/ documentation

Limits

File, network, and account limits: GitHub, manifests, the device API, polling, authorization, and backoff.

The limits below are constants in the code, not configurable values. Local and resolution limits end execution with code 1; the device API can also reject requests with its own errors, such as limit or rate-limit errors.

#Complete limits table

Actual CLI, core, and account limits
LimitValueWhere
GitHub HTTP response10 MiB (10485760 bytes)cli/src/runtime.ts
Aggregate size per skill5 MiB (5242880 bytes)cli/src/runtime.ts
Files per skill200cli/src/runtime.ts
Timeout per request10 s (10000 ms)cli/src/runtime.ts
Device API request timeout15 s (15000 ms)cli/src/deviceApi.ts
Minimum interval between polls10 s (10000 ms)cli/src/deviceApi.ts and site/lib/device.ts
Server-provided polling cadence30 s (30000 ms)cli/src/deviceApi.ts and site/lib/device.ts
Device API backoff ceiling5 min (300000 ms)cli/src/deviceApi.ts
Authorization code lifetime10 min (600000 ms)cli/src/deviceApi.ts and site/lib/device.ts
Devices per user20site/lib/device.ts
Cloud Maletas per user3site/lib/cloudMaleta.ts
Locally saved Maletas (browser)50 (aggregate 2 MiB)site/lib/maletaStorage.ts
Cloud Maleta request envelope1049600 bytes (1 MiB + 1024 bytes)site/lib/cloudMaleta.ts
Cloud Maleta client timeout15 s (15000 ms)site/lib/cloudMaletaClient.ts
Authorization requests per IP and window10 in 10 minsite/lib/device.ts
Device API request body8 KiB (8192 UTF-8 bytes)site/lib/device.ts
Binding status detail300 characterssite/lib/device.ts
maleta.json as string input1 MiB (1048576 UTF-8 bytes)packages/core/src/maleta.ts
skills[]500 entriespackages/core/src/maleta.ts
plugins[]200 entriespackages/core/src/maleta.ts
name80 characterspackages/core/src/maleta.ts
slug96 characterspackages/core/src/maleta.ts
description600 characterspackages/core/src/maleta.ts
source.path240 characterspackages/core/src/maleta.ts
source.ref160 characterspackages/core/src/maleta.ts

The HTTP response limit is applied twice: first using content-length, then using the actual size of the body read. Exceeding it results in download exceeded maximum size (10485760 bytes). The aggregate per-skill limit is checked file by file as the tree is traversed and results in skill exceeded maximum size (5242880 bytes).

#How each limit fails

Error message by limit
ConditionMessage
Response body over 10 MiBdownload exceeded maximum size (10485760 bytes)
More than 200 files in the resolved treeskill exceeded maximum file count (200)
Combined file size over 5 MiBskill exceeded maximum size (5242880 bytes)
Individual file larger than the remaining allowanceskill file exceeded maximum size (<restante> bytes)
Request stopped by the 10 s timeoutnetwork timeout
maleta.json over 1 MiBArquivo de Maleta muito grande
skills[] over 500 entriesLista de skills inválida
plugins[] over 200 entriesLista de plugins inválida
More than 3 Cloud Maletas on accountYou reached the limit of 3 Maletas on the account
Cloud Maleta document over 1 MiBMaleta too large. The limit is 1 MB

#GitHub resolution: no retries, backoff, or rate-limit handling

GitHub skill resolution has no retries, backoff, or rate-limit handling beyond a single message. No request is repeated: each has a 10-second timeout and, if it fails, the error propagates immediately. For a 404, the CLI makes separate diagnostic requests — described below — and never retries the same request. The device flow is different: it honors the server cadence and caps backoff at 5 minutes.

  • HTTP 401 and 403 produce exactly GitHub access denied or rate limited — the same string for both, without distinguishing an invalid token from an exceeded limit.
  • The CLI does not inspect rate-limit headers such as Retry-After, and does not wait before another attempt.
  • A 404 is not retried: the CLI makes diagnostic requests to distinguish a missing repository, ref, or skill path, and reports the most specific one.
  • Other statuses outside 2xx become GitHub request failed (HTTP <status>).
  • The only way to work around a rate limit is to set GITHUB_TOKEN and run the command again manually.