SkillAtlasSkill 详情

ai-ethics-review

In the official Anthropic plugin directory

审核状态:已审核Quality 72Security 78

复制安装命令

用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。

复制前请先查看来源、License 和安全提示。

项目 README

来源文件:README.md

抓取于 2026年8月16日

🧠 PM Skills — 1098 Professional Agent Skills for Claude, ChatGPT, Gemini, Cursor, Codex & Hermes

PM Skills — 1098 professional skills your AI assistant can read. Plain markdown, works with Claude, ChatGPT, Gemini, Cursor, and Codex. MIT licensed.

In the official Anthropic plugin directory Stars npm PyPI Skills SkillCheck SkillSpec Security Audit Version License Sponsor Listed in Awesome Claude Skills Skill of the day Free runs served Website & newsletter

What is PM Skills?

PM Skills is an open-source library of 1098 Agent Skills — plain-markdown SKILL.md files that teach an AI assistant to do one professional task to a senior professional's standard, from writing a PRD to decoding a lease or running a blameless postmortem. Each skill bundles the framework, an output template, quality checks, and anti-patterns. It is MIT-licensed and works with Claude, ChatGPT, Gemini, Cursor, and Codex.

Decode a lease before you sign it. Write a PRD your team can execute. Simulate the promotion committee before the real one meets. Check the weather with zero API keys. Generic AI gives you filler; these give you the structure a senior professional actually uses.

Works natively in Claude Code and Hermes Agent, with ready-to-paste exports for ChatGPT, Gemini, Cursor, Codex and 8 more tools. (PM stands for Professional, not just Product Management.)

Claude Code — native ChatGPT exports Gemini exports Cursor, Codex, Windsurf — one command MCP — any client
Telegram bot Slack app Raycast launcher Obsidian plugin n8n connector
Python — pip install pm-skills Hugging Face dataset Docker image on ghcr GitHub Actions

🐣 New here? Pick a door — each takes about 30 seconds

  1. Just looking → open the ▶ Playground and run a skill in your browser. Nothing to install, nothing to sign up for.
  2. You use Claude Code → type /plugin, search pm-skills, install. Done — ask "decode this lease" and watch.
  3. You use anything else → npx pm-claude-skills add and pick your tool from the menu (Cursor, Codex, Windsurf, ChatGPT, Gemini…).
  4. Want the guided tour → browse the searchable catalogue site and subscribe to get an email whenever new skills launch.

Nothing here can scare your setup. A skill is a markdown file your AI reads — no runtime, no telemetry, no accounts. Installing copies text files; uninstalling is deleting them. Skeptical? Good instinct: read one first — it's designed to be read by humans too.

Don't know what to look for? Describe your task in plain words at 🔎 find — "my landlord kept my deposit", "board meeting on Thursday" — and it names the skill.

Subscribe to the PM Skills newsletter

Never miss a new skill. New ones drop regularly — subscribe to the newsletter and get a short email with a real example whenever they launch. No spam, unsubscribe anytime. Prefer no email? Follow via RSS or browse the newsletter archive.


🧠 Not just what to do — how to think

Most skills here answer "do this task." A new family answers "think differently about my life."

LLMs have one big weakness: they're too correct. On open-ended questions they give the safe, average, textbook answer — technically right and completely forgettable. Two new bundles fight that head-on (inspired by parallel-divergent-ideation research):

💭 pm-thinking — think better

Escape the generic answer and stress-test your own decisions:

🎯 pm-focus — get unstuck

ADHD-friendly executive function (useful for everyone):

✨ See it in action

It's not just a folder of files — the whole library is explorable, runnable, and a little bit magic. All of this runs in your browser, free, nothing to install:

The Skill Playground: pick the Executive Update skill, fill in a few notes, hit run, and watch a structured executive briefing stream out — all in the browser
▶ Pick a skill → fill a short form → run it → a senior-grade artifact streams out. No install, your key stays in your browser (or run free with no key).

Galaxy 3D — fly through all 1098 skills as a glowing constellation you orbit and click into
🌌 Galaxy 3D — fly through all 1098 skills as a living constellation. The ones you've run burn brighter.
PM Skills Wrapped — your practice turned into a shareable, Spotify-Wrapped-style story
🎁 Wrapped — your practice, as a shareable story. 100% local — nothing leaves your browser.

▶ Open the Playground to run any of the 1098 skills with your own key — or just browse them all.

💬 What can I ask it to do?

