Product & Planning
Product & planning agent skills structure the thinking side of building: specs, PRDs, user stories, roadmaps, and prioritization frameworks. Install one and your AI agent produces planning documents with the same rigor and format every time.
-
aiunlocked1412 Bundle UX Designerออกแบบ UX ตั้งแต่ discovery, IA, user flow, wireframe, prototype จนถึง usability test สำหรับเว็บและแอป
-
haomingz Bundle Idea To Prd一句话需求生成完整产品需求文档(PRD),包含用户故事、功能清单、MoSCoW优先级排序和验收标准。当用户提及编写PRD、产品需求文档、需求分析,或使用如“帮我把这个想法写成PRD”、“这个需求帮我细化一下”、“帮我拆解功能点”、“写用户故事”、“排优先级”、“定验收标准”等具体请求时触发。
-
haomingz Bundle Okr PlannerOKR 制定/拆解/复盘教练。当用户提到以下场景时触发:OKR、目标管理、关键结果、OKR制定、OKR拆解、OKR复盘、OKR检查、OKR对齐、季度目标、objectives and key results、目标拆解、KR制定、OKR评分、OKR改进。即使用户只是说'帮我写个OKR''这个OKR写得好不好''帮我复盘一下这个季度的OKR''目标怎么拆解',也应触发。
-
haomingz Bundle Audience Adapter向上汇报与跨部门沟通助手,根据受众角色(CEO、VP、技术负责人或运营)自动调整信息粒度、语言风格和侧重点,生成邮件、汇报要点或文档。当用户提到向上汇报、跨部门沟通、stakeholder update、executive summary、管理层汇报、给老板/VP/CEO写邮件简报、技术团队同步、运营侧对齐、写汇报材料或项目进展同步时触发。
-
haomingz Bundle User Story Canvas将产品需求可视化为交互式HTML用户故事地图,按Epic → Feature → Story三层结构组织,支持MoSCoW优先级色标和版本发布划线分组。当用户提到用户故事地图、story mapping、需求地图、epic feature story、backlog可视化、MoSCoW优先级、release planning、版本规划地图、产品路线图可视化,或直接说“帮我画一张故事地图”、“把需求按版本排列出来”时触发。
-
haomingz Bundle Work Report Writer从零散的工作记录和 git log 生成结构化的周报或月报,支持数据导向、叙事型和 OKR 对齐等多种汇报风格。当用户提到周报、月报、工作总结、weekly report、monthly report、sprint summary、迭代总结、写周报、写月报、OKR 进展汇报,或需要把散乱的工作记录整理成结构化报告时触发。
-
haomingz Skill Glab Workitems列出和管理 GitLab 工作项(任务、OKR、关键结果、史诗)。适用于使用标准 Issue 之外的 GitLab 工作项类型。触发词:work items、任务、OKR、关键结果、史诗列表、工作项列表。
-
gianlucanaarden Skill AI Okr CoachVertaalt elke ambitie, doelstelling, kwartaalplanning of strategische richting naar scherpe Objectives en Key Results in de Andy Grove en John Doerr stijl. Gebruik deze skill ALTIJD wanneer iemand zegt "schrijf OKRs", "stel OKRs op", "OKR framework", "objectives and key results", "kwartaaldoelen", "stretch goals", "Measure What Matters", "Doerr methodiek", "Intel OKR", "Google OKR", "team doelen formuleren", "wat zijn mijn key results", "hoe meet ik dit doel", "mijn doelen zijn vaag", of "ik wil ambitieuzer plannen". Trigger ook bij "kwartaalplanning maken", "jaarplan vertalen naar acties", "outcome over output", "ik weet niet of dit een Objective of een Key Result is", of wanneer een ondernemer of team van vage intenties naar meetbare uitkomsten wil. Niet gebruiken voor pure to do lijsten of taakbeheer (dat is uitvoeringsniveau).
Audited -
uphiago Skill Web2 ReconWeb2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis (LinkFinder, SecretFinder), continuous monitoring (new subdomain alerts, JS change detection, GitHub commit watch). Use when starting recon on any web2 target or when asked about asset discovery, subdomain enum, or attack surface mapping.
