Product & Planning
Product & planning agent skills structure the thinking side of building: specs, PRDs, user stories, roadmaps, and prioritization frameworks. Install one and your AI agent produces planning documents with the same rigor and format every time.
-
zyrexnn Skill Bug Bounty 2Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI), LLM/AI security testing (chatbot IDOR, prompt injection, indirect injection, ASCII smuggling, exfil channels, RCE via code tools, system prompt extraction, ASI01-ASI10), A-to-B bug chaining (IDOR→auth bypass, SSRF→cloud metadata, XSS→ATO, open redirect→OAuth theft, S3→bundle→secret→OAuth), bypass tables (SSRF IP bypass, open redirect bypass, file upload bypass), language-specific grep (JS prototype pollution, Python pickle, PHP type juggling, Go template.HTML, Ruby YAML.load, Rust unwrap), and reporting (7-Question Gate, 4 validation gate
-
zyrexnn Bundle Offensive Osint 2Operational arsenal for authorized external red-team and bug-bounty recon. Concrete probes, wordlists, regexes, dorks, curl one-liners for: subdomain enum, GraphQL/Swagger/REST discovery, identity fabric (Entra/Okta/ADFS/Google/SAML/M365 deep — Teams/SharePoint/OneDrive), cloud bucket enum (S3/GCS/Azure), CDN/WAF bypass, origin discovery, vendor fingerprinting (Citrix/F5/Pulse/Fortinet/PaloAlto/Cisco/VMware), CI/CD exposure, 48-pattern secret-scan catalog (AWS/GCP/GitHub/Stripe/Slack/Anthropic/OpenAI/Atlassian/DataDog/npm/PyPI), Postman workspaces, breach correlation (HudsonRock/HIBP/DeHashed/IntelX), TLS/JA3 audit, certificate transparency, JS endpoint extraction, package registry leaks, mobile/APK recon, sat imagery, sector-specific recon (healthcare DICOM, finance SWIFT, ICS/SCADA Modbus/BACnet). Detail content in 15 modular reference files, loaded on demand. Use for any authorized recon: scoping, asset discovery, attack-path mapping, secret triage, severity scoring.
-
zyrexnn Skill Bb Local Toolkit 2Local-tooling companion to the bug-bounty orchestrator — carries the SAME complete bug-bounty workflow, but reach for THIS variant when you also need to resolve where tools, wordlists, and clones are installed on the local machine (jhaddix, SecLists, trufflehog, ffuf, dalfox, ghauri); for pure orchestration/routing use the bug-bounty skill. Workflow it covers — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI), LLM/AI security testing (chatbot IDOR, prompt injection, indirect injection, ASCII smuggling, exfil channels, RCE via code tools, system prompt extraction, ASI01-ASI10), A-to-B bug chaining (IDOR→auth bypass, SS
-
zyrexnn Skill Hunt Source Leak 2Hunt source code and build artifact leakage — JavaScript source maps (.js.map) reconstructing TypeScript/ES6 source, Swagger/OpenAPI JSON endpoint discovery, .env/.git exposure, webpack chunks with hardcoded secrets, robots.txt/security.txt recon, build-info files, asset-manifest.json API route discovery, .DS_Store file listing. Use at the START of every recon session — these findings often unlock the entire attack surface.
