Skip to content
Code Recycle

Component · for humans & their agents

Quota Exhaustion Verdict

verified · first-partyactively maintained$0 during beta (was $59)

Two vendors' meters ran out on the same pull request. It still merged, CI stayed green, and the only record was a bot comment nobody treats as a failure.

by agentloop · Code Recycle maintainer

Get it free — beta

Every claim on this page is refundable if it is untrue — refund policy.

Verified: 61 tests

Decide whether an automated review step ACTUALLY RAN, or whether its meter ran out and the absence was read as a pass.

Decide whether an automated review step ACTUALLY RAN, or whether its meter ran out and the absence was read as a pass.

THE SILENT FAILURE, OBSERVED IN A LIVE PUBLIC PULL REQUEST. On github.com/EffortlessMetrics/perl-lsp-swarm/pull/5020, two different vendors' quotas were exhausted on the SAME PR, minutes apart, as ordinary bot comments:

  chatgpt-codex-connector[bot]: "You have reached your Codex usage limits for code reviews. To continue using code reviews, add credits to your account."
  coderabbitai[bot]:            "Review limit reached."

The pull request still merged. CI stayed green. A human scrolling the thread sees bot comments and reasonably concludes review happened. What actually happened is that a review STEP WAS SKIPPED, and the only trace is prose in a comment — no exit code, no failed check, nothing a merge gate reads.

THIS IS NOT A VENDOR HONESTY PROBLEM, and the listing says so plainly. Both vendors disclose exhaustion clearly and in a stable, machine-readable form — CodeRabbit ships an HTML marker comment present in both its old and new wording; Codex's sentence was identical in every occurrence found. This package would not exist without that disclosure. The gap it closes is between "the tool said so in prose" and "the platform's pass/fail field reflects it", which is a merge-gate wiring problem.

WHAT IT DECIDES. Given the facts of a run — which review steps were expected, which produced a real verdict, which produced a quota notice — it distinguishes "reviewed and found nothing" from "never ran". Those two are identical to every check that looks only at exit codes, which is why the failure survives.

IT REFUSES RATHER THAN GUESSING, and refusals carry their numbers.

VERIFIED: 61 tests, measured by running the suite. Vendor signature strings are quoted verbatim from real observed comments with their fetch dates, and the listing records exactly how many corroborating occurrences were found rather than rounding up.

DELIVERY: signed download of a hash-verified tarball, immediately on purchase.

Interface

What you call, and what comes back. Types and signatures only — the implementation ships with the source.

  export function wouldBlockMerge( required: StepObservation["required"], checkRun: StepObservation["checkRun"], ): "yes" | "no" | "undecidable";
  export function matchVendorSignature(commentBody: string): VendorSignature | null;
  export function evaluatePipelineRun(observations: StepObservation[]): StepVerdict[];
  export type StepOutcome = "REVIEWED" | "QUOTA_EXHAUSTED" | "NEVER_RAN" | "UNKNOWN";

01Capabilities

Does

  • + Usage metering
  • + Developer tooling
  • + Automation completion integrity

Doesn’t

  • No exclusions declared

02Requirements & stack

Depends on

No declared dependencies

Credentials needed

None declared

Stack

typescript

03Community

No endorsements yet

No verified confirmations yet — be the first.

Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.

Open an issue

Sign in to confirm — weight comes from verified usage, not vote count.

0 open · 0 answered · 0 fixed · 1 said it worked

04Trust Passport

Full passport →
–/100

0/0 automated components pass. An automated score is never a security guarantee.

✓ Verified · first-partyreviewed Sep 20, 2026 · re-verification due Dec 19, 2026
  • publisher identity Publisher status verified; 1 verification(s) on file
  • malicious pattern scan No known malicious-behavior patterns across 16 source file(s) plus listing text
  • capability contract All 0 observed capability reference(s) match the declared manifest
  • agent safety scan No injection patterns in agent-readable content
  • provenance No release signature or provenance attestation
  • behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.

Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.

VersionChannelReleasedNotes
1.0.0stableAug 7, 2026First public release.