Rate limiting
Skill kimtth/agent-skill-100-lines-or-less/skills/rate-limiting
🧿 Minimal but effective AI agent skill definitions in 100 lines or less.
npx -y skills add kimtth/agent-skill-100-lines-or-less --skill rate-limitingAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
- 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Use when: protect a service with rate limiting and backpressure without harming legitimate users.
SKILL.md
1.1 KB, as published. Nobody here has run it
Goal: limit abuse and overload while staying fair to real traffic.
Use for:
- protecting APIs and expensive endpoints
- preventing abuse, scraping, and accidental floods
- shaping traffic to downstream capacity
Workflow:
- Pick the dimension: per IP, per user, per API key.
- Choose an algorithm: token bucket, sliding window, or leaky bucket.
- Set limits from real capacity and usage patterns.
- Return 429 with Retry-After and clear limit headers.
- Apply backpressure and timeouts to protect dependencies.
- Monitor rejection rates and adjust thresholds.
Patterns:
- token bucket for bursts with a steady refill
- sliding window for smooth enforcement
- distributed counter (e.g. Redis) for multi-instance limits
- separate limits for anonymous vs. authenticated
Rules:
- always return 429 with Retry-After, not a silent drop
- key limits on a stable identity, not just IP when possible
- fail closed on critical resources, open on best-effort ones
- expose remaining-quota headers so clients can adapt