rate-limit-audit

Installation
SKILL.md

Rate Limit Audit

Overview

A rate limiter that's configured but never tested is a rate limiter that might not actually work — wrong key extraction, wrong window, or a middleware ordering bug can all silently no-op it. This skill's job is proving the limit fires, not just confirming code that looks like a limiter exists. Required pre-launch on any endpoint that calls a paid API (Anthropic/Vercel AI SDK, email, SMS) and on all auth endpoints (login, password reset, OTP, signup) — per the house security rules.

Workflow

  1. Inventory every endpoint in scope — grep the App Router for candidates:
    # Paid-API-calling routes
    grep -rl "anthropic\|generateText\|streamText\|@ai-sdk" app/api
    grep -rl "sendEmail\|resend\|sendgrid\|nodemailer" app/api
    grep -rl "twilio\|sendSms" app/api
    
    # Auth-adjacent routes
    grep -rl "signIn\|signUp\|reset-password\|verify-otp\|magic-link" app/api
    
    Build a table: route path, category (LLM / email / SMS / auth), current limiter (none / found), limiter library used.
Installs
2
First Seen
Aug 7, 2026
rate-limit-audit — stylusnexus/agent-plugins