T09 · Insecure Skill Coding Practices
- Location
src/telegram_bot.py:151- Finding
Live Futures Trading Bypasses Configured Safety Controls
- Content
View full analysis
= AUTO_TRADE_MIN_CONFIDENCE: self._execute_auto_trade(chat_id, symbol, analysis) def _execute_auto_trade(self, chat_id: int, symbol: str, analysis): """자동매매 실행 (V5.2.2)""" signal = analysis.signal with self.trade_lock: try: live_positions = self.fetcher.get_all_positions() if any(p['symbol'] == symbol for p in live_positions): return if len(live_positions) >= MAX_OPEN_POSITIONS: return self.fetcher.set_leverage(symbol, signal.leverage) self.fetcher.set_margin_type(symbol, 'ISOLATED') current_price = self.fetcher.get_price(symbol) quantity = self.fetcher.calculate_position_size( symbol, current_price, signal.stop_loss, signal.leverage ) quantity = self.fetcher._round_quantity(symbol, quantity) if quantity <= 0: return side = 'BUY' if signal.direction == 'LONG' else 'SELL' order = self.fetcher.place_limit_order_with_fallback( symbol, side, quantity, current_price ) ``` The corresponding configuration advertises safe defaults: ```python # config/config.py:56-58 AUTO_TRADE_ENABLED = os.getenv("AUTO_TRADE_ENABLED", "false").lower() == "true" DRY_RUN = os.getenv("DRY_RUN", "true").lower() == "true" ``` ### Technical Analysis The Telegram bot initializes its persistent state with automatic trading enabled. Its order-exe ...[truncated 2034 chars]- Remediation
View remediation
bool: return ( AUTO_TRADE_ENABLED and not DRY_RUN and self.state.auto_trade and USE_TESTNET is False ) ``` 3. Call the centralized guard immediately before every order, leverage change, cancellation, or position modification. 4. Refuse to start production trading unless the operator explicitly acknowledges live mode. 5. Require a separate confirmation step before the first live trade in each process lifetime. 6. Keep dry-run and live exchange clients separate so dry-run code cannot invoke authenticated order endpoints. 7. Add automated tests proving that no order method is called when either `AUTO_TRADE_ENABLED` is false or `DRY_RUN` is true. 8. Default to Binance testnet and require an explicit production-mode setting. ]]>