Anything below is a real ask that activates a real skill — say it in your own words, the description does the routing:

🏠 "decode this lease before I sign" → lease-decoder📋 "write the PRD for our referral feature" → prd-template🚨 "blameless postmortem for Friday's outage" → incident-postmortem
💰 "practice my salary negotiation" → salary-negotiation📉 "why is churn up this quarter?" → churn-analysis⚖️ "rank the backlog with RICE" → rice-prioritisation
🛂 "prep me for the visa interview" → the-visa-interview🔨 "is this contractor quote fair?" → home-contractor-quote-decoder🏡 "should we rent or buy?" → rent-vs-buy
📝 "draft my self-review honestly" → performance-review🚀 "are we ready to launch?" → product-launch-checklist📬 "my inbox is 4,000 deep" → email-triage-system

…all 1098 asks live in the catalog.

⚡ Quick start

You want to…Do this
Browse the skillsSKILLS.md — the full catalog · or the searchable web catalog
Install in Claude Code/plugin → search pm-skills (it's in the official Anthropic directory) — or npx pm-claude-skills add --agent claude
Install in Cursor / Codex / Windsurf / Cline…npx pm-claude-skills add --agent cursor (or codex, windsurf, aider, cline, zed…)
Use one skill in ChatGPT / GeminiCopy it from exports/chatgpt/ or exports/gemini/ and paste as instructions
Skills over MCP, in any sessionclaude mcp add pm-skills -- npx -y pm-claude-skills-mcp

No npm install needed — npx pm-claude-skills … always runs the latest. npx pm-claude-skills list shows everything in your terminal. Full per-tool instructions: docs/installation.md.

📚 The skills

Every skill follows the same discipline: what it produces, the inputs it needs, a real framework (severity scales, decision rules — not vibes), a concrete output template, quality checks, and anti-patterns. All 1098 pass the SkillSpec L3 gate and a security audit in CI.

Decoders bundle crestSimulators bundle crestCalculators bundle crestLive data bundle crestCowork bundle crestTokens bundle crestSeatbelt bundle crestEssentials bundle crest
DecodersSimulatorsCalculatorsLive dataCoworkTokensSeatbeltEssentials

For everyone — life's paperwork and decisions

FamilyWhat it doesExamples (of many)
🔍 Decoders (25+)Read the document before you sign it — plain language, 🔴🟡🟢 severity, the money mathlease · medical bill · job offer · severance · insurance policy · contractor quote · timeshare
🎭 SimulatorsFace the adversary early — the real meeting, then an out-of-character debriefsalary negotiation · promotion committee · thesis defense · visa interview · due-diligence call
🧮 CalculatorsDeterministic Python scripts + honest models — assumptions labeled, no false precisionrent vs buy · FIRE number · debt payoff · raise vs jump · daycare vs stay-home
📡 Live data (17)Real-time answers with zero API keys — weather, rates, flights, scores, all over plain curlweather · currency · crypto · flights · earthquakes · is-it-down
🏠 Life adminThe unglamorous logistics, done in orderrelocation · new parent · caregiving · doctor visits · records requests
💼 Career momentsThe weeks that decide yearslayoff kit · resignation kit · PIP response · first 90 days as manager · interview gauntlet
🏛 Dead mentors (5) 🆕History's sharpest operators, resurrected — the real methods from public-domain classics, applied to modern workMachiavelli on office politics · Sun Tzu on picking your fights · Franklin's decision algebra · Marcus Aurelius on bad days · Bennett's 1908 time audit
🏛 Life systems (20) 🆕Navigating the bureaucracies and emergencies people face alone — civic, disability, immigration, disastervoting-navigator · disability-benefit-appeal · arrival-setup · credential-recognition · go-bag-builder · after-the-disaster
🧠 Human edges (20) 🆕The parts of life nobody built tools for — neurodivergence, invisible illness, grief, identity, the hard conversationsmasking-budget · spoon-planner · diagnosis-limbo-kit · coming-out-rehearsal · grief-admin · rabbit-hole-rescue
⚡ New-gen (10) 🆕How the next generation lives and earns — creator deals, clips, D&D, ranked, resale, the attention warcreator-deal-decoder · clip-factory · ttrpg-session-forge · the-vibe-check · ranked-climb-coach · attention-reset
🔮 2027 (10) 🆕Problems you don't have yet, but will — the agent era's operational skillsagent-severance · deepfake-drill · agent-hiring-panel · context-bankruptcy · clone-brief · api-for-yourself · the-org-simulator
🎲 Tabletop (5) 🆕Game night, upgraded — teach, judge, plan, design, and practice the tradesteach-the-game · rules-lawyer · game-night-planner · board-game-designer · tabletop-negotiator
🧾 Freelance & renters & parentsSmall bundles for specific livespricing your services · late invoices · deposit recovery · IEP meetings · students
🎲 Hobbies (12) 🆕Life outside work — the genuinely fun stuffwine pairing · houseplant care · board-game night · D&D campaign · stargazing · chess openings
💪 Wellbeing (12) 🆕Body and mind, sustainably — not another app streakhome workout · sleep reset · habit builder · posture reset · screen-time detox
🔐 Digital self-defense (12) 🆕When your digital life is under attackidentity-theft recovery · phishing triage · account recovery · data-broker removal · doxxing response
👪 Family & relationships (12) 🆕The people who matternew-baby logistics · wedding vows · co-parenting messages · condolences · in-law boundaries
💭 Thinking modes (24) 🆕Change how your AI reasons — escape the generic answer, stress-test decisionsthe-third-answer · five-minds · decision-panel · red-team-my-plan · devils-advocate · poke-holes-in-this
🎯 Focus & executive function (26) 🆕Get unstuck and run your own brain — ADHD-friendly, for everyonewhere-do-i-start · task-to-first-step · overwhelm-triage · the-one-thing · build-my-memory-file · weekly-unstuck
📖 Learning & mastery (10) 🆕Learn anything faster and make it sticklearn-anything-roadmap · feynman-explainer · spaced-repetition-setup · skill-plateau-breaker · deliberate-practice-plan
💰 Wealth-building (10) 🆕Build wealth on purpose — educational, not financial adviceinvesting-for-beginners · index-fund-starter · ask-for-a-raise · first-100k-plan · financial-independence-roadmap
🤝 Social & relationships (10) 🆕The hard conversations and the human onesmake-friends-as-an-adult · networking-for-introverts · boundary-setting-scripts · give-hard-feedback-kindly · repair-after-a-fight
🩺 Caregiving & aging (10) 🆕Care for aging parents and navigate the system — not medical/legal advicemedical-appointment-advocate · care-team-coordinator · caregiver-burnout-check · long-term-care-options · end-of-life-wishes-conversation
🤖 AI-native life (10) 🆕Use AI itself well — the meta-skills that make every tool betterprompt-library-builder · delegate-to-ai · ai-context-primer · spot-ai-mistakes · get-more-from-ai
🤝 Cowork (100)The office knowledge work an AI coworker actually does — the frameworks — the whole bundleemail triage · spreadsheet audit · meeting cost meter · deck outline first · saying no kindly · delegation brief
⚡ Cowork · Live (12)The same jobs, done — Claude Cowork acts on your real data via connectors + sandbox and returns an artifact — the whole bundleinbox triage (live) · meeting prep (live) · spreadsheet audit (live) · deck from doc · thread → decision · PR description (live)

