{"id":"a2b76a6b-33c4-4dad-b658-babac28db22f","entityType":"agent","slug":"clawhub-athola-nm-pensive-safety-critical-patterns","name":"safety-critical-patterns","canonicalUrl":"https://www.xpersona.co/agent/clawhub-athola-nm-pensive-safety-critical-patterns","canonicalPath":"/agent/clawhub-athola-nm-pensive-safety-critical-patterns","generatedAt":"2026-10-10T10:49:07.424Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-10T05:37:08.447Z","emptyReason":null},"description":"Applies NASA Power of 10 rules for safety-critical verifiable code Skill: safety-critical-patterns Owner: athola Summary: Applies NASA Power of 10 rules for safety-critical verifiable code Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-26T13:19:20.827Z | user Release v1.9.19 v1.9.17 | 2026-07-30T05:39:32.617Z | user Release v1.9.17 v1.9.16 | 2026-07-14T19:56:15.650Z | user Release v1.9.16 v1.9.14 | 2026-06-30T18:04:31.432Z | user Release v1.9.14 v1.9.13 | 2026-06-27T16:22:29","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.6K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s17emme0e2m3cpf7k2jvp3a84984b8z9:nm-pensive-safety-critical-patterns","sourceUrl":"https://clawhub.ai/athola/nm-pensive-safety-critical-patterns","homepage":"https://clawhub.ai/athola/skills/nm-pensive-safety-critical-patterns","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/athola/nm-pensive-safety-critical-patterns","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/athola/skills/nm-pensive-safety-critical-patterns","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":64,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Applies NASA Power of 10 rules for safety-critical verifiable code Skill: safety-critical-patterns Owner: athola Summary: Applies NASA Power of 10 rules for saf"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T05:37:08.447Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T05:37:08.447Z","emptyReason":null},"stars":null,"forks":null,"downloads":1649,"packageName":null,"latestVersion":"1.9.19","tractionLabel":"1.6K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T05:37:08.446Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T05:37:08.447Z","lastCrawledAt":"2026-10-10T05:37:08.446Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T05:37:08.447Z","lastVerifiedAt":null,"highlights":[{"version":"1.9.19","createdAt":"2026-08-26T13:19:20.827Z","changelog":"Release v1.9.19","fileCount":3,"zipByteSize":3834},{"version":"1.9.17","createdAt":"2026-07-30T05:39:32.617Z","changelog":"Release v1.9.17","fileCount":3,"zipByteSize":3822},{"version":"1.9.16","createdAt":"2026-07-14T19:56:15.650Z","changelog":"Release v1.9.16","fileCount":3,"zipByteSize":3751},{"version":"1.9.14","createdAt":"2026-06-30T18:04:31.432Z","changelog":"Release v1.9.14","fileCount":3,"zipByteSize":3735},{"version":"1.9.13","createdAt":"2026-06-27T16:22:29.454Z","changelog":"Release v1.9.13","fileCount":3,"zipByteSize":3713},{"version":"1.9.12","createdAt":"2026-06-19T03:17:42.653Z","changelog":"Release v1.9.12","fileCount":3,"zipByteSize":3818},{"version":"1.0.3","createdAt":"2026-06-18T15:16:12.926Z","changelog":"Release v1.9.12","fileCount":3,"zipByteSize":3652},{"version":"1.0.2","createdAt":"2026-05-09T02:19:26.727Z","changelog":"Release v1.9.5","fileCount":3,"zipByteSize":3774}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17emme0e2m3cpf7k2jvp3a84984b8z9:nm-pensive-safety-critical-patterns","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-safety-critical-patterns/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-safety-critical-patterns/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-safety-critical-patterns/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-safety-critical-patterns/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-safety-critical-patterns/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-safety-critical-patterns/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T10:49:07.422Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-safety-critical-patterns/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-safety-critical-patterns/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-safety-critical-patterns/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-safety-critical-patterns/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-10T05:37:08.447Z","emptyReason":null},"readme":"Skill: safety-critical-patterns\n\nOwner: athola\n\nSummary: Applies NASA Power of 10 rules for safety-critical verifiable code\n\nTags: latest:1.9.19\n\nVersion history:\n\nv1.9.19 | 2026-08-26T13:19:20.827Z | user\n\nRelease v1.9.19\n\nv1.9.17 | 2026-07-30T05:39:32.617Z | user\n\nRelease v1.9.17\n\nv1.9.16 | 2026-07-14T19:56:15.650Z | user\n\nRelease v1.9.16\n\nv1.9.14 | 2026-06-30T18:04:31.432Z | user\n\nRelease v1.9.14\n\nv1.9.13 | 2026-06-27T16:22:29.454Z | user\n\nRelease v1.9.13\n\nv1.9.12 | 2026-06-19T03:17:42.653Z | user\n\nRelease v1.9.12\n\nv1.0.3 | 2026-06-18T15:16:12.926Z | user\n\nRelease v1.9.12\n\nv1.0.2 | 2026-05-09T02:19:26.727Z | user\n\nRelease v1.9.5\n\nv1.0.1 | 2026-05-06T14:20:42.048Z | user\n\nRelease v1.9.4\n\nv1.0.0 | 2026-04-15T15:01:48.056Z | auto\n\n- Initial release of safety-critical-patterns skill, adapting NASA’s Power of 10 rules for robust, verifiable code.\n- Provides practical, context-driven guidelines for control flow, memory, assertions, variable scope, and more.\n- Includes advice on when to apply full, selective, or light rigor depending on software criticality.\n- Lists exceptions and adaptations for modern programming languages and typical uses.\n- Designed for integration with code refinement and review skills in the Claude Night Market ecosystem.\n\nArchive index:\n\nArchive v1.9.19: 3 files, 3834 bytes\n\nFiles: skill-card.md (2164b), SKILL.md (4579b), _meta.json (155b)\n\nFile v1.9.19:SKILL.md\n\n---\nname: safety-critical-patterns\ndescription: Applies NASA Power of 10 rules for safety-critical verifiable code\nversion: 1.9.8\ntriggers:\n  - safety\n  - defensive-coding\n  - assertions\n  - NASA\n  - robustness\n  - verification\n  - auditing financial\n  - medical\n  - or high-reliability system code\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/pensive\", \"emoji\": \"\\ud83e\\udd9e\", \"requires\": {\"config\": [\"night-market.pensive:shared\", \"night-market.pensive:code-refinement\"]}}}\nsource: claude-night-market\nsource_plugin: pensive\n---\n\n> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n# Safety-Critical Coding Patterns\n\nGuidelines adapted from NASA's Power of 10 rules for safety-critical software.\n\n## When to Apply\n\n**Full rigor**: Safety-critical systems, financial transactions, data integrity code\n**Selective application**: Business logic, API handlers, core algorithms\n**Light touch**: Scripts, prototypes, non-critical utilities\n\n> \"Match rigor to consequence\" - The real engineering principle\n\n## The 10 Rules (Adapted)\n\n### 1. Restrict Control Flow\nAvoid `goto`, `setjmp/longjmp`, and **limit recursion**.\n\n**Why**: Ensures acyclic call graphs that tools can verify.\n**Adaptation**: Recursion acceptable with provable termination (tail recursion, bounded depth).\n\n### 2. Fixed Loop Bounds\nAll loops should have verifiable upper bounds.\n\n```python\n# Good - bound is clear\nfor i in range(min(len(items), MAX_ITEMS)):\n    process(item)\n\n# Risky - unbounded\nwhile not_done:  # When does this end?\n    process_next()\n```\n\n**Adaptation**: Document expected bounds; add safety limits on potentially unbounded loops.\n\n### 3. No Dynamic Memory After Initialization\nAvoid heap allocation in critical paths after startup.\n\n**Why**: Prevents allocation failures at runtime.\n**Adaptation**: Pre-allocate pools; use object reuse patterns in hot paths.\n\n### 4. Function Length ~60 Lines\nFunctions should fit on one screen/page.\n\n**Why**: Cognitive limits on comprehension remain valid.\n**Adaptation**: Flexible for declarative code; strict for complex logic.\n\n### 5. Assertion Density\nInclude defensive assertions documenting expectations.\n\n```python\ndef transfer_funds(from_acct, to_acct, amount):\n    assert from_acct != to_acct, \"Cannot transfer to same account\"\n    assert amount > 0, \"Transfer amount must be positive\"\n    assert from_acct.balance >= amount, \"Insufficient funds\"\n    # ... implementation\n```\n\n**Adaptation**: Focus on boundary conditions and invariants, not arbitrary quotas.\n\n### 6. Minimal Variable Scope\nDeclare variables at narrowest possible scope.\n\n```python\n# Good - scoped tightly\nfor item in items:\n    total = calculate(item)  # Only exists in loop\n    results.append(total)\n\n# Avoid - unnecessarily broad\ntotal = 0  # Why is this outside?\nfor item in items:\n    total = calculate(item)\n    results.append(total)\n```\n\n### 7. Check Return Values and Parameters\nValidate inputs; never ignore return values.\n\n```python\n# Good\nresult = parse_config(path)\nif result is None:\n    raise ConfigError(f\"Failed to parse {path}\")\n\n# Bad\nparse_config(path)  # Ignored return\n```\n\n### 8. Limited Preprocessor/Metaprogramming\nRestrict macros, decorators, and code generation.\n\n**Why**: Makes static analysis possible.\n**Adaptation**: Document metaprogramming thoroughly; prefer explicit over magic.