Product & Planning
Product & planning agent skills structure the thinking side of building: specs, PRDs, user stories, roadmaps, and prioritization frameworks. Install one and your AI agent produces planning documents with the same rigor and format every time.
-
forgivesam168 Bundle SpecificationGenerate comprehensive specification documents (PRD/Spec). Use when asked to "write spec", "create PRD", "document requirements", "user stories", "acceptance criteria", "產生規格", "寫需求文件", "specifications", or transforming brainstorm results into formal structured requirements for features.
-
forgivesam168 Skill Implementation PlanningBreak down specifications into executable implementation plans with TDD integration. Use when asked to "create plan", "break down tasks", "implementation roadmap", "規劃實作", "拆解任務", "執行計畫", or need step-by-step implementation guidance with test strategies and impact analysis. Use when asked to "plan from spec", "spec to plan", "generate plan from requirements".
-
aki2022 Skill Origin Ws LoopAutonomously drain a repository's queue of active workstreams in one continuous run: pick the next workstream, execute it via origin-goal, close it via origin-close-session (merging green PRs autonomously under the default CD merge policy), park finished-but-unreviewed workstreams on a bounded review shelf, accumulate improvement observations as filed issues, and stop the entire loop the moment any human question arises. Use whenever the user wants accumulated workstreams processed in bulk or wants work to continue unattended until human input is needed, e.g. "wsを一気に消化", "溜まったws を処理して", "キューを回して", "自律で進められるところまで進めて", "run the ws queue", "drain the backlog", "process all workstreams", or /origin-ws-loop — typically right after mass-creating workstreams with origin-grill / origin-doc-update. Requires docs governance (docs/00_index.md + docs/workstreams/). Do NOT use for a single workstream (use origin-goal directly), for creating workstreams or specs (use origin-doc-update / origin-grill), or for recurring sche
-
victory-hugo Skill Opencli ExplorerUse when creating a new OpenCLI adapter from scratch, adding support for a new website or platform, or exploring a site's API endpoints via browser DevTools. Covers API discovery workflow, authentication strategy selection, YAML/TS adapter writing, and testing.
-
iamhenry Bundle Product IsaCreate or resume `_ai/docs/ISA.md` for a whole app through an eight-category product interview, detailed behavior contracts, binary Ideal State Criteria, verification probes, and a provenance-preserving Decision Ledger. Use when the user runs `/product-isa`, asks to define a whole app without a technical ADR or roadmap, or wants one behavior-first artifact that coding agents can implement directly.
-
iamhenry Bundle App Tiny BetsUse when finding validated tiny iOS app ideas or explicitly validating a wedge for one opportunity from an existing App Tiny Bets report. Phase 1 performs keyword-first discovery with Astro and competitor evidence. Phase 2 runs only when explicitly requested with a report and one selected opportunity, then mines competitor reviews and creates a wedge brief.
-
iamhenry Skill Metadata OptimizationWhen the user wants to optimize App Store metadata — title, subtitle, keyword field, or description. Also use when the user mentions "optimize my title", "ASO metadata", "keyword field", "character limits", "app description", or "write my subtitle". For keyword discovery, see keyword-research. For full ASO audits, see aso-audit.
-
firef1ie Skill Agentpmt Tool Local Business Discovery And Mapping 9329e4Use AgentPMT external API to run the Local Business Discovery and Mapping tool with wallet signatures, credits purchase, or credits earned from jobs.
-
trilwu Skill Exploiting SsrfFind and exploit server-side request forgery — reaching cloud instance metadata on AWS IMDSv1/IMDSv2, Azure IMDS, and GCP, internal service discovery, filter and allowlist bypasses via DNS rebinding, redirects, and encoding, and blind SSRF confirmation out of band. Use when an application fetches a URL supplied by the user, when testing webhooks, importers, PDF or screenshot renderers, or when reviewing outbound HTTP calls in source.
-
trilwu Skill Attacking OAUTH OidcAttack OAuth 2.0 and OpenID Connect flows — enumerate endpoints from the OIDC discovery document, break redirect_uri validation with path traversal, open-redirect chaining, subdomain and regex weakness, and %2F/@ parser tricks, exploit missing state (callback CSRF) and absent or downgraded PKCE, steal codes and tokens via open redirectors and referer leakage, replay and inject authorization codes across clients, escalate scope and bypass consent, confuse access_token with id_token, and take over accounts through "Sign in with X" email trust and device-code consent phishing. Use when you see /authorize, /oauth/token, response_type, redirect_uri, client_id, code= or state= parameters, a "Sign in with Google/Microsoft/GitHub" button, or an OIDC discovery document at /.well-known/openid-configuration.
