tenacity retry storm auditor

    1

    Detects and fixes nested retry loops and request amplification in Python call chains.

    $10

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    tenacity retry storm auditor

    Example session with this skill installed

    Audit the ./services/payment-processor directory for nested retries and compute the worst-case request multiplier. We are seeing high 429 rates on our upstream gateway.

    • Read your context and instructions
    • Compiled the tenacity retry storm
    • Generated the document

    I have audited the ./services/payment-processor directory. I identified 3 instances of retry amplification where nested decorators and library defaults were creating up to 27x request spikes per user action.

    Tenacity Retry Storm Audit

    IDSeverityLocationIssue
    STM-1-ACriticalclients/gateway.py:4227x Amplification: Handler(3) -> Service(3) -> SDK(3)
    STM-3-BHighadapters/stripe.py:112Ignores Retry-After on 429 responses
    STM-2-CMediumtasks/reconcile.py:15No stop_after_delay bound on background task

    Amplification Analysis: Payment Flow

    • Layer 1: @task(bind=True, max_retries=3) in tasks/process.py
    • Layer 2: @retry(stop=stop_after_attempt(3)) in logic/billing.py
    • Layer 3: urllib3.Retry(total=3) in clients/http.py
    • Worst-case Multiplier: 27x attempts
    • Result: One failure triggers 27 calls, likely causing the 429s you are seeing.

    Recommended Fix (Patched in ./output/patches/STM-1-A.py)

    from tenacity import retry, stop_after_attempt, stop_after_delay, wait_exponential_jitter
    
    def wait_retry_after(fallback, cap: float = 60.0):
        def _wait(retry_state):
            exc = retry_state.outcome.exception() if retry_state.outcome else None
            resp = getattr(exc, "response", None)
            header = resp.headers.get("Retry-After") if resp is not None else None
            if header and header.strip().isdigit():
                return min(float(header), cap)
            return fallback(retry_state)
        return _wait
    
    # Flattened: Single retry at the idempotent boundary
    @retry(
        stop=stop_after_attempt(4) | stop_after_delay(30),
        wait=wait_retry_after(wait_exponential_jitter(initial=1, max=10)),
        reraise=True,
    )
    def unified_payment_call():
        # Inner layers now set to 0 retries / 1 attempt
        return stripe_client.execute(retries=0)
    

    Next steps

    1. Review the detailed amplification table in ./output/tenacity-retry-storm-auditor-report.md.
    2. Apply the flattened retry patch to clients/gateway.py to reduce gateway load.
    3. Update environment variables to set the new 30s global deadline.

    tenacity-retry-storm-auditor.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Prevent self-inflicted DoS by flattening nested retry decorators.Calculate worst-case request multipliers across complex Python call chains.Add Retry-After header awareness to existing Tenacity implementations.Enforce global execution deadlines to prevent unbounded retry loops.

    About this skill

    The problem

    Nested retry logic in microservices and distributed tasks often creates exponential request amplification. Without coordination, a minor downstream delay can trigger a retry storm that self-inflicts a denial-of-service attack on your own infrastructure.

    What it does

    • Identifies recursive and stacked retries across call chains, including library-level retries like Boto3 and urllib3.
    • Calculates the worst-case attempt multiplier and total duration for complex execution paths.
    • Detects missing Retry-After header handling and lack of stop_after_delay bounds.
    • Generates flattened retry designs that move persistence to the outermost idempotent boundary.
    • Drafts dependency-free circuit breaker implementations for identified high-risk dependencies.

    Frameworks & tools

    Python, Tenacity, Celery, RQ, Boto3, and standard HTTP client libraries.

    Why this beats prompting it yourself

    Manual audits often miss implicit retries inside SDKs or cross-file imports. This skill systematically builds the call graph to multiply attempt counts across layers, catching amplification risks that look safe in isolation but fail at scale.

    Use cases

    • Auditing a service before a high-traffic launch to prevent cascading failures.
    • Refactoring legacy Celery tasks where retries are defined in both the task and the internal logic.
    • Hardening API clients to respect rate limits and downstream 429/503 responses.
    • Analyzing infrastructure costs driven by excessive, unsuccessful request attempts.

    Known limitations

    Only analyzes Python source code. Cross-service amplification is estimated based on visible repository code and assumed 1x hops for external calls.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 14 days ago

    • Passed all security checks, Safe to install

    Listed14 days ago

    What's inside

    Frequently Asked Questions