-
uphiago Skill Okta AttackOkta-as-IdP red-team attack chain — tenant discovery, user enumeration (multiple vectors), authentication flow analysis (factors enumeration, push-notification fatigue, SMS bypass), password spray with lockout discipline, Okta-specific phishing primitives (kits, FastPass abuse, OIDC redirect_uri tampering), MFA enumeration, post-compromise admin API surface. Many enterprise orgs use Okta instead of (or alongside) Entra ID. Distinct endpoints, distinct rate-limiting, distinct factor flows. Use when recon shows `<tenant>.okta.com`, `<tenant>.okta-emea.com`, `<tenant>.oktapreview.com`, or autodiscover-style records pointing at Okta IdP.
Audited -
uphiago Skill Hunt FirebaseHunt Firebase / Firestore / GCP exploitation — Firebase API key discovery in JS bundles, anonymous auth via signUp endpoint, Firestore collection enumeration with anon key, Realtime Database read/write without auth, Firebase Storage bucket listing, Firebase Hosting detection, GCP service account JSON exploitation, IAM policy enumeration from leaked SA keys. Built from field experience where Firebase API keys in JS bundles unlocked full Firestore read-access on 12+ targets including healthcare platforms and delivery apps. Use when a JS bundle, APK, or .env file reveals a Firebase API key (AIzaSy...) or when target uses firebaseio.com / firestore.googleapis.com endpoints.
-
uphiago Skill Hunt SupabaseHunt Supabase exploitation — Supabase anon key discovery in JS bundles, REST API table enumeration with anon key, Row Level Security (RLS) bypass via missing organization_id check, RPC function abuse returning cross-organization data, Storage bucket listing, Auth signUp/signIn with anon key, multi-tenant enumeration via WHOIS, bucket file upload/download without auth. Built from field observation of Lovable.dev + Supabase stack on rapidly-built platforms where RLS policies are consistently misconfigured. Use when a JS bundle, .env, or APK reveals a Supabase URL (project.supabase.co) and anon key (eyJ...).
Audited -
uphiago Skill Hunt SharepointHunt Microsoft SharePoint Server (2013/2016/2019/Subscription Edition) on-prem farms — anonymous endpoint enumeration, version disclosure, legacy SOAP login bypass (Authentication.asmx), ToolShell precondition chain (CVE-2025-53770), SafeControl reflection enumeration via Picker.aspx, NTLM Type-2 AD topology disclosure, custom-branding module discovery, EoL farm permanent-CVE-window exploitation, FormDigest anonymous issuance, file-extension blocklist NOT-an-oracle pattern, custom-zone Forms auth bridging on-prem AD. Use when target has SharePoint headers (SPRequestGuid, X-MS-InvokeApp, X-SharePointHealthScore, MicrosoftSharePointTeamServices) or paths (/_layouts/15/, /_vti_bin/, /_api/, /_catalogs/).
Audited -
uphiago Bundle Offensive OsintOperational arsenal for authorized external red-team and bug-bounty recon. Concrete probes, wordlists, regexes, dorks, curl one-liners for: subdomain enum, GraphQL/Swagger/REST discovery, identity fabric (Entra/Okta/ADFS/Google/SAML/M365 deep — Teams/SharePoint/OneDrive), cloud bucket enum (S3/GCS/Azure), CDN/WAF bypass, origin discovery, vendor fingerprinting (Citrix/F5/Pulse/Fortinet/PaloAlto/Cisco/VMware), CI/CD exposure, 48-pattern secret-scan catalog, Postman workspaces, breach correlation, TLS/JA3 audit, secret triage. Detail content in 15 modular reference files. Use for any authorized recon: scoping, asset discovery, attack-path mapping, secret triage, severity scoring.
Audited -
uphiago Skill Bb Local ToolkitComplete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning, vuln hunting (30+ classes), A-to-B chaining, AI/LLM testing, bypass tables, language-specific grep, reporting. Use for ANY bug bounty task.
