Install
$ agentstack add skill-mshadmanrahman-pm-pilot-search-first ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Search First
Mandatory research before writing any new code. Reuse beats reinvention.
When to Use
- Before implementing any new feature
- Before writing a utility function
- Before adding a new dependency
- Before building infrastructure (CI, deploy, tooling)
Procedure
Step 1: GitHub Code Search
# Search for existing implementations
gh search repos "{feature keywords}" --limit 5
gh search code "{function signature or pattern}" --limit 10
Look for:
- Battle-tested implementations with stars and activity
- Patterns that solve 80%+ of the problem
- Forkable/portable code with compatible licenses
Step 2: Package Registry Search
Check the relevant registry:
- npm:
npm search {keywords} - PyPI:
pip index versions {package}or web search - crates.io:
cargo search {keywords} - Go:
pkg.go.devsearch
Evaluate packages on:
- Download count and trend
- Last publish date (stale = risk)
- Dependency count (fewer = better)
- License compatibility
Step 3: Library Documentation
- Read official docs for candidate libraries
- Check API matches the use case
- Verify version compatibility with project
Step 4: Decision
Output one of:
REUSE: {package/repo} - {why it fits}
ADAPT: {package/repo} - {what needs modification}
BUILD: No suitable existing solution - {why}
Output Format
Search: {what was needed}
GitHub: 3 repos found, 1 strong match
- github.com/user/repo (2.1k stars, MIT, active)
Registry: 2 packages evaluated
- package-name (50k weekly downloads, v3.2.1)
Decision: REUSE package-name
Rationale: Covers all requirements, well-maintained, MIT license
Install: npm install package-name
Rules
- NEVER skip this step for non-trivial implementations
- Spending 5 minutes searching saves hours of coding
- A 90% solution from a library beats a 100% custom solution
- If BUILD is the decision, document why alternatives were rejected
- For trivial utilities (< 10 lines), skip registry search
- Always check license compatibility before adopting
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: mshadmanrahman
- Source: mshadmanrahman/pm-pilot
- License: MIT
- Homepage: https://github.com/mshadmanrahman/pm-pilot#readme
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.