For professionals — 35 fields

Product Management Engineering Marketing & GTM
Customer Success Data & Analytics Leadership & People
Design & UX Legal Finance
Founders Security Government

…plus HR, sales, operations, research, healthcare, educators, writers, social media, and more — the full profession index, or by bundle in plugins/ (121 bundles). Install any bundle: /plugin install pm-decoders@pm-skills.

Meta

Before installing anyone's skills (including these): skill-vetting — a security read for SKILL.md files. The library's own standard lives in SKILLSPEC.md; every skill's level is enforced in CI.

🔍 What does a skill look like?

A skill is a single markdown file with a name, a description that tells the assistant when to activate it, and a body containing the working framework: required inputs, decision rules or severity scales, a concrete output template, quality checks, and anti-patterns. The assistant reads it and gains the judgment; humans can read, audit, and edit the same file. No runtime, no lock-in.

---
name: lease-decoder
description: "Decode a residential lease into plain English and rank the
  clauses that can hurt you. Use when someone asks 'what am I signing'…"
---
## Framework: Severity Scale
- 🔴 Can cost you real money — auto-renewal into a full new term, break
  penalties beyond re-rental costs, deposit conditions written to fail…

That's the whole trick: it's markdown. Your agent reads it and gains the judgment; you can read it too, audit it, edit it, or write your own. No lock-in, no runtime, no telemetry.

💸 Cut your token bill

The pm-tokens bundle optimizes every stage of your agent's token journey — no API keys, stdlib Python, nothing leaves your machine. Five habits, typically 30–60% off a session's token flow:

# 1. Map the repo instead of reading it (~3% of the cost of reading everything)
python3 skills/repo-map/scripts/repo_map.py .

# 2. Crush bulk before it enters context (98% smaller on uniform JSON; errors always survive)
python3 skills/context-crusher/scripts/context_crush.py --mode json --file response.json

# 3. Measure what anything costs — at YOUR prices, times YOUR call volume
python3 skills/token-cost/scripts/token_cost.py --file CLAUDE.md --price-in 3 --calls 200

Plus the judgment skills: token-diet (output costs 3–5× input — diet it where safe), context-budget (cache-aware layout: stable first, volatile last), and session-handoff (resume at ~5% of transcript size). See your own breakdown in the 🪙 Token Dashboard — paste what rides in your context, get computed per-piece savings, all in-browser. The full how-to: docs/SAVE-TOKENS.md.

