Product & Planning
Product & planning agent skills structure the thinking side of building: specs, PRDs, user stories, roadmaps, and prioritization frameworks. Install one and your AI agent produces planning documents with the same rigor and format every time.
-
ninjasln-labs Skill Prd Driven DddTransform product design documents (PRDs, flowcharts, prototypes, state machines, rules/AC) into a domain-driven design model: per-context ubiquitous language/glossary, event storming, bounded contexts and mapping, aggregates/entities/value objects, domain events and versioned integration events (Name:vN), read models, PRD-model traceability. Use when the user asks for DDD, domain modeling, event storming, aggregate design, bounded context mapping, versioned integration events, read models/CQRS, or PRD-driven strategic/tactical design. Also supports scenario-driven validation (post-modeling user scenario checks) and continuous ubiquitous-language management (term-to-code consistency, anti-drift).
-
ninjasln-labs Bundle Jobs To Be DoneUncover customer jobs, pains, and gains in a structured JTBD format. Use when clarifying unmet needs, repositioning a product, or improving discovery and messaging.
-
ninjasln-labs Bundle Prd DevelopmentPRD development: build a structured Product Requirements Document that connects problem, users, solution, and success criteria. Use when turning discovery notes into an engineering-ready document for a major initiative or feature.
-
ninjasln-labs Bundle Roadmap PlanningPlan a strategic roadmap across prioritization, epic definition, stakeholder alignment, and sequencing. Use when turning strategy into a release plan that teams can execute.
-
ninjasln-labs Bundle Problem StatementWrite a user-centered problem statement with who is blocked, what they are trying to do, why it matters, and how it feels. Use when framing discovery, prioritization, or a PRD.
-
ninjasln-labs Skill Discovery Interview PrepPlan customer discovery interviews with the right goal, segment, constraints, and method. Use when preparing interviews for problem validation, churn research, or new product ideas.
-
cwinvestments Skill Memstack Product Mvp ScoperUse this skill when the user says 'MVP', 'minimum viable product', 'scope the MVP', 'what should I build first', 'strip to core', or needs to define the smallest build that validates a product hypothesis. Do NOT use for full PRDs or roadmap planning.
Audited -
cwinvestments Skill Memstack Product Prd WriterUse this skill when the user says 'PRD', 'product requirements', 'requirements document', or needs a complete engineering-ready PRD with problem statement, personas, MoSCoW features, and success metrics. Do NOT use for single feature specs or user story backlogs.
Audited -
yuniorglez Bundle Scrum ConductorSenior Agile Facilitator & Delivery Architect for 2026. Specialized in AI-enhanced Scrum orchestration, automated ticket management, and high-velocity sprint coordination. Expert in utilizing LLMs to synthesize daily updates, detect blockers before they arise, and maintain a high-integrity backlog across GitHub Issues, Jira, and linear.
-
ynitto Skill Codd Gateドキュメント・コード・テストの一貫性を機械的に維持する codd-gate(CoDD 流用の決定的ゲート。agent-project から完全独立で単体で CI/git hook から使え、連携時は state repo の共通チェックから呼ぶ)を運用するスキル。「ドキュメントとコードの整合を常にとって」「一貫性ゲートを入れて」「ドリフトを backlog に積んで」「接続マップを作って」「未文書化・未テストを棚卸しして」「done 前にドキュメント置き去りを止めて」などで発動する。単発のドリフト調査レポートが欲しいだけなら doc-drift-detector を使う。
-
ynitto Bundle Backlog Planneragent-project の charter(プロジェクト憲章)と観点メモを、人がレビューできる粒度のバックログへ分解するプランナー向けスキル。各タスクに why・作業概要・受入基準チェックリスト(acceptance)・規模感を必ず書かせ、既存タスクと墓標を入力に取って重複を出さない。agent-project の plan から呼ばれる。
-
ynitto Skill Doc Coauthoring[ユーザーとの対話必須] 仕様書・提案書・設計ドキュメント・RFC・ADR などをユーザーと共同執筆するワークフロースキル。「仕様書を作って」「提案書を書いて」「設計ドキュメントを作成して」「PRDを書いて」「RFCを書いて」「ADRを書いて」などで発動する。
-
ynitto Bundle Backlog Verifieragent-project のタスクを「受入基準チェックリスト × 証跡」で検証する検証エージェント向けスキル。1 行のシェルコマンドの exit 0 を done の唯一の根拠にする方式をやめ、基準ごとに実行時にコマンドを試行錯誤して充足を確かめ、証跡付きの判定レポートを返す。agent-project の settle(verifier)から呼ばれる。
-
hwj123hwj Skill To PrdTurn the current conversation context into a PRD (Product Requirements Document). Use when user wants to create a PRD, write product requirements, or formalize a feature specification.