-
trilwu Skill Analyzing Firmware ImagesExtract, analyze, and assess firmware images from embedded devices, IoT hardware, routers, and similar targets — filesystem extraction, hardcoded credential discovery, binary analysis across architectures, web interface review, network service enumeration, emulation, and cryptographic assessment. Use when analyzing a firmware update file, reviewing IoT device security, hunting for hardcoded secrets in device firmware, or assessing the attack surface of an embedded system.
-
everyone-needs-a-copilot Skill TaTechnical Architect for software systems. Use for architecture, decomposition, technical planning, tradeoff analysis, dependency mapping, PRD/task breakdowns, migration planning, interfaces, data flows, and implementation boundaries before coding.
-
everyone-needs-a-copilot Skill Call SummaryProcess call notes or a transcript — extract action items, draft follow-up email, generate internal summary. Use when pasting rough notes or a transcript after a discovery, demo, or negotiation call, drafting a customer follow-up, logging the activity for your CRM, or capturing objections and next steps for your team.
-
trilwu Skill Managing VulnerabilitiesPrioritize and drive remediation of a vulnerability backlog by real risk, not raw CVSS — combining severity with exploitation signals (EPSS, CISA KEV), asset exposure and business context, using SSVC-style decisions, distinguishing reachable from merely present, and tracking remediation and exceptions. Use when triaging scanner output, deciding what to patch first, building a risk-based vulnerability management process, or explaining why a critical CVE is not the top priority.
-
trilwu Skill Triaging Security AlertsWork a security alert queue to a defensible disposition — separating true positives from false positives and benign true positives, reasoning about base rates before escalating, ordering enrichment by cheapest discriminator, time-boxing, and documenting negative results so a closed alert is evidence rather than a guess. Use when triaging SOC or EDR alerts, deciding whether an alert warrants incident response, working through an alert backlog, or determining why a detection keeps firing.
-
trilwu Bundle Performing ReconnaissancePerform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access. Use when gathering intelligence or mapping attack surface.
-
trilwu Skill Orchestrating Vulnerability ResearchRun a sustained, multi-agent vulnerability-discovery campaign against a target — split its attack surface into slices, hunt each slice with a builder agent, and have a separate critic with fresh context adversarially refute every candidate against the real artifact (a reproduced crash, a working request, a proven bypass) before it counts as a finding. Use when tasked to find previously-unknown bugs across a whole codebase, a binary, or a named live target; when you want to fan out many agents and loop until findings are proven rather than plausible; or when a single audit pass has stalled and you need builder/critic separation so the hunter never grades its own work. Dispatches auditing-code-for-vulnerabilities, analyzing-binaries, and testing-web-applications as the per-slice hunters and hands proven findings to reporting-security-findings.
-
7a336e6e Skill Project PlanningDefine project scope, milestones, MVP requirements, and roadmap to turn vague ideas into executable plans.
-
caphtech Skill Eld Spec Discoverコード、テスト、要件、障害資料からELD v5のObservation、Term候補、Law候補を抽出し、出典・抽出確信度・反証事項を付ける。「Law候補を発見して」「語彙を抽出して」「既存コードからSpec候補を調べて」など、Card化前の読み取り専用Discoveryを依頼された時に使用する。候補をaccepted Lawへ自動昇格しない。
-
7a336e6e Skill Managing BacklogRefine, prioritize, and clean the product backlog to ensure the team is always working on the highest-value tasks.
-
boltaai Bundle Bolta Agent HireCreate and onboard a new AI agent teammate from marketplace presets with conversational discovery and preview generation.
-
dmzoneill Skill Sprint PlanningHelp with sprint planning by analyzing the backlog. Lists unassigned issues, identifies blocked items, shows issues ready for sprint, can add issues to sprint. Use when user says "sprint planning", "plan sprint", or "backlog analysis".
