developer-quota-credit-abuse-reviewlisted
Install: claude install-skill SylphxAI/skills
# Developer Quota Credit Abuse Review
Protect finite platform resources without making successful legitimate developers
look indistinguishable from abuse.
## Workflow
1. Define the developer journey, account/org/app units, quota and credit types,
costly operations, resource cost model, public promise, production criticality,
trust states, and decisions the system may take.
2. Read `references/developer-quota-credit-abuse-patterns.md`.
3. Verify current authority at use: entitlement and pricing contract, public
quota docs, credit terms, cost model, risk-policy version, typed threshold
configuration, privacy/identity rules, support/appeal policy, and incident state.
4. Separate entitlement, prepaid/purchased value, promotional grants, rate,
concurrency, capacity protection, and abuse-risk controls. Give each its own
ledger or policy authority instead of one ambiguous "quota".
5. Model the credit ledger from grant lot through reserve, consume, settle,
expire, refund/reverse, and adjustment. Preserve idempotency, attribution,
restrictions, and immutable audit history.
6. Build a signal registry and trust ladder. Use the least intrusive action that
contains expected harm: guidance -> warning -> soft limit -> verification ->
cooldown/queue -> scoped endpoint restriction -> review -> suspension.
7. Define a fast legitimate scale-up path with forecast, verification,
temporary increase, production-safe notice, expiry, upgrade/contract route,
and