🤝 Make the most of the cowork skills

The pm-cowork bundle is 100 skills for the office work an AI coworker actually does. Install it (/plugin install pm-cowork@pm-skills), then — the whole trick — describe your mess, don't name the skill: say "my inbox is 4,000 deep", "nobody reads my status updates", "this spreadsheet came from someone who left" — the right skill activates on the ask.

Start where it hurts:

Your painSay thisThe skill that answers
Drowning in email"triage my inbox and cut the volume at the source"email-triage-system → inbox-unsubscribe-purge
Calendar is all meetings"audit my recurring meetings and price them"standing-meeting-audit + meeting-cost-meter
Inherited a scary spreadsheet"audit this sheet before we trust it"spreadsheet-audit → formula-detangler
Docs get rewritten in review"outline first, get sign-off, then draft"outline-before-prose
Weeks just happen to you"set up my weekly review"weekly-review-ritual — the hub the others plug into

Three habits that compound: (1) The weekly review is the keystone — it feeds task-triage-matrix, deep-work-blocking, and personal-wip-limits automatically. (2) The skills chain on purpose — email-to-tasks feeds the task triage; the meeting audit feeds async-instead; delegation-brief hands off what the triage says to shed — follow the links inside each skill. (3) Teams adopt one norm at a time — start with agenda-or-cancel or working-agreements, let it stick, then add the next; the ten-norms-on-Monday rollout is how none of them survive.

🔬 Prove it, and stop paying rent

Two CLI tools for the trust-and-cost problems the ecosystem keeps hand-waving — both keyless-to-inspect, both one command:

# Does your skill actually work? Prove it. Paired A/B — skill on vs off, same tasks,
# REAL token counts from the API's usage fields, optional blind judge, sha-pinned receipt.
npx pm-claude-skills prove --skill ./my-skill --tasks tasks.txt --runs 2 --judge
npx pm-claude-skills prove --skill ./my-skill --tasks tasks.txt --dry-run   # plan + call count, spends nothing

# Your MCP servers are charging you rent. Measure it: per-server token cost,
# unused-in-N-days flags, "disconnect these three, save X tokens per message".
npx pm-claude-skills mcp-audit --connect

prove exists because the ecosystem is full of "65% better!" claims and almost none are measured — it's the honest-broker harness (the JetBrains "advertised 65%, measured 8.5%" story is exactly why). mcp-audit reads your Claude configs, speaks real MCP to each server to count its schema tokens, and scans your session logs for what you actually use. See also the 📊 AI Spend page — every agent's cost (Claude Code, Codex, Copilot) in one meter, all in-browser.

Agent safety: the pm-seatbelt bundle is the pre-flight checklist before an agent touches email, the browser, or files — least-privilege reviews, prompt-injection spotting, and the blast-radius drill for going autonomous. And RFC 0002 — HANDOFF.md is a dead-simple session-handoff convention (your agent, but it remembers Monday) — a file, not a server, with reference hooks.

✅ Quality, not just quantity

  • Every skill passes the SkillSpec L3 gate — structure, framework, quality checks, anti-patterns — enforced in CI on every commit
  • Eval-scored — 208 scored outputs, avg 4.8/5, judged blind
  • Security-audited — a dedicated CI workflow sweeps every skill and script; calculators are stdlib-only and deterministic with byte-exact output tests
  • Honest by design — decoders end with a not-legal-advice line, calculators name what they don't model, simulators debrief out of character, and skills that shouldn't ghostwrite (student statements) coach instead

🎁 Beyond the skills (the bonus material)

The library grew an ecosystem — all optional, all linked from the full showcase:

▶ Skill Playground — try any skill in your browser, no install · 📸 the Gallery — the creative side, in screenshots · Anti-Pattern Museum — 2,900+ shareable rules · The Handbook (also a real printed book) · Workflow recipes · Subagents & slash commands · MCP server + REST API · n8n / Slack / Obsidian integrations · The Boardroom · SkillBench · Org Edition · 🇪🇸 🇫🇷 🇨🇳 🇯🇵 translations

📄 The one-page cheatsheet

The whole library on one poster — start path, standout features, and install one-liners for every tool. Print it, share it, drop it in a slide.

PM Skills cheatsheet — one link to start, the standout features, and install paths for every tool on one poster.

