# Limits, dependencies and logs ## Limits (LLM06) - Find the loop that runs the agent. Is there a maximum number of model calls and tool calls per request, and what happens when it is reached? A loop that runs until the model stops asking for tools is a finding. - `max_tokens`, or its equivalent, on every model call. - Truncation of inputs, thread history and tool results before they enter the context. - Rate limits per user or tenant on every endpoint or event that triggers a model call, including retries. - Write actions that could repeat within one request: are they idempotent or limited? - Budgets and cost alerts: if they are configured outside the repository, list them as something you couldn't verify. ## Dependencies (LLM04) - Model identifiers: a pinned version or an alias that points to the latest one? An alias lets the model's behaviour change without a code change. - MCP servers: how they are started (`npx`, `uvx`, `docker`, a remote URL), whether the version is pinned, who publishes or operates them, and which credentials and environment variables they receive. - Agent frameworks and SDKs: pinned in a lock file? - Anything that downloads or runs plugins or tools at runtime. ## Misinformation (LLM07) - Do tool results and retrieved documents carry source identifiers, and does the output include them so a person can check a fact before acting on it? - Are actions shown to approvers built from the stored parameters, not from the model's summary? - Do outputs that state facts (summaries, descriptions) give a person a way to check them before they are acted on or published? ## Logs - Is every tool call logged with the invoker, the session or channel, the tool, its arguments, its result, the approver for write actions, and the time? - Are the model ID and token usage logged for every call? - If full prompts and outputs are logged, where do they go and who can read them? They can copy personal data or restricted content into a system that more people can access (LLM02). Report it as a trade-off for the owner to decide, not automatically as a finding. - Are secrets kept out of the logs, including tokens that appear in tool arguments or headers?