Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Q40 Safety Critical Functions

ASecurity

Identify and control the safety-critical functions of an ECSS-Q-ST-40C clause 6.5 design: decide criticality from the worst credible consequence, derive the failure tolerance that severity demands and the inhibits it needs, count only independent inhibits toward the tolerance achieved so a shared common-cause group collapses three inhibits into one, and assess the clause's control set - inadvertent-operation prevention, operator status information, safe shutdown, EEE component selection and s...

2 stars
0 votes
0 copies
0 views
Added 9/27/2026
ai-agentspython

Works with

claude code

Security Analysis

A100/100

Scanned 9/27/2026

Install to Claude Code

$npx -y skills add ashfordeOU/aero-agent-skills --skill q40-safety-critical-functions --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Q40 Safety Critical Functions?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Q40 Safety Critical Functions
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/ashfordeou-q40-safety-critical-functions/badge)](https://www.skillsdirectory.com/skills/ashfordeou-q40-safety-critical-functions)

More formats (shields.io, HTML) on the badges page.

Download with Pro
Files
SKILL.md
---
name: q40-safety-critical-functions
description: "Identify and control the safety-critical functions of an ECSS-Q-ST-40C clause 6.5 design: decide criticality from the worst credible consequence, derive the failure tolerance that severity demands and the inhibits it needs, count only independent inhibits toward the tolerance achieved so a shared common-cause group collapses three inhibits into one, and assess the clause's control set - inadvertent-operation prevention, operator status information, safe shutdown, EEE component selection and safety-critical software. Use when a function list is screened for criticality, an inhibit chain is argued, or a design review asks what a critical function still lacks. Trigger: ecss, q-st-40c, ecss-safety-critical-function, inadvertent-operation-prevention, independent-inhibit-count, ecss-safe-shutdown-control, safety-critical-software-function."
license: Apache-2.0
compliance: STANDARDS-REF
standards:
  - id: ecss
    reference-only: true
gated: false
domain: space-systems
pack: space-systems
compatibility: "agentskills.io SKILL.md; any SKILL.md host (Claude Code, Hermes, OpenClaw)"
metadata:
  domain: space-systems
  subdomain: ecss
  tags: [ecss, q-st-40c-safety-assurance-scope, q40-safety-critical-functions, ecss-safety-critical-function, inadvertent-operation-prevention, independent-inhibit-count, ecss-safe-shutdown-control, safety-critical-software-function, ecss-failure-tolerance-derivation]
  version: 0.1.0
  author: Aero Agent Skills
---

# ECSS Safety-Critical Functions (space-systems/ecss/q40-safety-critical-functions)

Use when the task is clause 6.5 of ECSS-Q-ST-40C: a function list has to be
sorted into what is safety-critical and what is not, and each critical
function then has to carry the failure tolerance and the control set the
clause puts on it.

## Domain quick reference

- Criticality is read off the consequence, not off the subsystem. A function
  whose loss or inadvertent operation is catastrophic or critical is
  safety-critical wherever it lives, and an explicit declaration can promote
  a lower-severity function that commands a hazardous event.
- Failure tolerance is a count of failures survived, not of parts fitted. Two
  failure tolerance needs three inhibits, one needs two, so the inhibit count
  is always one more than the tolerance the severity demands.
- Only independent inhibits count. Three inhibits on one power bus, in one
  box or driven from one command path are one inhibit between them, and
  grouping them by common cause before counting is the whole point of the
  exercise.
- The control areas are separate obligations, not a single checklist entry. A
  function can be fully tolerant and still owe inadvertent-operation
  prevention, status information to the operator and a safe shutdown path.
- Two of the areas are conditional on how the function is built. EEE
  component selection applies where the function sits in hardware, and the
  software control area where it sits in software; a function in both owes
  both.
- Status information is a control, not reporting. Without it the operator
  cannot tell an armed function from a safed one, so the safe shutdown path
  has nothing to act on.

## Workflow

1. Refuse a function record carrying an unknown key, an unknown control area,
   a non-boolean control value or a repeated inhibit identifier.
2. Decide criticality from the severity, honouring an explicit declaration
   where one is given.
3. Derive the demanded failure tolerance from the severity and the inhibit
   count that tolerance needs.
4. Group the declared inhibits by common cause and count the groups plus the
   ungrouped inhibits; the tolerance achieved is one less than that count.
5. Work out the control areas the function owes: the three universal areas
   plus EEE component selection where it is in hardware and the software area
   where it is in software.
6. Compare owed against provided and record the areas still open.
7. Roll the set up: the safety-critical count, the union of open control
   areas, and the findings - every tolerance shortfall and every open area.

## Pitfalls

- Counting inhibits instead of independent inhibits. Three switches on one
  bus read as two-failure tolerant and are not tolerant at all.
- Deriving tolerance from the subsystem rather than the consequence. The same
  valve driver is critical on one function and not on another.
- Treating the control areas as satisfied once the tolerance is met. They are
  separate obligations, and a tolerant function with no shutdown path is
  still open.
- Applying the EEE and software areas to everything. A function owes the area
  its implementation puts on it; demanding both of every function buries the
  real gaps in noise.
- Reading an absent control area as not applicable. An area that is owed and
  simply not mentioned is open, and it is reported as open.

## Behavior contract (gate 3)

The record validation and unknown-key refusal, the criticality decision with
its declared override, the tolerance and inhibit-count derivation, the
common-cause grouping of inhibits, the conditional control-area set, the
missing-area detection and the roll-up verdict are exercised by the gate 3
contract test: scripts/test_q40_safety_critical_functions.py against
scripts/q40_safety_critical_functions_logic.py (stdlib unittest, offline).
Run: python3 scripts/test_q40_safety_critical_functions.py

## Compliance

- ECSS standards are freely downloadable (ESA); cite the source and
  paraphrase per standards-map.yaml.
- compliance: STANDARDS-REF, gated: false.

Attribution

ashfordeOUashfordeOU
View sourceMore from ashfordeOU →
SSkills DirectorySkills Directory

Know which skills are safe — weekly.

Best new skills + every skill we flagged as malicious. From the team that scanned 103,619.

Join free

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Know which skills are safe — weekly.

Best new skills + every skill we flagged as malicious. From the team that scanned 103,619.

Join free

Related Skills

Caveman

Ultra-compressed communication mode that cuts output tokens while keeping technical accuracy. Levels: lite, full, ultra and the wenyan variants. Use for /caveman, "caveman mode", "talk like caveman", "be brief" or "less tokens".

1074701 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

694821 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3351 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

691 votes

math-skill

A comprehensive mathematical reasoning skill for AI assistants — handles arithmetic to research-level problems with rigorous step-by-step reasoning, systematic verification, and transparent uncertainty handling

381 votes
View all in ai-agents →