🖼️ PNG · 📄 PDF · 🌐 Live poster · 📥 Markdown

🆕 Latest

v76.0.0 — the systems wave: 20 new skills for the bureaucracies and emergencies people face alone — 🏛 pm-civic (vote, permits, jury duty, the letter that gets action, report a hazard), ♿ pm-accessibility (appeal a denied disability benefit, accommodations, accessible travel, disclosure), ✈️ pm-newcomer (first-90-days in a new country: arrival setup, credential recognition, healthcare, credit from scratch), and 🚨 pm-emergency (go-bag, your real local hazards, outage plan, after-the-disaster) — every one guard-railed and routed to official sources. 1098 skills, 121 bundles.

v75.0.0 — the human-edges wave: 20 new skills for the parts of life nobody built tools for — 🧠 pm-neurodivergent (masking-budget, meltdown-map, body-double-session, nt-translator, sensory-audit), 🩺 pm-invisible-illness (diagnosis-limbo-kit, spoon-planner, perimenopause-navigator, flare-day-planner), 🏳️‍🌈 pm-identity (coming-out-rehearsal, name-change-navigator, two-worlds-translator, faith-transition-companion) — plus grief-admin, legacy-letter, the-ick-decoder, and rabbit-hole-rescue; every sensitive one guard-railed. 1098 skills, 121 bundles.

v74.0.0 — the life-expansion wave: five new bundles for the parts of life beyond the office — 📖 pm-learning (learn anything and make it stick: learn-anything-roadmap, feynman-explainer, spaced-repetition-setup), 💰 pm-wealth (build wealth on purpose — educational, not advice: investing-for-beginners, first-100k-plan, ask-for-a-raise), 🤝 pm-social (the human conversations: make-friends-as-an-adult, boundary-setting-scripts, repair-after-a-fight), 🩺 pm-caregiving (care for aging parents — not medical/legal advice: medical-appointment-advocate, caregiver-burnout-check), and 🤖 pm-ai-native (use AI itself well: prompt-library-builder, delegate-to-ai, spot-ai-mistakes) — 50 new skills; 1098 skills, 121 bundles.

v73.0.0 — think differently: two bundles that change how your AI reasons, not just what it does — 💭 pm-thinking (escape the generic answer: the-third-answer, five-minds, red-team-my-plan, devils-advocate) and 🎯 pm-focus (ADHD-friendly executive function: where-do-i-start, overwhelm-triage, build-my-memory-file) — 50 skills inspired by parallel-divergent-ideation research; passes the 1,000 mark — now 1098 skills, 110 bundles.

v72.0.0 — the Everyday Life update: the biggest single drop yet — 100 new skills across four new bundles: 🎲 hobbies (wine pairing, board-game nights, D&D), 💪 wellbeing (workouts, sleep, habits), 🔐 digital self-defense (identity-theft recovery, phishing triage, doxxing response), and 👪 family (new-baby logistics, wedding vows, condolences) — plus new money, legal, home, career, freelance and learning skills; 1098 skills, 108 bundles.

v67.0.0 — the everywhere wave: six new rooms — the trades (quotes, stage payments, apprentices), the committee (AGMs, treasurers, the council mic), open-source maintainers, aging parents (the talks, the sibling summit), the kitchen, the band — plus used-car/mechanic-quote decoders, the group-trip fixer, and 🌱 daily practice; 1098 skills, 104 bundles. v66 — new-gen; pm-newgen — decode your first brand deal, clip the podcast, prep tonight's D&D, fix the dating profile honestly, vibe-check the weekend app, keep the flat peaceful, climb ranked on purpose, flip thrift finds, plan the micro-retirement, get your attention back; 1098 skills, 104 bundles. v65 — pm-2027; ten skills for problems you don't have yet (but will) — offboard an AI coworker, drill the deepfake wire-fraud call, hire your agent like an employee, declare context bankruptcy, send your position to meetings instead of your body, publish your personal API, simulate the reorg before announcing it; 1098 skills, 104 bundles. v64 — game night; pm-tabletop — teach any board game in 5 minutes, settle rules arguments fairly, plan the lineup, design your own game, and spar the Catan trade against a hidden agenda with a scored debrief; 1098 skills, 104 bundles. v63.1 — pixel confetti: pixel-gif-maker — custom retro Slack GIFs (scroll, pulse, party, sparkle) from a pure-stdlib deterministic encoder; 1098 skills. And v63.0.0 — the dead mentors: history's sharpest operators, resurrected as skills — Machiavelli reads your reorg (with the honest counterweight built in), Sun Tzu decides fight/reshape/decline, Franklin's decision algebra settles the offer you keep flip-flopping on, Marcus Aurelius debriefs the day that went badly, and Arnold Bennett (1908) finds your inner day — real methods from public-domain classics, chapter-cited, never misquoted. Earlier — v62.2, the distribution wave (SkillScan, telemetry, SkillBench v2, quiz, wins, WhatsApp); v62.1, nine frontiers. Full history: CHANGELOG · releases

