Product & Planning
Product & planning agent skills structure the thinking side of building: specs, PRDs, user stories, roadmaps, and prioritization frameworks. Install one and your AI agent produces planning documents with the same rigor and format every time.
-
greglas75 Bundle Refactor RadarSelect refactor candidates with immutable git measurements, evidence-backed module families and temporary collision checks. Use for ranked refactor/test-debt triage, not implementation. DISCOVER saves reports without changing product code; REGISTER requires validated decisions. Worktree names are hints, test LOC is not coverage, and discovery scores are not execution priorities.
-
greglas75 Skill Security AuditApplication security audit covering OWASP Top 10, injection, XSS, SSRF, auth/authz, multi-tenant isolation, secrets, headers, dependencies, business logic, infrastructure, and AI/LLM + MCP tool-invocation security (S15, incl. tool poisoning and confused-deputy). Uses Sentry 3-tier confidence model. Supports Next.js, NestJS, Express, FastAPI, Django, Flask. Dual scoring: static posture + runtime exploitability. Flags: zuvo:security-audit [path] | full | --live-url <url> | --static | --quick | --persist-backlog
-
greglas75 Skill Container AuditStatic Docker/container security audit across 6 dimensions (K1-K6): base image provenance and pinning, privilege and runtime hardening, secret and build-context hygiene, image minimalism and attack surface, known-vulnerability scan (Trivy/Grype), and compose/orchestration hardening. Static-first — parses Dockerfile, Containerfile, and docker-compose (incl. override/merge files) with zero Docker and zero network; the CVE dimension (K5) runs Trivy/Grype only when present, else degrades to N/A. Reserved dimensions K7-K10 (Kubernetes) activate behind --k8s. HEALTHY/NEEDS ATTENTION/AT RISK/CRITICAL grade with critical gates. Distinct from infra-audit (live host daemon over SSH) and ci-audit (Docker build speed in the pipeline). Switches: zuvo:container-audit full | [path] | --static | --scan | --dockerfile <p> | --compose <p> | --quick | --k8s | --persist-backlog
-
greglas75 Skill Performance AuditFull-stack performance health check across 12 dimensions. Rendering, bundles, assets, API/network, algorithms, memory, database, caching, Web Vitals, backend runtime, concurrency, and framework-specific pathologies. Evidence-based Impact Models with confidence tiers and a prioritized optimization roadmap. Switches: zuvo:performance-audit full | [path] | [file] | --frontend | --backend | --db | --bundle
-
owl-listener Skill Audit StoriesAudit user stories for disability inclusion. Chains: inclusive-user-stories, edge-case-identification. Use when reviewing an existing backlog, sprint, or set of user stories to check whether they account for diverse abilities.
1.7k -
owl-listener Skill Stakeholder CommunicationCommunicate accessibility decisions, requirements, and value to stakeholders who aren't accessibility specialists. Use when presenting accessibility work to leadership, product managers, engineers, or anyone who needs to understand why accessibility decisions matter. Triggers on: stakeholder, business case, justify accessibility, explain accessibility, leadership, executive, ROI, why accessibility, cost of accessibility, persuade, convince, accessibility presentation.
1.7k -
owl-listener Skill Accessibility Debt TrackingTrack and manage accessibility debt — known accessibility issues that have been deferred. Use when managing a backlog of accessibility issues, planning remediation, or when accessibility problems are accumulating faster than they're being fixed. Triggers on: accessibility debt, tech debt, known issues, backlog, deferred, we'll fix it later, remediation, accessibility backlog, accumulating issues, regression.
1.7k -
wedabro Skill Speckit BacklogBacklog Manager - Manage Ideas, Pending Requests and scan TODO/FIXME from codebase.
-
wedabro Skill Speckit RoadmapRoadmap Strategist - Manage high-level roadmaps (Milestones) and transitions between Phases.
-
5dive-ai Skill TldrCompress a long channel, call, thread, or document into the few lines that change what someone does next — decisions made, things now owed and by whom, and what is still open — with everything that changes no decision cut. Use this for "catch me up on this channel", "summarize this call", "what happened in this thread while I was out", "read this 90-page doc and tell me what matters", or any backlog of unread material someone has to act on.
Audited -
5dive-ai Bundle Ticket TriageWork a support inbox end to end — read every ticket, separate a real defect from a bad day, decide refund or no refund against a stated policy, and write the reply that ends the thread instead of extending it. Use this for "work through my support queue", "is this a bug or a user error", "should I refund this", "draft a reply to this angry customer", "why is my queue growing", chargeback and dispute triage, duplicate-ticket merging, or any inbox of customer complaints someone has to answer. Also use when the ask is about the QUEUE rather than one ticket: backlog age, first-response time, or which tickets are one bug wearing forty faces.
