Product & Planning
Product & planning agent skills structure the thinking side of building: specs, PRDs, user stories, roadmaps, and prioritization frameworks. Install one and your AI agent produces planning documents with the same rigor and format every time.
-
yanacuti1121 Skill Venice Venice X402Manage Venice x402 wallet credits. Covers POST /x402/top-up (payment discovery + signed USDC settlement), GET /x402/balance/{walletAddress}, GET /x402/transactions/{walletAddress}, USDC on Base (chain 8453), minimum $5 top-up, transaction types TOP_UP/CHARGE/REFUND, and the x402 v2 PAYMENT-REQUIRED
2 -
yanacuti1121 Skill Prd WritingWhen the user needs to define a product feature, write a product requirements document, or translate an idea into a structured spec.
2 -
yanacuti1121 Skill Sales ScriptWhen a founder needs demo scripts, discovery call frameworks, objection handling, RFP/RFI responses, competitive feature matrices, POC planning, or closing playbooks. Activate for sales calls, demo prep, talk tracks, bid responses, competitor comparisons, or pre-sales engineering.
2 -
yanacuti1121 Skill Pairwise PrioritizationPrioritize a task list by direct pairwise comparison instead of isolated scoring — compare every pair on importance, urgency, and impact, then produce a ranked execution order. Use when asked 'so từng cặp', 'sắp xếp ưu tiên', 'prioritize these tasks', 'việc nào làm trước', 'rank this backlog', 'đặt độ ưu tiên', or 'compare tasks head to head'. Do NOT use for: choosing between solution options — see option-tournament. Do NOT use for: sprint ceremony planning — see /sprint-planning.
2 -
yanacuti1121 Skill Roadmap PlanningWhen the user needs to organize product initiatives into a prioritized, time-sequenced plan with outcomes and dependencies.
2 -
yanacuti1121 Bundle Detecting Rootkit ActivityDetects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, hidden files, and covert network connections using memory forensics, cross-view detection, and integrity checking techniques. Activates for requests involving rootkit detection, hidden process discovery, kernel integrity checking, or system call hook analysis.
2 -
yanacuti1121 Skill Community DiscoveryWhen the user wants to find Slack groups, Discord servers, Reddit communities, forums, or online communities where their target audience hangs out. Also use when the user mentions "where to promote", "find communities", "community marketing", or "distribution channels".
2 -
yanacuti1121 Bundle Detecting Shadow API EndpointsDiscover and inventory shadow API endpoints that operate outside documented specifications using traffic analysis, code scanning, and API discovery platforms.
2 -
yanacuti1121 Bundle Managing Intelligence LifecycleManages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to ensure intelligence products meet stakeholder requirements and continuously improve. Use when establishing or maturing a CTI program, defining intelligence requirements with business stakeholders, or building feedback loops between intelligence consumers and producers. Activates for requests involving CTI program maturity, intelligence requirements, PIRs, or intelligence lifecycle management.
2 -
yanacuti1121 Bundle Performing Service Account AuditAudit service accounts across enterprise infrastructure to identify orphaned, over-privileged, and non-compliant accounts. This skill covers discovery of service accounts in Active Directory, cloud pl
2 -
yanacuti1121 Skill Scrum Master AgentComprehensive Scrum Master assistant for sprint planning, backlog grooming, retrospectives, capacity planning, and daily standups with intelligent context-aware reporting
2 -
yanacuti1121 Bundle Conducting Network Penetration TestConducts comprehensive network penetration tests against authorized target environments by performing host discovery, port scanning, service enumeration, vulnerability identification, and controlled exploitation to assess the security posture of network infrastructure. The tester follows PTES methodology from reconnaissance through post-exploitation and reporting. Activates for requests involving network pentest, infrastructure security assessment, internal network testing, or external perimeter testing.
