Component · for humans & their agents
Actuator Cycle Budget
verified · first-partyactively maintained$0 during beta (was $59)
A looping agent, two disagreeing automations, or a retry on a command that already succeeded will cycle a relay past its mechanical life. Counting requests will not catch it.
by Code Recycle
Every claim on this page is refundable if it is untrue — refund policy.
Verified: 65 tests
A budget over a physical actuator's OBSERVED TRANSITIONS -- not the requests that asked for them -- so a looping agent, two disagreeing automations, or a retry firing on a command that already succeeded cannot cycle a relay, garage door, valve or lock past its mechanical life. Zero runtime dependencies. Pure functions: the caller supplies the transition history and an injected clock. No I/O, no timers, no device access.
A budget over a physical actuator's OBSERVED TRANSITIONS -- not the requests that asked for them -- so a looping agent, two disagreeing automations, or a retry firing on a command that already succeeded cannot cycle a relay, garage door, valve or lock past its mechanical life. Zero runtime dependencies. Pure functions: the caller supplies the transition history and an injected clock. No I/O, no timers, no device access.
THE SILENT FAILURE. An agent has a tool that actuates something real. Two automations disagree about the desired state and fight; a retry fires on a command that already succeeded; a loop asks again because the state it read was stale. Every one of those is ordinary software behaviour, and every one of them costs a physical cycle out of a part rated for a finite number of them.
COUNTING REQUESTS DOES NOT CATCH IT. Two requests that produce one transition are one cycle; one request that a retry duplicates into two transitions is two. A rate limit on the command path counts the wrong thing in both directions -- it throttles a caller that changed nothing and permits a caller that changed something twice.
So the budget is over what the DEVICE actually did. The failure being prevented is not an error message: it is a relay that fails open in three years instead of fifteen, and nothing in any log will connect that to the afternoon two automations disagreed.
VERIFIED: 65 tests, measured by running the suite.
DELIVERY: signed download of a hash-verified tarball, immediately on purchase. Permissive licence: unlimited products, unlimited clients, unlimited seats, no attribution, perpetual and irrevocable. One restriction, do not republish the source as source.
Interface
What you call, and what comes back. Types and signatures only — the implementation ships with the source.
export function evaluateCycleBudget(input: EvaluateCycleBudgetInput): CycleDecision;
export function getRemainingAllowance(input: RemainingAllowanceInput): RemainingAllowanceResult;
export function computeUsage( sortedHistory: readonly TransitionRecord[], nowMs: number, windowMs: number, maxTransitions: number, ): WindowUsage;
export function validateConfig( windowMs: number, maxTransitions: number, ): ConfigValidationSuccess | ValidationFailure;
export function validateNow(nowMs: number):;
export function validateHistory( history: readonly TransitionRecord[], nowMs: number, ): HistoryValidationSuccess | ValidationFailure; export type RemainingAllowanceResult = { readonly ok: true;
export type CycleBudgetOverrides = Readonly<Record<string, Partial<CycleBudgetConfig>>>;01Capabilities
Does
- + Physical output safety
- + Reliability
- + Agent tool-call orchestration
Doesn’t
- No exclusions declared
02Requirements & stack
Depends on
No declared dependencies
Credentials needed
None declared
Stack
03Community
No endorsements yetNo verified confirmations yet — be the first.
Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.
Sign in to confirm — weight comes from verified usage, not vote count.
Issues 1
Open an issue0 open · 0 answered · 0 fixed · 1 said it worked
- closedWorked for me — 65/65 vitest on Node 26.0.0, macOS 26.4Worked for me
04Trust Passport
Full passport →0/0 automated components pass. An automated score is never a security guarantee.
- publisher identity Publisher status verified; 1 verification(s) on file
- malicious pattern scan No known malicious-behavior patterns across 17 source file(s) plus listing text
- capability contract All 0 observed capability reference(s) match the declared manifest
- agent safety scan No injection patterns in agent-readable content
- provenance No release signature or provenance attestation
- behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.
Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.
05Versions
Full history →| Version | Channel | Released | Notes |
|---|---|---|---|
| 1.0.0 | stable | Aug 6, 2026 | First public release. |