我看 X 的真物案例"、"/case-radar"时触发。不适合:① 已有明确目标的深度调研(用 long-research)② 写文章/出 PRD(用 writing-assistant / prd-doc-writer)③ 单纯求知不需要 HTML(直接问就好)。
-
yunshu0909 Bundle Goal Setter把模糊诉求收敛成另一个 AI 能自主执行且可验收的 goal contract(scope / non-goals / success criteria / verification / stop conditions)。本 skill 只写目标契约,**绝不替用户执行任务**。触发硬条件:这份 goal 是要交给别人跑的——subagent、Codex、另一个 AI 会话或另一个人。用于写 goal、优化 goal、改 handoff prompt,或把"今天做完、尽量优化、帮我研究并执行"这类请求变成执行方不会乱猜、不会越界的任务契约。不适用于:自己团队的需求管理和版本拆解(用 issue-pool——它产出的是给人开工的 task,不是给 AI 的契约)、界面设计探索(用 design-exploration)、PRD/验收标准/测试用例文档(用 prd-test-writer)、框架计划和版本路线(用 issue-pool)、以及用户其实是想让你**直接把这件事做了**的情况——那就直接做,不要走本 skill 把活变成一份文档。
-
yunshu0909 Bundle Article Study带用户精读一篇文章/文档并真正学透(不是出摘要)。五步:抽干货 → 切讲次 → 每讲跑「学-考-讲」循环 → 对号入座 → 实操+测验+讲错题+蒸馏。每讲产出 HTML 课件 + 笔记落盘;讲完必考一次,用户复述后必须挑不精确处拧紧;抽象概念上可交互演示(能点能跑);全程用用户自己的业务场景当案例;学完出多题型自动判分测验卷,最后把收获蒸馏回用户的工具。核心触发条件是用户要的是"学会"而不是"要一份结果",例如"我们一起学这篇文章/这个链接"、"带我学"、"精读"、"我想学会 X"、"这篇我看不懂你给我讲讲"。有具体材料(链接、本地文件、PDF,或用户自己的 skill/文档/代码)时直接开跑;只有学习意图而没材料时仍走本 skill,但开工第一件事是和用户一起把材料定下来,禁止凭记忆开讲。不适用于:只要一份总结/摘要/教程长文,用户读完就完、不需要答题(用 readable-output)、只是搜集资料做调研(使用可用的网页/平台取材工具)、帮我写 PRD/测试用例(用 prd-test-writer)、以及用户其实是想让你直接把活干了(那就直接做)。
-
yunshu0909 Bundle Prd Test WriterPRD + 可执行测试用例双文档一体化协作(开发范式 v2 定义段)。输入是已经拆定型的 task/需求;产出 4 个文件:PRD-MD 与 测试用例-MD(给 AI 的事实源)+ 两份套模板的 review HTML(给人查阅,与 MD 严格 1:1)。与用户共同写并迭代:理解需求后自主读代码再写;故事驱动 + 分阶段单点确认;UI 故事内置 ASCII 线框图 + Mermaid 能力。触发:梳理/撰写/完善 PRD、需求文档、用户故事、验收标准、测试用例、测试基准、测试方案。不适用于:需求还糊、还没拆成 task(先用 issue-pool)、界面方案本身还没探索过(先用 design-exploration,它产出的需求总结.md 正是本 skill 的输入)、只是改一个已上线功能的小需求(用 req-change-workflow)、写给人读的 HTML 长文/复盘/报告(用 readable-output)、项目级的框架计划和版本路线(用 issue-pool)、写代码或跑测试(本 skill 只出文档,不实现、不执行用例)。
-
yunshu0909 Skill Readable Output产出给人读的 HTML 长文——把已有的素材、经历、资料想清楚再写出来。每次触发先用 AskUserQuestion 一次性问清「给谁看 / 读完拿什么 / 多长 / 风格 + 侧重」4 个关键参数,再按 6 阶段框架输出。**产出只有 HTML 一种格式**——用户要 markdown 或要在聊天里直接说,就不该用本 skill。当用户说"做个复盘""汇总一下""总结这堆""整理成 HTML""做个教程/学习指南""把 X 讲清楚"等需要 >500 字结构化阅读内容时触发。不适用于:项目的计划报告/框架计划/版本路线(用 issue-pool,它自带 md2html)、PRD/需求文档/测试用例(用 prd-test-writer)、界面设计稿(用 design-exploration)、起名(用 product-naming)、写代码/修 bug/改文件、一两句话就能答完的问题。
-
yunshu0909 Bundle Prd Auto Test LoopPRD 驱动的自动化测试编排技能。用于把每版 PRD 的测试计划、AI 自测与自修复、测试报告标准化落地;适用于按验收标准拆分 Unit/Integration/E2E、划分自动化与人工边界、生成版本化 TEST_PLAN/TEST_REPORT 的场景。
-
yunshu0909 Bundle Req Change Workflow已有功能的需求变更闭环(门禁式七步)。触发硬条件:要改的功能已经实现并跑起来了。当用户说"改需求""需求变更""调整交互""改功能""重构流程",或改动容易散到多个文件、碰到鉴权/存储/配置/权限、需要可靠验证 + 回滚方案时使用。流程:锁 scope 写 change brief → 从代码确认当前行为(不靠记忆和假设)→ 影响面与风险评估 + 回滚计划 → 提出新设计等用户批准(**未获批准绝不动代码**)→ 小而局部的 diff → 跑固定回归清单 → 更新文档和决策日志。产出:change brief + 代码 diff + 回归记录 + decision log。不适用于:全新功能从零做(走 issue-pool → design-exploration → prd-test-writer)、只改视觉样式不动任何逻辑(用 ui-design)、新想法还没定要不要做(先用 issue-pool 入池)、写 PRD/测试用例(用 prd-test-writer)、提交推送发版(用 git-push)。注意:本 skill 的七步流程通用于任何项目,但 references/regression-checklist.md 和 scripts/impact_scan.sh 目前是 Chrome 扩展专用(manifest/service worker 等)——非扩展项目照流程走,但回归清单需按该项目实际重写,不要照搬。