-
communitytoolkit Bundle AspireUse this skill when the user is working with an Aspire distributed application and needs to operate the AppHost or its resources through the Aspire CLI: start, restart, stop, or wait on the app; inspect resources, logs, traces, docs, or health; add integrations; manage secrets or config; publish, deploy, or rerun a named pipeline step; initialize Aspire in an existing app; recover missing `.aspire/modules` files in a TypeScript AppHost; discover the right frontend URL for Playwright from Aspire state; expose custom dashboard/resource commands; or understand unfamiliar Aspire AppHost APIs in C# or TypeScript. Use it even if they describe the task in terms of an AppHost, resources, dashboard, existing app bootstrap, missing generated modules, Playwright URL discovery, C# API understanding, or local distributed app workflow without explicitly naming Aspire. Do not use it for non-Aspire .NET apps, container-only repos with no AppHost, or ordinary build and test tasks.
-
amo-tech-ai-rocket-path-ai Bundle Startup PositioningMarket positioning strategy using the April Dunford framework, enriched with JTBD discovery, Moore positioning statement, and Neumeier's Onliness Test. Produces a complete positioning document, positioning statement, competitive alternatives map, and market category analysis. Use when the user wants to define or refine their market positioning, find their unique position, differentiate from competitors, craft a positioning statement, choose a market category, or figure out "how should we position this product." Triggers for "positioning", "how to position", "market position", "differentiation strategy", "positioning statement", "competitive positioning", "category strategy", "where do we fit in the market", "how are we different", "unique value proposition", or any request to define, sharpen, or rethink positioning. Works standalone — no prior startup-design or startup-competitors session needed, but leverages their output if available.
-
mashharuki Bundle Mpp DevComprehensive development support for MPP (Machine Payments Protocol) — the open, IETF-draft-style HTTP payment standard co-authored by Stripe and Tempo, built on HTTP 402 with a Challenge / Credential / Receipt model. Covers protocol design, client (payer) integration, server (payee) middleware, MCP server monetization, service discovery, method selection (Tempo, EVM/x402-compatible, Stripe Shared Payment Tokens, Lightning, and other rails), security review, and testing. USE THIS SKILL whenever the user: - Asks about MPP, the Machine Payments Protocol, paymentauth.org, mpp.dev, or mpp-specs - Wants to add pay-per-request/agentic pricing to an API using the `mppx` package - Integrates MPP with Express, Hono, Next.js, Elysia, or a plain fetch/Request-Response server - Builds an AI agent or coding agent that pays for tools/APIs autonomously via MPP - Implements an MCP server with payment-gated tools using the MPP JSON-RPC/MCP transport - Needs to choose or implement a payment method (Tempo, EVM/Permit2/EIP-3009
-
mashharuki Bundle X402 DevComprehensive development support for x402 protocol — the open HTTP payment standard built on HTTP 402. Covers client (buyer) integration, server (seller) middleware, MCP server monetization, and AWS CloudFront/Lambda@Edge deployments. USE THIS SKILL whenever the user: - Asks about x402, HTTP 402 payments, or machine-to-machine micropayments - Wants to add pay-per-request pricing to an API, endpoint, or HTTP resource - Integrates x402 with Express, Next.js, Hono, FastAPI, Flask, or any HTTP framework - Builds an AI agent that pays for tools/APIs automatically (agentic commerce) - Implements an MCP server with payment-gated tools - Deploys x402 on AWS CloudFront, Lambda@Edge, or AgentCore - Needs wallet setup, facilitator config, EVM/Solana network configuration, or USDC payments - Asks about Bazaar service discovery, x402 whitepaper concepts, or x402 architecture - Migrates from testnet (Base Sepolia) to mainnet (Base Mainnet / Solana Mainnet) Even if the user just says "add payments to my API", "charge per A
-
microsoft Bundle Create SiteCreates a new Power Pages code site (SPA) using React, Angular, Vue, or Astro. Guides through the full process from initial concept to deployed site: requirements discovery, scaffolding, component planning, design, implementation, validation, and deployment. Use when the user wants to create, build, or scaffold a new Power Pages website or portal.
2.7k -
huytieu Skill Generate PrdGenerate product requirements documents with optional publishing to Confluence or other wiki platforms
-
talont-org Skill Make ReqDecompose a task, plan, roadmap, or feature description into a structured set of requirements grouped for independent planning. Use when user says "make req", "make requirements", "decompose requirements", "extract requirements", or wants to break down a task into what needs to be true.
