Agent skill

Rate Limiting

by dev-toolings in dev-toolings/superpowers-symfony

Implement rate limiting with the Symfony RateLimiter (sliding window, token bucket, fixed window) and the [RateLimit] controller attribute

MITAuto-check: notesBackend & APIs

Install Rate Limiting

skills CLI
$ npx skills add dev-toolings/superpowers-symfony --skill rate-limiting -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dev-toolings/superpowers-symfony rate-limiting --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dev-toolings/superpowers-symfony.git skills-src && mkdir -p .claude/skills && cp -r skills-src/content/skills/rate-limiting .claude/skills/rate-limiting && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rate-limiting
GitHub stars
222
Token cost
~518 tokens
SKILL.md length
261 words
Files
2
Skills in repo
44
Repo updated
First seen
Licence
MIT

At a glance

Implement rate limiting with the Symfony RateLimiter (sliding window, token bucket, fixed window) and the [RateLimit] controller attribute

  • Works in 5 steps: Name what is limited and what identifies… → Pick the algorithm the traffic shape… → Declare the policy under… → …
  • Tasks that involve Rate limiting
  • SKILL.md covers Use when, Default workflow, Guardrails and Progressive disclosure, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Rate Limiting is an agent skill from dev-toolings/superpowers-symfony. Implement rate limiting with the Symfony RateLimiter (sliding window, token bucket, fixed window) and the [RateLimit] controller attribute

Its SKILL.md is about 520 tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `reference.md`).

It sits in Backend & APIs, covering Rate limiting. It works with Symfony. The repository describes itself as: Claude Code plugin for Symfony 7.4 LTS & 8.x — 44 skills, 7 AI subagents & 13 commands for API Platform v4, Doctrine ORM 3, TDD (Pest/PHPUnit), Messenger, security & DDD. The licence is MIT.

When your agent uses it

  • Tasks that involve Rate limiting

Example prompts

  • “/rate-limiting”

Requirements

  • Pre-approved tools (allowed-tools): Read, Glob, Grep, Write, Edit, Bash

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Name what is limited and what identifies the caller.
  2. Pick the algorithm the traffic shape calls for, and state the rate and the burst.
  3. Declare the policy under framework.rate_limiter, one entry per limiter.
  4. Apply it where the request is refused, and answer 429 with Retry-After.
  5. Prove the limit under test: the call that passes, the one refused, the reset.

What it can do on your machine

Read from SKILL.md and the folder at commit 459bcd0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Glob
    • Grep
    • Write
    • Edit
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Rate Limiting loads about 518 tokens when it runs. Until then it costs about 38 tokens; SKILL.md has 261 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~38
When it runs · the whole SKILL.md, loaded when a task matches
~518

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Glob, Grep, Write, Edit, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dev-toolings/superpowers-symfony at commit 459bcd0, republished under its MIT licence (© dev-toolings). 261 words, ~518 tokens.

Download SKILL.mdSave it as .claude/skills/rate-limiting/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
rate-limiting
description
Implement rate limiting with the Symfony RateLimiter (sliding window, token bucket, fixed window) and the #[RateLimit] controller attribute
allowed-tools
Read, Glob, Grep, Write, Edit, Bash
capabilities
read, search, edit, shell
tags
security

Rate Limiting (Symfony)

Use when

  • Capping how often a caller may reach an endpoint: login, password reset, public API, any public write.
  • Choosing between sliding window, token bucket and fixed window.
  • Applying a limiter by controller attribute, in a service, or globally through an event subscriber.
  • Returning a correct 429 with Retry-After.
  • Blocking until a token frees up, rather than refusing outright.

Default workflow

  1. Name what is limited and what identifies the caller.
  2. Pick the algorithm the traffic shape calls for, and state the rate and the burst.
  3. Declare the policy under framework.rate_limiter, one entry per limiter.
  4. Apply it where the request is refused, and answer 429 with Retry-After.
  5. Prove the limit under test: the call that passes, the one refused, the reset.

Guardrails

  • The caller identity decides who is counted. Behind a proxy, an untrusted client address counts everyone as one.
  • A limiter is not authorization. It caps a rate; it never decides a right.
  • Refuse with 429 and Retry-After, never with a silent drop or a 500.
  • A limiter whose storage is per process does not limit anything across several workers.
  • Reserving tokens blocks the calling process: never on a web request.

Progressive disclosure

  • Use this file for execution posture and risk controls.
  • Open references when deep implementation details are needed.

Output contract

  • Limiter policies, with the algorithm, the rate and the burst for each.
  • Where each limiter is applied, and on what caller identity.
  • The 429 response shape, headers included.
  • Tests covering the accepted call, the refused one, and the reset.

References

  • reference.md

© dev-toolings, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in content/skills/rate-limiting of dev-toolings/superpowers-symfony.

  • SKILL.md
  • reference.md

Open the folder on GitHubat commit 459bcd0

Compare with similar skills

Rate Limiting next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Rate Limiting compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Rate Limiting this skilldev-toolings/superpowers-symfony222—~518Automated safety check: NotesMIT
Upstash Ratelimit TSupstash/ratelimit-js2.1k1 repos~313Automated safety check: PassMIT
API Gatewayitsmostafa/aws-agent-skills1.2k1 repos~2.2kAutomated safety check: PassMIT
Add Hosted Keysimstudioai/sim30k—~3.4kAutomated safety check: PassApache-2.0
Repo2skillzhangyanxs/repo2skill246—~3.6kAutomated safety check: PassNone
Better Auth Security Best PracticesEpicenterHQ/epicenter4.8k—~896Automated safety check: PassCustom licence

Similar skills

  • Upstash Ratelimit TS

    upstash/ratelimit-js

    Official

    Lightweight guidance for using the Redis Rate Limit TypeScript SDK, including setup steps, basic usage, and pointers to advanced algorithm, features, pricing, and traffic‑protection docs.