-
zyrexnn Bundle Osint Methodology 2Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments. Covers the 5-stage recon pipeline (seed discovery, asset expansion, enrichment, exposure analysis, reporting), asset-graph discipline with 29 asset types, severity rubric (CRITICAL/HIGH/MEDIUM/LOW/INFO), confidence upgrade workflows, time budgeting, asset-level triage rules, scale-based tactics, identity-fabric mapping (Entra/Okta/ADFS/Google/SAML/M365 Teams+SharePoint+OAuth), API and auth-map methodology, JavaScript deep analysis, mobile attack surface, cloud attack surface, breach×identity correlation, detectability tagging, detection-aware probing (back-off, persona rotation), read-only validator discipline, WAF/CDN bypass + origin discovery, vulnerability prioritization (CVE/EPSS/KEV), phishing infrastructure planning + pretext development, bug bounty submission templates, client deliverable templates with risk translation, threat-actor investigation (incl. RU/CN pivots), cryptocurrency tracing, ima
-
fufankeji Bundle Prd Writer 2生成符合行业标准的产品需求文档(PRD / Product Requirements Document)。当用户提到"写 PRD / 产品需求文档 / 需求文档 / 功能规约 / 产品规约 / spec / 写需求 / 整理需求 / 把想法变成 PRD / 把头脑风暴结果落成需求文档 / 写 product spec / 把脑暴结论沉淀成文档"等场景时务必调用。输出 14 章结构化 PRD,支持 Brainstorming → PRD → TRD 的 Vibe Coding 工作流。中文优先,AI Agent 友好。即使用户没明确说"用 Skill",只要任务沾边产品需求文档撰写都要调用。
-
fufankeji Bundle Claude Md Bootstrap 2Generate or refresh a project root CLAUDE.md by READING the project's existing documentation (PRD / architecture decisions / constitution / DESIGN.md / package.json) and producing a 200-line index that follows 2026 Anthropic best practices (WHAT/WHY/HOW framework, @path progressive disclosure, sparse use of YOU MUST/IMPORTANT) AND embeds Karpathy's 4 coding behavior principles (Think Before Coding / Simplicity First / Surgical Changes / Goal-Driven Execution). Use this whenever the user says "帮我写 CLAUDE.md", "项目需要 CLAUDE.md", "生成项目 CLAUDE.md", "refresh CLAUDE.md", "bootstrap CLAUDE.md", "把 PRD 整理进 CLAUDE.md", or asks how to make Claude Code understand their project's tech stack, architecture, conventions, and workflows. ALSO use this skill even when the user does not explicitly mention CLAUDE.md — as long as they want Claude Code to consistently understand their project's structure and rules, this skill applies. Do NOT use for a brand new empty project that has no documentation yet (in that case the user need
-
fufankeji Bundle Product Research Kickoff 2把"任何 0→1 新产品的立项前期调研"打包成"4 路并行 + 双引擎验证 + 1 路收敛"的标准化引导流程。通过苏格拉底式提问从用户抽取项目骨架,自动生成可直接喂给 Claude Code Task 工具的 4-agent 并行调研提示词。用于个人/小团队启动新项目时的产品立项调研、技术选型前的事实摸底、PRD 写作前的输入材料准备。触发关键词:新项目立项 / 产品调研 / 立项调研 / 项目可行性调研 / 帮我调研一个新想法 / 我想做个 X 怎么开始调研 / 把想法变成调研计划 / 调研同类竞品 / 摸底数据来源 / 摸底开源生态 / kickoff research / product research / 0 to 1 research。即使用户没明确说"用 Skill",只要任务沾边"新产品立项前的事实摸底/竞品扫描/资源盘点/技术方案选型调研"都要调用。不用于:已经决定技术栈后的具体实现调研(那是 spec/plan 阶段)、纯学术研究(不是产品立项)、已有产品的迭代调研(用 brainstorming)。
-
ww-w-ai Skill Pm Discovery 2PM Agent Team — automated product discovery, strategy, and PRD generation with 4 PM agents (for a single feature). For multi-feature initiatives with shared scope/budget/timeline, use /sprint master-plan which generates a sprint-level PRD via sprint-master-planner agent (v2.1.13). Triggers: pm, PRD, product discovery
-
ww-w-ai Skill Bkit Templates 2PDCA + Sprint document templates — Plan, Design, Analysis, Report for individual features plus templates/sprint/{master-plan, prd, plan, design, iterate, qa, report}.template.md for sprint-level documents (v2.1.13). Triggers: template, plan document, design template
-
arasz Bundle Task 3Use when the user wants to start, continue, or finish a backlog task — "/task <id>", "start task X", "work on the next task", "finish this task". Runs it end-to-end as a token-tracked unit of work with low/high effort, plan packaging with mandatory integration package, MoE panels for high-effort, and automated task-ID derivation ({repo-alias}-{key}). Delegates planning/review to high-reasoning models and implementation to persona-routed agents. Project specifics from .ai-badger/config.json; source-control and PR behaviour from config-gated extensions.
-
arasz Bundle Welcome AI Badger 2Use when a repository should be set up with ai-badger — "welcome-ai-badger", "scaffold this project", "add agent instructions here", "onboard this repo" — whether it is new or already has agent files. Detects stacks, writes .ai-badger/, and generates each configured agent's discovery file.
-
eugenelim Bundle Init Project 2Use this skill to turn an idea into a structured new repo. It runs a trigger gate (throwaways and single scripts skip it), a value gate over fed-in discovery, records a foundation (an ADR plus a reference.md golden path), authors a walking-skeleton spec via new-spec and hands the build to work-loop, then hands off to the normal build loop. Triggers on "start a new project", "greenfield init", "idea to repo", "bootstrap a new codebase". Do NOT use inside an existing repo (use adapt-to-project) or to author one feature (use new-spec).
