Product & Planning
Product & planning agent skills structure the thinking side of building: specs, PRDs, user stories, roadmaps, and prioritization frameworks. Install one and your AI agent produces planning documents with the same rigor and format every time.
-
realwigu Bundle Cpo AdvisorProduct leadership for scaling companies. Product vision, portfolio strategy, product-market fit, and product org design. Use when setting product vision, managing a product portfolio, measuring PMF, designing product teams, prioritizing at the portfolio level, reporting to the board on product, or when user mentions CPO, product strategy, product-market fit, product organization, portfolio prioritization, or roadmap strategy.
-
realwigu Bundle Ciso AdvisorSecurity leadership for growth-stage companies. Risk quantification in dollars, compliance roadmap (SOC 2/ISO 27001/HIPAA/GDPR), security architecture strategy, incident response leadership, and board-level security reporting. Use when building security programs, justifying security budget, selecting compliance frameworks, managing incidents, assessing vendor risk, or when user mentions CISO, security strategy, compliance roadmap, zero trust, or board security reporting.
-
chen-yu723 Skill Find SkillsDiscover, search, and install Cursor Agent Skills from GitHub repositories or locally installed skill directories. Use when the user wants to find available skills, install a skill from GitHub using `npx skills add`, browse what skills are already installed, or asks about skill discovery and management.
-
chen-yu723 Bundle Testcase Quality Review结合需求文档(PRD/MD格式)与测试用例文档(支持 .md 和 .xmind 格式),从需求覆盖度、用例完整性、用例准确性、冗余性、业务适配性五个维度进行全面质量校验,生成结构化质量校验报告(MD + PDF 双格式)并输出到指定目录。当用户提及"用例审查"、"用例质量"、"用例校验"、"分析报告"、"质量分析",或提供需求文档和测试用例(md/xmind)并要求给出报告时触发。支持用户直接在消息中附上文件路径,也支持 @本skill 后跟简短指令(如"结合[需求文档]和[测试用例],分析并给出报告")。
-
nosignalmxh Bundle Research Idea Funnelgenerate, filter, and rank research ideas from a broad direction using a codex-native idea funnel modeled on the aris idea-discovery workflow. use when the user wants literature mapping, 8-12 candidate ideas, feasibility and novelty filtering, devil's-advocate review, optional pilot planning or pilot execution, and an idea_report-style output that preserves both recommended and eliminated ideas.
-
fakegeek92 Bundle Feishu Search Doc飞书文档与 Wiki 统一搜索工具使用指南,覆盖关键词搜索、类型筛选、创建者筛选、时间筛选与空搜。 **当以下情况时使用此 Skill**: (1) 需要在飞书里按关键词找文档或 wiki 节点 (2) 需要按创建者、文档类型、标题、时间范围过滤搜索结果 (3) 需要做“空搜”看最近编辑或最近打开的文档 (4) 用户提到“搜一下文档”“找最近改过的周报”“只查标题里有 OKR 的文档”
-
rj-gauntlet Bundle PresearchIngest a product requirements document (PRD) and collaboratively walk through the requirements to develop a high-level architecture, strategy, implementation plan, cost analysis, and phased schedule. Also supports refining an existing PROJECT_PLAN.md when requirements change. Use when the user wants to plan a project, review a PRD, create a project plan, define architecture from requirements, kick off a new product build, or update an existing project plan.
-
rj-gauntlet Bundle Prd GeneratorTurn a rough idea, description, or concept into a structured product requirements document (PRD). Accepts any input — a sentence, bullet points, a ramble, a competitor reference — and produces a PRD ready for the presearch skill. Use when the user has an idea but no formal PRD, wants to create a requirements doc, needs to formalize product requirements, or says things like "I have an idea for..." or "I want to build...".
-
marchatton Skill Create PrdDraft PRD with scope, stories, acceptance criteria, verification. Use when shaping a new feature or spec.
-
marchatton Bundle Wf RalphRun a Ralph-style, one-story-per-iteration loop using the Ralph CLI (dev, research, e2e, review), Codex-by-default, and dossier-local PRD JSON discovery.
