Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

E2020 Failure Propagation Containment

ASecurity

Verify that a failed current limiter puts no fault effect onto the distribution bus or a neighbouring output line, per clause 5.2.7.3.1 of ECSS-E-ST-20-20C. Use when a containment argument has to hold for every way a limiter fails and not just the convenient one: trace failing conducting, failing open, losing the limiting function and oscillating apart, keep a barrier to the modes it genuinely covers, turn the uncontained fault current into a bus droop across the source impedance, and refuse ...

2 stars
0 votes
0 copies
0 views
Added 9/27/2026
ai-agentspythongo

Works with

claude code

Security Analysis

A100/100

Scanned 9/27/2026

Install to Claude Code

$npx -y skills add ashfordeOU/aero-agent-skills --skill e2020-failure-propagation-containment --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of E2020 Failure Propagation Containment?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for E2020 Failure Propagation Containment
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/ashfordeou-e2020-failure-propagation-containment/badge)](https://www.skillsdirectory.com/skills/ashfordeou-e2020-failure-propagation-containment)

More formats (shields.io, HTML) on the badges page.

Download with Pro
Files
SKILL.md
---
name: e2020-failure-propagation-containment
description: "Verify that a failed current limiter puts no fault effect onto the distribution bus or a neighbouring output line, per clause 5.2.7.3.1 of ECSS-E-ST-20-20C. Use when a containment argument has to hold for every way a limiter fails and not just the convenient one: trace failing conducting, failing open, losing the limiting function and oscillating apart, keep a barrier to the modes it genuinely covers, turn the uncontained fault current into a bus droop across the source impedance, and refuse a backup device that clears after the bus has gone. Trigger: ecss, e-st-20-20c-clause-5-2-7-3-1, limiter-failure-containment, limiter-fault-propagation-to-bus, limiter-barrier-mode-coverage, limiter-fault-bus-droop, limiter-backup-clearing-time."
license: Apache-2.0
compliance: STANDARDS-REF
standards:
  - id: ecss
    reference-only: true
gated: false
domain: space-systems
pack: space-systems
compatibility: "agentskills.io SKILL.md; any SKILL.md host (Claude Code, Hermes, OpenClaw)"
metadata:
  domain: space-systems
  subdomain: ecss
  tags: [ecss, e-st-20-20-power-distribution-scope, e-st-20-20c-clause-5-2-7-3-1, e2020-failure-propagation-containment, limiter-failure-containment, limiter-fault-propagation-to-bus, limiter-barrier-mode-coverage, limiter-fault-bus-droop, limiter-backup-clearing-time]
  version: 0.1.0
  author: Aero Agent Skills
---

# ECSS Power Distribution -- Limiter Failure Propagation Containment (space-systems/ecss/e2020-failure-propagation-containment)

Use when the task is clause 5.2.7.3.1 of ECSS-E-ST-20-20C: a limiter
failure is contained, so no fault effect from it reaches the
distribution bus or a neighbouring output line. Containment is not a
property of the limiter -- it is a property of what stands between the
limiter and everything else -- so this leaf grades the argument one
failure mode at a time instead of one device at a time.

## Domain quick reference

- A limiter fails in several ways and they do not behave alike. Failing
  conducting hands the line whatever the source can deliver. Failing
  open loses the load on that line and nothing beyond it. Losing the
  limiting function leaves a plain switch where a limiter used to be.
  Failing oscillating puts energy onto the bus at a rate no steady-state
  current sum will ever show. An argument that says "the limiter is
  protected" without saying against which of these has argued nothing.
- A barrier only contains the modes it actually covers. A blocking diode
  does nothing about an oscillation. An output filter does nothing about
  a hard short. A backup fuse and an upstream limiter both answer an
  overcurrent and neither answers a ringing loop. Coverage is read from
  the barrier type, not from its presence on the schematic.
- Where no barrier covers the mode, the fault current is still bounded
  by something: it lands on the source impedance, and the product is the
  droop everybody else on that bus sees. Two thresholds sit on that one
  number -- the droop a neighbouring line tolerates, and the larger one
  at which the bus itself is out of limits -- so the same fault reaches
  a neighbour before it reaches the bus.
- A covering barrier still has to act in time. A backup device that
  clears after the bus has already collapsed contained nothing; it
  tidied up afterwards. Clearing is therefore compared against a budget
  that itself sits inside the bus ride-through.
- A mode nobody traced is not a mode that passed. It is the part of the
  argument where no one looked, and it outranks a mode traced and found
  to propagate, because the two need different work.