❓ First-timer questions, straight answers

Is it actually free? Yes — MIT, all 1098 skills, forever. The skills are markdown; there is nothing to gate. Sponsors fund the playground's free model runs, not access.
Do I need an API key? Not to browse, read, install, or use skills inside a tool you already have (Claude Code, ChatGPT, Cursor…). The playground even serves a few sponsor-funded free runs a day. A key only enters the picture for optional extras like running skills from CI.
I'm not a product manager. Is this for me? PM stands for Professional here. Most of the library is decoders for leases and medical bills, salary-negotiation practice, career-moment kits, life admin, and 35 professions from teaching to veterinary. The product-management corner is just where it started.
Will this mess with my existing setup? No. Skills are inert text files in a folder; your assistant reads them when relevant. Remove the folder and it's like they were never there. The CLI never touches anything outside the skills directory it tells you about.
How do I know these are any good? Every skill passes a structural gate (SkillSpec L3) and a security scan in CI; 208 outputs are eval-scored in the open (avg 4.8/5), and the benchmark report publishes the negative findings too. When something's machine-translated or unscored, it's labelled.

🤝 Contributing

The library grows a skill at a time — plant one of your own. One markdown file, one PR.

Add a skill via PR (the standard, CONTRIBUTING), request one via issue, or publish your own repo to the community index and earn the badge. Translations follow the pattern in skills-i18n/.

❤️ Support

If a skill saved you real money or a real mistake, star the repo — it's how others find it. Sponsors fund the playground's free runs and get naming rights, not influence: become a sponsor.

📄 License

MIT — use them, fork them, ship them at work. Skills are judgment, and judgment wants to be free.


Built by Mohit with Claude. 1098 skills · 121 bundles · 35 professions · every commit gated. The long version of this README — every feature, wave, and frontier bet — lives in the Showcase.

DevOps 与部署

中风险

  • 来源需自行核对维护者身份。
  • 未检测到明显脚本安装指令。
  • 可能需要外部 token、网络权限或第三方服务。
  • 未检测到高风险命令。
  • 扫描发现:1 条。

Codex — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/mohitagw15856/pm-claude-skills.git
  3. 将 "skills/ai-ethics-review" 文件夹复制到 Codex 的 skills 目录中。
  4. 重启 Codex 让新的 skill 生效。

Codex — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Codex 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Codex 让新的 skill 生效。

Claude Code — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/mohitagw15856/pm-claude-skills.git
  3. 将 "skills/ai-ethics-review" 文件夹复制到 Claude Code 的 skills 目录中。
  4. 重启 Claude Code 让新的 skill 生效。

Claude Code — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Claude Code 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Claude Code 让新的 skill 生效。

Cursor — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/mohitagw15856/pm-claude-skills.git
  3. 将 "skills/ai-ethics-review" 文件夹复制到 Cursor 的 skills 目录中。
  4. 重启 Cursor 让新的 skill 生效。

Cursor — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Cursor 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Cursor 让新的 skill 生效。

GitHub Copilot — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/mohitagw15856/pm-claude-skills.git
  3. 将 "skills/ai-ethics-review" 文件夹复制到 GitHub Copilot 的 skills 目录中。
  4. 重启 GitHub Copilot 让新的 skill 生效。

GitHub Copilot — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 GitHub Copilot 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 GitHub Copilot 让新的 skill 生效。

Windsurf — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/mohitagw15856/pm-claude-skills.git
  3. 将 "skills/ai-ethics-review" 文件夹复制到 Windsurf 的 skills 目录中。
  4. 重启 Windsurf 让新的 skill 生效。

Windsurf — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Windsurf 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Windsurf 让新的 skill 生效。
查看 SKILL.md 原文
name: ai-ethics-review
description: "Conduct a structured ethical review of an AI or ML feature, model, or product. Use when preparing to deploy an AI system, assessing algorithmic risk, auditing a model for bias, or producing a responsible AI impact assessment. Produces a structured ethics review covering fairness, transparency, privacy, safety, accountability, and societal impact with a risk tier score, pre-deployment checklist, and prioritised mitigations."

AI Ethics Review Skill

This skill produces a structured ethical review of an AI or machine learning feature, model, or product. Output covers fairness, transparency, privacy, safety, accountability, and societal impact — with risk scoring, prioritised mitigations, and a checklist suitable for governance review or responsible AI documentation.

⚠️ This skill provides a structured framework for identifying and documenting ethical risks. It is not a substitute for legal advice, regulated algorithmic impact assessments, or specialist ethics review required in specific jurisdictions (e.g. EU AI Act, UK AI regulation).