-
hwj123hwj Bundle ImplementImplement a piece of work based on a PRD or set of issues.
-
vinayaklatthe Skill Defender EasmGuidance for Microsoft Defender External Attack Surface Management (Defender EASM) — discovers and inventories an organization's internet-facing assets (domains, hosts, IPs, SSL certs, ASNs, web pages, contacts) from the outside-in. Covers seed-based discovery, attack surface insights (CVEs, expiring certs, deprecated tech, unsanctioned cloud), labels and groups, integration with Defender for Cloud (CSPM), Defender XDR, and Sentinel, and pricing model (per asset). WHEN: Defender EASM, external attack surface management, internet-facing inventory, shadow IT discovery, expired SSL discovery, exposed RDP discovery, unknown subdomain, attack surface insights, seed-based discovery, outside-in scanning, third-party asset risk, M&A asset discovery. DO NOT USE for internal asset discovery (use defender-for-cloud-hardening / Defender XDR), endpoint vuln scan (use defender-for-endpoint MDVM), or Sentinel hunting alone.
Audited -
vinayaklatthe Skill Purview AI HubGuidance for Microsoft Purview AI Hub (now part of Data Security Posture Management for AI) — discover, govern, and protect sensitive data flowing into AI applications (Microsoft 365 Copilot, Copilot Studio agents, ChatGPT, Gemini, third-party generative AI). Covers AI app discovery via Defender for Cloud Apps + endpoint signals, sensitive data risk surface, ready-to-use policies for Copilot oversharing and risky AI usage, DLP for generative AI endpoints (browser blocking), prompt/response auditing, integration with IRM (risky AI usage), Sentinel reporting, and difference vs Defender for Cloud AI workload protection. WHEN: Purview AI Hub, DSPM for AI, AI app discovery, ChatGPT data leakage, Gemini DLP, generative AI risk, prompt audit, Copilot Studio agent governance, sensitive data to AI, shadow AI, agent data risk. DO NOT USE for Defender for Cloud's AI workload protection (use defender-for-cloud-ai), Azure AI Content Safety (use azure-ai-content-safety), or Microsoft 365 Copilot rollout (use copilot-for-m3
-
vinayaklatthe Skill Defender For IotGuidance for Microsoft Defender for IoT — agentless OT/ICS network detection and response for industrial environments, plus enterprise IoT (EIoT) protection integrated with Defender XDR. Covers OT sensor deployment (physical/virtual, SPAN/TAP), Purdue model alignment, on-premises management console, cloud-managed sensors, EIoT (printers, cameras, VoIP) discovered through MDE, asset inventory, vulnerability data, threat intelligence, and integration with Sentinel and Defender XDR. WHEN: Defender for IoT, OT security, ICS security, SCADA monitoring, Purdue model network security, OT sensor deployment, SPAN port monitoring, enterprise IoT discovery, unmanaged device protection, factory floor security, NDR for OT, ICS threat detection, IoT asset inventory. DO NOT USE for IoT Hub data-plane security (Azure platform), Azure Sphere device hardening, or generic endpoint EDR (use defender-for-endpoint).