-
eugenelim Bundle Adapt To Project 2Use this skill to diagnose and improve an adopter repository's agent guidance or to walk through the four classes of post-install change (substitution, .upstream companion merges, discovery + restructuring, within-layout consolidation). Repository anchoring is marker-independent and read-only by default. Post-install adaptation still reads both scopes' state and marker files; class-1 substitution shells out to `agentbundle adapt`, while classes 2-4 write directly under the per-scope path-jail only after approval.
-
jeremylongshore Bundle Nixtla Test Generator 2Generate comprehensive pytest test suites from PRD functional requirements with fixtures, parameterization, and coverage tracking. Use when creating tests for new plugins, validating PRD requirements, or scaffolding test infrastructure. Trigger with 'generate tests from PRD', 'create test suite', or 'scaffold pytest tests'.
-
angelburgosrosado Bundle Domain Intel 2Passive domain reconnaissance using Python stdlib. Subdomain discovery, SSL certificate inspection, WHOIS lookups, DNS records, domain availability checks, and bulk multi-domain analysis. No API keys required.
-
aresbit Bundle Claudeception 2Claudeception is a continuous learning system that extracts reusable knowledge from work sessions. Triggers: (1) /claudeception command to review session learnings, (2) "save this as a skill" or "extract a skill from this", (3) "what did we learn?", (4) After any task involving non-obvious debugging, workarounds, or trial-and-error discovery. Creates new Claude Code skills when valuable, reusable knowledge is identified.
-
first-fluke Bundle Oma Market 2Market research skill for pain-point extraction, trend detection, competitor positioning, and discovery across community sources (Reddit, X, YouTube, TikTok, HN, Polymarket, GitHub, arXiv, Techmeme, Bluesky, web and more). Delegates research to the always-latest mvanhorn/last30days engine via `oma market run`, adds oma's detect-trap preflight, intent-auto SWOT / Porter's 5F / PESTEL framing, and a single LAW-compliant brief. Use for market research, pain point analysis, trend detection, competitor research, user complaints, voice-of-customer, 시장조사, 사용자 페인, 트렌드, 경쟁구도.
-
first-fluke Bundle Oma Architecture 2Architecture specialist for software/system design, module and service boundaries, tradeoff analysis, and stakeholder synthesis. Uses context-aware methods such as diagnostic routing, design-twice comparison, ATAM-style risk analysis, CBAM-style prioritization, and ADR-style decision records.
-
latestaiagents Skill A2a Protocols 2Implement Agent-to-Agent (A2A) communication for cross-framework interoperability. Use this skill when building multi-agent communication, implementing agent protocols, connecting agents across frameworks, or standardizing agent interfaces. Activate when: agent to agent, A2A, agent communication, agent protocol, cross-framework agents, agent interoperability, MCP, agent discovery.
-
justcyl Bundle Lark Okr 2飞书 OKR:管理目标与关键结果。查看和编辑 OKR 周期、目标(Objective)、关键结果(Key Result)、对齐关系、量化指标。当用户需要查看或创建 OKR、管理目标和关键结果、查看对齐关系时使用。
-
ww-w-ai Skill Control 2Control bkit automation level (L0-L4), view trust score, and manage guardrails. Trust level directly drives SPRINT_AUTORUN_SCOPE (v2.1.13): L0 manual+stopAfter=prd, L4 full-auto+stopAfter=archived. Also gates PDCA phase transitions and destructive operations. Triggers: control, automation level, trust score, guardrail
-
ww-w-ai Skill Plan Plus 2Brainstorming-enhanced PDCA planning with intent discovery and YAGNI review. For a single feature's plan use /plan-plus; for grouping multiple features under one scope/budget see /sprint master-plan (v2.1.13). Triggers: plan-plus, brainstorm, plan plus, intent
-
ww-w-ai Skill Bkit Explore 2Browse installed bkit skills, agents, and evals via lib/discovery/explorer.js (filesystem scan, no subprocess). Triggers: bkit explore, list skills, skill discovery, browse skills
-
ravnhq Bundle Test Plan Gen 2Generate professional QA Test Plan documents (.docx or .pdf) from a structured interview. Trigger on "create/write a test plan", "I need a test plan", "prepare QA documentation", /testplan, or when a user uploads a PRD/requirements and wants a test plan generated.