-
5dive-ai Skill Channel DiscoveryMap marketing channels for a target audience, score each on 5 criteria (audience fit, speed, cost, effort, learning value), and recommend the top 3 to prioritize.
Audited -
5dive-ai Skill Community DiscoveryDiscover 100+ online communities across Reddit, Slack, Discord, Facebook, LinkedIn, and forums, scored by Signal-to-Noise ratio.
Audited -
5dive-ai Skill Competitor DiscoverySearch the web for competitors based on product category, produce a ranked list of direct, adjacent, and tangential competitors.
-
5dive-ai Skill Influencer DiscoveryDiscover 100+ influencers across YouTube, X/Twitter, blogs, newsletters, podcasts, and Instagram — scored by Audience Overlap.
Audited -
genfeedai Bundle Email FinderFind and verify contact emails associated with a domain using free discovery methods first and APIs when keys are available. Triggers on domain email scans, contact discovery, email pattern finding, and email enrichment.
-
genfeedai Bundle Leads ResearcherResearch prospect accounts, company data, decision makers, contact details, and buyer intent signals. Triggers on lead research, account research, prospect enrichment, decision-maker discovery, tech stack research, and buying signals.
-
devinchen2014 Bundle Media SearchSearch social media content by keyword for social research, competitor research, topic discovery, content planning, market observation, and trend scanning. This version is backed by hosted platform MCP services and supports Xiaohongshu / XHS / RedNote, Douyin, Kuaishou, Bilibili, Zhihu, Instagram, X / Twitter, YouTube, TikTok, Weibo, and WeChat Channels.
-
sananthanarayan Bundle Prd DraftDraft a Product Requirements Document from a feature idea or brief — evidence-backed problem statement with zero solution language, testable MoSCoW-prioritized requirements, mandatory non-goals, and a success line per goal. Use when the user needs a PRD, wants to capture business requirements for a feature, or asks to turn an idea, pitch, or brief into a requirements doc.
-
sananthanarayan Bundle Okr CascadeCascade company OKRs to team-level OKRs — with a gap registry for objectives no team credibly owns, and a causal metric tree connecting each team KR to the north-star it's supposed to move. Use when the user wants to set or cascade OKRs, align team goals to company goals, "turn strategy into quarterly objectives", or audit existing OKRs for gaps and vanity metrics.
-
sananthanarayan Bundle Incident CommsDraft audience-segmented updates during a live incident — customer status-page posts, internal stakeholder updates, and exec notifications — each leading with user-facing impact, never speculative cause or ETA, always naming the next-update time. Use when an incident is in progress and the user needs a status page post, customer notification, internal update, exec brief, or the resolved/all-clear message.
-
sananthanarayan Bundle Audience ProfileTranslate an audience type (exec, board, technical, sales, investor, internal, partner, customer) into structural rules — slide count, density, tone, must-have sections, things to avoid. Reusable across deck-builder, slide-outliner, and exec-summary. Use whenever a stakeholder communication deliverable is being designed for a specific audience.
-
sananthanarayan Bundle User Story SplitterSplit an epic, feature request, or PRD chunk into independently shippable user stories with testable Gherkin acceptance criteria and a recommended build order. Use whenever the user wants to "break this down", turn an epic or PRD into a backlog, slice a feature for sprint planning, or write acceptance criteria for a story.
-
sananthanarayan Bundle Requirements InterviewGenerate per-stakeholder interview kits for feature discovery — ≤7 questions per stakeholder ranked by how much the answer changes the design, each naming the decision it informs, with at least one disconfirming question per script and an assumptions-to-validate ledger. Use when the user is gathering business requirements, preparing stakeholder or user interviews, or asks "what should I ask the sponsor/users/ops before we build this".
-
swiftpostlabs Bundle Ref Sp Web Social MediaDecide whether and how a site or brand should invest in social and video platforms (TikTok, YouTube, Instagram, LinkedIn, X) for organic discovery — separating what the platforms and independent research actually document from the large layer of agency folklore, and measuring it honestly inside walled-garden analytics. Use when: asked whether to be on TikTok/YouTube/Instagram for reach, how discovery or in-app search works on a platform, whether outbound links hurt reach, how younger audiences find things, how social content shows up in Google, or judging a social-strategy claim or agency deck.
