{
  "kind": "rate_limited",
  "product_version": "0.12.897",
  "wheel_sha256": "a9c3bf17b036c5f661df05ba4a02cf3afa834b44c2492f3e60fb3b66061a0a24",
  "method": "Published detector functions evaluated on authored inert events or disposable configuration files.",
  "scope": "No live agent, runtime adapter, daemon ingestion, product UI, external command or network action was exercised.",
  "cases": [
    {
      "case": "two-provider-refusals",
      "inputs": {
        "events_newest_first": [
          {
            "event_type": "api_error",
            "ts": "2026-09-27T12:00:01Z",
            "data": {
              "status_code": 429,
              "message": "Too many requests"
            }
          },
          {
            "event_type": "api_error",
            "ts": "2026-09-27T12:00:00Z",
            "data": {
              "status_code": 429,
              "message": "Too many requests"
            }
          }
        ]
      },
      "expected_severity": "warning",
      "actual_severity": "warning",
      "findings": [
        {
          "kind": "rate_limited",
          "session_id": "claude_code:example",
          "runtime": "claude_code",
          "severity": "warning",
          "title": "claude_code is being rate limited (2 refusals)",
          "detail": "The model provider or a tool refused 2 requests for capacity reasons (429, overloaded, quota). The agent may be retrying quietly or has stopped making progress. Check the provider's status page and your plan limits. You can Stop or Pause this agent from the ClawMetry dashboard or device.",
          "evidence": {
            "refusals": 2,
            "threshold": 2,
            "threshold_source": "static",
            "observed": "HTTP 429/529 status or rate-limit text on tool results and API error events",
            "sample": ""
          },
          "first_bad_step": 0,
          "spend_at_risk_usd": 0.0,
          "spend_basis": "unknown",
          "burn_rate_usd_per_min": 0.0,
          "session_cost_usd": 0.0,
          "frameworks": {
            "mapping_version": "2026-09-27.1",
            "owasp_llm": [],
            "owasp_asi": [],
            "atlas": [],
            "mapped": false,
            "mode": "detect",
            "pre_action_control": false
          }
        }
      ]
    },
    {
      "case": "one-provider-refusal",
      "inputs": {
        "events_newest_first": [
          {
            "event_type": "api_error",
            "ts": "2026-09-27T12:00:00Z",
            "data": {
              "status_code": 429,
              "message": "Too many requests"
            }
          }
        ]
      },
      "expected_severity": null,
      "actual_severity": null,
      "findings": []
    }
  ]
}