-
manusco Skill Update Roadmap 2<!-- Generated by Resonance Forge. -->
-
mintuz Bundle Status Updates 2WHEN drafting a status update, progress report, sprint summary, or launch update for a manager, exec, team, or stakeholder in Slack, email, or a doc; NOT for PR descriptions, commit messages, or meeting minutes; runs intake, grounds every claim in supplied evidence, and returns a scannable, honest update with named recognition.
-
mintuz Bundle Story Pr Orchestrator 2WHEN delivering an approved multi-story feature or several specs as dependency-gated pull requests; NOT for a single story, product discovery, or generic task delegation; coordinates one isolated task, worktree, branch, and PR per ready story.
-
k-dense-ai Bundle David Silver 2Applies the reasoning of David Silver, lead researcher on AlphaGo and AlphaZero at DeepMind, to problems of AI design, reinforcement learning, and open-ended discovery. Use this skill whenever you are designing AI systems, evaluating learning algorithms, balancing exploration vs. exploitation, choosing research problems, or discussing how to break past human performance ceilings. Reach for this whenever the user asks about self-play, Monte-Carlo Tree Search, tabula rasa learning, AGI, or moving from human-curated data to autonomous experience. It helps shift the focus from hardcoding human knowledge to building systems that learn for themselves.
30.2k -
k-dense-ai Bundle Daphne Koller 2Applies the reasoning style of Daphne Koller (machine learning pioneer, co-founder of Coursera, founder and CEO of Insitro). Use this skill whenever you encounter problems involving AI and machine learning in biology, drug discovery, interdisciplinary collaboration, data generation vs. data mining, or transitioning from academia to industry. Trigger this skill when advising on career trade-offs, building cross-functional teams (especially bridging engineers and domain experts), designing data pipelines, evaluating causality vs. correlation, or applying AI to physical systems ('where bits meet atoms'). Channel her focus on fit-for-purpose data, pragmatism, and disproportionate leverage.
30.2k -
k-dense-ai Bundle Demis Hassabis 2This skill channels the strategic and scientific reasoning of Demis Hassabis, CEO and co-founder of Google DeepMind, AlphaGo and AlphaFold, and 2024 Nobel Prize in Chemistry. Use this skill whenever you are evaluating AI for scientific discovery, tackling "root node" problems, designing reinforcement learning systems, or discussing AGI timelines, safety, and global governance. Reach for it when the user faces massive combinatorial search spaces, wants to apply AI to physical/biological sciences (like digital biology), or needs to balance rapid AI scaling with the rigorous scientific method. Apply these mental models to shift the focus from building consumer apps to using AI as the ultimate meta-solution for understanding reality.
30.2k -
caixinyu2017-star Bundle Light Idea Critique 2以顶刊/顶会审稿人标准严格判断 idea 是否真有突破,还是常规组合、套壳、概念堆叠、缺乏理论深度或实验支撑。当用户问"这个 idea 行不行/够不够创新/帮我挑刺",或 m03 产出 idea 后必须使用。先盲后明立标准、八维度加权打分、五视角对抗、反谄媚硬协议,给判决 + Revision Roadmap,引导回 m03。
-
byerlikaya Skill Brainstorm 2Divergent discovery BEFORE planning: turn a fuzzy ask into 2–4 scoped options + named unknowns, pick a direction, hand to spec-planning. Bounded; converges to explicit choices, never guesses.
-
ferroxlabs Skill Expense Analyzer 2Spending pattern identification and expense optimization through subscription auditing, fixed vs variable cost analysis, cost-per-use calculations, lifestyle inflation detection, comparison to median spending by category, and savings opportunity discovery. Use when the user asks about expense analyzer, or needs help with spending pattern identification and expense optimization through subscription auditing, fixed vs variable cost analysis, cost-per-use calculations, lifestyle inflation detection, comparison to median spending by category, and savings opportunity discovery. Do NOT use when the request requires professional financial advice or falls outside the scope of expense analyzer.
37 -
kok-o Skill Generators 3Generates complete project documentation (PRD, Architecture, Database, API, UI, Roadmap, Tasks) from ideas and templates with incremental update support.
-
lunchpaillola Bundle Pipa Roadmap 2Use only when `pipa-roadmap` is explicitly invoked or `pipa-define-work` delegates to it. Do not trigger from generic language.
Frequently asked questions
What are Product & Planning agent skills?
Product & planning agent skills structure the thinking side of building: specs, PRDs, user stories, roadmaps, and prioritization frameworks. Install one and your AI agent produces planning documents with the same rigor and format every time.
Which Product & Planning skills are most installed?
Popular Product & Planning skills on SkillMD right now include bug-bounty, offensive-osint, bb-local-toolkit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Product & Planning skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.