-
swiftpostlabs Skill Tool Sp Handle Agents Local TasksRead the local `.agents/tasks/` workspace — the `TODO.md` notes list and the tracked task folders under `10-new/`, `20-open/`, `90-closed/` — choose the next actionable item, and work it through with code changes, validation, folder moves, and status updates. Use when: the user asks to check `.agents/tasks/TODO.md`, continue remaining local tasks, or process the repo's local agent-task backlog.
Audited -
whyashthakker Bundle Creator DiscoveryBuilds a creator sourcing strategy and discovery brief for influencer campaigns, ambassador programs, UGC pipelines, and affiliate recruitment. Use when the user asks to find creators, shortlist influencers, define creator criteria, map audience fit, source creators by niche or platform, or turn a campaign goal into a practical discovery workflow. Best suited for Infloq-powered creator search and campaign sourcing.
-
breverdbidder Bundle Exa DiscoveryExa Discovery
-
breverdbidder Bundle Directory SubmissionsWhen the user wants to submit their product to startup, SaaS, AI, agent, MCP, no-code, or review directories for backlinks, domain rating, and discovery. Also use when the user mentions "directory submissions," "submit to directories," "backlinks from directories," "list my product," "submit to Product Hunt," "BetaList," "TAAFT," "Futurepedia," "G2 listing," "Capterra listing," "AlternativeTo," "SaaSHub," "AI directories," "MCP registry," "agent directory," "dofollow backlinks," "launch directories," or "directory tracker." Use this whenever someone is planning the directory layer of a product launch or an ongoing backlink campaign. For the broader launch moment, see launch. For programmatic SEO pages that should live behind these backlinks, see programmatic-seo. For AI citation optimization, see ai-seo.
-
marcioaltoe Bundle CouncilOrchestrates multi-advisor council debates on high-impact architecture, technology, or product decisions. Dispatches 3-5 domain archetype subagents (pragmatic-engineer, architect-advisor, security-advocate, product-mind, devils-advocate, the-thinker) through opening statements, tensions, position evolution, and synthesis phases. Preserves dissent and delivers actionable recommendations with captured risks. Use when evaluating trade-offs, stress-testing a PRD or tech spec, resolving dilemmas with multiple viable options, or when a decision needs diverse expert perspectives. Don't use for simple yes/no questions, factual lookups, creative brainstorming without tradeoffs, or tasks where a single expert perspective suffices.
-
marcioaltoe Bundle Write PrdWrite a PRD as a durable local artifact at docs/specs/<slug>/_prd.md — research first, clarify with one multiple-choice question at a time, record decisions as ADRs, then write directly without draft-approval rounds.
-
marcioaltoe Bundle Write IdeaExpand a raw product idea into a research-backed spec at docs/specs/<slug>/_idea.md — targeted questions, parallel codebase + market research, business-viability scoring, council debate, and an opportunity scan before drafting. The _idea.md feeds write-prd.
-
marcioaltoe Skill QA GateExecute the self-contained final QA gate as a Spec's authored terminal `qa` Task — derive a resumable QA matrix from the PRD and task evidence, execute real user flows through every declared surface, probe high-risk user behavior, capture auditable evidence, classify findings by user impact, and write the spec-local dated QA report. Do not use as a substitute for implementation tests or a broad standalone QA knowledge base.
-
marcioaltoe Skill BrainstormingYou MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design through one question at a time, then routes the outcome to write-idea, write-prd, write-techspec (refactors/bug fixes), or a direct task.
-
marcioaltoe Bundle Exa Web SearchDeep research powered by Exa. Use for lead generation, literature reviews, deep dives, competitive analysis, or any query where one search falls short, including phrases like 'research this', 'find everything about', 'find me all', or 'deep dive on'.
-
marcioaltoe Skill Setup Context DrivenAdopt, update, or verify a repository's Context-Driven Baseline through the public Roundfix Baseline Command. Use when preparing a repository for the write-prd/write-tasks/implement pipeline, changing its Baseline Profile, preserving existing instructions, restoring its Repository Skill Set, or confirming that Baseline-owned content is current.
Frequently asked questions
What are Product & Planning agent skills?
Product & planning agent skills structure the thinking side of building: specs, PRDs, user stories, roadmaps, and prioritization frameworks. Install one and your AI agent produces planning documents with the same rigor and format every time.
Which Product & Planning skills are most installed?
Popular Product & Planning skills on SkillMD right now include refactor-radar, security-audit, container-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Product & Planning skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.