Per-transaction cap
Reject any single proposed charge above a dollar amount.
How to configure it
In sipi.bot: max_amount_usd: 500. Once set, every transaction matching the
causes below is BLOCKed or FLAGged
before any money moves.
A single runaway purchase, a fat-finger API call, or an attacker testing how much they can move at once.
7 incidents this rule would have stopped
| Incident | Loss | Cause | Year |
|---|---|---|---|
| OpenAI agents burned $72,000 in a single night | $72,000 | Unattended sessions | 2025 |
| Leaked Gemini API key led to a $55,444.78 Google Cloud bill | $55,444.78 | Leaked credentials | 2025 |
| AI coding agent bills hit $2,000–$20,000 per developer per month | $2,000–$20,000/mo | Unattended sessions | 2026 |
| Developer spent $11,922 on Cursor in under four weeks | $11,922 | Unattended sessions | 2026 |
| OpenAI charged $1,200 past a configured $50 hard limit | $1,200 | Caps that didn't enforce | 2025 |
| Account billed $1,100 after hard monthly cap was removed | $1,100 | Caps that didn't enforce | 2025 |
| Opaque per-token pricing triggered billing shock | Cost not disclosed | Unattended sessions | 2025 |
Configure this rule in sipi.bot
The pre-spend firewall evaluates every agent transaction in <5ms. Set this rule once and it runs on every proposed charge, forever.