\n\n### 9. Pointer/Reference Discipline\nLimit indirection levels; be explicit about ownership.\n\n**Adaptation**: Use type hints, avoid deep nesting of optionals, prefer immutable data.\n\n### 10. Enable All Warnings\nCompile/lint with strictest settings from day one.\n\n```bash\n# Python\nruff check --select=ALL\nmypy --strict\n\n# TypeScript\ntsc --strict --noImplicitAny\n```\n\n## Rules That May Not Apply\n\n| Rule | When to Relax |\n|------|---------------|\n| No recursion | Tree traversal, parser combinators with bounded depth |\n| No dynamic memory | GC languages, short-lived processes |\n| 60-line functions | Declarative configs, state machines |\n| No function pointers | Callbacks, event handlers, strategies |\n\n## Integration\n\nReference this skill from:\n- `pensive:code-refinement` - Clean code dimension\n- `pensive:code-refinement` - Quality checks\n- `sanctum:pr-review` - Code quality phase\n\n## Sources\n\n- NASA JPL Power of 10 Rules (Gerard Holzmann, 2006)\n- MISRA C Guidelines\n- HN discussion insights on practical application\n\nFile v1.9.19:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-pensive-safety-critical-patterns\",\n  \"version\": \"1.9.19\",\n  \"publishedAt\": 1787750360827\n}\n\nFile v1.9.19:skill-card.md\n\n## Description:\n\nApplies NASA Power of 10 rules for safety-critical verifiable code.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[athola](https://clawhub.ai/user/athola)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and engineers use this skill to apply a NASA Power of 10 inspired checklist when reviewing safety-critical, financial, medical, data-integrity, and other high-reliability code.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Python assert examples may be mistaken for complete runtime validation in financial or safety-sensitive code.\n\nMitigation: Treat assertions as internal invariant documentation and require explicit validation for untrusted input, authorization, financial rules, and safety constraints.\n\nRisk: Broad activation triggers may apply the skill outside the intended review context.\n\nMitigation: Review the generated guidance before applying it and scope use to code where safety-critical or high-reliability patterns are relevant.\n\nRisk: The security scan verdict is suspicious.\n\nMitigation: Review the skill carefully before installing it for financial, medical, safety-critical, production, or other high-consequence work.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/athola/skills/nm-pensive-safety-critical-patterns)\n- [Publisher profile](https://clawhub.ai/user/athola)\n- [Configured homepage](https://github.com/athola/claude-night-market/tree/master/plugins/pensive)\n\n## Skill Output:\n\n**Output Type(s):** [guidance, markdown, code, shell commands]\n\n**Output Format:** [Markdown with checklist guidance and inline code blocks]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Advisory review guidance; users should validate recommendations against their project requirements.]\n\n## Skill Version(s):\n\n1.9.19 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.9.17: 3 files, 3822 bytes\n\nFiles: skill-card.md (2158b), SKILL.md (4579b), _meta.json (155b)\n\nFile v1.9.17:SKILL.md\n\n---\nname: safety-critical-patterns\ndescription: Applies NASA Power of 10 rules for safety-critical verifiable code\nversion: 1.9.8\ntriggers:\n  - safety\n  - defensive-coding\n  - assertions\n  - NASA\n  - robustness\n  - verification\n  - auditing financial\n  - medical\n  - or high-reliability system code\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/pensive\", \"emoji\": \"\\ud83e\\udd9e\", \"requires\": {\"config\": [\"night-market.pensive:shared\", \"night-market.pensive:code-refinement\"]}}}\nsource: claude-night-market\nsource_plugin: pensive\n---\n\n> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n# Safety-Critical Coding Patterns\n\nGuidelines adapted from NASA's Power of 10 rules for safety-critical software.\n\n## When to Apply\n\n**Full rigor**: Safety-critical systems, financial transactions, data integrity code\n**Selective application**: Business logic, API handlers, core algorithms\n**Light touch**: Scripts, prototypes, non-critical utilities\n\n> \"Match rigor to consequence\" - The real engineering principle\n\n## The 10 Rules (Adapted)\n\n### 1. Restrict Control Flow\nAvoid `goto`, `setjmp/longjmp`, and **limit recursion**.\n\n**Why**: Ensures acyclic call graphs that tools can verify.\n**Adaptation**: Recursion acceptable with provable termination (tail recursion, bounded depth).\n\n### 2. Fixed Loop Bounds\nAll loops should have verifiable upper bounds.\n\n```python\n# Good - bound is clear\nfor i in range(min(len(items), MAX_ITEMS)):\n    process(item)\n\n# Risky - unbounded\nwhile not_done:  # When does this end?\n    process_next()\n```\n\n**Adaptation**: Document expected bounds; add safety limits on potentially unbounded loops.\n\n### 3. No Dynamic Memory After Initialization\nAvoid heap allocation in critical paths after startup.\n\n**Why**: Prevents allocation failures at runtime.\n**Adaptation**: Pre-allocate pools; use object reuse patterns in hot paths.\n\n### 4. Function Length ~60 Lines\nFunctions should fit on one screen/page.\n\n**Why**: Cognitive limits on comprehension remain valid.\n**Adaptation**: Flexible for declarative code; strict for complex logic.\n\n### 5. Assertion Density\nInclude defensive assertions documenting expectations.\n\n```python\ndef transfer_funds(from_acct, to_acct, amount):\n    assert from_acct != to_acct, \"Cannot transfer to same account\"\n    assert amount > 0, \"Transfer amount must be positive\"\n    assert from_acct.balance >= amount, \"Insufficient funds\"\n    # ... implementation\n```\n\n**Adaptation**: Focus on boundary conditions and invariants, not arbitrary quotas.\n\n### 6. Minimal Variable Scope\nDeclare variables at narrowest possible scope.\n\n```python\n# Good - scoped tightly\nfor item in items:\n    total = calculate(item)  # Only exists in loop\n    results.append(total)\n\n# Avoid - unnecessarily broad\ntotal = 0  # Why is this outside?\nfor item in items:\n    total = calculate(item)\n    results.append(total)\n```\n\n### 7. Check Return Values and Parameters\nValidate inputs; never ignore return values.\n\n```python\n# Good\nresult = parse_config(path)\nif result is None:\n    raise ConfigError(f\"Failed to parse {path}\")\n\n# Bad\nparse_config(path)  # Ignored return\n```\n\n### 8. Limited Preprocessor/Metaprogramming\nRestrict macros, decorators, and code generation.\n\n**Why**: Makes static analysis possible.\n**Adaptation**: Document metaprogramming thoroughly; prefer explicit over magic.\n\n### 9. Pointer/Reference Discipline\nLimit indirection levels; be explicit about ownership.\n\n**Adaptation**: Use type hints, avoid deep nesting of optionals, prefer immutable data.\n\n### 10. Enable All Warnings\nCompile/lint with strictest settings from day one.\n\n```bash\n# Python\nruff check --select=ALL\nmypy --strict\n\n# TypeScript\ntsc --strict --noImplicitAny\n```\n\n## Rules That May Not Apply\n\n| Rule | When to Relax |\n|------|---------------|\n| No recursion | Tree traversal, parser combinators with bounded depth |\n| No dynamic memory | GC languages, short-lived processes |\n| 60-line functions | Declarative configs, state machines |\n| No function pointers | Callbacks, event handlers, strategies |\n\n## Integration\n\nReference this skill from:\n- `pensive:code-refinement` - Clean code dimension\n- `pensive:code-refinement` - Quality checks\n- `sanctum:pr-review` - Code quality phase\n\n## Sources\n\n- NASA JPL Power of 10 Rules (Gerard Holzmann, 2006)\n- MISRA C Guidelines\n- HN discussion insights on practical application\n\nFile v1.9.17:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-pensive-safety-critical-patterns\",\n  \"version\": \"1.9.17\",\n  \"publishedAt\": 1785389972617\n}\n\nFile v1.9.17:skill-card.md\n\n## Description: <br>\nApplies NASA Power of 10 rules for safety-critical verifiable code. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[athola](https://clawhub.ai/user/athola) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineers use this skill to review safety-critical, financial, medical, data-integrity, or high-reliability code against practical adaptations of NASA Power of 10 coding rules. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Broad safety and verification triggers may invoke the skill in contexts where lightweight review is sufficient. <br>\nMitigation: Apply the skill's own posture of matching rigor to consequence, and use full rigor only for safety-critical, financial, medical, data-integrity, or high-reliability code. <br>\nRisk: Guidance-only recommendations could still lead to overly strict or misplaced coding requirements if applied without review. <br>\nMitigation: Have developers review recommendations before adoption and adapt the NASA Power of 10 rules to the language, system risk, and operational context. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/athola/skills/nm-pensive-safety-critical-patterns) <br>\n- [Metadata homepage for pensive plugin](https://github.com/athola/claude-night-market/tree/master/plugins/pensive) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Guidance, Markdown, Code, Shell commands] <br>\n**Output Format:** [Markdown guidance with inline code and shell command examples] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Guidance-only checklist; no executable behavior, persistence, credentials, or data access.] <br>\n\n## Skill Version(s): <br>\n1.9.17 (source: server release metadata; artifact frontmatter lists 1.9.8) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.9.16: 3 files, 3751 bytes\n\nFiles: skill-card.md (1984b), SKILL.md (4579b), _meta.json (155b)\n\nFile v1.9.16:SKILL.md\n\n---\nname: safety-critical-patterns\ndescription: Applies NASA Power of 10 rules for safety-critical verifiable code\nversion: 1.9.8\ntriggers:\n  - safety\n  - defensive-coding\n  - assertions\n  - NASA\n  - robustness\n  - verification\n  - auditing financial\n  - medical\n  - or high-reliability system code\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/pensive\", \"emoji\": \"\\ud83e\\udd9e\", \"requires\": {\"config\": [\"night-market.pensive:shared\", \"night-market.pensive:code-refinement\"]}}}\nsource: claude-night-market\nsource_plugin: pensive\n---\n\n> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n# Safety-Critical Coding Patterns\n\nGuidelines adapted from NASA's Power of 10 rules for safety-critical software.\n\n## When to Apply\n\n**Full rigor**: Safety-critical systems, financial transactions, data integrity code\n**Selective application**: Business logic, API handlers, core algorithms\n**Light touch**: Scripts, prototypes, non-critical utilities\n\n> \"Match rigor to consequence\" - The real engineering principle\n\n## The 10 Rules (Adapted)\n\n### 1. Restrict Control Flow\nAvoid `goto`, `setjmp/longjmp`, and **limit recursion**.\n\n**Why**: Ensures acyclic call graphs that tools can verify.\n**Adaptation**: Recursion acceptable with provable termination (tail recursion, bounded depth).\n\n### 2. Fixed Loop Bounds\nAll loops should have verifiable upper bounds.\n\n```python\n# Good - bound is clear\nfor i in range(min(len(items), MAX_ITEMS)):\n    process(item)\n\n# Risky - unbounded\nwhile not_done:  # When does this end?\n    process_next()\n```\n\n**Adaptation**: Document expected bounds; add safety limits on potentially unbounded loops.\n\n### 3. No Dynamic Memory After Initialization\nAvoid heap allocation in critical paths after startup.\n\n**Why**: Prevents allocation failures at runtime.\n**Adaptation**: Pre-allocate pools; use object reuse patterns in hot paths.\n\n### 4. Function Length ~60 Lines\nFunctions should fit on one screen/page.\n\n**Why**: Cognitive limits on comprehension remain valid.\n**Adaptation**: Flexible for declarative code; strict for complex logic.\n\n### 5. Assertion Density\nInclude defensive assertions documenting expectations.\n\n```python\ndef transfer_funds(from_acct, to_acct, amount):\n    assert from_acct != to_acct, \"Cannot transfer to same account\"\n    assert amount > 0, \"Transfer amount must be positive\"\n    assert from_acct.balance >= amount, \"Insufficient funds\"\n    # ... implementation\n```\n\n**Adaptation**: Focus on boundary conditions and invariants, not arbitrary quotas.\n\n### 6. Minimal Variable Scope\nDeclare variables at narrowest possible scope.\n\n```python\n# Good - scoped tightly\nfor item in items:\n    total = calculate(item)  # Only exists in loop\n    results.append(total)\n\n# Avoid - unnecessarily broad\ntotal = 0  # Why is this outside?\nfor item in items:\n    total = calculate(item)\n    results.append(total)\n```\n\n### 7. Check Return Values and Parameters\nValidate inputs; never ignore return values.\n\n```python\n# Good\nresult = parse_config(path)\nif result is None:\n    raise ConfigError(f\"Failed to parse {path}\")\n\n# Bad\nparse_config(path)  # Ignored return\n```\n\n### 8. Limited Preprocessor/Metaprogramming\nRestrict macros, decorators, and code generation.\n\n**Why**: Makes static analysis possible.\n**Adaptation**: Document metaprogramming thoroughly; prefer explicit over magic.\n\n### 9. Pointer/Reference Discipline\nLimit indirection levels; be explicit about ownership.\n\n**Adaptation**: Use type hints, avoid deep nesting of optionals, prefer immutable data.\n\n### 10. Enable All Warnings\nCompile/lint with strictest settings from day one.\n\n```bash\n# Python\nruff check --select=ALL\nmypy --strict\n\n# TypeScript\ntsc --strict --noImplicitAny\n```\n\n## Rules That May Not Apply\n\n| Rule | When to Relax |\n|------|---------------|\n| No recursion | Tree traversal, parser combinators with bounded depth |\n| No dynamic memory | GC languages, short-lived processes |\n| 60-line functions | Declarative configs, state machines |\n| No function pointers | Callbacks, event handlers, strategies |\n\n## Integration\n\nReference this skill from:\n- `pensive:code-refinement` - Clean code dimension\n- `pensive:code-refinement` - Quality checks\n- `sanctum:pr-review` - Code quality phase\n\n## Sources\n\n- NASA JPL Power of 10 Rules (Gerard Holzmann, 2006)\n- MISRA C Guidelines\n- HN discussion insights on practical application\n\nFile v1.9.16:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-pensive-safety-critical-patterns\",\n  \"version\": \"1.9.16\",\n  \"publishedAt\": 1784058975650\n}\n\nFile v1.9.16:skill-card.md\n\n## Description: <br>\nApplies NASA Power of 10 rules for safety-critical verifiable code. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[athola](https://clawhub.ai/user/athola) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and code reviewers use this skill to apply higher-rigor safety-critical coding review patterns to financial, medical, data-integrity, and other high-reliability software. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill may be used to guide changes in safety-critical or high-reliability code where incorrect advice could have meaningful impact. <br>\nMitigation: Require human review, tests, and domain-specific verification before applying suggested patterns to production code. <br>\nRisk: The referenced external pensive plugin may add agents, hooks, or commands that are not present in this markdown-only skill. <br>\nMitigation: Review and scan the external plugin separately before installing or enabling it. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/athola/skills/nm-pensive-safety-critical-patterns) <br>\n- [Pensive plugin homepage](https://github.com/athola/claude-night-market/tree/master/plugins/pensive) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [guidance, markdown, code, shell commands] <br>\n**Output Format:** [Markdown guidance with inline code and shell command examples] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Documentation-only guidance; no commands are run by the skill itself.] <br>\n\n## Skill Version(s): <br>\n1.9.16 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.9.14: 3 files, 3735 bytes\n\nFiles: skill-card.md (1895b), SKILL.md (4579b), _meta.json (155b)\n\nFile v1.9.14:SKILL.md\n\n---\nname: safety-critical-patterns\ndescription: Applies NASA Power of 10 rules for safety-critical verifiable code\nversion: 1.9.8\ntriggers:\n  - safety\n  - defensive-coding\n  - assertions\n  - NASA\n  - robustness\n  - verification\n  - auditing financial\n  - medical\n  - or high-reliability system code\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/pensive\", \"emoji\": \"\\ud83e\\udd9e\", \"requires\": {\"config\": [\"night-market.pensive:shared\", \"night-market.pensive:code-refinement\"]}}}\nsource: claude-night-market\nsource_plugin: pensive\n---\n\n> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n# Safety-Critical Coding Patterns\n\nGuidelines adapted from NASA's Power of 10 rules for safety-critical software.\n\n## When to Apply\n\n**Full rigor**: Safety-critical systems, financial transactions, data integrity code\n**Selective application**: Business logic, API handlers, core algorithms\n**Light touch**: Scripts, prototypes, non-critical utilities\n\n> \"Match rigor to consequence\" - The real engineering principle\n\n## The 10 Rules (Adapted)\n\n### 1. Restrict Control Flow\nAvoid `goto`, `setjmp/longjmp`, and **limit recursion**.\n\n**Why**: Ensures acyclic call graphs that tools can verify.\n**Adaptation**: Recursion acceptable with provable termination (tail recursion, bounded depth).\n\n### 2. Fixed Loop Bounds\nAll loops should have verifiable upper bounds.\n\n```python\n# Good - bound is clear\nfor i in range(min(len(items), MAX_ITEMS)):\n    process(item)\n\n# Risky - unbounded\nwhile not_done:  # When does this end?\n    process_next()\n```\n\n**Adaptation**: Document expected bounds; add safety limits on potentially unbounded loops.\n\n### 3. No Dynamic Memory After Initialization\nAvoid heap allocation in critical paths after startup.\n\n**Why**: Prevents allocation failures at runtime.\n**Adaptation**: Pre-allocate pools; use object reuse patterns in hot paths.\n\n### 4. Function Length ~60 Lines\nFunctions should fit on one screen/page.\n\n**Why**: Cognitive limits on comprehension remain valid.\n**Adaptation**: Flexible for declarative code; strict for complex logic.\n\n### 5. Assertion Density\nInclude defensive assertions documenting expectations.