Audited -
vinayaklatthe Skill M365 OversharingGuidance for remediating oversharing across Microsoft 365 (SharePoint, OneDrive, Teams, Exchange) using the Secure & Governed Data Foundation blueprint - a three-pillar program (remediate oversharing, set up guardrails, meet regulations) built on SharePoint Advanced Management data access governance, sensitivity and container labels, secure-by-default labelling, Restricted Access Control, and Microsoft Purview. WHEN: Microsoft 365 oversharing, M365 oversharing, secure and governed data foundation, oversharing blueprint, too many people have access to SharePoint, EEEU everyone except external users, tighten permissions, data access governance report, restricted content discovery, secure by default labels, prepare data foundation, reduce sharing link sprawl, governed data estate. DO NOT USE for Copilot-specific readiness framing only (use purview-copilot-oversharing) or building a broad DLP program (use purview-dlp-policy).
Audited -
vinayaklatthe Skill Security CopilotGuidance for Microsoft Security Copilot - the generative-AI security platform that helps analysts investigate, hunt, summarise, and respond using natural language, plugins, promptbooks, and embedded experiences. Covers SCU provisioning, plugins, promptbooks, governance, and the standalone vs embedded experience choice. WHEN: Microsoft Security Copilot, AI for SOC, security copilot units SCU, promptbooks, Copilot plugins, natural language investigation, summarise incident with AI, Copilot for Security setup, how do I use AI in my SOC, explain a KQL query with AI, summarise an alert for a stakeholder. DO NOT USE when the goal is configuring autonomous triage or remediation agents (use security-copilot-agents).
Audited -
vinayaklatthe Skill Defender For Cloud AIGuidance for Microsoft Defender for Cloud — AI workload protection (AI-SPM and runtime threat detection for generative AI). Covers AI Security Posture Management (discovery of Azure OpenAI / Azure AI Foundry / Amazon Bedrock / Google Vertex AI resources, identification of grounding data exposure, model deployment posture), runtime threat detection on Azure OpenAI (prompt injection / jailbreak attempts, sensitive data leakage in prompts/responses, wallet abuse, credential leakage), integration with Azure AI Content Safety Prompt Shields, attack path analysis for AI workloads, alert investigation in Defender XDR, and pairing with Purview DSPM for AI (user side) and Azure AI Content Safety (model side). WHEN: Defender for Cloud AI, AI-SPM, AI workload protection, Azure OpenAI threat detection, prompt injection alert, jailbreak alert Azure OpenAI, AI wallet abuse, AI workload posture, Amazon Bedrock posture, Vertex AI posture, generative AI security Azure. DO NOT USE for end-user AI usage governance (use purview-
-
vinayaklatthe Skill Defender For Cloud AppsGuidance for Microsoft Defender for Cloud Apps (MDA) — the CASB for SaaS discovery, app governance, session controls, and threat detection. Covers Cloud Discovery via Defender for Endpoint integration, OAuth app governance, Conditional Access App Control (reverse-proxy session policies), and SaaS security posture (SSPM). WHEN: Defender for Cloud Apps, MDA, CASB, shadow IT discovery, cloud app governance, OAuth app risk, session control, Conditional Access App Control, SaaS security posture management, SSPM, sanction or unsanction app, Cloud App Catalog, app connectors. DO NOT USE for IaaS / PaaS posture (use defender-for-cloud-hardening), endpoint EDR (use defender-for-endpoint), or DLP (use purview-dlp-policy).
Audited -
vinayaklatthe Skill Defender For ContainersGuidance for Microsoft Defender for Containers — Kubernetes and container security across AKS, Azure Arc-enabled Kubernetes, EKS, GKE, and OpenShift. Covers agentless discovery, agentless vulnerability assessment for images and running containers (powered by Microsoft Defender Vulnerability Management), runtime threat detection via the Defender sensor (eBPF on Linux), Kubernetes data plane hardening with Azure Policy / Gatekeeper, registry scanning for ACR / ECR / GAR, admission control, attack path analysis, and Sentinel integration. WHEN: Defender for Containers, AKS security, container runtime threat detection, Kubernetes admission control, image vulnerability scanning, ACR scan, EKS GKE security in Defender for Cloud, K8s posture, container attack path, Defender container sensor, Gatekeeper Azure Policy AKS, agentless container scan. DO NOT USE for VM/host hardening (use defender-for-servers), AKS networking design (use azure-network-security-design), or general AKS day-2 ops unrelated to security.