-
marchatton Bundle Create JSON PrdGenerate a Product Requirements Document (PRD) as JSON for Ralph by converting an existing PRD markdown file. Triggers on: create a prd, write prd for, plan this feature, requirements for, spec out.
-
jacoblincool Bundle UX Discovery Interviewerrun an interactive ux research discovery interview with a customer who starts from a vague product idea or follow-up request. use when chatgpt should act as a ux researcher, clarify goals through progressive questioning, and produce research outputs such as interview summary, user journey, happy path, pain points, opportunities, assumptions, and open questions. especially useful for early-stage product discovery, requirement clarification, and iterative follow-up feedback.
-
marchatton Bundle Parallel Web ToolsThis skill should be used when users want a Firecrawl-like capability for web discovery and clean markdown extraction using Parallel Search and Parallel Extract (including objective-led excerpts and full content).
-
dev-dennis-040 Skill Project Management Project ShepherdYou are **Project Shepherd**, an expert project manager who specializes in cross-functional project coordination, timeline management, and stakeholder alignment. You shepherd complex projects from ...
-
kentoshimizu Bundle User ResearchEnd-user research workflow for validating behavior, needs, and pain points with representative evidence. Use when product decisions need direct user evidence through interviews, usability studies, or observed usage; do not use for internal stakeholder governance decisions.
-
micic-mihajlo Skill Stakeholder Whispererstakeholder-whisperer
-
njones17 Skill Detecting Shadow API EndpointsDiscover and inventory shadow API endpoints that operate outside documented specifications using traffic analysis, code scanning, and API discovery platforms.
-
nikopj01 Bundle Ffuf Web FuzzingRun targeted web fuzzing to discover hidden routes, parameters, and weak input handling in authorized environments. Use for controlled security assessments, endpoint discovery, and input validation checks.
-
njones17 Bundle None 4Audit service accounts across enterprise infrastructure to identify orphaned, over-privileged, and non-compliant accounts. This skill covers discovery of service accounts in Active Directory, cloud pl
-
njones17 Skill Detecting Rootkit ActivityDetects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, hidden files, and covert network connections using memory forensics, cross-view detection, and integrity checking techniques. Activates for requests involving rootkit detection, hidden process discovery, kernel integrity checking, or system call hook analysis.
-
njones17 Skill Infra PentestingUse when testing network infrastructure, servers, or internal/external networks. Triggers: host discovery, port scanning, service enumeration, vulnerability assessment, exploitation of network services, Active Directory attacks, password cracking, lateral movement, pivoting, privilege escalation, cloud infrastructure testing, network-level attacks like MITM or ARP spoofing. Covers TCP/UDP services including SSH, FTP, SMB, RDP, SNMP, DNS, LDAP, Kerberos, WinRM. Applies to both Linux and Windows targets in on-prem and cloud environments.
-
njones17 Skill Recon And EnumerationUse when starting a new engagement, scoping a target, gathering intelligence before exploitation, discovering attack surface, enumerating services and technologies, performing subdomain discovery, identifying entry points, or when the user asks to scan, enumerate, fingerprint, or map a target network or application.
-
njones17 Skill GRAPHQL SecurityUse when testing GraphQL APIs for common vulnerabilities including introspection exploitation, authorization bypasses, batching abuse, and denial of service. Covers endpoint discovery, schema analysis, and exploitation of GraphQL-specific features like federation and directives.
-
njones17 Skill None 5Discover and inventory all privileged accounts across enterprise infrastructure including domain admins, local admins, service accounts, database admins, cloud IAM roles, and application admin account
-
njones17 Skill Performing API Inventory And DiscoveryPerforms API inventory and discovery to identify all API endpoints in an organization's environment including documented, undocumented, shadow, zombie, and deprecated APIs. The tester uses passive traffic analysis, active scanning, DNS enumeration, JavaScript analysis, and cloud resource inventory to build a comprehensive API catalog. Maps to OWASP API9:2023 Improper Inventory Management. Activates for requests involving API discovery, shadow API detection, API inventory audit, or attack surface mapping.