    2.1k GitHub starsUsed in 1 repo~313 tokens
    Backend & APIsAuto-check passed
  • API Gateway

    itsmostafa/aws-agent-skills

    AWS API Gateway for REST and HTTP API management. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.2k tokens
    Backend & APIsAuto-check passed
  • Add Hosted Key

    simstudioai/sim

    Add hosted API key support to a tool so Sim provides the key (metered and billed to the workspace) when a user has not brought their own.

    30k GitHub stars~3.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Repo2skill

    zhangyanxs/repo2skill

    Convert GitHub/GitLab/Gitee repositories into comprehensive OpenCode Skills using embedded LLM calls with multiple mirrors and rate limit handling

    246 GitHub stars~3.6k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

    4.8k GitHub stars~896 tokensUpdated today
    Backend & APIsAuto-check passed
  • Dload Fetch Tool

    php-internal/dload

    Get a CLI tool — native binary or PHAR — from a GitHub release into a project folder with dload (vendor/bin/dload).

    105 GitHub stars~1.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from dev-toolings/superpowers-symfony

All 44 skills in this repo
  • Symfony Scheduler

    dev-toolings/superpowers-symfony

    Schedule recurring tasks with the Symfony Scheduler component (native since 7.x); define schedules, triggers, and integrate with Messenger

    222 GitHub stars~526 tokensUpdated 2 days ago
    Auto-check: notes
  • API Platform Dto Resources

    dev-toolings/superpowers-symfony

    Map entities to API DTOs in API Platform (v5, 4.4, 4.3) with the Symfony Object Mapper ([Map], stateOptions) for decoupled input/output contracts

    222 GitHub stars~593 tokensUpdated 2 days ago
    Auto-check: notes
  • API Platform Filters

    dev-toolings/superpowers-symfony

    Implement API Platform filters - Parameters API (QueryParameter, v5/4.4/4.3) and the [ApiFilter] attribute deprecated since 4.4 - for search, date, range, boolean, and custom filtering

    222 GitHub stars~610 tokensUpdated 2 days ago
    Auto-check: notes
  • API Platform Resources

    dev-toolings/superpowers-symfony

    Configure API Platform resources (v5, 4.4, 4.3) with explicit operations, pagination, and typed OpenAPI for clean, versioned REST/GraphQL APIs

    222 GitHub stars~560 tokensUpdated 2 days ago
    Auto-check: notes
  • API Platform Security

    dev-toolings/superpowers-symfony

    Secure API Platform resources with security expressions, voters, securityPostValidation, and operation-level access control

    222 GitHub stars~551 tokensUpdated 2 days ago
    Auto-check: notes
  • API Platform Serialization

    dev-toolings/superpowers-symfony

    Control API Platform serialization with groups, [Context], IRI links (readableLink/writableLink), and custom context builders

    222 GitHub stars~519 tokensUpdated 2 days ago
    Auto-check: notes

Works with

Categories

Questions about Rate Limiting

What does Rate Limiting do?

Implement rate limiting with the Symfony RateLimiter (sliding window, token bucket, fixed window) and the [RateLimit] controller attribute. Rate Limiting is an agent skill from dev-toolings/superpowers-symfony.

When should I use Rate Limiting?

Rate Limiting fits situations like: tasks that involve Rate limiting.

How do I install Rate Limiting in Claude Code?

Run `npx skills add dev-toolings/superpowers-symfony --skill rate-limiting -a claude-code`. Or copy the skill folder (content/skills/rate-limiting in dev-toolings/superpowers-symfony) into .claude/skills/rate-limiting in your project. Claude Code loads it when a task matches its description.

How do I install Rate Limiting in Codex?

Run `npx skills add dev-toolings/superpowers-symfony --skill rate-limiting -a codex`. Or copy the skill folder (content/skills/rate-limiting in dev-toolings/superpowers-symfony) into .agents/skills/rate-limiting in your project. Codex loads it when a task matches its description.

Can I use Rate Limiting in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dev-toolings/superpowers-symfony --skill rate-limiting -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rate-limiting, .gemini/skills/rate-limiting, .github/skills/rate-limiting and .opencode/skills/rate-limiting in your project.

What does Rate Limiting need to run?

SKILL.md names no scripts, command-line tools or credentials: Rate Limiting is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Glob, Grep, Write, Edit, Bash.

Does Rate Limiting access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Rate Limiting safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Rate Limiting use?

Rate Limiting is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Rate Limiting use?

About 518 tokens (SKILL.md is roughly 2.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Rate Limiting?

Skills that share tags, products or a category with Rate Limiting: Upstash Ratelimit TS (upstash/ratelimit-js, 2.1k stars), API Gateway (itsmostafa/aws-agent-skills, 1.2k stars), Add Hosted Key (simstudioai/sim, 30k stars) and Repo2skill (zhangyanxs/repo2skill, 246 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Rate Limiting?

dev-toolings (a GitHub organization) maintains it in dev-toolings/superpowers-symfony, which has 222 GitHub stars. The repository holds 44 skills in this directory. The repository was last updated on October 5, 2026.

Source: dev-toolings/superpowers-symfony on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.