-
mashharuki Bundle Erc8004 Trustless AgentsERC-8004(Trustless Agents)準拠のスマートコントラクト開発を包括的に支援するスキル。 ブロックチェーンを活用した事前信頼不要のAgent発見・レピュテーション・検証プロトコルの 設計・実装・テスト・デプロイをカバー。 3つのレジストリ(Identity / Reputation / Validation)、ERC-721ベースのAgent ID、 階層的信頼モデル(レピュテーション / ステーク担保 / zkML / TEE)、 マルチチェーンデプロイ(35+ネットワーク)、ERC-8183 Agentic Commerce連携、 A2A/MCPプロトコル統合、UUPSアップグレーダブル実装まで完全対応。 Use when building AI agent discovery systems, implementing ERC-8004 or EIP-8004, creating agent identity registries, building reputation systems for AI agents, implementing validation registries, integrating agent trust mechanisms, or working with trustless agent protocols. Also use when the user mentions agent discovery, agent reputation, agent validation, trustless agents, identity registry, reputation registry, validation registry, A2A protocol integration, MCP tool registration, or asks about on-chain agent identity and trust infrastructure.
-
microsoft Bundle Ensure Pipelines HostEnsures the tenant has a usable Power Platform Pipelines host environment before any pipeline operation runs. Detects host state via the same resolution order as the Power Apps UI (org-db setting → BAP env metadata → default-custom-host setting); if any existing host (Platform or Custom) is found, uses it. If no host is bound to the source env, provisions a new **Platform Host** (recommended, idempotent) or a **Custom Host** via the BAP env-create API with the `D365_ProjectHost` template, or guides the user through PPAC install / `New custom host` (manual fallbacks). Polls lifecycle operations, verifies the host responds to Pipelines API calls, writes a host-check artifact other ALM skills consume. Use when asked to: "set up pipelines host", "ensure pipelines host", "no pipelines host", "install pipelines", "create pipelines host", "provision platform host", "provision custom host". Also invoked transparently by /power-pages:setup-pipeline when its host discovery step finds nothing.
2.7k -
amhuppert Bundle Create RequirementsCreate a PRD / product requirements document with app summary, design principles, and detailed requirements.
-
microsoft Skill Generate Native ExtensionRead the approved PRD.md and generate the native sources for a third-party PAM control (the compiled `.ppmplugin` track) — iOS Obj-C `<Pascal>Module` plus optional system-frameworks podspec, Android Kotlin `<Pascal>Module` with build.gradle, AndroidManifest and ReactPackage, a dev-only private package.json (react + react-native devDeps for the builds), and the committed `./manifest.json` dispatch contract the PCF and build stage both read. No TypeScript INativeExtension layer — the contract is the manifest plus the native modules' dispatch surface. Emits the layout in shared/repo-layout.md and generates substantially complete native code (compiled later by /build-android-binary and /build-ios-binary, not here). Local only — writes files, runs no git and touches no remote or feed. PCF is generated by /generate-pcf-companion; the bundle is built by /generate-ppmplugin.
2.7k -
microsoft Skill Design Native Extension FeatureCapture a 2-3 line pitch from the user, draft a product overview (PRD.md) and a technical design (ARCHITECTURE.md) for a third-party `.ppmplugin` native control, then walk through every operation's iOS + Android implementation strategy with opinionated recommendations (library choice, hosting, key APIs, edge cases) and capture the agreed spec in ARCHITECTURE.md §3.<n>. The depth of ARCHITECTURE.md is what lets the scaffold skill generate complete working code instead of TODO placeholders. Iterates with the user until they approve both docs. Optionally seeds from a design doc / FRD URL. PRD.md + ARCHITECTURE.md are the source of truth for every downstream skill (generate, build, assemble). Run this BEFORE any code is generated.
2.7k -
talont-org Skill Exp Lens Governance RiskCreate a risk register and stakeholder impact assessment for experiments with deployment implications. Governance lens answering "What risks arise from acting on this result?"
-
georgekhananaev Bundle SEO PlanStrategic SEO planning for new or existing websites. Industry-specific templates, competitive analysis, content strategy, and implementation roadmap. Use when user says "SEO plan", "SEO strategy", "SEO planning", "content strategy", "keyword strategy", "content calendar", "site architecture", or "SEO roadmap".
Frequently asked questions
What are Product & Planning agent skills?
Product & planning agent skills structure the thinking side of building: specs, PRDs, user stories, roadmaps, and prioritization frameworks. Install one and your AI agent produces planning documents with the same rigor and format every time.
Which Product & Planning skills are most installed?
Popular Product & Planning skills on SkillMD right now include project-planning, Managing Backlog, ensure-pipelines-host. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Product & Planning skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.