Agent skill

Utility Pm Skill Auditor

by product-on-purpose in product-on-purpose/pm-skills

Run a repo-wide cross-cutting governance audit via the pm-skill-auditor sub-agent.

Apache-2.0Auto-check passedProduct & Project Management

Install Utility Pm Skill Auditor

skills CLI
$ npx skills add product-on-purpose/pm-skills --skill utility-pm-skill-auditor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install product-on-purpose/pm-skills utility-pm-skill-auditor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/product-on-purpose/pm-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/utility-pm-skill-auditor .claude/skills/utility-pm-skill-auditor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
utility-pm-skill-auditor
GitHub stars
716
Token cost
~1.2k tokens
SKILL.md length
503 words
Files
5 (incl. references)
Skills in repo
68
Repo updated
First seen
Licence
Apache-2.0

At a glance

Run a repo-wide cross-cutting governance audit via the pm-skill-auditor sub-agent.

  • Works in 5 steps: Read the canonical sub-agent definition… → Execute the system prompt body in that… → Run the four-step audit flow → …
  • Pre-release readiness checks
  • SKILL.md covers When to Use, When NOT to Use, Instructions and Cross-Client Notes, plus 1 more section
  • Calls bash

What it does

Utility Pm Skill Auditor is an agent skill from product-on-purpose/pm-skills. Run a repo-wide cross-cutting governance audit via the pm-skill-auditor sub-agent. Aggregates the enforcing validator suite, re-derives aggregate counters, and surfaces cross-cutting issues no single validator catches, graded P0/P1/P2/P3 with a machine-readable status. Use for pre-release readiness checks or a periodic repo health audit.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `HISTORY.md`, `evals/trigger-fixtures.json` and `references/EXAMPLE.md`).

It sits in Product & Project Management, covering Subagents and Feature launches and release readiness. The repository describes itself as: 68 plug-and-play, best-practice product management skills for AI agents: 30 Triple Diamond phase + 11 foundation + 12 utility + 15 tool (Foundation Sprint + Design Sprint). Plus… The licence is Apache-2.0.

When your agent uses it

  • Pre-release readiness checks
  • A periodic repo health audit

Example prompts

  • “/utility-pm-skill-auditor”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Read the canonical sub-agent definition at agents/pm-skill-auditor.md
  2. Execute the system prompt body in that file as your operating instructions for this turn
  3. Run the four-step audit flow
  4. Apply scope and severity-floor arguments from $ARGUMENTS
  5. Return the layered output per master plan D26 (full report + Status Summary + Status YAML)

What it can do on your machine

Read from SKILL.md and the folder at commit 1cef1a9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Utility Pm Skill Auditor loads about 1.2k tokens when it runs, and up to ~4.6k if it reads all its reference files. Until then it costs about 91 tokens; SKILL.md has 503 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~91
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from product-on-purpose/pm-skills at commit 1cef1a9, republished under its Apache-2.0 licence (© product-on-purpose). 503 words, ~1,217 tokens.

Download SKILL.mdSave it as .claude/skills/utility-pm-skill-auditor/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
utility-pm-skill-auditor
description
Run a repo-wide cross-cutting governance audit via the pm-skill-auditor sub-agent. Aggregates the enforcing validator suite, re-derives aggregate counters, and surfaces cross-cutting issues no single validator catches, graded P0/P1/P2/P3 with a machine-readable status. Use for pre-release readiness checks or a periodic repo health audit.
license
Apache-2.0
metadata.classification
utility
metadata.version
1.1.0
metadata.updated
2026-06-10
metadata.category
governance
metadata.frameworks
triple-diamond
metadata.author
product-on-purpose
<!-- PM-Skills | https://github.com/product-on-purpose/pm-skills | Apache 2.0 -->

PM Skill Auditor (Dispatch Skill)

Cross-client dispatch wrapper for the pm-skill-auditor sub-agent. Detects runtime; dispatches to the native sub-agent on Claude Code; reads agents/pm-skill-auditor.md and executes inline on non-Claude clients.

When to Use

  • You need a repo-wide audit pass: all enforcing validators, cross-cutting checks (skill-without-command, sample gaps, family contract orphans, etc.), and aggregate counter re-derivation against declared values in CONTEXT.md + AGENTS.md + README.md
  • You are running on a non-Claude AI client without native pm-skill-auditor sub-agent support
  • You are running on Claude Code and prefer skill-invocation semantics (e.g., for chaining inside a workflow that also uses other dispatch skills)

When NOT to Use

  • You want to review a specific PM artifact (PRD, OKR, persona) -> use utility-pm-critic instead
  • You want to draft a CHANGELOG entry -> use utility-pm-changelog-curator (ships in Phase 4)
  • You want to ship a release -> use utility-pm-release-conductor (ships in Phase 5)
  • You want to FIX issues found in an audit -> the auditor is detection-only; remediation is maintainer judgment or future pm-frontmatter-doctor (v2.17+)
  • You want a deep, single-skill check against the authoring conventions -> use utility-pm-skill-validate. The auditor goes wide across the catalog; it does not go deep on one skill.

