User Story Mapping WorkshopSAFE
Product Management skills framework built on battle-tested methods for Claude Code, Cowork, Codex, and AI agents.
Overview
Product Management skills framework built on battle-tested methods for Claude Code, Cowork, Codex, and AI agents.
0b657a54b6d7OBSERVED · 2026-10-07What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: user-story-mapping-workshop argument-hint: "[system or workflow]" description: Run a user story mapping workshop with adaptive questions and a structured map output. Use when you need backbone activities, tasks, and release slices for a workflow. intent: >- Guide product managers through creating a user story map by asking adaptive questions about the system, users, workflow, and priorities—then generating a two-dimensional map with backbone (activities), user tasks, and release slices. Use this to move from flat backlogs to visual story maps that communicate the big picture, identify missing functionality, and enable meaningful release planning—avoiding "context-free mulch" where stories lose connection to the overall system narrative. type: interactive theme: workshops-facilitation best_for: - "Running a facilitated story mapping session with a real team" - "Building a backbone, tasks, and release slices collaboratively" - "Getting a shared view of the workflow before slicing an MVP" scenarios: - "I'm facilitating a mapping session tomorrow and need the structure and questions" - "The team needs a shared map of the workflow before we can scope an MVP" estimated_time: "60-120 min" --- ## Purpose Guide product managers through creating a user story map by asking adaptive questions about the system, users, workflow, and priorities—then generating a two-dimensional map with backbone (activities), user tasks, and release slices. Use this to move from flat backlogs to visual story maps that communicate the big picture, identify missing functionality, and enable meaningful release planning—avoiding "context-free mulch" where stories lose connection to the overall system narrative. This is not a backlog generator—it's a visual communication framework that organizes work by user workflow (horizontal) and priority (vertical). ## Input **Works best with:** The system or workflow to map. **Also useful:** The primary users, workflow steps you already know, and what the map must decide (MVP scope, release plan). Anything supplied with the invocation itself — text after the skill name, a pasted context dump, or an appended `ARGUMENTS:` line — counts as answers already given. Use it and skip whatever it covers; don't re-ask. **Arriving empty-handed? That works too.** The workshop opens by asking about the system and its users (Q1), then proceeds per the facilitation protocol. **Example invocation:** `Run a story mapping workshop for our vendor onboarding portal — output should give us a first release slice.` ## Key Concepts ### What is a User Story Map? A story map (Jeff Patton) organizes user stories in **two dimensions**: **Horizontal axis (left to right):** Activities arranged in narrative/workflow order—the sequence you'd use explaining the system to someone **Vertical axis (top to bottom):** Priority within each activity, with the most essential tasks at the top **Structure:** ``` Backbone (Activities across top) ↓ User Tasks (descending vertically by priority) ↓ Details/Acceptance Criteria (at the bottom) ``` ### Key Principles **The Backbone:** Essential activities form the system's structural core—these aren't prioritized against each other; they're the narrative flow. **Walking Skeleton:** The highest-priority tasks across all activities form the minimal viable product—the smallest end-to-end functionality. **Ribs:** Supporting tasks descend vertically under each activity, indicating priority through placement. **Left-to-Right, Top-to-Bottom Build Strategy:** Build incrementally across all major features rather than completing one feature fully before starting another. ### Why This Works - **Visual communication:** Story maps remain displayed as information radiators, maintaining focus on the big picture - **Narrative structure:** Organizes by user workflow, not technical architecture - **Release planning:** Horizontal slices reveal MVPs and incremental releases - **Gap identification:** Reveals missing functionality that flat backlogs obscure ### Anti-Patterns (What This Is NOT) - **Not a Gantt chart:** Story maps show priority, not time estimates - **Not technical architecture:** Maps follow user workflow, not system layers (UI → API → DB) - **Not a project plan:** It's a discovery and communication tool, not a schedule ### When to Use This - Starting a new product or major feature - Reframing an existing backlog (moving from flat list to visual map) - Aligning stakeholders on scope and priorities - Planning MVP or incremental releases ### When NOT to Use This - Single-feature projects (story map overkill) - When backlog is already well-understood and prioritized - For technical refactoring work (no user workflow to map) --- ### Facilitation Source of Truth Use [`workshop-facilitation`](../workshop-facilitation/SKILL.md) as the default interaction protocol for this skill. It defines: - session heads-up + entry mode (Guided, Context dump, Best guess) - one-question turns with plain-language prompts - progress labels (for example, Context Qx/8 and Scoring Qx/5) - interruption handling and pause/resume behavior - numbered recommendations at decision points - quick-select numbered response options for regular questions (include `Other (specify)` when useful) This file defines the domain-specific assessment content. If there is a conflict, follow this file's domain logic. ## Application This interactive skill asks **up to 5 adaptive questions**, offering **3-4 enumerated options** at each step. Use `template.md` for the facilitation agenda and outputs checklist. Interaction pattern: Pair with `skills/workshop-facilitation/SKILL.md` when you want a one-step-at-a-time flow with numbered recommendations at decision points and quick-select options for regular questions. If the user asks for a single-shot output, skip the multi-turn facilitation. --- ### Step 0: Gather Context (Before Questions) **Agent suggests:** Before we create your story
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
0b657a54b6d7full audit observations/trust-audit/skill/deanpeters__user-story-mapping-workshop.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 0b657a54b6d7 | SAFE | B | 89 | first audit |
Questions
What does the User Story Mapping Workshop skill do?
Product Management skills framework built on battle-tested methods for Claude Code, Cowork, Codex, and AI agents.
Is User Story Mapping Workshop safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can User Story Mapping Workshop access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (0b657a54b6d7), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.