Required Inputs

Ask the user for these if not provided:

  • Feature or model name and what it does
  • Who it affects — which users or people does the AI interact with, make decisions about, or collect data from?
  • What decisions or outputs it produces — recommendations, predictions, classifications, generation, automation?
  • Consequentiality — how significant are the AI's decisions? (low-stakes suggestions vs decisions that affect employment, credit, health, safety, etc.)
  • Data used — what training data, user data, or third-party data is used?
  • Human oversight — is there a human in the loop, and at what stage?
  • Deployment context — who will use this and how? (internal tool / consumer-facing / automated pipeline)

Output Structure


AI Ethics Review: [Feature / Model Name]

Product / system: [Name and brief description] Review type: [Pre-deployment review / Post-deployment audit / Change review] Risk tier: [High / Medium / Low — based on consequentiality, scale, and affected population] Reviewer: [Name / Team] Date: [Date] Status: [Draft / Approved / Requires escalation]


1. Feature Summary

What it does[1–2 sentences — plain English description of the AI feature and its purpose]
Who uses it[End users / internal teams / automated system]
Who is affected by its outputs[May be different from who uses it — e.g. an AI hiring tool is used by HR but affects candidates]
Output type[Recommendation / Classification / Prediction / Generation / Automation / Scoring]
Scale[How many people affected per day/month?]
Consequentiality[High: affects access to services, employment, credit, health, safety / Medium: influences decisions / Low: suggestions with easy override]
Human oversight level[Full automation / Human review before action / Human can override after action / Advisory only]

2. Risk Tier Assessment

FactorScore (1–3)Rationale
Consequentiality (impact on individuals)[1=low, 3=high][e.g. 3 — model output influences hiring decisions]
Scale (number of people affected)[1=few, 3=many][e.g. 2 — internal tool used for ~500 candidates/year]
Reversibility (can harm be undone?)[1=reversible, 3=irreversible][e.g. 2 — unfair rejection can be appealed but may not be caught]
Vulnerability of affected group[1=general population, 3=protected or vulnerable group][e.g. 2 — includes protected characteristics in the decision context]
Transparency (do affected people know?)[1=informed, 3=opaque][e.g. 3 — candidates are not told AI is used in screening]

Composite risk tier: [High (12–15) / Medium (7–11) / Low (3–6)]

Risk tier implications:

  • High: Mandatory senior ethics review, DPA/DPIA required, human-in-loop for all consequential decisions, ongoing monitoring required
  • Medium: Ethics review recommended, document mitigations, quarterly monitoring
  • Low: Standard review, document assumptions, annual review

3. Fairness & Bias

Does the AI treat people equitably across groups?

Protected characteristics relevant to this feature: [List applicable protected characteristics — age, gender, race/ethnicity, disability, religion, national origin, etc.]

RiskAnalysisMitigation
Training data bias[Does the training data reflect historical discrimination? e.g. hiring data that reflects past biases in who was hired][Audit training data for demographic representation / use debiasing techniques / document data lineage]
Proxy discrimination[Could the model use a proxy for a protected characteristic? e.g. using postcode as a proxy for race][Identify proxy features / test for disparate impact using adversarial debiasing]
Differential performance[Does the model perform differently across demographic groups? — e.g. lower accuracy for underrepresented groups][Disaggregate performance metrics by group / set minimum performance thresholds per group]
Feedback loops[Does the model's output reinforce existing disparities? e.g. recommending content that keeps disadvantaged groups in lower-engagement patterns][Monitor outcome distributions over time / implement feedback loop detection]

Fairness evaluation method: [What method will be used to measure fairness — statistical parity / equalised odds / individual fairness? Who is responsible for running it and how often?]


4. Transparency & Explainability

Can affected people understand how the AI makes decisions?

DimensionCurrent stateRequired stateGap
User disclosure[Are users told they're interacting with AI?][Yes — required for trust and regulation][e.g. No disclosure on current UI]
Decision explanation[Can the system explain why it reached a conclusion?][For high-stakes decisions: yes][e.g. Black-box model — no feature attribution available]
Right to know[Can affected people ask how a decision was made?][Yes — required under GDPR Art. 22 for automated decisions][e.g. No process exists]
Confidence calibration[Does the model express appropriate uncertainty?][Yes — overconfident models cause over-reliance][e.g. Model outputs binary label without confidence score]

Explainability approach: [LIME / SHAP / rule-based surrogate / LLM-generated rationale / none — and why]


5. Privacy & Data

Is personal data used responsibly and lawfully?

RiskAnalysisMitigation
Data minimisation[Does the model use more personal data than necessary?][Audit input features — remove any that don't improve performance and involve unnecessary data collection]
Data retention[How long is personal data retained for training and inference?][Define retention policy aligned to GDPR / CCPA / sector requirements]
Re-identification risk[Could model outputs or training data be used to identify individuals?][Differential privacy / k-anonymity / output rate limiting]
Third-party data[Is data from third parties used? Is it licensed for this use?][Audit data licensing / get legal sign-off on each third-party source]
Cross-border data transfer[Is personal data transferred across jurisdictions?][Legal review — Standard Contractual Clauses or equivalent]

DPIA required? [Yes / No / Uncertain — for High tier or whenever processing is likely to result in high risk to individuals under GDPR Art. 35]


6. Safety & Reliability

What happens when the AI gets it wrong?

