Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Q1009 Waiver Deviation

ASecurity

Prepare and route a deviation or waiver request against an agreed requirement under ECSS-Q-ST-10-09C clause 5.2.3.5 and the M-ST-40 configuration rules. Use when a departure has to be authorised before build or accepted after the fact, when the request package is short of fields, or when affected items risk being used before approval: derive deviation against waiver from whether the departure already exists, complete the configuration record and its impact headings, route the signature to the...

2 stars
0 votes
0 copies
0 views
Added 9/27/2026
ai-agentspythongo

Works with

claude code

Security Analysis

A100/100

Scanned 9/27/2026

Install to Claude Code

$npx -y skills add ashfordeOU/aero-agent-skills --skill q1009-waiver-deviation --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Q1009 Waiver Deviation?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Q1009 Waiver Deviation
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/ashfordeou-q1009-waiver-deviation/badge)](https://www.skillsdirectory.com/skills/ashfordeou-q1009-waiver-deviation)

More formats (shields.io, HTML) on the badges page.

Download with Pro
Files
SKILL.md
---
name: q1009-waiver-deviation
description: "Prepare and route a deviation or waiver request against an agreed requirement under ECSS-Q-ST-10-09C clause 5.2.3.5 and the M-ST-40 configuration rules. Use when a departure has to be authorised before build or accepted after the fact, when the request package is short of fields, or when affected items risk being used before approval: derive deviation against waiver from whether the departure already exists, complete the configuration record and its impact headings, route the signature to the customer or the supplier board, and permit use only inside the authorised effectivity and calendar life. Trigger: ecss, q-st-10-09c, deviation-request, waiver-request, m-st-40-configuration-record, customer-ccb-routing, authorised-effectivity, use-before-approval, departure-justification."
license: Apache-2.0
compliance: STANDARDS-REF
standards:
  - id: ecss
    reference-only: true
gated: false
domain: space-systems
pack: space-systems
compatibility: "agentskills.io SKILL.md; any SKILL.md host (Claude Code, Hermes, OpenClaw)"
metadata:
  domain: space-systems
  subdomain: ecss
  tags: [ecss, q-st-10-09c-nonconformance-scope, q1009-waiver-deviation, deviation-request, waiver-request, m-st-40-configuration-record, customer-ccb-routing, authorised-effectivity, use-before-approval]
  version: 0.1.0
  author: Aero Agent Skills
---

# ECSS Nonconformance Control — Deviation and Waiver Requests (space-systems/ecss/q1009-waiver-deviation)

Use when the task is the deviation-and-waiver step of ECSS-Q-ST-10-09C
clause 5.2.3.5 — turning a proposed or existing departure from an
agreed requirement into a configuration record that somebody with the
authority to do so has approved, before the affected items are used.

## Domain quick reference

- One fact separates the two request types: whether the departure has
  already been incurred. Asked before the item is built or the activity
  is performed, the request is a deviation and authorises the departure
  in advance. Asked once the departure exists, it is a waiver and asks
  for acceptance of what is already there. The words are not
  interchangeable, because the configuration record they produce has
  different standing.
- Both are configuration management records under the M-ST-40 branch,
  so both name a configuration item, the requirement departed from, the
  departure itself, a justification, the items covered, and how long
  the authorisation lasts — one-off, a limited effectivity, or
  permanent.
- The impact assessment is a set of headings, not a free paragraph.
  Safety, reliability, interfaces, lifetime and verification each get an
  answer; an unanswered heading is a missing field, not a silent no.
- Routing follows the impact and the baseline. A requirement that sits
  in the customer-approved baseline, or a departure that reaches safety
  or an interface, is the customer board's to approve. Everything else
  stays with the supplier's own board.
- Approval is not open-ended. It covers a stated number of units and,
  where one is given, an expiry date; once either is spent the
  authorisation no longer covers the next item and a fresh request is
  owed.
- Using an affected item before the request is approved is not a
  paperwork lag. It is a departure with no authorisation behind it, so
  it is raised as a nonconformance in its own right.

## Workflow

1. Establish whether the departure already exists and name the request
   accordingly; do not let a late deviation stand in for a waiver.
2. Assemble the configuration record: request identifier the register
   can hold, configuration item, requirement identifier, description of
   the departure, justification, the items it covers, and the duration.
3. Answer every impact heading explicitly and carry the affected areas
   forward; an incomplete assessment stops the request before it
   reaches anyone's signature.
4. Route the approval. Baseline requirements and safety or interface
   impacts go to the customer board; the rest stay with the supplier
   board, and the reason for the routing is recorded with it.
5. Check the state of the request against the use of the items. Draft
   and submitted requests authorise nothing, and items already used
   under one are escalated as a separate nonconformance.
6. For an approved request, take the authorised unit count and the
   expiry date against the date of the decision and report what is
   left; release only while both remain.
7. Report the type, the missing fields, the routing, the remaining
   authorisation and the findings, so the change is traceable from the
   requirement to the delivered item.

## Pitfalls

- Filing a waiver as a deviation because the request form was started
  before the part was cut. The test is the departure, not the
  paperwork, and a mislabelled record overstates how much control the
  programme had at the time.
- Approving a request whose effectivity is a phrase rather than a list.
  "The affected units" covers everything and nothing; the record names
  the items, and a later unit needs its own coverage.
- Treating an expiry date as advisory. An approval that has run out
  authorises nothing, and the next item built under it is a fresh
  departure.
- Letting the supplier board sign a departure from a customer baseline
  requirement. That is the one routing rule the clause does not leave
  to judgement, and it is the one most often taken as an internal
  matter.
- Answering the impact headings with silence. An unanswered safety
  heading reads as a no to every later reader, and nothing in the
  record shows that nobody looked.
- Using the hardware while approval is pending and regularising it
  afterwards. The use is the nonconformance; approving the request
  later does not remove it from the record.

## Behavior contract (gate 3)

The request-type derivation, field and impact completeness, approval
routing, authorisation arithmetic and the use-before-approval verdict
are exercised by the gate 3 contract test:
scripts/test_q1009_waiver_deviation.py against
scripts/q1009_waiver_deviation_logic.py (stdlib unittest, offline).
Run: python3 scripts/test_q1009_waiver_deviation.py

## Compliance

- ECSS standards are freely downloadable (ESA); cite the source and
  paraphrase per standards-map.yaml.
- compliance: STANDARDS-REF, gated: false.

Attribution

ashfordeOUashfordeOU
View sourceMore from ashfordeOU →
SSkills DirectorySkills Directory

Know which skills are safe — weekly.

Best new skills + every skill we flagged as malicious. From the team that scanned 103,619.

Join free

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Know which skills are safe — weekly.

Best new skills + every skill we flagged as malicious. From the team that scanned 103,619.

Join free

Related Skills

Caveman

Ultra-compressed communication mode that cuts output tokens while keeping technical accuracy. Levels: lite, full, ultra and the wenyan variants. Use for /caveman, "caveman mode", "talk like caveman", "be brief" or "less tokens".

1074701 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

694821 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3351 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

691 votes

math-skill

A comprehensive mathematical reasoning skill for AI assistants — handles arithmetic to research-level problems with rigorous step-by-step reasoning, systematic verification, and transparent uncertainty handling

381 votes
View all in ai-agents →