\n\n```python\ndef transfer_funds(from_acct, to_acct, amount):\n    assert from_acct != to_acct, \"Cannot transfer to same account\"\n    assert amount > 0, \"Transfer amount must be positive\"\n    assert from_acct.balance >= amount, \"Insufficient funds\"\n    # ... implementation\n```\n\n**Adaptation**: Focus on boundary conditions and invariants, not arbitrary quotas.\n\n### 6. Minimal Variable Scope\nDeclare variables at narrowest possible scope.\n\n```python\n# Good - scoped tightly\nfor item in items:\n    total = calculate(item)  # Only exists in loop\n    results.append(total)\n\n# Avoid - unnecessarily broad\ntotal = 0  # Why is this outside?\nfor item in items:\n    total = calculate(item)\n    results.append(total)\n```\n\n### 7. Check Return Values and Parameters\nValidate inputs; never ignore return values.\n\n```python\n# Good\nresult = parse_config(path)\nif result is None:\n    raise ConfigError(f\"Failed to parse {path}\")\n\n# Bad\nparse_config(path)  # Ignored return\n```\n\n### 8. Limited Preprocessor/Metaprogramming\nRestrict macros, decorators, and code generation.\n\n**Why**: Makes static analysis possible.\n**Adaptation**: Document metaprogramming thoroughly; prefer explicit over magic.\n\n### 9. Pointer/Reference Discipline\nLimit indirection levels; be explicit about ownership.\n\n**Adaptation**: Use type hints, avoid deep nesting of optionals, prefer immutable data.\n\n### 10. Enable All Warnings\nCompile/lint with strictest settings from day one.\n\n```bash\n# Python\nruff check --select=ALL\nmypy --strict\n\n# TypeScript\ntsc --strict --noImplicitAny\n```\n\n## Rules That May Not Apply\n\n| Rule | When to Relax |\n|------|---------------|\n| No recursion | Tree traversal, parser combinators with bounded depth |\n| No dynamic memory | GC languages, short-lived processes |\n| 60-line functions | Declarative configs, state machines |\n| No function pointers | Callbacks, event handlers, strategies |\n\n## Integration\n\nReference this skill from:\n- `pensive:code-refinement` - Clean code dimension\n- `pensive:code-refinement` - Quality checks\n- `sanctum:pr-review` - Code quality phase\n\n## Sources\n\n- NASA JPL Power of 10 Rules (Gerard Holzmann, 2006)\n- MISRA C Guidelines\n- HN discussion insights on practical application\n\nFile v1.9.14:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-pensive-safety-critical-patterns\",\n  \"version\": \"1.9.14\",\n  \"publishedAt\": 1782842671432\n}\n\nFile v1.9.14:skill-card.md\n\n## Description: <br>\nApplies NASA Power of 10 rules for safety-critical verifiable code. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[athola](https://clawhub.ai/user/athola) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineers use this advisory skill to apply NASA Power of 10-style coding patterns to safety-critical, financial, medical, data-integrity, and other high-reliability code reviews. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Review before execution as proposals could introduce incorrect or misleading guidance into skills. <br>\nMitigation: Review and scan skill before deployment. <br>\n\n## Reference(s): <br>\n- [ClawHub Skill Page](https://clawhub.ai/athola/skills/nm-pensive-safety-critical-patterns) <br>\n- [Configured Homepage](https://github.com/athola/claude-night-market/tree/master/plugins/pensive) <br>\n- [NASA JPL Power of 10 Rules](https://spinroot.com/gerard/pdf/P10.pdf) <br>\n- [MISRA C Guidelines](https://misra.org.uk/misra-c/) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Guidance, Markdown, Code, Shell commands] <br>\n**Output Format:** [Markdown with code examples and inline shell commands] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Advisory documentation-only output; broad safety, medical, financial, and verification triggers may lead to stricter guidance than a light review requires.] <br>\n\n## Skill Version(s): <br>\n1.9.14 (source: server release metadata; artifact frontmatter reports 1.9.8) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.9.13: 3 files, 3713 bytes\n\nFiles: skill-card.md (1821b), SKILL.md (4579b), _meta.json (155b)\n\nFile v1.9.13:SKILL.md\n\n---\nname: safety-critical-patterns\ndescription: Applies NASA Power of 10 rules for safety-critical verifiable code\nversion: 1.9.8\ntriggers:\n  - safety\n  - defensive-coding\n  - assertions\n  - NASA\n  - robustness\n  - verification\n  - auditing financial\n  - medical\n  - or high-reliability system code\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/pensive\", \"emoji\": \"\\ud83e\\udd9e\", \"requires\": {\"config\": [\"night-market.pensive:shared\", \"night-market.pensive:code-refinement\"]}}}\nsource: claude-night-market\nsource_plugin: pensive\n---\n\n> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n# Safety-Critical Coding Patterns\n\nGuidelines adapted from NASA's Power of 10 rules for safety-critical software.\n\n## When to Apply\n\n**Full rigor**: Safety-critical systems, financial transactions, data integrity code\n**Selective application**: Business logic, API handlers, core algorithms\n**Light touch**: Scripts, prototypes, non-critical utilities\n\n> \"Match rigor to consequence\" - The real engineering principle\n\n## The 10 Rules (Adapted)\n\n### 1. Restrict Control Flow\nAvoid `goto`, `setjmp/longjmp`, and **limit recursion**.\n\n**Why**: Ensures acyclic call graphs that tools can verify.\n**Adaptation**: Recursion acceptable with provable termination (tail recursion, bounded depth).\n\n### 2. Fixed Loop Bounds\nAll loops should have verifiable upper bounds.\n\n```python\n# Good - bound is clear\nfor i in range(min(len(items), MAX_ITEMS)):\n    process(item)\n\n# Risky - unbounded\nwhile not_done:  # When does this end?\n    process_next()\n```\n\n**Adaptation**: Document expected bounds; add safety limits on potentially unbounded loops.\n\n### 3. No Dynamic Memory After Initialization\nAvoid heap allocation in critical paths after startup.\n\n**Why**: Prevents allocation failures at runtime.\n**Adaptation**: Pre-allocate pools; use object reuse patterns in hot paths.\n\n### 4. Function Length ~60 Lines\nFunctions should fit on one screen/page.\n\n**Why**: Cognitive limits on comprehension remain valid.\n**Adaptation**: Flexible for declarative code; strict for complex logic.\n\n### 5. Assertion Density\nInclude defensive assertions documenting expectations.\n\n```python\ndef transfer_funds(from_acct, to_acct, amount):\n    assert from_acct != to_acct, \"Cannot transfer to same account\"\n    assert amount > 0, \"Transfer amount must be positive\"\n    assert from_acct.balance >= amount, \"Insufficient funds\"\n    # ... implementation\n```\n\n**Adaptation**: Focus on boundary conditions and invariants, not arbitrary quotas.\n\n### 6. Minimal Variable Scope\nDeclare variables at narrowest possible scope.\n\n```python\n# Good - scoped tightly\nfor item in items:\n    total = calculate(item)  # Only exists in loop\n    results.append(total)\n\n# Avoid - unnecessarily broad\ntotal = 0  # Why is this outside?\nfor item in items:\n    total = calculate(item)\n    results.append(total)\n```\n\n### 7. Check Return Values and Parameters\nValidate inputs; never ignore return values.\n\n```python\n# Good\nresult = parse_config(path)\nif result is None:\n    raise ConfigError(f\"Failed to parse {path}\")\n\n# Bad\nparse_config(path)  # Ignored return\n```\n\n### 8. Limited Preprocessor/Metaprogramming\nRestrict macros, decorators, and code generation.\n\n**Why**: Makes static analysis possible.\n**Adaptation**: Document metaprogramming thoroughly; prefer explicit over magic.\n\n### 9. Pointer/Reference Discipline\nLimit indirection levels; be explicit about ownership.\n\n**Adaptation**: Use type hints, avoid deep nesting of optionals, prefer immutable data.\n\n### 10. Enable All Warnings\nCompile/lint with strictest settings from day one.\n\n```bash\n# Python\nruff check --select=ALL\nmypy --strict\n\n# TypeScript\ntsc --strict --noImplicitAny\n```\n\n## Rules That May Not Apply\n\n| Rule | When to Relax |\n|------|---------------|\n| No recursion | Tree traversal, parser combinators with bounded depth |\n| No dynamic memory | GC languages, short-lived processes |\n| 60-line functions | Declarative configs, state machines |\n| No function pointers | Callbacks, event handlers, strategies |\n\n## Integration\n\nReference this skill from:\n- `pensive:code-refinement` - Clean code dimension\n- `pensive:code-refinement` - Quality checks\n- `sanctum:pr-review` - Code quality phase\n\n## Sources\n\n- NASA JPL Power of 10 Rules (Gerard Holzmann, 2006)\n- MISRA C Guidelines\n- HN discussion insights on practical application\n\nFile v1.9.13:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-pensive-safety-critical-patterns\",\n  \"version\": \"1.9.13\",\n  \"publishedAt\": 1782577349454\n}\n\nFile v1.9.13:skill-card.md\n\n## Description: <br>\nApplies NASA Power of 10 rules for safety-critical verifiable code. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[athola](https://clawhub.ai/user/athola) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and code reviewers use this skill to apply safety-critical coding patterns, defensive checks, bounded control flow, and verification-oriented review practices to financial, medical, data-integrity, and other high-reliability code. