rate-limit-audit
Installation
SKILL.md
Rate Limit Audit
Overview
A rate limiter that's configured but never tested is a rate limiter that might not actually work — wrong key extraction, wrong window, or a middleware ordering bug can all silently no-op it. This skill's job is proving the limit fires, not just confirming code that looks like a limiter exists. Required pre-launch on any endpoint that calls a paid API (Anthropic/Vercel AI SDK, email, SMS) and on all auth endpoints (login, password reset, OTP, signup) — per the house security rules.
Workflow
- Inventory every endpoint in scope — grep the App Router for candidates:
Build a table: route path, category (LLM / email / SMS / auth), current limiter (none / found), limiter library used.# Paid-API-calling routes grep -rl "anthropic\|generateText\|streamText\|@ai-sdk" app/api grep -rl "sendEmail\|resend\|sendgrid\|nodemailer" app/api grep -rl "twilio\|sendSms" app/api # Auth-adjacent routes grep -rl "signIn\|signUp\|reset-password\|verify-otp\|magic-link" app/api