Product & Planning
Product & planning agent skills structure the thinking side of building: specs, PRDs, user stories, roadmaps, and prioritization frameworks. Install one and your AI agent produces planning documents with the same rigor and format every time.
-
tonone-ai Skill Keel ReconOperations reconnaissance — audit process documentation, vendor contracts, compliance posture, OKR health, and cross-functional friction points to understand where operations is the bottleneck. Use when asked to "audit our operations", "where are we slow", "what processes are broken", or "before designing a compliance program".
-
outlinedriven-odin-claude-plugin Bundle Drift DetectUse when roadmap, plans, or docs may have drifted from code, or when restarting a stalled project. Not for PR doc sync: use docs-update.
-
outlinedriven-odin-claude-plugin Bundle Idea SparkboxUse when the user asks to park ideas or inspiration for later. Not for code, backlog, or divergence-class cards, or remote, credential, publish, deploy, or irreversible changes.
-
tonone-ai Skill Crest ReconStrategic context reconnaissance — read existing roadmaps, OKRs, competitive docs, and briefs to establish context before planning. Use when asked to "understand our strategy", "what's the current roadmap", "what OKRs do we have", "strategic context", or before starting any prioritization or roadmap work.
-
tonone-ai Skill Forge ReconInfrastructure reconnaissance — inventory all cloud resources, map connections, flag risks. Use when asked to "inventory our infra", "what infrastructure do we have", "map our cloud resources", "infra discovery", or "what's running in our cloud".
-
tonone-ai Skill Keel ComplyBuild or audit compliance program — SOC2, GDPR, HIPAA, or ISO 27001 readiness assessment, gap analysis, and remediation roadmap. Use when asked to "do we need SOC2", "are we GDPR compliant", "what does our compliance program need", or "build a security policy".
-
outlinedriven-odin-claude-plugin Bundle Doc CoauthoringUse when drafting a doc, proposal, spec, RFC, design doc, decision doc, or PRD in chat. Not for reviewing an existing plan: use doc-review. No source or remote-system changes.
-
outlinedriven-odin-claude-plugin Bundle Git History AnalysisUse when the user asks about recent engineering work, what the team is working on, planning or roadmap material, or an explicitly requested Slack summary. Not for remote or irreversible changes.
-
tonone-ai Skill Zero DesignDesign a zero trust architecture — phased roadmap, identity pillar, and network segmentation. Use when asked to "design a zero trust architecture", "build a zero trust roadmap", or "plan network microsegmentation".
-
outlinedriven-odin-claude-plugin Bundle Github Backlog TriageUse when the user invokes backlog triage for a GitHub repo's open issues and PRs. Not for proactive triage, non-GitHub trackers, or single bug issues: use github-bug-report-triage.
-
outlinedriven-odin-claude-plugin Bundle To QuestionnaireUse when user wants an async questionnaire, a discovery questionnaire, or a knowledge gap needs answers outside the repo. Not for direct conversation: use askme. Not for agent research: use research.
-
outlinedriven-odin-claude-plugin Bundle Write Product SpecUse when a user asks for a product spec with invariants, a tech spec, or a PRD. Modes: product (default), technical, requirements. Not for task breakdown: use plan.
-
tonone-ai Skill Atlas PresentGenerate a polished HTML presentation page and Obsidian Canvas for big releases — new products, takeovers, major migrations. Non-technical audience. Use when asked to "present this", "release announcement", "show what we built", or "stakeholder update".
-
tonone-ai Skill Crest RoadmapBuild a product roadmap with sequenced bets and explicit tradeoffs. Use when asked to "build a roadmap", "prioritize the backlog strategically", "what do we build next quarter", "sequence our bets", "what should we focus on", or "product strategy for the next N months".
-
tonone-ai Skill Deal PlaybookWrite sales playbooks — outbound sequences, discovery call guides, objection handling scripts, and demo frameworks. Use when asked to "write a sales playbook", "build an outbound sequence", "help me handle objections", or "design a discovery call".
-
tonone-ai Skill Form CritiqueExpert 5-dimension design critique — philosophical, scored, actionable. Use when asked to "critique this design", "expert review", "score my design", "how does this look", "is this good design", "design feedback", or "review this UI". Different from /form-audit (which is technical QA for consistency/compliance) — form-critique evaluates design as a craft object: philosophy, hierarchy, execution, function, and innovation each scored 0–10 with a punch list. Add "as a report" or "give me a visual report" to produce an HTML file with SVG radar chart, evidence cards, and Keep/Fix/Quick-wins action lists — useful for design reviews and stakeholder presentations instead of CLI output.
