Not sure what you mean by that, you would not be locked out, you would only be locked out if you don’t have an alternative scenario to decrypt the drive. The way Purism’s script sets it up with the Librem Key is that you still have a passphrase (hopefully a good one) to fall back onto.
Rate limiting is fine I guess, but I don’t understand why I would not want to only have 3 tries for the PIN and then the card for the user PIN is locked.
Librem Key users OpenPGP v3.3, the YubiKey I have v2.1. They are set up the same way with respect to LUKS decryption: Set it up with the Librem Key and above mentioned script and simply added the GPG key to the Yubikey as well so I have a backup. So I’m not asking about the yubikey-luks specific decryption method, in fact, I don’t know a lot about this.
I’m not fully sure I follow here, could you elaborate?