Incidents/Per-transaction cap
Per-transaction cap 7 incidents stopped

Per-transaction cap

Reject any single proposed charge above a dollar amount.

How to configure it

In sipi.bot: max_amount_usd: 500. Once set, every transaction matching the causes below is BLOCKed or FLAGged before any money moves.

A single runaway purchase, a fat-finger API call, or an attacker testing how much they can move at once.

7 incidents this rule would have stopped

IncidentLossCauseYear
OpenAI agents burned $72,000 in a single night $72,000 Unattended sessions 2025
Leaked Gemini API key led to a $55,444.78 Google Cloud bill $55,444.78 Leaked credentials 2025
AI coding agent bills hit $2,000–$20,000 per developer per month $2,000–$20,000/mo Unattended sessions 2026
Developer spent $11,922 on Cursor in under four weeks $11,922 Unattended sessions 2026
OpenAI charged $1,200 past a configured $50 hard limit $1,200 Caps that didn't enforce 2025
Account billed $1,100 after hard monthly cap was removed $1,100 Caps that didn't enforce 2025
Opaque per-token pricing triggered billing shock Cost not disclosed Unattended sessions 2025

Configure this rule in sipi.bot

The pre-spend firewall evaluates every agent transaction in <5ms. Set this rule once and it runs on every proposed charge, forever.