-
outlinedriven-odin-claude-plugin Bundle Github Bug Report TriageUse when evaluating whether a bug issue has sufficient detail and identifying missing reporter information. Not for non-bug issues or backlog triage: use github-backlog-triage.
-
tonone-ai Skill Pave ContributeContribute a session learning back to the upstream tonone repo. Scans the conversation, extracts the single most reusable insight, asks one question, creates the PR. Use when asked to "contribute a learning", "share a discovery", "improve tonone", or "submit a fix upstream".
-
abelrguezr Bundle Burp MCP IntegrationSet up and use Burp Suite's MCP Server extension to enable LLM-assisted passive vulnerability discovery. Use this skill whenever the user wants to integrate Burp with MCP-capable AI tools (Codex, Gemini, Ollama, Claude), configure the MCP proxy, troubleshoot handshake issues, or analyze intercepted HTTP traffic for security findings. Trigger on mentions of Burp MCP, Burp AI Agent, MCP proxy setup, or LLM-assisted traffic review.
-
abelrguezr Bundle Timing AttacksHow to perform timing attacks on web applications to discover hidden parameters, headers, and scoped SSRFs. Use this skill whenever the user mentions timing analysis, response time differences, hidden attack surface discovery, race conditions, or wants to detect backend behavior through response latency. Make sure to use this skill for any web pentesting task involving parameter discovery, proxy detection, or when traditional methods aren't revealing the full attack surface.
-
abelrguezr Bundle Web Fuzzing WfuzzHow to use WFuzz for web application fuzzing and brute force testing. Use this skill whenever the user mentions web fuzzing, brute forcing login forms, directory enumeration, parameter discovery, header testing, cookie brute forcing, HTTP method testing, or any web application security assessment that involves testing multiple values against a target. Make sure to use this skill for any web penetration testing task that requires systematic testing of inputs, even if the user doesn't explicitly mention "fuzzing" or "brute force."
-
abelrguezr Bundle Cassandra PentestPentest Apache Cassandra databases. Use this skill whenever you need to enumerate, assess, or test Cassandra instances on ports 9042 or 9160. Trigger this skill for any Cassandra security assessment, database enumeration, credential discovery, or when you find open Cassandra ports during network reconnaissance. Don't forget to use this skill even if the user just mentions "Cassandra" or "9042" or "9160" in the context of security testing.
-
abelrguezr Bundle Unsupervised Learning SecurityApply unsupervised machine learning algorithms to security data for anomaly detection, clustering, and dimensionality reduction. Use this skill whenever the user needs to analyze unlabeled security data, detect unknown threats, cluster network events, reduce feature dimensions, or identify outliers in logs, traffic, or behavioral data. Trigger for tasks involving K-Means, DBSCAN, HDBSCAN, Isolation Forest, GMM, PCA, t-SNE, or any unsupervised pattern discovery in cybersecurity contexts.
-
abelrguezr Bundle Sap PentestingHow to perform authorized penetration testing on SAP systems. Use this skill whenever the user mentions SAP security testing, SAP penetration testing, SAP vulnerability assessment, SAP GUI testing, SAP web interface testing, SAP configuration review, or needs to assess SAP system security. This includes discovery, credential testing, configuration parameter analysis, and exploit research for SAP environments.
-
abelrguezr Bundle Ident PentestingPentest the Ident Protocol (port 113) to enumerate usernames associated with TCP connections. Use this skill whenever you need to identify users running services on a target, enumerate usernames for password attacks, or assess if a target has identd running. Trigger for any pentesting task involving port 113, user enumeration, connection ownership discovery, or when you want to build username lists for further attacks.
-
abelrguezr Bundle AI Fuzzing AssistantAI-assisted fuzzing and vulnerability discovery. Use this skill whenever the user wants to generate fuzzing seeds, evolve grammars, analyze crashes, create proof-of-vulnerability exploits, or generate patches for discovered bugs. Trigger on mentions of fuzzing, AFL++, libFuzzer, vulnerability discovery, crash analysis, exploit generation, or security testing with LLMs.
-
abelrguezr Bundle Opc Ua PentestingPentest OPC UA (Open Platform Communications Unified Access) industrial control systems. Use this skill whenever the user mentions OPC UA, industrial protocols, PLCs, SCADA systems, port 4840, or wants to assess OT/ICS security. This skill covers discovery, enumeration, vulnerability assessment, and exploitation of OPC UA servers including legacy security policy attacks and CVE exploitation.
