Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
product-on-purpose avatar

Utility Pm Skill Auditor

  • 379 installs
  • 518 repo stars
  • Updated August 4, 2026
  • product-on-purpose/pm-skills

utility-pm-skill-auditor is an agent skill that runs a repo-wide governance audit of a PM-skills repository and grades cross-cutting issues P0 through P3.

About

utility-pm-skill-auditor is a dispatch skill that runs a repo-wide governance audit of a PM-skills repository via the pm-skill-auditor sub-agent. It aggregates the enforcing validator suite, re-derives aggregate counters, and surfaces cross-cutting issues like skill-without-command or family contract orphans, graded P0 through P3. Developers use it for pre-release readiness checks or periodic repo health audits, and it detects issues only, leaving remediation to the maintainer. Despite the current Security tag, it audits skill-repo governance, not code vulnerabilities.

  • Repo-wide governance audit via sub-agent dispatch
  • P0-P3 severity grading with machine-readable status
  • Cross-client fallback for non-Claude AI clients

Utility Pm Skill Auditor by the numbers

  • 379 all-time installs (skills.sh)
  • +24 installs in the week ending Aug 4, 2026 (Skillselion tracking)
  • Ranked #117 of 782 Skill Development skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
At a glance

utility-pm-skill-auditor capabilities & compatibility

free, no API key

Capabilities
repo audit · governance check · validator orchestration
Use cases
project management · code review
Pricing
Free
From the docs

What utility-pm-skill-auditor says it does

Run a repo-wide cross-cutting governance audit via the pm-skill-auditor sub-agent
SKILL.md
the auditor is detection-only; remediation is maintainer judgment
SKILL.md
npx skills add https://github.com/product-on-purpose/pm-skills --skill utility-pm-skill-auditor

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs379
repo stars518
Last updatedAugust 4, 2026
Repositoryproduct-on-purpose/pm-skills

How do I catch cross-cutting governance issues across a skill repository that no single validator detects?

project-management

Who is it for?

Maintainers of a PM-skills repository needing a pre-release readiness or periodic repo health audit.

Skip if: Reviewing a specific PM artifact like a PRD or persona, drafting changelogs, or fixing the issues it finds.

When should I use this skill?

You need a repo-wide audit pass over all enforcing validators, cross-cutting checks, and aggregate counter re-derivation before a release.

What you get

A layered audit report with re-derived aggregate counters and a machine-readable Status YAML graded by severity.

  • Layered audit report
  • Status Summary
  • machine-readable Status YAML

By the numbers

  • Four-step audit flow
  • P0/P1/P2/P3 severity grading

Files

SKILL.mdMarkdownGitHub ↗

<!-- PM-Skills | https://github.com/product-on-purpose/pm-skills | Apache 2.0 -->

PM Skill Auditor (Dispatch Skill)

Cross-client dispatch wrapper for the pm-skill-auditor sub-agent. Detects runtime; dispatches to the native sub-agent on Claude Code; reads agents/pm-skill-auditor.md and executes inline on non-Claude clients.

When to Use

  • You need a repo-wide audit pass: all enforcing validators, cross-cutting checks (skill-without-command, sample gaps, family contract orphans, etc.), and aggregate counter re-derivation against declared values in CONTEXT.md + AGENTS.md + README.md
  • You are running on a non-Claude AI client without native pm-skill-auditor sub-agent support
  • You are running on Claude Code and prefer skill-invocation semantics (e.g., for chaining inside a workflow that also uses other dispatch skills)

When NOT to Use

  • You want to review a specific PM artifact (PRD, OKR, persona) -> use utility-pm-critic instead
  • You want to draft a CHANGELOG entry -> use utility-pm-changelog-curator (ships in Phase 4)
  • You want to ship a release -> use utility-pm-release-conductor (ships in Phase 5)
  • You want to FIX issues found in an audit -> the auditor is detection-only; remediation is maintainer judgment or future pm-frontmatter-doctor (v2.17+)

Instructions

Runtime detection step. Determine which AI client is invoking this skill.

If you are running in Claude Code with the pm-skills plugin installed

Invoke @agent-pm-skills:pm-skill-auditor on the repo. Pass any scope arguments from $ARGUMENTS (e.g., --scope changed, --since-tag v2.15.0, --severity-floor P1). Return the sub-agent's audit report to the user.

If you are running in any other AI client

Codex CLI, Cursor, Windsurf, Copilot, Gemini CLI, or any other client without native pm-skills plugin sub-agent support:

1. Read the canonical sub-agent definition at agents/pm-skill-auditor.md 2. Execute the system prompt body in that file as your operating instructions for this turn 3. Run the four-step audit flow:

  • Step 1: Invoke validators via Bash (prefer bash scripts/pre-tag-validate.sh as canonical entry point)
  • Step 2: Run cross-cutting checks from the catalog at docs/internal/release-plans/v2.16.0/spec_pm-skill-auditor.md#cross-cutting-check-catalog
  • Step 3: Re-derive aggregate counters from filesystem and compare to declared values
  • Step 4: Compose layered output report

4. Apply scope and severity-floor arguments from $ARGUMENTS 5. Return the layered output per master plan D26 (full report + Status Summary + Status YAML)

Cross-Client Notes

See Sub-Agent Compatibility Matrix for the canonical cross-client status. Summary for this skill as of v2.16.0: PRODUCTION on Claude Code + Codex CLI (Codex CLI successfully invoked the validator suite via Bash + produced a layered audit report with re-derived aggregate counters); EXPERIMENTAL on Cursor / Windsurf / Copilot CLI / Gemini CLI.

The "read canonical agent definition and execute inline" pattern depends on the AI client being able to:

1. Read a referenced file path 2. Execute Bash to invoke validator scripts 3. Treat the agent definition body as operating instructions for the current turn

Most AI clients support all three. If any are unreliable on a specific client, that client falls back to manual validator invocation + manual cross-cutting checks.

Reference Files

  • Canonical sub-agent definition: `agents/pm-skill-auditor.md`
  • Behavioral spec: `docs/internal/release-plans/v2.16.0/spec_pm-skill-auditor.md`
  • Runtime components catalog: `docs/reference/runtime-components.md`
  • Cross-cutting check catalog: docs/internal/release-plans/v2.16.0/spec_pm-skill-auditor.md#cross-cutting-check-catalog
  • Pre-tag validator bundle: scripts/pre-tag-validate.{sh,ps1}
  • Output template: references/TEMPLATE.md
  • Worked example: references/EXAMPLE.md

Related skills

FAQ

Does this fix the issues it finds?

No. The auditor is detection-only; remediation is maintainer judgment or a future frontmatter-doctor skill.

Does it work outside Claude Code?

Yes. On non-Claude clients it reads the canonical sub-agent definition and executes the four-step audit flow inline.

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.