Incidents/Velocity limit
Velocity limit 7 incidents stopped

Velocity limit

Cap the number of transactions per minute/hour, not just dollars.

How to configure it

In sipi.bot: max_per_minute: 20. Once set, every transaction matching the causes below is BLOCKed or FLAGged before any money moves.

Infinite retry loops and credential-abuse bursts before the dollars pile up.

7 incidents this rule would have stopped

IncidentLossCauseYear
Leaked Gemini API key led to a $55,444.78 Google Cloud bill $55,444.78 Leaked credentials 2025
Google Maps API bill hit ~$10,000 in four days ~$10,000 Retry loops 2025
Autonomous agent ran up a $6,531.30 AWS bill in a retry loop $6,531.30 Retry loops 2026
Developer spent $4,000 on AI coding when prod behaved like dev $4,000 Retry loops 2025
No-code agent silently burned $800+ in API calls overnight $800+ Retry loops 2025
Founder spent $638 on Cursor AI coding in six weeks $638 Retry loops 2024
Background orchestration agent stuck in an error-handling loop Cost not disclosed Retry loops 2025

Configure this rule in sipi.bot

The pre-spend firewall evaluates every agent transaction in <5ms. Set this rule once and it runs on every proposed charge, forever.