-
abelrguezr Bundle Ipsec Ike Vpn PentestingPentest IPsec/IKE VPN services on UDP ports 500 and 4500. Use this skill whenever the user mentions VPN pentesting, IPsec testing, IKE vulnerability assessment, or needs to enumerate and exploit IPsec/IKE VPN gateways. Trigger for any task involving VPN discovery, transformation enumeration, PSK cracking, XAuth attacks, or IKEv2 exploitation. Don't wait for explicit "pentest" language - if they mention VPN, IPsec, IKE, or port 500/4500, this skill applies.
-
abelrguezr Bundle Saprouter PentestHow to pentest SAProuter (port 3299) for security assessments. Use this skill whenever the user mentions SAProuter, port 3299, SAP network penetration, SAP service discovery, or needs to enumerate/exploit SAP infrastructure. This skill covers Metasploit modules, CVE-2022-27668 exploitation, Nmap fingerprinting, and hardening recommendations. Make sure to use this skill for any SAP-related penetration testing, even if the user doesn't explicitly mention 'SAProuter' but describes SAP network access or port 3299 scanning.
-
abelrguezr Bundle Mdns PentestingMulticast DNS (mDNS) and DNS-SD pentesting skill. Use this whenever the user mentions mDNS, DNS-SD, service discovery, zeroconf, port 5353, .local domain, Avahi, Bonjour, AirPlay, printer spoofing, or any local network service discovery attacks. Trigger for network enumeration, service spoofing, MitM attacks, credential harvesting via mDNS, or defensive hardening of mDNS services. Make sure to use this skill for any local network reconnaissance involving service discovery protocols.
-
abelrguezr Bundle Drupal PentestHow to perform security assessments and penetration testing on Drupal websites. Use this skill whenever the user mentions Drupal, wants to enumerate a Drupal site, check for Drupal vulnerabilities, test Drupal security, or perform any kind of Drupal penetration testing. This includes version detection, user enumeration, module discovery, RCE exploitation, and post-exploitation activities on Drupal installations.
-
abelrguezr Bundle Tomcat PentestPerform Apache Tomcat security assessments including enumeration, vulnerability scanning, and exploitation. Use this skill whenever the user mentions Tomcat, Apache Tomcat, port 8080, web application manager, WAR file upload, or needs to assess a Java web server for security vulnerabilities. This skill covers discovery, version identification, credential testing, path traversal attacks, and RCE via manager access.
-
abelrguezr Bundle Snmp PentestPentest SNMP services on network devices. Use this skill whenever the user needs to enumerate SNMP (ports 161/162/10161/10162), discover community strings, extract system information from network devices (routers, switches, printers, IoT), or perform SNMP-based reconnaissance. Trigger for any request involving SNMP enumeration, community string discovery, OID queries, or network device information gathering.
-
abelrguezr Bundle Ws Discovery PentestingPentest WS-Discovery (Web Services Dynamic Discovery) services on UDP port 3702. Use this skill whenever you need to discover network services via multicast, probe for devices like IP cameras, printers, or other WS-Discovery enabled endpoints, or analyze WS-Discovery traffic. Trigger this skill for any network reconnaissance involving port 3702/UDP, service discovery attacks, or when investigating devices that use SOAP-based discovery protocols.
-
abelrguezr Bundle Cloudflare BypassHow to uncover and bypass Cloudflare protection to find origin server IPs or scrape protected websites. Use this skill whenever the user mentions Cloudflare bypass, origin IP discovery, WAF bypass, scraping protected sites, or needs to find real server IPs behind CDN protection. Trigger for any pentesting task involving Cloudflare, CDN bypass, or web scraping challenges with bot protection.
-
abelrguezr Bundle Lansweeper AssessmentSecurity assessment skill for Lansweeper IT asset management platforms. Use this skill whenever the user needs to assess Lansweeper deployments, harvest scanning credentials, decrypt stored secrets, abuse AD ACLs related to Lansweeper groups, or execute deployment-based RCE. Trigger on mentions of Lansweeper, IT asset discovery, scanning credentials, web.config decryption, deployment packages, or any Lansweeper-related attack surface during penetration testing or red team engagements.
Frequently asked questions
What are Product & Planning agent skills?
Product & planning agent skills structure the thinking side of building: specs, PRDs, user stories, roadmaps, and prioritization frameworks. Install one and your AI agent produces planning documents with the same rigor and format every time.
Which Product & Planning skills are most installed?
Popular Product & Planning skills on SkillMD right now include saprouter-pentest, burp-mcp-integration, timing-attacks. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Product & Planning skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.