Audited -
uphiago Bundle Hunt Source LeakHunt source code and build artifact leakage — JavaScript source maps (.js.map) reconstructing TypeScript/ES6 source, Swagger/OpenAPI JSON endpoint discovery, .env/.git exposure, webpack chunks with hardcoded secrets, robots.txt/security.txt recon, build-info files, asset-manifest.json API route discovery, .DS_Store file listing. Use at the START of every recon session — these findings often unlock the entire attack surface.
Audited -
uphiago Skill Origin Ip DiscoveryDiscover origin IPs behind CDN/WAF via favicon hash, DNS history, and SSL certs.
Audited -
uphiago Bundle Osint MethodologyComprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments. Covers the 5-stage recon pipeline (seed discovery, asset expansion, enrichment, exposure analysis, reporting), asset-graph discipline with 29 asset types, severity rubric (CRITICAL/HIGH/MEDIUM/LOW/INFO), confidence upgrade workflows, time budgeting, asset-level triage rules, scale-based tactics, identity-fabric mapping (Entra/Okta/ADFS/Google/SAML/M365 Teams+SharePoint+OAuth), API and auth-map methodology, JavaScript deep analysis, mobile attack surface, cloud attack surface, breach×identity correlation, detectability tagging, detection-aware probing (back-off, persona rotation), read-only validator discipline, WAF/CDN bypass + origin discovery, vulnerability prioritization (CVE/EPSS/KEV), phishing infrastructure planning + pretext development, bug bounty submission templates, client deliverable templates with risk translation, threat-actor investigation (incl. RU/CN pivots), cryptocurrency tracing, ima
-
uphiago Skill Wp Plugin Cve HuntSystematic approach to finding and testing CVEs for identified WordPress plugins. Covers plugin discovery, version extraction from multiple sources (readme.txt, assets, inline JS), CVE database cross-referencing with WPScan/Patchstack/NVD/NVD API, version-based vulnerability matching, exploitation PoC generation, and false-positive elimination. Built from field experience finding exploitable plugin CVEs across 58-company mass recon including ElementsKit (CVE-2023-6851/CVE-2023-6853), Revslider (CVE-2024-2534), WPDM (CVE-2023-49753), Gravity Forms (CVE-2024-6115), and Jetpack (CVE-2024-1782).
Audited -
uphiago Skill Port Service DiscoveryNmap scan for MySQL, Redis, FTP, SSH, internal API services.
Audited -
archsightlabs Bundle Cogx PrdPRD 生成 / PRD writing。生成最小产品需求文档,用于目标用户、核心假设、MVP 范围、验证实验和停止条件。
-
archsightlabs Skill Prd WritingPRD 写作 / PRD writing。用于产品需求、用户问题、范围、验收标准、指标、发布风险和研发交接。
Audited -
archsightlabs Bundle Cogp Grove高输出技术管理(格鲁夫) / High-output engineering management (Grove)。用于战略拐点、十倍力、管理杠杆、OKR、任务成熟度、会议机制和组织执行。
-
build-with-dhiraj Skill To PrdTurn the current conversation context into a PRD and publish it to the project issue tracker. Use when user wants to create a PRD from the current context.
Audited -
build-with-dhiraj Bundle Product ManagementFounder-PM toolkit: discovery, roadmaps, prioritization, PMF measurement. Use for product strategy or roadmaps.