2 -
yanacuti1121 Bundle Performing Fuzzing With AflplusplusPerform coverage-guided fuzzing of compiled binaries using AFL++ (American Fuzzy Lop Plus Plus) to discover memory corruption, crashes, and security vulnerabilities. The tester instruments target binaries with afl-cc/afl-clang-fast, manages input corpora with afl-cmin and afl-tmin, runs parallel fuzzing campaigns with afl-fuzz, and triages crashes using CASR or GDB scripts. Activates for requests involving binary fuzzing, crash discovery, coverage-guided testing, or AFL++ fuzzing campaigns.
2 -
yanacuti1121 Bundle Implementing Attack Surface ManagementImplements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting, and exposure scoring. Includes a weighted risk scoring algorithm based on OWASP attack surface analysis methodology and the Relative Attack Surface Quotient (RSQ). Use when building continuous ASM programs or performing external reconnaissance for security assessments.
2 -
yanacuti1121 Bundle Performing API Inventory And DiscoveryPerforms API inventory and discovery to identify all API endpoints in an organization's environment including documented, undocumented, shadow, zombie, and deprecated APIs. The tester uses passive traffic analysis, active scanning, DNS enumeration, JavaScript analysis, and cloud resource inventory to build a comprehensive API catalog. Maps to OWASP API9:2023 Improper Inventory Management. Activates for requests involving API discovery, shadow API detection, API inventory audit, or attack surface mapping.
2 -
yanacuti1121 Bundle Performing Binary Exploitation AnalysisAnalyze binary exploitation techniques including buffer overflows and ROP chains using pwntools Python library. Covers checksec analysis, gadget discovery with ROPgadget, and exploit development for CTF and authorized security assessments.
2 -
yanacuti1121 Bundle Performing Privileged Account DiscoveryDiscover and inventory all privileged accounts across enterprise infrastructure including domain admins, local admins, service accounts, database admins, cloud IAM roles, and application admin account
2 -
yanacuti1121 Skill Openai Codex Security Finding DiscoveryUse when Codex is already in the finding-discovery phase of a security scan or the user explicitly asks to discover candidate security findings in a repository or code change. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
2 -
yanacuti1121 Bundle Performing Indicator Lifecycle ManagementIndicator lifecycle management tracks IOCs from initial discovery through validation, enrichment, deployment, monitoring, and eventual retirement. This skill covers implementing systematic processes f
2 -
yanacuti1121 Bundle Auditing Tls Certificate Transparency LogsMonitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains. Uses the crt.sh API and direct CT log querying based on RFC 6962 to build continuous monitoring pipelines that catch rogue certificates, track CA behavior, and map the external attack surface. Activates for requests involving certificate transparency monitoring, CT log auditing, subdomain discovery via certificates, or certificate issuance alerting.
2 -
yanacuti1121 Skill Openai Codex Security Deep Security ScanUse when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide Codex Security scan. Run repeated independent repository-wide discovery passes with worker-specific threat models, semantically merge candidates, synthesize one canonical validation threat model, then run validation, attack-path analysis, and final reporting once. Repository-wide targets only; do not use for PRs, commits, branch diffs, working-tree diffs, or scoped paths.
2 -
yanacuti1121 Bundle Performing Agentless Vulnerability ScanningConfigure and execute agentless vulnerability scanning using network protocols, cloud snapshot analysis, and API-based discovery to assess systems without installing endpoint agents.
2 -
yanacuti1121 Bundle Performing Firmware Extraction With BinwalkPerforms firmware image extraction and analysis using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material. Covers entropy analysis for detecting encrypted or compressed regions, recursive extraction of nested archives, SquashFS/CramFS/JFFS2 filesystem mounting, and string analysis for credential and configuration discovery. Activates for requests involving firmware reverse engineering, IoT device analysis, embedded system security assessment, or router/camera firmware extraction.
2 -
yanacuti1121 Bundle Performing Ics Asset Discovery With ClarotyPerform comprehensive ICS/OT asset discovery using Claroty xDome platform, leveraging passive monitoring, Claroty Edge active queries, and integration ecosystem to gain full visibility into industrial control system assets including PLCs, RTUs, HMIs, and network infrastructure across Purdue Model levels.