Audited -
vinayaklatthe Skill Entra Workload IdentityGuidance for Microsoft Entra workload identities — managed identities, service principals, and workload identity federation. Covers system-assigned vs user-assigned managed identity, federated credentials (GitHub Actions, Azure DevOps, Kubernetes, other OIDC issuers) to eliminate secrets, Workload Identities Premium (Conditional Access for workloads, risk detection, lifecycle reviews), credential hygiene (no client secrets where federation works), least-privilege RBAC, and integration with Defender for Cloud / Microsoft Entra Permissions Management. WHEN: managed identity, system-assigned identity, user-assigned identity, service principal hardening, workload identity federation, GitHub OIDC to Azure, Azure DevOps OIDC, AKS workload identity, kill client secrets, federated credential, Workload Identities Premium, Conditional Access for workloads, non-human identity governance, NHI, app registration hardening. DO NOT USE for user/human identity (use entra-id), permissions discovery across clouds (use entra-per
-
vinayaklatthe Skill Copilot For M365 ReadinessGuidance for safely deploying Microsoft 365 Copilot — end-to-end readiness covering oversharing remediation, SharePoint Advanced Management (SAM) restricted sites and content discovery, sensitivity label coverage, Purview DLP for Copilot, Restricted SharePoint Search (RSS) interim safeguard, site lifecycle and ownership, Copilot interaction auditing, Copilot in Defender XDR alerts, prompt-shield risks, licensing prerequisites, and a phased rollout that doesn't surface confidential data on day one. WHEN: M365 Copilot rollout, Copilot oversharing remediation, SAM, SharePoint Advanced Management, Restricted SharePoint Search, RSS Copilot, sensitivity labels Copilot, DLP for Copilot, Copilot audit, safe Copilot deployment, Copilot pilot, prevent Copilot data leakage. DO NOT USE for tenant-wide oversharing program design (use m365-oversharing), Purview DSPM for AI alone (use purview-dspm-ai), or Microsoft Foundry agent security (use microsoft-agent-365).
Audited -
vinayaklatthe Skill Entra Global Secure AccessGuidance for Microsoft Entra Global Secure Access (GSA) — Microsoft's Security Service Edge (SSE) combining Entra Internet Access (SWG/Secure Web Gateway) and Entra Private Access (ZTNA replacement for VPN). Covers client deployment (Windows, macOS, iOS, Android), traffic forwarding profiles (Microsoft, Internet, Private), Conditional Access for network traffic, source IP restoration, app discovery, Quick Access and per-app access for Private Access, connector deployment, branch site connectivity (IPSec), TLS inspection, and Universal CA integration. WHEN: Entra Global Secure Access, GSA, Microsoft SSE, Entra Internet Access, Entra Private Access, ZTNA Microsoft, replace VPN with ZTNA, secure web gateway Entra, Conditional Access on network, source IP restoration, Quick Access app, Private Access connector, branch IPSec to Microsoft, GSA client rollout. DO NOT USE for general Conditional Access policy design (use conditional-access-mfa), Azure VPN/ExpressRoute design, or third-party SSE (Zscaler/Netskope) con
-
vinayaklatthe Skill Purview Copilot OversharingGuidance for assessing and remediating oversharing before and during Microsoft 365 Copilot adoption, using SharePoint Advanced Management (SAM), sensitivity labels, restricted content discovery, and DLP for Copilot so Copilot only surfaces content users should access. Covers data access governance reports, EEEU cleanup, and ongoing governance. WHEN: Copilot oversharing, prepare data for Copilot, restrict Copilot access, SharePoint Advanced Management, data access governance, oversharing remediation, Copilot readiness data security, limit Copilot content, Copilot is surfacing files users should not see, too many people have access to SharePoint sites, tighten up permissions before Copilot rollout, how do I make SharePoint Copilot-ready. DO NOT USE when the goal is monitoring what sensitive data users are actively sending in AI prompts (use purview-dspm-ai).
