stpa-step3-unsafe-control-actions

Generate prioritized UCA analysis tables using STPA 4-type analysis.

130|8|Updated Jan 23, 2026
One-click install
npx skills add https://github.com/sandgardenhq/sgai --skill stpa-step3-unsafe-control-actions
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: stpa-step3-unsafe-control-actions
Source: https://github.com/sandgardenhq/sgai/tree/main/cmd/sgai/skel/.sgai/skills/stpa/stpa-step3-unsafe-control-actions
Command: npx skills add https://github.com/sandgardenhq/sgai --skill stpa-step3-unsafe-control-actions

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Identifying unsafe control actions is essential for safety‑critical systems, but manually applying the 4‑type STPA analysis can be error‑prone and time‑consuming.

Core Features & Use Cases

  • Structured 4‑type analysis: Guides you through Not Provided, Provided, Wrong Timing, and Wrong Duration scenarios for each control action.
  • Template‑driven UCA recording: Provides ready‑made tables and markdown templates to capture hazards, link to earlier STPA steps, and apply prioritization criteria.
  • Applicable domains: Automotive braking systems, authentication services, medical device controllers, and any safety‑critical control architecture.

Quick Start

Ask the skill to run STPA Step 3 on the control actions you collected in Step 2.

Frequently Asked Questions about stpa-step3-unsafe-control-actions

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What are unsafe control actions in STPA safety analysis?

Unsafe control actions in STPA are control commands that could lead to a hazard if provided, not provided, or executed with wrong timing or duration. The Skill systematically identifies these four action types for each control action across safety-critical automotive, cybersecurity, and medical device contexts.

How do I identify unsafe control actions for a safety-critical system?

To identify unsafe control actions, apply the STPA 4-type analysis to each control action collected in Step 2. The Skill guides you through Not Provided, Provided, Wrong Timing, and Wrong Duration scenarios, generating a prioritized UCA table that links each action to hazards, severity, and likelihood.

Can I use STPA hazard identification for medical device and automotive controllers?

Yes, STPA hazard identification works for medical device controllers, automotive braking systems, and authentication services. The Skill applies the 4-type unsafe control action analysis to safety-critical control architectures across these domains to capture domain-specific hazards.

What's the best way to prioritize hazards found during STPA Step 3?

The best way to prioritize hazards during STPA Step 3 is to generate a structured UCA analysis table. The Skill links each unsafe control action to its corresponding hazard, severity, likelihood, and detectability requirements, providing template-driven prioritization criteria for your safety analysis.

Do I need control actions from STPA Step 2 before analyzing unsafe actions?

Yes, you need the control actions collected in STPA Step 2 before analyzing unsafe actions. The Skill takes these previously identified control actions and applies the 4-type analysis to systematically uncover unsafe scenarios across your safety-critical system contexts.

Why does manual STPA analysis take so long and miss hazards?

Manual STPA analysis is error-prone and time-consuming because applying the 4-type analysis to every control action across multiple contexts requires extensive tracking. The Skill automates this structured analysis, ensuring consistent coverage of Not Provided, Provided, Wrong Timing, and Wrong Duration scenarios.