2 -
yanacuti1121 Bundle Triaging Vulnerabilities With Ssvc FrameworkTriage and prioritize vulnerabilities using CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) decision tree framework to produce actionable remediation priorities.
2 -
yanacuti1121 Bundle Implementing Gdpr Data Subject Access RequestAutomates GDPR Data Subject Access Request (DSAR) workflows including identity verification, PII discovery across databases and files using regex and NER, data mapping, response templating per Article 15 requirements, deadline tracking, and audit logging. Covers ICO/EDPB guidance compliance, exemption handling, and scalable batch processing. Use when building or auditing DSAR response capabilities under GDPR/UK GDPR.
2 -
yanacuti1121 Bundle Building Malware Incident Communication TemplateBuild structured communication templates for malware incidents including stakeholder notifications, executive briefings, technical advisories, and regulatory disclosures with severity-based escalation procedures.
2 -
yanacuti1121 Bundle Performing Ot Vulnerability Assessment With ClarotyThis skill covers performing vulnerability assessments in OT environments using the Claroty xDome platform for comprehensive asset discovery, risk scoring, vulnerability correlation, and remediation prioritization. It addresses passive vulnerability identification through traffic analysis, active safe querying of OT devices, integration with CVE databases and ICS-CERT advisories, and risk-based prioritization that accounts for operational impact and compensating controls.
2 -
tangchunwu Skill Product CapabilityTranslate PRD intent, roadmap asks, or product discussions into an implementation-ready capability plan that exposes constraints, invariants, interfaces, and unresolved decisions before multi-service work starts. Use when the user needs an ECC-native PRD-to-SRS lane instead of vague planning prose.
1 -
tangchunwu Skill Laravel Plugin DiscoveryDiscover and evaluate Laravel packages via LaraPlugins.io MCP. Use when the user wants to find plugins, check package health, or assess Laravel/PHP compatibility.
1 -
srednoff888-art Bundle Webflow MCP Site GovernanceUse when a Webflow site, CMS, Designer context, components, styles, pages, assets, or variables must be inspected or changed through Webflow MCP. Keep discovery read-only first and require explicit approval before any mutation or publish action.
1 -
srednoff888-art Bundle Yandex Direct Account AuditUse for PPC work when Codex should audit Yandex Direct account structure, spend, delivery, conversion evidence, and safe optimization backlog.
1 -
srednoff888-art Bundle Site Commerce Conversion ArchitectureUse for Site Building work when Codex should design ecommerce discovery, product, cart, checkout, trust, tracking, and recovery flows.
1 -
solizardking Bundle Metaplex AgentPremiere Metaplex Agent skill — package every Metaplex agent operation into one playbook: CLI/RPC setup, wallet funding, Core identity registration (EIP-8004), Asset Signer PDA activation, executive delegation/revocation, agent commerce (services discovery, x402Support, A2A payments), agent finance, Genesis agent token launch (LaunchPool or Bonding Curve), and setAgentToken. Use when the user mentions Metaplex agents, Agent Registry, mplx agents, mintAndSubmitAgent, AgentIdentity, executive delegation, agent commerce, agent finance, agent token, EIP-8004 registration, or autonomous Solana agents on Metaplex.
0 -
hoangnguyen0403 Skill Implementation ReadinessVerify BRD-lite, PRD, SRS/FRS, UX, and test prerequisites before implementation starts.
542 -
hoangnguyen0403 Bundle Common Product RequirementsStandardize PRD discovery and drafting for product scope, user outcomes, requirement IDs, and acceptance criteria. Use when creating PRD, product requirements, feature specification, or acceptance criteria plan.
542
Frequently asked questions
What are Product & Planning agent skills?
Product & planning agent skills structure the thinking side of building: specs, PRDs, user stories, roadmaps, and prioritization frameworks. Install one and your AI agent produces planning documents with the same rigor and format every time.
Which Product & Planning skills are most installed?
Popular Product & Planning skills on SkillMD right now include performing-ot-vulnerability-assessment-with-claroty, laravel-plugin-discovery, site-commerce-conversion-architecture. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Product & Planning skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.