Agent skill

Safety Critical Patterns

by athola in athola/claude-night-market

Applies NASA Power of 10 rules for safety-critical verifiable code.

MITAuto-check passedDevelopment

Install Safety Critical Patterns

skills CLI
$ npx skills add athola/claude-night-market --skill safety-critical-patterns -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install athola/claude-night-market safety-critical-patterns --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/pensive/skills/safety-critical-patterns .claude/skills/safety-critical-patterns && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
safety-critical-patterns
GitHub stars
341
Token cost
~1.5k tokens
SKILL.md length
529 words
Files
1
Skills in repo
152
Repo updated
First seen
Licence
MIT

At a glance

Applies NASA Power of 10 rules for safety-critical verifiable code.

  • Works in 10 steps: Restrict Control Flow → Fixed Loop Bounds → No Dynamic Memory After Initialization → …
  • Auditing financial
  • SKILL.md covers When to Apply, When NOT To Use, The 10 Rules (Adapted) and Rules That May Not Apply, plus 4 more sections
  • Calls ruff, mypy and tsc

What it does

Safety Critical Patterns is an agent skill from athola/claude-night-market. Applies NASA Power of 10 rules for safety-critical verifiable code. Use when auditing financial, medical, or high-reliability system code.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. The repository describes itself as: 23 Claude Code plugins: TDD enforcement hooks, git/PR workflows, spec-driven development, code review, project lifecycle, fix-from-error, maintenance automation, context… The licence is MIT.

When your agent uses it

  • Auditing financial
  • High-reliability system code

Example prompts

  • “Use the safety-critical-patterns skill to apply NASA Power of 10 rules for safety-critical verifiable code”
  • “/safety-critical-patterns”

Requirements

  • Python 3

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Restrict Control Flow
  2. Fixed Loop Bounds
  3. No Dynamic Memory After Initialization
  4. Function Length ~60 Lines
  5. Assertion Density
  6. Minimal Variable Scope
  7. Check Return Values and Parameters
  8. Limited Preprocessor/Metaprogramming
  9. Pointer/Reference Discipline
  10. Enable All Warnings

What it can do on your machine

Read from SKILL.md and the folder at commit 9f3eb00. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • ruff
    • mypy
    • tsc

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Safety Critical Patterns loads about 1.5k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 529 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from athola/claude-night-market at commit 9f3eb00, republished under its MIT licence (© athola). 529 words, ~1,482 tokens.

Download SKILL.mdSave it as .claude/skills/safety-critical-patterns/SKILL.md (or your agent's skills folder).
name
safety-critical-patterns
description
Applies NASA Power of 10 rules for safety-critical verifiable code. Use when auditing financial, medical, or high-reliability system code.
alwaysApply
false
category
code-quality
tags
safety, defensive-coding, assertions, NASA, robustness, verification
complexity
intermediate
model_hint
standard
estimated_tokens
600
dependencies
pensive:code-refinement, imbue:review-core, imbue:structured-output

Safety-Critical Coding Patterns

Guidelines adapted from NASA's Power of 10 rules for safety-critical software.

When to Apply

Full rigor: Safety-critical systems, financial transactions, data integrity code Selective application: Business logic, API handlers, core algorithms Light touch: Scripts, prototypes, non-critical utilities

"Match rigor to consequence" - The real engineering principle

When NOT To Use

  • Ordinary application code, where these defensive checks become the bloat that prefer-invariants-over-fallbacks targets (use conserve:code-quality-principles)

The 10 Rules (Adapted)

1. Restrict Control Flow

Avoid goto, setjmp/longjmp, and limit recursion.

Why: Ensures acyclic call graphs that tools can verify. Adaptation: Recursion acceptable with provable termination (tail recursion, bounded depth).

2. Fixed Loop Bounds

All loops should have verifiable upper bounds.

python
# Good - bound is clear
for i in range(min(len(items), MAX_ITEMS)):
    process(item)

# Risky - unbounded
while not_done:  # When does this end?
    process_next()

Adaptation: Document expected bounds; add safety limits on potentially unbounded loops.

3. No Dynamic Memory After Initialization

Avoid heap allocation in critical paths after startup.

Why: Prevents allocation failures at runtime. Adaptation: Pre-allocate pools; use object reuse patterns in hot paths.

4. Function Length ~60 Lines

Functions should fit on one screen/page.

Why: Cognitive limits on comprehension remain valid. Adaptation: Flexible for declarative code; strict for complex logic.

5. Assertion Density

Include defensive assertions documenting expectations.

python
def transfer_funds(from_acct, to_acct, amount):
    assert from_acct != to_acct, "Cannot transfer to same account"
    assert amount > 0, "Transfer amount must be positive"
    assert from_acct.balance >= amount, "Insufficient funds"
    # ... implementation

Adaptation: Focus on boundary conditions and invariants, not arbitrary quotas.

6. Minimal Variable Scope

Declare variables at narrowest possible scope.

python
# Good - scoped tightly
for item in items:
    total = calculate(item)  # Only exists in loop
    results.append(total)

# Avoid - unnecessarily broad
total = 0  # Why is this outside?
for item in items:
    total = calculate(item)
    results.append(total)
7. Check Return Values and Parameters

Validate inputs; never ignore return values.

python
# Good
result = parse_config(path)
if result is None:
    raise ConfigError(f"Failed to parse {path}")

# Bad
parse_config(path)  # Ignored return
8. Limited Preprocessor/Metaprogramming

Restrict macros, decorators, and code generation.

Why: Makes static analysis possible. Adaptation: Document metaprogramming thoroughly; prefer explicit over magic.

9. Pointer/Reference Discipline

Limit indirection levels; be explicit about ownership.

