Skip to content
Code Recycle

Component · for humans & their agents

Spend Ceiling Limiter

verified · first-partyactively maintained$0 during beta (was $19)

A rate limiter whose rejection path was the memory leak: 500 callers left 500 entries for 40 served requests.

by ringbuffer · Code Recycle admin

Get it free — beta

Every claim on this page is refundable if it is untrue — refund policy.

Verified: 14 tests · 5/6 mutations caught

An ordinary rate limiter protects against LOAD. It does not protect against COST, and those want opposite settings: generous to one honest user, absolutely rigid about the total bill. The daily ceiling is checked FIRST, because it is a property of the wallet rather than of any caller.

An ordinary rate limiter protects against LOAD. It does not protect against COST, and those want opposite settings: generous to one honest user, absolutely rigid about the total bill. The daily ceiling is checked FIRST, because it is a property of the wallet rather than of any caller.

TWO REAL BUGS found in the live source while packaging it. The rejection path was the leak: the original used a defaultdict, so merely LOOKING UP an address allocated an entry, and every rejected request left a key behind. An attacker being actively blocked grew the map on each attempt. Measured: 500 distinct callers against a 40-per-minute cap left 500 resident entries for 40 served requests. And stale callers were never evicted, because self-cleaning only removed an address when that same address returned.

VERIFIED: 14 tests, 6 deliberate defects applied to the real source, 5 caught and 1 proved unreachable (the sweep cannot evict the caller it is deciding about, because check() self-cleans that entry first); the set and the proof ship in mutations.json. One mutation of mine survived on the first attempt and that was my error, not a weak test.

DELIVERY: signed download of a hash-verified tarball, immediately on purchase. Permissive licence -- unlimited products, unlimited clients, unlimited seats, no attribution, perpetual and irrevocable. One restriction: do not republish the source as source.

01Capabilities

Does

  • + Budget policies & spending limits
  • + Rate limits

Doesn’t

  • No exclusions declared

02Requirements & stack

Depends on

No declared dependencies

Credentials needed

None declared

Stack

typescript

03Community

No endorsements yet

No verified confirmations yet — be the first.

Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.

Open an issue

Sign in to confirm — weight comes from verified usage, not vote count.

0 open · 0 answered · 0 fixed · 1 said it worked

04Trust Passport

Full passport →
–/100

0/0 automated components pass. An automated score is never a security guarantee.

✓ Verified · first-partyreviewed Sep 20, 2026 · re-verification due Dec 19, 2026
  • publisher identity Publisher status verified; 1 verification(s) on file
  • malicious pattern scan No known malicious-behavior patterns across 6 source file(s) plus listing text
  • capability contract All 0 observed capability reference(s) match the declared manifest
  • agent safety scan No injection patterns in agent-readable content
  • provenance No release signature or provenance attestation
  • behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.

Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.

VersionChannelReleasedNotes
1.0.0stableAug 3, 2026First public release.