Lesson 20 / 25

Budgets and Rate Limits

Cap steps, time, tokens and risky actions per session.

Limit how much damage one session can do

Add limits that apply to the whole session: maximum steps, wall-clock time, tokens or spend, and a cap on risky actions (for example no more than 5 file deletions or 3 package installs). Hitting a limit should stop the agent and ask a human to continue. This catches loops and runaway behaviour that no single action check would notice.

A simple action limiter, run

I ran this. With a limit of 3, the first three risky actions pass and the next two are refused.

class Limiter:
    def __init__(self, n): self.n, self.used = n, 0
    def hit(self):
        self.used += 1
        return self.used <= self.n

l = Limiter(3)
print([l.hit() for _ in range(5)])

Output:

[True, True, True, False, False]

Ask a human at the limit

When a budget is hit, show what the agent did and what it wanted to do next. A person can then extend the limit knowingly, instead of the agent silently carrying on.

Quick check: What does a session-wide budget catch that per-action checks miss?

  • Spelling mistakes
  • Loops and runaway behaviour across many individually fine actions
  • Slow keyboards
  • Missing semicolons
Answer

Loops and runaway behaviour across many individually fine actions — Each action may look fine alone while the total is clearly excessive.