Adaptation: Use type hints, avoid deep nesting of optionals, prefer immutable data.

10. Enable All Warnings

Compile/lint with strictest settings from day one.

bash
# Python
ruff check --select=ALL
mypy --strict

# TypeScript
tsc --strict --noImplicitAny

Rules That May Not Apply

RuleWhen to Relax
No recursionTree traversal, parser combinators with bounded depth
No dynamic memoryGC languages, short-lived processes
60-line functionsDeclarative configs, state machines
No function pointersCallbacks, event handlers, strategies
Show full SKILL.md (217 more words)Show less

Integration

Reference this skill from:

  • pensive:code-refinement - Clean code and quality dimension
  • sanctum:pr-review - Code quality phase
  • /harden - composed in the hardening pipeline
  • /full-review safety-critical - focused entry point, and an auto-detection row when assertion density is low, loops are unbounded, or recursion lacks a termination proof

Violation Output Format

For each rule violation, report:

Rule N: <rule name>
Location: file.py:42
Anchor: `<verbatim source text at line 42>`
Issue: <what violates the rule>
Fix: <concrete remediation>
Verify Findings Are Grounded (safety-critical:findings-verified)

Write findings to .review/findings.json, run the citation verifier (Skill(imbue:review-core) Step 5), and drop or label UNVERIFIED any the verifier rejects.

Exit Criteria

  • Each of the 10 rules has an explicit verdict for the target (applies / violated / not applicable), not a silent skip
  • Every reported violation cites a concrete file:line and the rule number it breaks
  • Rules deemed not applicable name the reason (e.g. "no dynamic allocation in this module") rather than being omitted
  • Loops flagged under Rule 2 are checked for a statically provable upper bound; unbounded loops are reported
  • Recursion flagged under Rule 1 is reported when it lacks a termination argument
  • A summary states whether the target is suitable for safety-critical use, or which rules block that judgment
  • Every reported violation carries a Location + verbatim Anchor confirmed by citation_verifier.py (exit 0), or unverified violations were dropped or labeled UNVERIFIED.

Sources

  • NASA JPL Power of 10 Rules (Gerard Holzmann, 2006)
  • MISRA C Guidelines
  • HN discussion insights on practical application

© athola, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/pensive/skills/safety-critical-patterns of athola/claude-night-market.

Open the folder on GitHubat commit 9f3eb00

Compare with similar skills

Safety Critical Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Safety Critical Patterns compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Safety Critical Patterns this skillathola/claude-night-market341—~1.5kAutomated safety check: PassMIT
Vercel Composition Patternssupabase/supabase111k58 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers297k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k4 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 58 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 4 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

More from athola/claude-night-market

All 152 skills in this repo
  • Night Market Diagnostics Toolkit

    athola/claude-night-market

    Run and interpret repo diagnostic scripts (ratchets, validators, token stats).

    341 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Skills Eval

    athola/claude-night-market

    Evaluate Claude skill quality through auditing. An agent skill from athola/claude-night-market.

    341 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Agent Teams

    athola/claude-night-market

    Coordinates Claude agent teams via filesystem protocol. An agent skill from athola/claude-night-market.

    341 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Delegation Core

    athola/claude-night-market

    Delegates execution to eight CLIs (Gemini, Qwen, MiniMax, GLM, Muse, Codex, OpenCode, Glimmer).

    341 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Elegant Code

    athola/claude-night-market

    Guide minimal code via a decision ladder with full safety, edge, and negative-case coverage.

    341 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • Skill Library Mission

    athola/claude-night-market

    Build a project skill library in .claude/skills/ via discovery, parallel authoring, and review.

    341 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Safety Critical Patterns

What does Safety Critical Patterns do?

Applies NASA Power of 10 rules for safety-critical verifiable code. Safety Critical Patterns is an agent skill from athola/claude-night-market. Applies NASA Power of 10 rules for safety-critical verifiable code.

When should I use Safety Critical Patterns?

Safety Critical Patterns fits situations like: auditing financial; high-reliability system code.

How do I install Safety Critical Patterns in Claude Code?

Run `npx skills add athola/claude-night-market --skill safety-critical-patterns -a claude-code`. Or copy the skill folder (plugins/pensive/skills/safety-critical-patterns in athola/claude-night-market) into .claude/skills/safety-critical-patterns in your project. Claude Code loads it when a task matches its description.

How do I install Safety Critical Patterns in Codex?

Run `npx skills add athola/claude-night-market --skill safety-critical-patterns -a codex`. Or copy the skill folder (plugins/pensive/skills/safety-critical-patterns in athola/claude-night-market) into .agents/skills/safety-critical-patterns in your project. Codex loads it when a task matches its description.

Can I use Safety Critical Patterns in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add athola/claude-night-market --skill safety-critical-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/safety-critical-patterns, .gemini/skills/safety-critical-patterns, .github/skills/safety-critical-patterns and .opencode/skills/safety-critical-patterns in your project.

What does Safety Critical Patterns need to run?

Going by SKILL.md and its folder, Safety Critical Patterns needs the command-line tools its instructions call (ruff, mypy and tsc). Our summary lists: Python 3.

Does Safety Critical Patterns access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Safety Critical Patterns safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Safety Critical Patterns use?

Safety Critical Patterns is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Safety Critical Patterns use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Safety Critical Patterns?

Skills that share tags, products or a category with Safety Critical Patterns: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 297k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Safety Critical Patterns?

athola (a GitHub user) maintains it in athola/claude-night-market, which has 341 GitHub stars. The repository holds 152 skills in this directory. The repository was last updated on October 9, 2026.

Source: athola/claude-night-market on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.