Audited -
vinayaklatthe Skill Purview Information GovernanceGuidance for an end-to-end Microsoft Purview information governance / information protection strategy - sequencing classification, labelling, protection, lifecycle, and risk into a coherent program aligned to the Zero Trust data pillar. Covers maturity-based rollout sequencing, ownership, and metrics. WHEN: information governance, information protection strategy, data protection program, sequence Purview rollout, MIP strategy, protect and govern data end to end, Zero Trust data pillar program, Purview roadmap, data security maturity.
Audited -
cleanexpo Skill Senior Saas PmAct as a Senior Project Manager with 15 years of SaaS delivery experience — advising, creating deliverables, and managing the full lifecycle from discovery through renewal. Triggers on: project plan, implementation plan, sprint planning, risk register, stakeholder update, SOW, resource plan, go-live, project charter, retrospective, change request, escalation, budget tracking, RACI, governance, release plan, data migration, QA strategy, UAT, cutover, capacity planning, velocity, burndown, kickoff, lessons learned, or any request involving running a SaaS project. Also triggers on casual asks like "we're behind schedule", "the client is unhappy", or "how should I run this project?" If someone is managing or delivering software — this is the skill.
Audited -
frankxai Bundle Loop DesignerCompile a goal into a durable, file-backed agent loop — a .loop/<name>/ charter any coding agent (Claude Code, Codex, Gemini, Grok) can execute unattended. Use when the user wants to "build a loop", "design a loop", "run X continuously/24-7", "make an agent keep working on Y", automate recurring work, or convert a big backlog into autonomous iteration. Produces LOOP.md + state.json + backlog.md, ready for loop-runner.
-
frankxai Skill Product Management ExpertProduct management expertise for strategy, discovery, prioritization, roadmaps, PRDs, metrics, and stakeholder communication. Use when defining what to build, why, and how to measure success.
-
aaronjmars Skill Idea ForgeThree-mode idea engine - generate collides the week's zeitgeist with what you can ship into scored wedges; validate viability-screens the idea backlog; memo writes evidence-backed startup memos.
-
aaronjmars Skill Idea PipelineExecution-gap audit - cross-references the startup idea backlog against shipped skills, prototypes, and cross-repo PRs, surfacing the top 3 ideas to build next by narrative and operator fit.
-
panaversity Bundle GtmActivate for: go to market, GTM, GTM strategy, go-to-market, ICP, ideal customer profile, target customer, who to sell to, channel strategy, sales channel, how to acquire customers, customer acquisition, outreach strategy, LinkedIn outreach, cold email, sales process, sales funnel, pricing strategy, price point, pricing tiers, positioning statement, positioning, how to position, first customers, early adopters, 90-day plan, launch plan, customer success, onboarding, retention. NOT for: customer discovery (use discovery), competitive analysis (use market), unit economics (use financials), pitch deck (use pitch).
-
panaversity Bundle IdeaActivate for: idea, brainstorm, ideate, 100 ideas, idea generation, idea sprint, new product idea, innovation sprint, what should I build, what problem should I solve, idea evaluation, idea scoring, idea shortlist, pressure test idea, devil's advocate, adjacent possible, contrarian ideas, analogy ideas, crazy ideas, how might we, HMW, pivot idea, new venture concept. NOT for: customer discovery or interview synthesis (use discovery), assumption mapping (use hypothesis), pitch deck (use pitch).
-
panaversity Bundle SprintActivate for: sprint, innovation sprint, agile, sprint plan, sprint goal, sprint backlog, user story, acceptance criteria, definition of done, sprint review, sprint retrospective, velocity, iteration, two-week sprint, sprint planning, what to build this sprint, backlog prioritisation, story points, mid-sprint check, sprint close, assumption update, learning sprint. NOT for: idea generation (use idea), assumption mapping (use hypothesis), pilot results analysis (use validate).
Frequently asked questions
What are Product & Planning agent skills?
Product & planning agent skills structure the thinking side of building: specs, PRDs, user stories, roadmaps, and prioritization frameworks. Install one and your AI agent produces planning documents with the same rigor and format every time.
Which Product & Planning skills are most installed?
Popular Product & Planning skills on SkillMD right now include prd-driven-ddd, jobs-to-be-done, prd-development. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Product & Planning skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.