## Workflow

1. Validate the policy: the neighbour droop limit must sit at or below
   the bus limit, and the clearing budget must sit inside the bus
   ride-through, or the policy permits the collapse it is meant to
   prevent.
2. Name every declared failure mode and refuse an unrecognised one
   before it enters the argument.
3. For each mode, resolve which declared barriers genuinely cover it;
   refuse a barrier declared twice and a barrier type nobody recognises.
4. Compute the droop the mode's fault current produces across the source
   impedance at the bus voltage.
5. Decide the reach: a covered mode clearing inside the budget is
   contained; otherwise the droop places it against the neighbour limit
   and then the bus limit.
6. Collect the modes covered by a barrier that acts outside the budget
   separately -- they are a timing finding, not a coverage one.
7. List the modes never traced at all, then rank the channel at its
   worst standing: untraced, reaching the bus, reaching a neighbour,
   cleared too late, contained.

## Pitfalls

- Arguing containment for the short-circuit case and stopping. The hard
  short is the mode everyone designs for; the oscillation and the
  silently lost limiting function are the ones that arrive at review
  unanswered.
- Counting a barrier because it is in the line rather than because it
  covers the mode. A diode in series with an oscillating limiter is a
  diode in series with an oscillating limiter.
- Reading a failed-open limiter as a containment failure. It takes its
  own load down and puts nothing anywhere else; the finding belongs to
  availability, not to containment.
- Comparing the fault current against a rating and never turning it into
  a bus droop. The neighbours do not feel amps, they feel volts, and the
  source impedance is what converts one into the other.
- Accepting a backup fuse as containment without its clearing time. A
  fuse that opens after the bus undervoltage has tripped everything else
  has cleared a fault on a bus that was already gone.
- Reporting a mode nobody analysed inside the same list as the modes
  that passed. The first needs an analysis and the second needs nothing,
  and merging them buries the one that matters.

## Behavior contract (gate 3)

The failure mode and barrier vocabularies, the per-mode coverage map
that keeps a diode away from an oscillation, the bus droop built from
fault current, source impedance and bus voltage, the neighbour and bus
thresholds on that one droop, the failed-open mode treated as contained,
the clearing budget inside the bus ride-through, the untraced modes kept
apart from the traced ones and the worst-reach channel verdict are
exercised by the gate 3 contract test:
scripts/test_e2020_failure_propagation_containment.py against
scripts/e2020_failure_propagation_containment_logic.py (stdlib unittest,
offline). Run:
python3 scripts/test_e2020_failure_propagation_containment.py

## Compliance

- ECSS standards are freely downloadable (ESA); cite the source and
  paraphrase per standards-map.yaml.
- compliance: STANDARDS-REF, gated: false.

Attribution

ashfordeOUashfordeOU
View sourceMore from ashfordeOU →
SSkills DirectorySkills Directory

Know which skills are safe — weekly.

Best new skills + every skill we flagged as malicious. From the team that scanned 103,619.

Join free

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Know which skills are safe — weekly.

Best new skills + every skill we flagged as malicious. From the team that scanned 103,619.

Join free

Related Skills

Caveman

Ultra-compressed communication mode that cuts output tokens while keeping technical accuracy. Levels: lite, full, ultra and the wenyan variants. Use for /caveman, "caveman mode", "talk like caveman", "be brief" or "less tokens".

1074701 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

694821 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3351 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

691 votes

math-skill

A comprehensive mathematical reasoning skill for AI assistants — handles arithmetic to research-level problems with rigorous step-by-step reasoning, systematic verification, and transparent uncertainty handling

381 votes
View all in ai-agents →