Failure modeLikelihoodImpactMitigation
False positives[H/M/L][e.g. Flagging a legitimate transaction as fraud — customer locked out][Set threshold conservatively; human review for edge cases]
False negatives[H/M/L][e.g. Missing a real fraud case — financial loss][Monitor false negative rate; set minimum recall threshold]
Out-of-distribution inputs[H/M/L][Model behaves unpredictably on inputs outside training distribution][Input validation; confidence thresholding — route uncertain inputs to human review]
Model degradation[M][Performance degrades as data distributions shift post-deployment][Scheduled performance monitoring; drift detection alerts]
Adversarial inputs[L/M][Deliberate manipulation of inputs to game the model][Adversarial testing; rate limiting; anomaly detection on inputs]
Single point of failure[L/M][Model outage causes downstream system failure][Graceful degradation — define fallback behaviour when model is unavailable]

Fallback behaviour: [What happens if the AI is unavailable or returns low-confidence output? — e.g. route to human review / use rule-based fallback / block the action]


7. Accountability & Governance

Who is responsible when things go wrong?

QuestionAnswer
Who owns this AI feature?[Team or individual with end-to-end accountability]
Who approved deployment?[Name and role — must be documented]
Who is responsible for ongoing monitoring?[Team and cadence]
Who can shut it down?[Who has kill-switch authority and under what conditions?]
How are incidents reported?[Internal escalation path + external disclosure process if required]
Is this subject to regulation?[EU AI Act / UK AI regulation / sector-specific rules — FINRA, FDA, FCA, etc.]

Incident response plan: [Link to or describe what happens if the model causes harm — detection, escalation, remediation, disclosure]


8. Societal Impact

Beyond individual users — what are the broader effects?

Impact areaRiskMitigation
Labour displacement[Does this AI automate tasks that currently employ people?][Transition plan / human-AI collaboration framing / skills retraining commitment]
Environmental impact[What is the carbon cost of training and inference?][Measure and offset; prefer efficient architectures; use renewable-energy infrastructure where possible]
Power concentration[Does this AI give the deploying organisation disproportionate power over individuals?][Ensure right to opt out; avoid lock-in; consider open alternatives]
Information ecosystem[Could this AI contribute to misinformation, filter bubbles, or manipulation?][Provenance labelling / content policies / algorithmic diversity requirements]

9. Mitigation Priorities

#RiskSeverityActionOwnerDeadline
1[Highest risk — e.g. No disclosure to affected candidates]Critical[Add AI disclosure to UI and candidate-facing documentation][PM + Legal][Before launch]
2[e.g. No fairness evaluation across demographic groups]High[Commission third-party fairness audit using [method]][ML team + external auditor][Within 30 days of launch]
3[e.g. No model monitoring in place]High[Deploy performance and drift monitoring dashboard][ML Ops][Launch day]
4[e.g. DPIA not completed]High[Complete DPIA with DPO before deployment][Legal / DPO][Before launch]

10. Pre-Deployment Checklist

  • Ethics review completed and approved by required reviewers
  • DPIA completed (if required)
  • Fairness evaluation completed and results documented
  • AI disclosure is in place wherever required
  • Human oversight mechanism is defined and tested
  • Kill-switch and escalation path is documented and tested
  • Model monitoring is deployed and alerting is configured
  • Data lineage and training data audit documented
  • Legal sign-off obtained on data licensing and cross-border transfers
  • Incident response plan in place

Quality Checks

  • "Who is affected" includes people the AI makes decisions about, not just who uses the product
  • Fairness analysis names specific protected characteristics, not just "diverse groups"
  • Safety section covers both false positive and false negative failure modes
  • Accountability section names real people, not teams or roles
  • Mitigations are specific and time-bound — not "monitor and review"

Anti-Patterns

  • Do not limit the affected-population analysis to users of the product — AI that makes decisions about people (hiring, credit, content moderation) affects non-users who have no opt-out
  • Do not accept "we will monitor" as a mitigation without specifying what is monitored, at what threshold, and who acts
  • Do not assign fairness analysis to the model team alone — protected characteristic analysis requires input from legal, HR, or a subject-matter expert
  • Do not defer the DPIA to post-launch — for high-risk tier systems, a DPIA is a pre-requisite for lawful deployment under GDPR
  • Do not conflate statistical accuracy with fairness — a model can be 95% accurate overall while performing significantly worse for a protected group

Example Trigger Phrases

  • "Run an AI ethics review for [feature]"
  • "Conduct an ethical impact assessment for our new ML model"
  • "Review the AI risks for our hiring / credit / recommendation system"
  • "Build a responsible AI checklist for our product"
  • "What are the ethical risks of using AI for [use case]?"

发现问题?提交给管理员复核

评分:

评论 (0)

暂无评论,成为第一个评论者吧!