-
gianlucanaarden Skill AI Mom Test CoachToetst elke interviewvraag aan de drie regels van The Mom Test van Rob Fitzpatrick, geeft per vraag een oordeel met kleurlabel, herschrijft de zwakke vragen naar feitelijke varianten en levert per scenario drie doorvraagopties plus een verplichte complimentcheck. Gebruik deze skill ALTIJD wanneer iemand zegt "mom test", "Rob Fitzpatrick", "klantinterview", "customer interview", "validatiegesprek", "discovery gesprek", "mijn vragenlijst checken", "goede vragen stellen aan klanten", "hoe valideer ik mijn idee", "iedereen zegt dat het een goed idee is", "hoe weet ik of ze het echt zouden kopen", "vragenlijst voor marktonderzoek", "intakevragen verbeteren", "sales discovery vragen", "waarom koopt niemand terwijl iedereen enthousiast is" of "welke vragen moet ik stellen". Trigger ook bij founders die een product valideren, bij sales discovery, marktonderzoek, intakegesprekken en customer success calls, en bij iedereen die een script of vragenlijst voorlegt waarin naar meningen of naar de toekomst wordt gevraagd. N
-
gianlucanaarden Skill AI Smart Doelen CoachZet vage voornemens om naar volledig uitgewerkte SMART doelen. Gebruik deze skill wanneer iemand zegt "ik wil meer omzet", "ik wil gezonder leven", "ik wil groeien", of een ander vaag doel heeft. Trigger ook bij: doel stellen, doelen schrijven, SMART, KPI opstellen, target formuleren, jaarplan, kwartaaldoel, teamdoel, persoonlijk doel, nieuwjaarsvoornemen, OKR key result schrijven, voornemen concreet maken, plan formuleren, of wanneer iemand een doel heeft dat geen deadline of meetpunt heeft. De skill stelt per SMART-criterium een gerichte vraag en bouwt het antwoord om naar een heldere, volledig uitgeschreven SMART-zin met toelichting.
Audited -
gianlucanaarden Skill AI Rice PrioriteringPast de RICE prioriteringsmethode toe op een lijst features, projecten, taken, ideeen of initiatieven. RICE staat voor Reach, Impact, Confidence en Effort. Berekent voor elk item een objectieve score met de formule (Reach x Impact x Confidence) / Effort en levert een geprioriteerde lijst op met onderbouwing. Gebruik deze skill ALTIJD wanneer iemand zegt "wat moet ik eerst doen", "help me prioriteren", "RICE", "RICE scoring", "RICE framework", "rice prioritering", "rice score", "prioritisatie framework", "roadmap prioriteren", "welke feature eerst", "ik heb te veel ideeen", "objectief kiezen", "scoring model", "product roadmap kiezen", "feature prioritering", "Sean McBride", of "Intercom prioritering". Trigger ook bij een lijst projecten of features zonder duidelijke volgorde. Niet gebruiken voor pure urgentie sortering (gebruik dan Eisenhower) of voor stop-go beslissingen op een enkel project (gebruik dan pre-mortem of inversie).
Audited -
gianlucanaarden Skill AI Kano Model AnalistAnalyseert product features via het Kano Model van Noriaki Kano. Categoriseert elke functie als basisfeature, prestatiefeature, wow feature, neutrale feature of omgekeerde feature en koppelt er een prioriteit en ontwikkelactie aan. Gebruik deze skill ALTIJD wanneer iemand zegt "kano model", "kano analyse", "feature prioriteren", "welke features eerst", "wat moet in mijn MVP", "product roadmap", "must have versus nice to have", "wat is een delighter", "klanttevredenheid model", "noriaki kano", "feature classificatie" of "wow factor product". Trigger ook bij product managers die kiezen tussen features, bij MVP scope discussies, bij roadmap planning, bij surveys voor klantonderzoek en bij het opzetten van een Kano vragenlijst (functional plus dysfunctional vraag). Niet gebruiken voor algemene SWOT of generieke prioritering, daarvoor zijn andere skills.
Audited -
gianlucanaarden Skill AI Spin VerkoopgesprekBereid verkoopgesprekken voor, oefen ze en evalueer ze volgens de SPIN-methode van Neil Rackham (SPIN Selling, 1988): Situatievragen, Probleemvragen, Implicatievragen en Nutvragen, in die vaste volgorde, zodat de klant zijn koopbehoefte zelf verwoordt voordat jij je oplossing noemt. Gebruik deze skill ALTIJD wanneer iemand zegt 'bereid mijn verkoopgesprek voor', 'spin verkoopgesprek', 'spin selling', 'discovery call voorbereiden', 'demo voorbereiden', 'salesgesprek oefenen', 'ik pitch te vroeg', 'de klant haakte af na mijn prijs', 'hoe stel ik betere vragen in een klantgesprek', 'rollenspel verkoopgesprek', of 'maak een gespreksverslag van dit salesgesprek'. Ook triggeren wanneer er een belangrijk klantgesprek voorligt bij een complex product of een complexe dienst. Niet gebruiken voor het schrijven van offertes (AI Offerte Schrijver), voor prijsonderhandelingen (AI Onderhandelaar) of voor klantinterviews zonder verkoopdoel (AI Mom Test Coach).