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Broad activation wording may apply safety-critical review guidance where full rigor is not needed. <br>\nMitigation: Narrow activation triggers where supported and apply the skill's own selective or light-touch posture for non-critical code. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/athola/skills/nm-pensive-safety-critical-patterns) <br>\n- [Metadata homepage](https://github.com/athola/claude-night-market/tree/master/plugins/pensive) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Guidance, Markdown, Code, Shell commands] <br>\n**Output Format:** [Markdown guidance with inline code and shell command examples] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Documentation-only skill; no credentials, MCP tools, or API calls were detected.] <br>\n\n## Skill Version(s): <br>\n1.9.13 (source: server release evidence; artifact frontmatter lists 1.9.8) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.9.12: 3 files, 3818 bytes\n\nFiles: skill-card.md (2146b), SKILL.md (4579b), _meta.json (155b)\n\nFile v1.9.12:SKILL.md\n\n---\nname: safety-critical-patterns\ndescription: Applies NASA Power of 10 rules for safety-critical verifiable code\nversion: 1.9.8\ntriggers:\n  - safety\n  - defensive-coding\n  - assertions\n  - NASA\n  - robustness\n  - verification\n  - auditing financial\n  - medical\n  - or high-reliability system code\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/pensive\", \"emoji\": \"\\ud83e\\udd9e\", \"requires\": {\"config\": [\"night-market.pensive:shared\", \"night-market.pensive:code-refinement\"]}}}\nsource: claude-night-market\nsource_plugin: pensive\n---\n\n> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n# Safety-Critical Coding Patterns\n\nGuidelines adapted from NASA's Power of 10 rules for safety-critical software.\n\n## When to Apply\n\n**Full rigor**: Safety-critical systems, financial transactions, data integrity code\n**Selective application**: Business logic, API handlers, core algorithms\n**Light touch**: Scripts, prototypes, non-critical utilities\n\n> \"Match rigor to consequence\" - The real engineering principle\n\n## The 10 Rules (Adapted)\n\n### 1. Restrict Control Flow\nAvoid `goto`, `setjmp/longjmp`, and **limit recursion**.\n\n**Why**: Ensures acyclic call graphs that tools can verify.\n**Adaptation**: Recursion acceptable with provable termination (tail recursion, bounded depth).\n\n### 2. Fixed Loop Bounds\nAll loops should have verifiable upper bounds.\n\n```python\n# Good - bound is clear\nfor i in range(min(len(items), MAX_ITEMS)):\n    process(item)\n\n# Risky - unbounded\nwhile not_done:  # When does this end?\n    process_next()\n```\n\n**Adaptation**: Document expected bounds; add safety limits on potentially unbounded loops.\n\n### 3. No Dynamic Memory After Initialization\nAvoid heap allocation in critical paths after startup.\n\n**Why**: Prevents allocation failures at runtime.\n**Adaptation**: Pre-allocate pools; use object reuse patterns in hot paths.\n\n### 4. Function Length ~60 Lines\nFunctions should fit on one screen/page.\n\n**Why**: Cognitive limits on comprehension remain valid.\n**Adaptation**: Flexible for declarative code; strict for complex logic.\n\n### 5. Assertion Density\nInclude defensive assertions documenting expectations.\n\n```python\ndef transfer_funds(from_acct, to_acct, amount):\n    assert from_acct != to_acct, \"Cannot transfer to same account\"\n    assert amount > 0, \"Transfer amount must be positive\"\n    assert from_acct.balance >= amount, \"Insufficient funds\"\n    # ... implementation\n```\n\n**Adaptation**: Focus on boundary conditions and invariants, not arbitrary quotas.\n\n### 6. Minimal Variable Scope\nDeclare variables at narrowest possible scope.\n\n```python\n# Good - scoped tightly\nfor item in items:\n    total = calculate(item)  # Only exists in loop\n    results.append(total)\n\n# Avoid - unnecessarily broad\ntotal = 0  # Why is this outside?\nfor item in items:\n    total = calculate(item)\n    results.append(total)\n```\n\n### 7. Check Return Values and Parameters\nValidate inputs; never ignore return values.\n\n```python\n# Good\nresult = parse_config(path)\nif result is None:\n    raise ConfigError(f\"Failed to parse {path}\")\n\n# Bad\nparse_config(path)  # Ignored return\n```\n\n### 8. Limited Preprocessor/Metaprogramming\nRestrict macros, decorators, and code generation.\n\n**Why**: Makes static analysis possible.\n**Adaptation**: Document metaprogramming thoroughly; prefer explicit over magic.\n\n### 9. Pointer/Reference Discipline\nLimit indirection levels; be explicit about ownership.\n\n**Adaptation**: Use type hints, avoid deep nesting of optionals, prefer immutable data.\n\n### 10. Enable All Warnings\nCompile/lint with strictest settings from day one.\n\n```bash\n# Python\nruff check --select=ALL\nmypy --strict\n\n# TypeScript\ntsc --strict --noImplicitAny\n```\n\n## Rules That May Not Apply\n\n| Rule | When to Relax |\n|------|---------------|\n| No recursion | Tree traversal, parser combinators with bounded depth |\n| No dynamic memory | GC languages, short-lived processes |\n| 60-line functions | Declarative configs, state machines |\n| No function pointers | Callbacks, event handlers, strategies |\n\n## Integration\n\nReference this skill from:\n- `pensive:code-refinement` - Clean code dimension\n- `pensive:code-refinement` - Quality checks\n- `sanctum:pr-review` - Code quality phase\n\n## Sources\n\n- NASA JPL Power of 10 Rules (Gerard Holzmann, 2006)\n- MISRA C Guidelines\n- HN discussion insights on practical application\n\nFile v1.9.12:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-pensive-safety-critical-patterns\",\n  \"version\": \"1.9.12\",\n  \"publishedAt\": 1781839062653\n}\n\nFile v1.9.12:skill-card.md\n\n## Description: <br>\nApplies NASA Power of 10 rules for safety-critical verifiable code. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[athola](https://clawhub.ai/user/athola) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and code reviewers use this skill to evaluate safety-critical, financial, medical, data-integrity, and other high-reliability code with adapted NASA Power of 10 guidance. It helps an agent recommend stricter control-flow, loop-bound, assertion, validation, scope, and linting practices while matching rigor to consequence. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Broad triggers such as safety, medical, or high-reliability system code may activate the skill during unrelated work. <br>\nMitigation: Narrow triggers locally when broad activation is unwanted. <br>\nRisk: Safety-critical guidance can be too strict for prototypes, scripts, or non-critical utilities. <br>\nMitigation: Apply the skill as advisory review guidance and match rigor to the consequence of the code being reviewed. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/athola/nm-pensive-safety-critical-patterns) <br>\n- [Publisher profile](https://clawhub.ai/user/athola) <br>\n- [Metadata homepage](https://github.com/athola/claude-night-market/tree/master/plugins/pensive) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [guidance, markdown, code, shell commands, configuration] <br>\n**Output Format:** [Markdown guidance with code, shell command, and configuration examples] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Documentation-only output; the skill does not request runtime access or perform actions.] <br>\n\n## Skill Version(s): <br>\n1.9.12 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.3: 3 files, 3652 bytes\n\nFiles: skill-card.md (1686b), SKILL.md (4579b), _meta.json (154b)\n\nFile v1.0.3:SKILL.md\n\n---\nname: safety-critical-patterns\ndescription: Applies NASA Power of 10 rules for safety-critical verifiable code\nversion: 1.9.8\ntriggers:\n  - safety\n  - defensive-coding\n  - assertions\n  - NASA\n  - robustness\n  - verification\n  - auditing financial\n  - medical\n  - or high-reliability system code\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/pensive\", \"emoji\": \"\\ud83e\\udd9e\", \"requires\": {\"config\": [\"night-market.pensive:shared\", \"night-market.pensive:code-refinement\"]}}}\nsource: claude-night-market\nsource_plugin: pensive\n---\n\n> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n# Safety-Critical Coding Patterns\n\nGuidelines adapted from NASA's Power of 10 rules for safety-critical software.\n\n## When to Apply\n\n**Full rigor**: Safety-critical systems, financial transactions, data integrity code\n**Selective application**: Business logic, API handlers, core algorithms\n**Light touch**: Scripts, prototypes, non-critical utilities\n\n> \"Match rigor to consequence\" - The real engineering principle\n\n## The 10 Rules (Adapted)\n\n### 1. Restrict Control Flow\nAvoid `goto`, `setjmp/longjmp`, and **limit recursion**.\n\n**Why**: Ensures acyclic call graphs that tools can verify.\n**Adaptation**: Recursion acceptable with provable termination (tail recursion, bounded depth).\n\n### 2. Fixed Loop Bounds\nAll loops should have verifiable upper bounds.\n\n```python\n# Good - bound is clear\nfor i in range(min(len(items), MAX_ITEMS)):\n    process(item)\n\n# Risky - unbounded\nwhile not_done:  # When does this end?\n    process_next()\n```\n\n**Adaptation**: Document expected bounds; add safety limits on potentially unbounded loops.