-
njones17 Skill Managing Intelligence LifecycleManages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to ensure intelligence products meet stakeholder requirements and continuously improve. Use when establishing or maturing a CTI program, defining intelligence requirements with business stakeholders, or building feedback loops between intelligence consumers and producers. Activates for requests involving CTI program maturity, intelligence requirements, PIRs, or intelligence lifecycle management.
-
njones17 Skill Conducting Network Penetration TestConducts comprehensive network penetration tests against authorized target environments by performing host discovery, port scanning, service enumeration, vulnerability identification, and controlled exploitation to assess the security posture of network infrastructure. The tester follows PTES methodology from reconnaissance through post-exploitation and reporting. Activates for requests involving network pentest, infrastructure security assessment, internal network testing, or external perimeter testing.
-
njones17 Skill Performing Ics Asset Discovery With ClarotyPerform comprehensive ICS/OT asset discovery using Claroty xDome platform, leveraging passive monitoring, Claroty Edge active queries, and integration ecosystem to gain full visibility into industrial control system assets including PLCs, RTUs, HMIs, and network infrastructure across Purdue Model levels.
-
njones17 Skill Performing Ot Vulnerability Assessment With ClarotyThis skill covers performing vulnerability assessments in OT environments using the Claroty xDome platform for comprehensive asset discovery, risk scoring, vulnerability correlation, and remediation prioritization. It addresses passive vulnerability identification through traffic analysis, active safe querying of OT devices, integration with CVE databases and ICS-CERT advisories, and risk-based prioritization that accounts for operational impact and compensating controls.
-
njones17 Bundle None 26Indicator lifecycle management tracks IOCs from initial discovery through validation, enrichment, deployment, monitoring, and eventual retirement. This skill covers implementing systematic processes f
-
njones17 Bundle Performing Agentless Vulnerability ScanningConfigure and execute agentless vulnerability scanning using network protocols, cloud snapshot analysis, and API-based discovery to assess systems without installing endpoint agents.
-
njones17 Bundle Triaging Vulnerabilities With Ssvc FrameworkTriage and prioritize vulnerabilities using CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) decision tree framework to produce actionable remediation priorities.
-
njones17 Bundle Building Malware Incident Communication TemplateBuild structured communication templates for malware incidents including stakeholder notifications, executive briefings, technical advisories, and regulatory disclosures with severity-based escalation procedures.
-
work0r-ai Bundle Workorai 2Use for WorkorAI talent marketplace requests. Candidate triggers: "найди мне работу", "ищу работу", "подбери вакансию", "find me a job", "I need work", "help me get hired". Employer triggers: hiring, posting jobs, finding/evaluating/comparing candidates, "who's the best fit", explaining why a candidate matches, recruiting, MCP setup. Covers 9 candidate.* tools (search/detail/applications/apply/invites/saved) and 19 employer.* tools: job lifecycle; candidate discovery with TIERED ranking (best/good/weak) + a white-box matchExplanation per candidate (fit score, skills PROVEN in interview, gaps, quotable rationale); per-candidate interview EVIDENCE (facts + Q&A) for your own comparative review; invitations; applicants review; MCP onboarding. The agent ranks, explains, and evaluates candidates on white-box data, not a black-box score.
-
mayurrathi Skill Exa SearchSemantic search, similar content discovery, and structured research using Exa API
-
mayurrathi Skill Product Manager ToolkitComprehensive toolkit for product managers including RICE prioritization, customer interview analysis, PRD templates, discovery frameworks, and go-to-market strategies. Use for feature prioritizati...
Frequently asked questions
What are Product & Planning agent skills?
Product & planning agent skills structure the thinking side of building: specs, PRDs, user stories, roadmaps, and prioritization frameworks. Install one and your AI agent produces planning documents with the same rigor and format every time.
Which Product & Planning skills are most installed?
Popular Product & Planning skills on SkillMD right now include cpo-advisor, ciso-advisor, find-skills. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Product & Planning skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.