-
amplitude Skill Analyze FeedbackSynthesizes customer feedback into actionable themes including feature requests, bugs, pain points, and praise. Use when planning product roadmap, understanding user sentiment, investigating specific issues, or preparing voice-of-customer reports.
Audited -
amplitude Skill Live Data ForensicsInvestigates live product issues against Amplitude data — "is X firing today", "did the release break Y", "which users are affected by Z". Covers the verify-then-query loop, query_amplitude_data parameterization, and its common failure modes. Use for incident analysis, instrumentation checks, and affected-user discovery.
-
amplitude Skill Discover OpportunitiesDiscovers product opportunities by analyzing Amplitude analytics, experiments, session replays, and customer feedback. Synthesizes evidence into prioritized, actionable opportunities with RICE scoring. Use when the user asks to "find opportunities", "what should we build", "where are we losing users", "product gaps", or wants a data-driven backlog of improvements.
-
revenuecat Skill Revenuecat CLIDrive RevenueCat from the terminal with the `rc` CLI, an alternative to the RevenueCat MCP server for humans, CI, and agents. Covers install, authentication, command discovery, and output conventions. Referenced by the other RevenueCat skills whenever they offer a CLI path.
-
bmad-code-org Bundle Bmad PrdCreate, update, or validate a PRD. Use when the user wants help producing, editing, or validating a PRD
-
bmad-code-org Bundle Bmad SpecCondense any input — an idea, brief, PRD, transcript, or mixed notes — into a short spec: SPEC.md plus supporting files that downstream skills build from. Also updates and validates existing specs, and can break a spec into stories. Use when the user says "create a spec", "distill this into a spec", "validate this spec", "update the spec", or "break this into stories"
-
bmad-code-org Bundle Bmad PrfaqTest a product concept with Amazon's Working Backwards method: write the press release for the finished product first, then answer hard customer and stakeholder questions, ending in a complete PRFAQ document. Use when the user requests to 'create a PRFAQ', 'work backwards', or 'run the PRFAQ challenge'
Frequently asked questions
What are Product & Planning agent skills?
Product & planning agent skills structure the thinking side of building: specs, PRDs, user stories, roadmaps, and prioritization frameworks. Install one and your AI agent produces planning documents with the same rigor and format every time.
Which Product & Planning skills are most installed?
Popular Product & Planning skills on SkillMD right now include find-exposed-servers, security-comms, find-hidden-subdomains. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Product & Planning skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.