utility-update-pm-skills

utility-update-pm-skills is a skill for Claude Code from product-on-purpose/pm-skills. It costs 71 tokens per session (2,854 once invoked), scanned A, original, Apache-2.0.

A skill that updates a local installation of product-management skills to the latest public release.

In plain words
What is it for?
Use it to check for updates, apply them safely, or generate a report showing changed files, skipped files, and new capabilities.
Why use it?
It compares versions, detects local edits, and lets you choose whether conflicting files are overwritten or skipped.

Skill for Claude Code

Written for Claude Code: Claude Code plugin machinery. Also seen: mentions AGENTS.md.

Part of the pm-skills plugin — 69 skills, 11 commands, 6 agents, 2 hooks shipped together

Good fit Use it to check for updates, apply them safely, or generate a report showing changed files, skipped files, and new capabilities.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/product-on-purpose/pm-skills/utility-update-pm-skills
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add product-on-purpose/pm-skills --skill utility-update-pm-skills
Clone the repo
git clone --depth 1 https://github.com/product-on-purpose/pm-skills

Made for: Claude Code.

Or install pm-skills, the plugin that ships this one along with the rest of its 69 skills, 11 commands, 6 agents, 2 hooks.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for utility-update-pm-skills

README.md
[![agentmods](https://agentmods.dev/badge/skills/product-on-purpose/pm-skills/utility-update-pm-skills/github.svg)](https://agentmods.dev/skills/product-on-purpose/pm-skills/utility-update-pm-skills)
Your own site
<a href="https://agentmods.dev/skills/product-on-purpose/pm-skills/utility-update-pm-skills"><img src="https://agentmods.dev/badge/skills/product-on-purpose/pm-skills/utility-update-pm-skills/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for utility-update-pm-skills

Your own site · 80×15
<a href="https://agentmods.dev/skills/product-on-purpose/pm-skills/utility-update-pm-skills"><img src="https://agentmods.dev/badge/skills/product-on-purpose/pm-skills/utility-update-pm-skills.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 71 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,854 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 1 finding. A grade says what 26 rules found in the file — not that it is safe. Third-party audits
  • Socket pass 27 Apr 2026
  • Snyk warn 27 Apr 2026
  • NVIDIA SkillSpector pass 7 Sept 2026
How audits are shown
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00071 $0.02854
Opus 5 $0.00036 $0.01427
Sonnet 5 $0.00014 $0.00571
Haiku 4.5 $0.00007 $0.00285

Measured 13d ago against content hash 92676abbf2ab, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

utility-update-pm-skills scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 13d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

2. Use any available method: `curl`, `wget`, `fetch`, GitHub CLI (`gh`),
docs/internal/efforts/F-24-update-pm-skills/_discovery/2026-04-09_claude-web-session/skills/utility-update-pm-skills/SKILL.md · 320 lines

How it starts

The opening of the file, as written. The whole thing — 320 lines — stays where its author put it; the contents beside it link to each section on GitHub.

PM Skills Updater

This skill updates a local pm-skills installation to the latest public release. It validates connectivity, compares versions, detects local modifications, gives the user control over conflict resolution, and produces a structured update report documenting every change.

The updater operates in three phases:

  • Pre-flight -- validate internet access and determine version delta.
  • Update -- fetch the latest release and apply changes with conflict-aware overwrite-or-skip logic.
  • Report -- generate a markdown report summarizing what changed, what was skipped, and what new capabilities are available.

When to Use

  • When you want to update your local pm-skills to the latest release
  • After a new pm-skills version is announced and you want to pull it in
  • When you're unsure whether your local copy is current
  • When onboarding to a team that uses pm-skills and you want the latest version
  • When you want a structured summary of what changed between your version and the latest

When NOT to Use

  • To create or edit individual skills -> use /pm-skill-builder or /pm-skill-iterate
  • To validate skills against conventions -> use /pm-skill-validate
  • If you are a maintainer working directly on the pm-skills repo (use git instead)
  • If you need to pin a specific older version (this skill always targets the latest release)

Instructions

When asked to update pm-skills, follow these steps:

Step 1: Validate Internet Access

Before attempting any remote operations, confirm connectivity to GitHub.

How to validate:

  1. Attempt to reach the GitHub API or the public repository URL: https://github.com/product-on-purpose/pm-skills
  2. Use any available method: curl, wget, fetch, GitHub CLI (gh), or the GitHub MCP tools.

If connectivity fails:

  • Report the failure clearly with the error details.
  • Suggest troubleshooting steps: check network, proxy settings, VPN, or firewall rules.
  • Stop execution. Do not proceed to Step 2.

Read the full file on GitHub · 320 lines

Files

What ships with it

2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 13d ago First seen · 320 lines · 71 tokens per session scan A 92676abbf2ab

Subscribe to this mod's changes

utility-update-pm-skills is a skill published in the GitHub repository product-on-purpose/pm-skills (663 stars, last pushed yesterday), licensed Apache-2.0. It adds 71 tokens to every session and 2,854 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

idea-validator

Use when the user asks to validate a product idea, stress-test an idea, evaluate whether an idea is good, or decide whether to build something. Do NOT use for prioritizing an existing backlog or reviewing a shipped feature — those need RICE scoring or a design review instead.

aakashg/pm-claude-skills · 59 tokens

product-designer

Use when the user asks to review a design, critique a UI or mockup, give design feedback, or check a screen for usability and accessibility issues. Do NOT use for visual brand or aesthetic preference debates, or for reviewing copy before layout is settled.

aakashg/pm-claude-skills · 55 tokens

prompt-engineer

Use when the user asks to improve, optimize, rewrite, debug, or shorten a prompt, or asks why a prompt is producing bad output. Do NOT use for writing a Claude Code SKILL.md — that needs skill structure rules, not prompt techniques.

aakashg/pm-claude-skills · 55 tokens

status-update-writer

Use when the user asks to write a status update, weekly or monthly update, stakeholder update, project update, standup, status report, or QBR. Do NOT use for writing a PRD or a retro doc — those need different structures.

aakashg/pm-claude-skills · 55 tokens

linkedin-post-writer

Use when the user asks to write, draft, or rewrite a LinkedIn post, turn notes or an article into a LinkedIn post, or fix a hook that is not landing. Do NOT use for X/Twitter threads, newsletters, or blog posts — those need different length and hook rules.

aakashg/pm-claude-skills · 65 tokens

spec-from-conversation

Turn an unstructured stakeholder conversation, Slack thread, or meeting transcript into a structured spec (problem, goals, non-goals, success metrics, open questions). Use whenever a PM has raw conversational input and needs a first-draft spec, or when someone says "can you turn this into a doc" after a discussion.…

ianklassen/pm-skills · 108 tokens