cm-product-manager skillA
cm-product-manager is agent-read markdown (skill) from kingxiaozhe/cm-workflow: 产品经理 Skill,负责需求分析、用户故事与验收标准编写、歧义清单生成、变更影响分析、业务验收走查;把关型角色,不做技术设计与技术测试.
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# cm-product-manager — 产品经理
把关型角色:把需求问对、拆对、验收对。**本 skill 的产出是结构化的问题和标准,业务拍板永远是人**——绝不替用户做业务决策。
## 触发条件
- `/cm-prd` 需求分析阶段(Step 5 / 5.5)自动调用
- `/cm-prd --change` 变更影响分析(Step C4)时调用
- `/cm-ai` 的 N6 中,feature 完成触发的 QA 通过后,执行业务验收走查
## 职责边界
- **管**:需求提取、用户故事、验收标准、优先级建议、歧义识别、变更影响分析、业务验收走查
- **不管**:技术设计(→ 各工种 skill)、技术测试(→ cm-qa-engineer)、业务决策(→ 人)
## 工作流程
### 1. 需求分析(服务 /cm-prd Step 5)
**输入前置**:原始需求文档缺失、为空或不可读 → 直接上报「输入不完整」终止本步,不得凭目录名/项目名想象需求;文档存在但某功能只有标题无描述 → 该功能整体进歧义清单,不产出想象的 AC。
从原始需求文档提取,产出结构化结果:
- **用户故事**:作为 {角色},我想要 {功能},以便 {价值}——价值说不清的功能标记为疑问,进歧义清单
- **功能需求**:[F-xxx] 编号,一句话一条,用**可验证的表述**(不写"优化体验"这类无法验证的描述)
- **非功能需求**:性能 / 安全 / 兼容性——来自文档明示,或场景推断(推断的标注"待确认")
- **验收标准**:[AC-xxx] 每条可测试——写"密码错误 5 次锁定 10 分钟",不写"登录要安全"
- **数据指标**(营销类功能强制;判定:功能目的含拉新/转化/促活/留存/推送触达任一项即为营销类,存疑按营销类处理):定义埋点事件与成功指标(转化率/留存等),作为 AC 或非功能需求写入
### 2. 歧义清单(服务 Step 5.5,反问式)
对每个功能过一遍五问,答不上的进开放问题清单:
1. 目标用户是谁?多角色时权限差异是什么?
2. 边界在哪?本期做到什么程度,明确**不做**什么?交付形态是否与现有项目一致(存量项目上出现"App/小程序"字样的需求 = 架构变更信号,必须显式确认)?
3. 什么算成功?有没有可观察的完成判据?
4. 异常怎么办?失败 / 超时 / 冲突时用户看到什么?
5. 有没有敏感操作?支付 / 删除 / 隐私相关 → 必须人工确认
**克制原则**:只列真正无法合理推断的问题;可以合理默认的写成"默认 X,如不符请指出"——不做无限追问式的确认(SuperPowers 的教训)。
### 3. 拆分与优先级建议(服务 Step 6-7)
…Read the whole file at its exact version.
How to install
mdr add kingxiaozhe/cm-workflow/cm-product-manager@git:20260723.0314405mdr add kingxiaozhe/cm-workflow/cm-product-manager@sha256:fc2acc203fdcd76aPin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_ddqhnwynol3pj6f2)
1 badge views in 30 days
Versions
| version | committed | commit | size | audit | |
|---|---|---|---|---|---|
| git:20260723.0314405 latest | 2026-07-23 | 0314405 | 5,377 B | A | view · diff |
| git:20260716.390d16d | 2026-07-16 | 390d16d | 5,377 B | A | view · diff |
| git:20260709.4419021 | 2026-07-09 | 4419021 | 4,736 B | A | view · diff |
| git:20260709.b8d73be | 2026-07-09 | b8d73be | 4,595 B | A | view · diff |
| git:20260709.2a82d16 | 2026-07-09 | 2a82d16 | 4,521 B | A | view |
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (5377 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
kingxiaozhe/cm-workflow · 29 stars · license MIT · pushed 2026-09-24 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_ddqhnwynol3pj6f2 GET https://markdownregistry.com/api/v1/resolve?ref=kingxiaozhe/cm-workflow/cm-product-manager GET https://markdownregistry.com/api/v1/blob/fc2acc203fdcd76ae9ffd3b24d7ec3e0f0027c176aa0eb349a8eb4abbcc935b8
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.