Audited -
gianlucanaarden Skill AI Backcasting StrateegPast Backcasting toe op elk doel, plan of toekomstvisie. In plaats van vooruit voorspellen vanuit vandaag, start de skill bij een gewenste toekomst en redeneert daar stap voor stap terug naar nu. Gebruik deze skill ALTIJD wanneer iemand een ambitieus doel heeft, een visie wil omzetten naar een pad, of wanneer voorspellend plannen vastloopt op huidige beperkingen. Trigger ook bij "ik weet niet hoe ik daar moet komen", "mijn doel is te groot", "backcasting", "back casting", "reverse roadmap", "future back planning", "start bij het eindpunt", "hoe kom ik in 10 jaar bij X", "ik wil een visie naar acties vertalen", of "mijn plan voelt incrementeel niet ambitieus genoeg". Gebaseerd op het werk van John B. Robinson (1982, University of Waterloo, energy futures) en Karl-Henrik Robèrt (1989, The Natural Step framework, sustainability planning).
Audited -
gianlucanaarden Skill AI Moscow Prioritering CoachSorteert eisen, features, taken en ideeen in Must Have, Should Have, Could Have en Won't Have this time volgens de MoSCoW methode van Dai Clegg, zoals gebruikt in DSDM. Doel is een haalbare scope voor een release, sprint, MVP of project, met een expliciete Won't lijst die scope creep voorkomt. Gebruik deze skill ALTIJD wanneer iemand zegt "MoSCoW", "Moscow methode", "Must Should Could Wont", "must have should have", "prioriteer mijn backlog", "wat moet er in de MVP", "release plannen", "sprint plannen", "scope bepalen", "scope creep", "te veel features", "wat kan eruit", "stakeholders willen alles tegelijk", of een lijst eisen of taken plakt met de vraag wat erin moet. Niet gebruiken voor een fijnmazige ranking binnen een categorie (gebruik dan RICE), voor pure urgentie sortering (gebruik dan Eisenhower) of voor een go of no go beslissing op een enkel project (gebruik dan pre-mortem of inversie).
Audited -
grandamenium Skill MCP IntegrationIntegrate Model Context Protocol (MCP) servers with Claude Code agents. Covers server setup, tool discovery, and multi-server orchestration.
-
grandamenium Skill M2c1 WorkerYou need to build software autonomously — a new project, a major feature, or any structured development task. You will act as the 'human' supervisor for a dedicated M2C1 worker session, managing it through all 12 phases: provide the brain dump, answer discovery questions, configure tools and credentials, monitor progress via bus messages and git, validate the output, and clean up when done. Use when the work is large enough to warrant a dedicated isolated build session.
Audited -
grandamenium Skill Tool DiscoveryDiscover, research, and CONNECT the tools a tool-agnostic personal assistant needs — email, calendar, contacts, meeting notes, messaging, CRM. CLI-first, research-driven, verified. Use during setup and whenever a workflow fails because a tool is missing or not authed.
-
spike-faye-lei Bundle Autosci InitBootstrap ΩmegaWiki from user sources plus optional discovery, then ingest the final paper set in parallel
Frequently asked questions
What are Product & Planning agent skills?
Product & planning agent skills structure the thinking side of building: specs, PRDs, user stories, roadmaps, and prioritization frameworks. Install one and your AI agent produces planning documents with the same rigor and format every time.
Which Product & Planning skills are most installed?
Popular Product & Planning skills on SkillMD right now include ux-designer, idea-to-prd, okr-planner. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Product & Planning skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.