\n\n### 3. No Dynamic Memory After Initialization\nAvoid heap allocation in critical paths after startup.\n\n**Why**: Prevents allocation failures at runtime.\n**Adaptation**: Pre-allocate pools; use object reuse patterns in hot paths.\n\n### 4. Function Length ~60 Lines\nFunctions should fit on one screen/page.\n\n**Why**: Cognitive limits on comprehension remain valid.\n**Adaptation**: Flexible for declarative code; strict for complex logic.\n\n### 5. Assertion Density\nInclude defensive assertions documenting expectations.\n\n```python\ndef transfer_funds(from_acct, to_acct, amount):\n    assert from_acct != to_acct, \"Cannot transfer to same account\"\n    assert amount > 0, \"Transfer amount must be positive\"\n    assert from_acct.balance >= amount, \"Insufficient funds\"\n    # ... implementation\n```\n\n**Adaptation**: Focus on boundary conditions and invariants, not arbitrary quotas.\n\n### 6. Minimal Variable Scope\nDeclare variables at narrowest possible scope.\n\n```python\n# Good - scoped tightly\nfor item in items:\n    total = calculate(item)  # Only exists in loop\n    results.append(total)\n\n# Avoid - unnecessarily broad\ntotal = 0  # Why is this outside?\nfor item in items:\n    total = calculate(item)\n    results.append(total)\n```\n\n### 7. Check Return Values and Parameters\nValidate inputs; never ignore return values.\n\n```python\n# Good\nresult = parse_config(path)\nif result is None:\n    raise ConfigError(f\"Failed to parse {path}\")\n\n# Bad\nparse_config(path)  # Ignored return\n```\n\n### 8. Limited Preprocessor/Metaprogramming\nRestrict macros, decorators, and code generation.\n\n**Why**: Makes static analysis possible.\n**Adaptation**: Document metaprogramming thoroughly; prefer explicit over magic.\n\n### 9. Pointer/Reference Discipline\nLimit indirection levels; be explicit about ownership.\n\n**Adaptation**: Use type hints, avoid deep nesting of optionals, prefer immutable data.\n\n### 10. Enable All Warnings\nCompile/lint with strictest settings from day one.\n\n```bash\n# Python\nruff check --select=ALL\nmypy --strict\n\n# TypeScript\ntsc --strict --noImplicitAny\n```\n\n## Rules That May Not Apply\n\n| Rule | When to Relax |\n|------|---------------|\n| No recursion | Tree traversal, parser combinators with bounded depth |\n| No dynamic memory | GC languages, short-lived processes |\n| 60-line functions | Declarative configs, state machines |\n| No function pointers | Callbacks, event handlers, strategies |\n\n## Integration\n\nReference this skill from:\n- `pensive:code-refinement` - Clean code dimension\n- `pensive:code-refinement` - Quality checks\n- `sanctum:pr-review` - Code quality phase\n\n## Sources\n\n- NASA JPL Power of 10 Rules (Gerard Holzmann, 2006)\n- MISRA C Guidelines\n- HN discussion insights on practical application\n\nFile v1.0.3:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-pensive-safety-critical-patterns\",\n  \"version\": \"1.0.3\",\n  \"publishedAt\": 1781795772926\n}\n\nFile v1.0.3:skill-card.md\n\n## Description: <br>\nApplies NASA Power of 10 rules for safety-critical verifiable code. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[athola](https://clawhub.ai/user/athola) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineers use this skill to review safety-critical, financial, medical, data-integrity, and high-reliability code for verifiable defensive coding patterns. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Broad trigger terms may activate the skill on general safety or assertion-related prompts where this guidance is not needed. <br>\nMitigation: Narrow or disable trigger terms if the skill becomes noisy, and review the guidance for the specific code context before applying it. <br>\n\n\n## Reference(s): <br>\n- [Pensive plugin homepage](https://github.com/athola/claude-night-market/tree/master/plugins/pensive) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Guidance, Markdown, Code, Shell commands] <br>\n**Output Format:** [Markdown guidance with inline code and shell command examples] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Advisory content only; no credential, API, MCP, or hidden execution behavior was identified in the evidence.] <br>\n\n## Skill Version(s): <br>\n1.0.3 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.2: 3 files, 3774 bytes\n\nFiles: skill-card.md (2018b), SKILL.md (4543b), _meta.json (154b)\n\nFile v1.0.2:SKILL.md\n\n---\nname: safety-critical-patterns\ndescription: |\n  NASA Power of 10 rules adapted for writing robust, verifiable code with context-appropriate rigor\nversion: 1.9.5\ntriggers:\n  - safety\n  - defensive-coding\n  - assertions\n  - NASA\n  - robustness\n  - verification\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/pensive\", \"emoji\": \"\\ud83e\\udd9e\", \"requires\": {\"config\": [\"night-market.pensive:shared\", \"night-market.pensive:code-refinement\"]}}}\nsource: claude-night-market\nsource_plugin: pensive\n---\n\n> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n# Safety-Critical Coding Patterns\n\nGuidelines adapted from NASA's Power of 10 rules for safety-critical software.\n\n## When to Apply\n\n**Full rigor**: Safety-critical systems, financial transactions, data integrity code\n**Selective application**: Business logic, API handlers, core algorithms\n**Light touch**: Scripts, prototypes, non-critical utilities\n\n> \"Match rigor to consequence\" - The real engineering principle\n\n## The 10 Rules (Adapted)\n\n### 1. Restrict Control Flow\nAvoid `goto`, `setjmp/longjmp`, and **limit recursion**.\n\n**Why**: Ensures acyclic call graphs that tools can verify.\n**Adaptation**: Recursion acceptable with provable termination (tail recursion, bounded depth).\n\n### 2. Fixed Loop Bounds\nAll loops should have verifiable upper bounds.\n\n```python\n# Good - bound is clear\nfor i in range(min(len(items), MAX_ITEMS)):\n    process(item)\n\n# Risky - unbounded\nwhile not_done:  # When does this end?\n    process_next()\n```\n\n**Adaptation**: Document expected bounds; add safety limits on potentially unbounded loops.\n\n### 3. No Dynamic Memory After Initialization\nAvoid heap allocation in critical paths after startup.\n\n**Why**: Prevents allocation failures at runtime.\n**Adaptation**: Pre-allocate pools; use object reuse patterns in hot paths.\n\n### 4. Function Length ~60 Lines\nFunctions should fit on one screen/page.\n\n**Why**: Cognitive limits on comprehension remain valid.\n**Adaptation**: Flexible for declarative code; strict for complex logic.\n\n### 5. Assertion Density\nInclude defensive assertions documenting expectations.\n\n```python\ndef transfer_funds(from_acct, to_acct, amount):\n    assert from_acct != to_acct, \"Cannot transfer to same account\"\n    assert amount > 0, \"Transfer amount must be positive\"\n    assert from_acct.balance >= amount, \"Insufficient funds\"\n    # ... implementation\n```\n\n**Adaptation**: Focus on boundary conditions and invariants, not arbitrary quotas.\n\n### 6. Minimal Variable Scope\nDeclare variables at narrowest possible scope.\n\n```python\n# Good - scoped tightly\nfor item in items:\n    total = calculate(item)  # Only exists in loop\n    results.append(total)\n\n# Avoid - unnecessarily broad\ntotal = 0  # Why is this outside?\nfor item in items:\n    total = calculate(item)\n    results.append(total)\n```\n\n### 7. Check Return Values and Parameters\nValidate inputs; never ignore return values.\n\n```python\n# Good\nresult = parse_config(path)\nif result is None:\n    raise ConfigError(f\"Failed to parse {path}\")\n\n# Bad\nparse_config(path)  # Ignored return\n```\n\n### 8. Limited Preprocessor/Metaprogramming\nRestrict macros, decorators, and code generation.\n\n**Why**: Makes static analysis possible.\n**Adaptation**: Document metaprogramming thoroughly; prefer explicit over magic.\n\n### 9. Pointer/Reference Discipline\nLimit indirection levels; be explicit about ownership.\n\n**Adaptation**: Use type hints, avoid deep nesting of optionals, prefer immutable data.\n\n### 10. Enable All Warnings\nCompile/lint with strictest settings from day one.\n\n```bash\n# Python\nruff check --select=ALL\nmypy --strict\n\n# TypeScript\ntsc --strict --noImplicitAny\n```\n\n## Rules That May Not Apply\n\n| Rule | When to Relax |\n|------|---------------|\n| No recursion | Tree traversal, parser combinators with bounded depth |\n| No dynamic memory | GC languages, short-lived processes |\n| 60-line functions | Declarative configs, state machines |\n| No function pointers | Callbacks, event handlers, strategies |\n\n## Integration\n\nReference this skill from:\n- `pensive:code-refinement` - Clean code dimension\n- `pensive:code-refinement` - Quality checks\n- `sanctum:pr-review` - Code quality phase\n\n## Sources\n\n- NASA JPL Power of 10 Rules (Gerard Holzmann, 2006)\n- MISRA C Guidelines\n- HN discussion insights on practical application\n\nFile v1.0.2:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-pensive-safety-critical-patterns\",\n  \"version\": \"1.0.2\",\n  \"publishedAt\": 1778293166727\n}\n\nFile v1.0.2:skill-card.md\n\n## Description: <br>\nNASA Power of 10 rules adapted for writing robust, verifiable code with context-appropriate rigor. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[athola](https://clawhub.ai/user/athola) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineers use this skill to apply safety-critical coding patterns, defensive checks, bounded control flow, stricter linting, and context-appropriate rigor to robust software work. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can recommend stricter coding practices or lint settings that may not fit every codebase or risk level. <br>\nMitigation: Apply the guidance proportionally to the system's consequence level and review proposed changes before adopting them. <br>\nRisk: The release references external plugin components that are not part of this documentation-only artifact. <br>\nMitigation: Review and scan any separately installed plugin, hook, agent, or command independently before use. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/athola/nm-pensive-safety-critical-patterns) <br>\n- [Pensive plugin homepage](https://github.com/athola/claude-night-market/tree/master/plugins/pensive) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [guidance, markdown, code, shell commands] <br>\n**Output Format:** [Markdown guidance with code and shell command examples] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Documentation-only coding guidance; no executable behavior is included in the release artifact.] <br>\n\n## Skill Version(s): <br>\n1.0.2 (source: ClawHub release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.1: 2 files, 2653 bytes\n\nFiles: SKILL.md (4543b), _meta.json (154b)\n\nFile v1.0.1:SKILL.md\n\n---\nname: safety-critical-patterns\ndescription: |\n  NASA Power of 10 rules adapted for writing robust, verifiable code with context-appropriate rigor\nversion: 1.9.4\ntriggers:\n  - safety\n  - defensive-coding\n  - assertions\n  - NASA\n  - robustness\n  - verification\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/pensive\", \"emoji\": \"\\ud83e\\udd9e\", \"requires\": {\"config\": [\"night-market.pensive:shared\", \"night-market.pensive:code-refinement\"]}}}\nsource: claude-night-market\nsource_plugin: pensive\n---\n\n> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n# Safety-Critical Coding Patterns\n\nGuidelines adapted from NASA's Power of 10 rules for safety-critical software.\n\n## When to Apply\n\n**Full rigor**: Safety-critical systems, financial transactions, data integrity code\n**Selective application**: Business logic, API handlers, core algorithms\n**Light touch**: Scripts, prototypes, non-critical utilities\n\n> \"Match rigor to consequence\" - The real engineering principle\n\n## The 10 Rules (Adapted)\n\n### 1. Restrict Control Flow\nAvoid `goto`, `setjmp/longjmp`, and **limit recursion**.\n\n**Why**: Ensures acyclic call graphs that tools can verify.\n**Adaptation**: Recursion acceptable with provable termination (tail recursion, bounded depth).\n\n### 2. Fixed Loop Bounds\nAll loops should have verifiable upper bounds.\n\n```python\n# Good - bound is clear\nfor i in range(min(len(items), MAX_ITEMS)):\n    process(item)\n\n# Risky - unbounded\nwhile not_done:  # When does this end?\n    process_next()\n```\n\n**Adaptation**: Document expected bounds; add safety limits on potentially unbounded loops.\n\n### 3. No Dynamic Memory After Initialization\nAvoid heap allocation in critical paths after startup.\n\n**Why**: Prevents allocation failures at runtime.\n**Adaptation**: Pre-allocate pools; use object reuse patterns in hot paths.\n\n### 4. Function Length ~60 Lines\nFunctions should fit on one screen/page.\n\n**Why**: Cognitive limits on comprehension remain valid.\n**Adaptation**: Flexible for declarative code; strict for complex logic.\n\n### 5. Assertion Density\nInclude defensive assertions documenting expectations.\n\n```python\ndef transfer_funds(from_acct, to_acct, amount):\n    assert from_acct != to_acct, \"Cannot transfer to same account\"\n    assert amount > 0, \"Transfer amount must be positive\"\n    assert from_acct.balance >= amount, \"Insufficient funds\"\n    # ... implementation\n```\n\n**Adaptation**: Focus on boundary conditions and invariants, not arbitrary quotas.\n\n### 6. Minimal Variable Scope\nDeclare variables at narrowest possible scope.\n\n```python\n# Good - scoped tightly\nfor item in items:\n    total = calculate(item)  # Only exists in loop\n    results.append(total)\n\n# Avoid - unnecessarily broad\ntotal = 0  # Why is this outside?\nfor item in items:\n    total = calculate(item)\n    results.append(total)\n```\n\n### 7. Check Return Values and Parameters\nValidate inputs; never ignore return values.\n\n```python\n# Good\nresult = parse_config(path)\nif result is None:\n    raise ConfigError(f\"Failed to parse {path}\")\n\n# Bad\nparse_config(path)  # Ignored return\n```\n\n### 8. Limited Preprocessor/Metaprogramming\nRestrict macros, decorators, and code generation.\n\n**Why**: Makes static analysis possible.\n**Adaptation**: Document metaprogramming thoroughly; prefer explicit over magic.\n\n### 9. Pointer/Reference Discipline\nLimit indirection levels; be explicit about ownership.\n\n**Adaptation**: Use type hints, avoid deep nesting of optionals, prefer immutable data.\n\n### 10. Enable All Warnings\nCompile/lint with strictest settings from day one.\n\n```bash\n# Python\nruff check --select=ALL\nmypy --strict\n\n# TypeScript\ntsc --strict --noImplicitAny\n```\n\n## Rules That May Not Apply\n\n| Rule | When to Relax |\n|------|---------------|\n| No recursion | Tree traversal, parser combinators with bounded depth |\n| No dynamic memory | GC languages, short-lived processes |\n| 60-line functions | Declarative configs, state machines |\n| No function pointers | Callbacks, event handlers, strategies |\n\n## Integration\n\nReference this skill from:\n- `pensive:code-refinement` - Clean code dimension\n- `pensive:code-refinement` - Quality checks\n- `sanctum:pr-review` - Code quality phase\n\n## Sources\n\n- NASA JPL Power of 10 Rules (Gerard Holzmann, 2006)\n- MISRA C Guidelines\n- HN discussion insights on practical application\n\nFile v1.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-pensive-safety-critical-patterns\",\n  \"version\": \"1.0.1\",\n  \"publishedAt\": 1778077242048\n}\n\nArchive v1.0.0: 2 files, 2654 bytes\n\nFiles: SKILL.md (4543b), _meta.json (154b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: safety-critical-patterns\ndescription: |\n  NASA Power of 10 rules adapted for writing robust, verifiable code with context-appropriate rigor\nversion: 1.8.2\ntriggers:\n  - safety\n  - defensive-coding\n  - assertions\n  - NASA\n  - robustness\n  - verification\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/pensive\", \"emoji\": \"\\ud83e\\udd9e\", \"requires\": {\"config\": [\"night-market.pensive:shared\", \"night-market.pensive:code-refinement\"]}}}\nsource: claude-night-market\nsource_plugin: pensive\n---\n\n> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n# Safety-Critical Coding Patterns\n\nGuidelines adapted from NASA's Power of 10 rules for safety-critical software.\n\n## When to Apply\n\n**Full rigor**: Safety-critical systems, financial transactions, data integrity code\n**Selective application**: Business logic, API handlers, core algorithms\n**Light touch**: Scripts, prototypes, non-critical utilities\n\n> \"Match rigor to consequence\" - The real engineering principle\n\n## The 10 Rules (Adapted)\n\n### 1. Restrict Control Flow\nAvoid `goto`, `setjmp/longjmp`, and **limit recursion**.\n\n**Why**: Ensures acyclic call graphs that tools can verify.\n**Adaptation**: Recursion acceptable with provable termination (tail recursion, bounded depth).\n\n### 2. Fixed Loop Bounds\nAll loops should have verifiable upper bounds.\n\n```python\n# Good - bound is clear\nfor i in range(min(len(items), MAX_ITEMS)):\n    process(item)\n\n# Risky - unbounded\nwhile not_done:  # When does this end?\n    process_next()\n```\n\n**Adaptation**: Document expected bounds; add safety limits on potentially unbounded loops.\n\n### 3. No Dynamic Memory After Initialization\nAvoid heap allocation in critical paths after startup.\n\n**Why**: Prevents allocation failures at runtime.\n**Adaptation**: Pre-allocate pools; use object reuse patterns in hot paths.\n\n### 4. Function Length ~60 Lines\nFunctions should fit on one screen/page.\n\n**Why**: Cognitive limits on comprehension remain valid.\n**Adaptation**: Flexible for declarative code; strict for complex logic.\n\n### 5. Assertion Density\nInclude defensive assertions documenting expectations.\n\n```python\ndef transfer_funds(from_acct, to_acct, amount):\n    assert from_acct != to_acct, \"Cannot transfer to same account\"\n    assert amount > 0, \"Transfer amount must be positive\"\n    assert from_acct.balance >= amount, \"Insufficient funds\"\n    # ... implementation\n```\n\n**Adaptation**: Focus on boundary conditions and invariants, not arbitrary quotas.\n\n### 6. Minimal Variable Scope\nDeclare variables at narrowest possible scope.\n\n```python\n# Good - scoped tightly\nfor item in items:\n    total = calculate(item)  # Only exists in loop\n    results.append(total)\n\n# Avoid - unnecessarily broad\ntotal = 0  # Why is this outside?