Instructions

Runtime detection step. Determine which AI client is invoking this skill.

If you are running in Claude Code with the pm-skills plugin installed

Invoke @agent-pm-skills:pm-skill-auditor on the repo. Pass any scope arguments from $ARGUMENTS (e.g., --scope changed, --since-tag v2.15.0, --severity-floor P1). Return the sub-agent's audit report to the user.

If you are running in any other AI client

Codex CLI, Cursor, Windsurf, Copilot, Gemini CLI, or any other client without native pm-skills plugin sub-agent support:

  1. Read the canonical sub-agent definition at agents/pm-skill-auditor.md
  2. Execute the system prompt body in that file as your operating instructions for this turn
  3. Run the four-step audit flow:
    • Step 1: Invoke validators via Bash (prefer bash scripts/pre-tag-validate.sh as canonical entry point)
    • Step 2: Run cross-cutting checks from the catalog at docs/internal/release-plans/v2.16.0/spec_pm-skill-auditor.md#cross-cutting-check-catalog
    • Step 3: Re-derive aggregate counters from filesystem and compare to declared values
    • Step 4: Compose layered output report
  4. Apply scope and severity-floor arguments from $ARGUMENTS
  5. Return the layered output per master plan D26 (full report + Status Summary + Status YAML)
Show full SKILL.md (145 more words)Show less

Cross-Client Notes

See Sub-Agent Compatibility Matrix for the canonical cross-client status. Summary for this skill as of v2.16.0: PRODUCTION on Claude Code + Codex CLI (Codex CLI successfully invoked the validator suite via Bash + produced a layered audit report with re-derived aggregate counters); EXPERIMENTAL on Cursor / Windsurf / Copilot CLI / Gemini CLI.

The "read canonical agent definition and execute inline" pattern depends on the AI client being able to:

  1. Read a referenced file path
  2. Execute Bash to invoke validator scripts
  3. Treat the agent definition body as operating instructions for the current turn

Most AI clients support all three. If any are unreliable on a specific client, that client falls back to manual validator invocation + manual cross-cutting checks.

Reference Files

© product-on-purpose, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in skills/utility-pm-skill-auditor of product-on-purpose/pm-skills.

  • SKILL.md
  • HISTORY.md
  • evals/trigger-fixtures.json
  • references/EXAMPLE.md
  • references/TEMPLATE.md

Open the folder on GitHubat commit 1cef1a9

Compare with similar skills

Utility Pm Skill Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Utility Pm Skill Auditor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Utility Pm Skill Auditor this skillproduct-on-purpose/pm-skills716—~1.2kAutomated safety check: PassApache-2.0
Personal Assistant Reviewedonyzpc/personal-assistant147—~3.2kAutomated safety check: PassAGPL-3.0
QA Releasejitpass/jit161—~1.1kAutomated safety check: PassCustom licence
Release Readiness Reviewbbartling/open-fdd173—~1.3kAutomated safety check: PassCustom licence
Theboardroomdavepoon/buildwithclaude3.6k—~1.5kAutomated safety check: PassMIT
CCPM Project Managementautomazeio/ccpm8.4k—~1.1kAutomated safety check: PassMIT

Similar skills

  • Personal Assistant Review

    edonyzpc/personal-assistant

    Review uncommitted or PR diffs in the personal-assistant Obsidian plugin with project-specific risk lanes, second-layer future-risk checks, severity discipline, subagent review routing, and…

    147 GitHub stars~3.2k tokensUpdated today
    Product & Project ManagementAuto-check passed
  • QA Release

    jitpass/jit

    Run jit's pre-release QA — a team of QA-engineer subagents (functionality, integrations, UX, bug-hunting, code review) that exercise a release candidate on this real Mac and hand back a consolidated…

    161 GitHub stars~1.1k tokensUpdated 6 days ago
    Product & Project ManagementAuto-check passed
  • Release Readiness Review

    bbartling/open-fdd

    Use before merging, shipping, publishing, or handing off work.

    173 GitHub stars~1.3k tokensUpdated yesterday
    Product & Project ManagementAuto-check passed
  • Theboardroom

    davepoon/buildwithclaude

    Convene an AI executive board of directors (CEO, CFO, COO, CLO, CISO sub-agent personas) to vet a business idea, product concept, new service offering, M&A target, or operational initiative — and…

    3.6k GitHub stars~1.5k tokensUpdated 2 days ago
    Business, Finance & HRAuto-check passed
  • Runs a spec-driven workflow from PRD to epic to GitHub issues to parallel agents, with status, standup and blocked-work reports from bundled scripts.