\nfor item in items:\n    total = calculate(item)\n    results.append(total)\n```\n\n### 7. Check Return Values and Parameters\nValidate inputs; never ignore return values.\n\n```python\n# Good\nresult = parse_config(path)\nif result is None:\n    raise ConfigError(f\"Failed to parse {path}\")\n\n# Bad\nparse_config(path)  # Ignored return\n```\n\n### 8. Limited Preprocessor/Metaprogramming\nRestrict macros, decorators, and code generation.\n\n**Why**: Makes static analysis possible.\n**Adaptation**: Document metaprogramming thoroughly; prefer explicit over magic.\n\n### 9. Pointer/Reference Discipline\nLimit indirection levels; be explicit about ownership.\n\n**Adaptation**: Use type hints, avoid deep nesting of optionals, prefer immutable data.\n\n### 10. Enable All Warnings\nCompile/lint with strictest settings from day one.\n\n```bash\n# Python\nruff check --select=ALL\nmypy --strict\n\n# TypeScript\ntsc --strict --noImplicitAny\n```\n\n## Rules That May Not Apply\n\n| Rule | When to Relax |\n|------|---------------|\n| No recursion | Tree traversal, parser combinators with bounded depth |\n| No dynamic memory | GC languages, short-lived processes |\n| 60-line functions | Declarative configs, state machines |\n| No function pointers | Callbacks, event handlers, strategies |\n\n## Integration\n\nReference this skill from:\n- `pensive:code-refinement` - Clean code dimension\n- `pensive:code-refinement` - Quality checks\n- `sanctum:pr-review` - Code quality phase\n\n## Sources\n\n- NASA JPL Power of 10 Rules (Gerard Holzmann, 2006)\n- MISRA C Guidelines\n- HN discussion insights on practical application\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-pensive-safety-critical-patterns\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1776265308056\n}","readmeExcerpt":"Skill: safety-critical-patterns Owner: athola Summary: Applies NASA Power of 10 rules for safety-critical verifiable code Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-26T13:19:20.827Z | user Release v1.9.19 v1.9.17 | 2026-07-30T05:39:32.617Z | user Release v1.9.17 v1.9.16 | 2026-07-14T19:56:15.650Z | user Release v1.9.16 v1.9.14 | 2026-06-30T18:04:31.432Z | user Release v1.9.14 v1.9.13 | 2026-06-27T16:22:29","codeSnippets":[],"executableExamples":[{"language":"python","snippet":"# Good - bound is clear\nfor i in range(min(len(items), MAX_ITEMS)):\n    process(item)\n\n# Risky - unbounded\nwhile not_done:  # When does this end?\n    process_next()"},{"language":"python","snippet":"def transfer_funds(from_acct, to_acct, amount):\n    assert from_acct != to_acct, \"Cannot transfer to same account\"\n    assert amount > 0, \"Transfer amount must be positive\"\n    assert from_acct.balance >= amount, \"Insufficient funds\"\n    # ... implementation"},{"language":"python","snippet":"# Good - scoped tightly\nfor item in items:\n    total = calculate(item)  # Only exists in loop\n    results.append(total)\n\n# Avoid - unnecessarily broad\ntotal = 0  # Why is this outside?\nfor item in items:\n    total = calculate(item)\n    results.append(total)"},{"language":"python","snippet":"# Good\nresult = parse_config(path)\nif result is None:\n    raise ConfigError(f\"Failed to parse {path}\")\n\n# Bad\nparse_config(path)  # Ignored return"},{"language":"bash","snippet":"# Python\nruff check --select=ALL\nmypy --strict\n\n# TypeScript\ntsc --strict --noImplicitAny"},{"language":"python","snippet":"# Good - bound is clear\nfor i in range(min(len(items), MAX_ITEMS)):\n    process(item)\n\n# Risky - unbounded\nwhile not_done:  # When does this end?\n    process_next()"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: safety-critical-patterns\ndescription: Applies NASA Power of 10 rules for safety-critical verifiable code\nversion: 1.9.8\ntriggers:\n  - safety\n  - defensive-coding\n  - assertions\n  - NASA\n  - robustness\n  - verification\n  - auditing financial\n  - medical\n  - or high-reliability system code\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/pensive\", \"emoji\": \"\\ud83e\\udd9e\", \"requires\": {\"config\": [\"night-market.pensive:shared\", \"night-market.pensive:code-refinement\"]}}}\nsource: claude-night-market\nsource_plugin: pensive\n---\n\n> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n# Safety-Critical Coding Patterns\n\nGuidelines adapted from NASA's Power of 10 rules for safety-critical software.\n\n## When to Apply\n\n**Full rigor**: Safety-critical systems, financial transactions, data integrity code\n**Selective application**: Business logic, API handlers, core algorithms\n**Light touch**: Scripts, prototypes, non-critical utilities\n\n> \"Match rigor to consequence\" - The real engineering principle\n\n## The 10 Rules (Adapted)\n\n### 1. Restrict Control Flow\nAvoid `goto`, `setjmp/longjmp`, and **limit recursion**.\n\n**Why**: Ensures acyclic call graphs that tools can verify.\n**Adaptation**: Recursion acceptable with provable termination (tail recursion, bounded depth).\n\n### 2. Fixed Loop Bounds\nAll loops should have verifiable upper bounds.\n\n```python\n# Good - bound is clear\nfor i in range(min(len(items), MAX_ITEMS)):\n    process(item)\n\n# Risky - unbounded\nwhile not_done:  # When does this end?\n    process_next()\n```\n\n**Adaptation**: Document expected bounds; add safety limits on potentially unbounded loops.\n\n### 3. No Dynamic Memory After Initialization\nAvoid heap allocation in critical paths after startup.\n\n**Why**: Prevents allocation failures at runtime.\n**Adaptation**: Pre-allocate pools; use object reuse patterns in hot paths.\n\n### 4. Function Length ~60 Lines\nFunctions should fit on one screen/page.\n\n**Why**: Cognitive limits on comprehension remain valid.\n**Adaptation**: Flexible for declarative code; strict for complex logic.\n\n### 5. Assertion Density\nInclude defensive assertions documenting expectations.\n\n```python\ndef transfer_funds(from_acct, to_acct, amount):\n    assert from_acct != to_acct, \"Cannot transfer to same account\"\n    assert amount > 0, \"Transfer amount must be positive\"\n    assert from_acct.balance >= amount, \"Insufficient funds\"\n    # ... implementation\n```\n\n**Adaptation**: Focus on boundary conditions and invariants, not arbitrary quotas.\n\n### 6. Minimal Variable Scope\nDeclare variables at narrowest possible scope.\n\n```python\n# Good - scoped tightly\nfor item in items:\n    total = calculate(item)  # Only exists in loop\n    results.append(total)\n\n# Avoid - unnecessarily broad\ntotal = 0  # Why is this"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-pensive-safety-critical-patterns\",\n  \"version\": \"1.9.19\",\n  \"publishedAt\": 1787750360827\n}"},{"path":"skill-card.md","content":"## Description:\n\nApplies NASA Power of 10 rules for safety-critical verifiable code.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[athola](https://clawhub.ai/user/athola)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and engineers use this skill to apply a NASA Power of 10 inspired checklist when reviewing safety-critical, financial, medical, data-integrity, and other high-reliability code.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Python assert examples may be mistaken for complete runtime validation in financial or safety-sensitive code.\n\nMitigation: Treat assertions as internal invariant documentation and require explicit validation for untrusted input, authorization, financial rules, and safety constraints.\n\nRisk: Broad activation triggers may apply the skill outside the intended review context.\n\nMitigation: Review the generated guidance before applying it and scope use to code where safety-critical or high-reliability patterns are relevant.\n\nRisk: The security scan verdict is suspicious.\n\nMitigation: Review the skill carefully before installing it for financial, medical, safety-critical, production, or other high-consequence work.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/athola/skills/nm-pensive-safety-critical-patterns)\n- [Publisher profile](https://clawhub.ai/user/athola)\n- [Configured homepage](https://github.com/athola/claude-night-market/tree/master/plugins/pensive)\n\n## Skill Output:\n\n**Output Type(s):** [guidance, markdown, code, shell commands]\n\n**Output Format:** [Markdown with checklist guidance and inline code blocks]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Advisory review guidance; users should validate recommendations against their project requirements.]\n\n## Skill Version(s):\n\n1.9.19 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Applies NASA Power of 10 rules for safety-critical verifiable code Skill: safety-critical-patterns Owner: athola Summary: Applies NASA Power of 10 rules for safety-critical verifiable code Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-26T13:19:20.827Z | user Release v1.9.19 v1.9.17 | 2026-07-30T05:39:32.617Z | user Release v1.9.17 v1.9.16 | 2026-07-14T19:56:15.650Z | user Release v1.9.16 v1.9.14 | 2026-06-30T18:04:31.432Z | user Release v1.9.14 v1.9.13 | 2026-06-27T16:22:29","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1009,"uniquenessScore":57,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T05:37:08.447Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T05:37:08.447Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T10:49:07.424Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}