    8.4k GitHub stars~1.1k tokensUpdated 6 mo ago
    Product & Project ManagementAuto-check passed
  • Review

    fossasia/eventyay-interpretation

    Review the changes since a fixed point (commit, branch, tag, or merge-base) along two axes — Standards (does the code follow this repo's documented coding standards?) and Spec (does the code match…

    1.6k GitHub starsUsed in 35 repos~996 tokens
    Product & Project ManagementAuto-check passed

More from product-on-purpose/pm-skills

All 68 skills in this repo
  • Define Hypothesis

    product-on-purpose/pm-skills

    Defines a testable hypothesis with clear success metrics and a validation approach.

    716 GitHub stars~966 tokensUpdated 2 days ago
    Auto-check passed
  • Define Jtbd Canvas

    product-on-purpose/pm-skills

    Creates a Jobs to be Done canvas capturing the functional, emotional, and social dimensions of a customer job.

    716 GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Define Opportunity Tree

    product-on-purpose/pm-skills

    Creates an opportunity solution tree connecting a desired outcome to customer opportunities and candidate solutions, preventing solution-first jumps in continuous discovery.

    716 GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Define Problem Statement

    product-on-purpose/pm-skills

    Creates a clear problem framing document with user impact, business context, and success criteria.

    716 GitHub stars~932 tokensUpdated 2 days ago
    Auto-check passed
  • Deliver Acceptance Criteria

    product-on-purpose/pm-skills

    Generates structured Given/When/Then acceptance criteria for a user story or feature slice, covering the happy path, key failure scenarios, and non-functional expectations in testable form.

    716 GitHub stars~1k tokensUpdated 2 days ago
    Auto-check passed
  • Deliver Launch Checklist

    product-on-purpose/pm-skills

    Creates a cross-functional pre-launch checklist covering engineering, design, marketing, support, legal, and operations readiness, with owners, dates, and go/no-go criteria so nothing is missed…

    716 GitHub stars~970 tokensUpdated 2 days ago
    Auto-check passed

Questions about Utility Pm Skill Auditor

What does Utility Pm Skill Auditor do?

Run a repo-wide cross-cutting governance audit via the pm-skill-auditor sub-agent. Utility Pm Skill Auditor is an agent skill from product-on-purpose/pm-skills. Run a repo-wide cross-cutting governance audit via the pm-skill-auditor sub-agent.

When should I use Utility Pm Skill Auditor?

Utility Pm Skill Auditor fits situations like: pre-release readiness checks; A periodic repo health audit.

How do I install Utility Pm Skill Auditor in Claude Code?

Run `npx skills add product-on-purpose/pm-skills --skill utility-pm-skill-auditor -a claude-code`. Or copy the skill folder (skills/utility-pm-skill-auditor in product-on-purpose/pm-skills) into .claude/skills/utility-pm-skill-auditor in your project. Claude Code loads it when a task matches its description.

How do I install Utility Pm Skill Auditor in Codex?

Run `npx skills add product-on-purpose/pm-skills --skill utility-pm-skill-auditor -a codex`. Or copy the skill folder (skills/utility-pm-skill-auditor in product-on-purpose/pm-skills) into .agents/skills/utility-pm-skill-auditor in your project. Codex loads it when a task matches its description.

Can I use Utility Pm Skill Auditor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add product-on-purpose/pm-skills --skill utility-pm-skill-auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/utility-pm-skill-auditor, .gemini/skills/utility-pm-skill-auditor, .github/skills/utility-pm-skill-auditor and .opencode/skills/utility-pm-skill-auditor in your project.

What does Utility Pm Skill Auditor need to run?

Going by SKILL.md and its folder, Utility Pm Skill Auditor needs the command-line tools its instructions call (bash).

Does Utility Pm Skill Auditor access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Utility Pm Skill Auditor safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Utility Pm Skill Auditor use?

Utility Pm Skill Auditor is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Utility Pm Skill Auditor use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.4k tokens, read only when the agent opens those files.

What are the alternatives to Utility Pm Skill Auditor?

Skills that share tags, products or a category with Utility Pm Skill Auditor: Personal Assistant Review (edonyzpc/personal-assistant, 147 stars), QA Release (jitpass/jit, 161 stars), Release Readiness Review (bbartling/open-fdd, 173 stars) and Theboardroom (davepoon/buildwithclaude, 3.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Utility Pm Skill Auditor?

product-on-purpose (a GitHub organization) maintains it in product-on-purpose/pm-skills, which has 716 GitHub stars. The repository holds 68 skills in this directory. The repository was last updated on October 8, 2026.

Source: product-on-purpose/pm-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.