T09 · Insecure Skill Coding Practices
- Location
trader.py:113- Finding
Markets from different years are merged into the same trading distribution
- Content
View full analysis
str | None: m = _PERIOD_PATTERN.search(question) if m: return m.group(1).strip().lower() return None ``` The resulting period is subsequently used in the distribution key: ```python key = f"{city}|{period}" pb = PrecipBin(m, city, period, bin_info, float(p)) distributions.setdefault(key, []).append(pb) ``` ### Technical Analysis The regular expression accepts an optional four-digit year but does not capture it. `parse_period()` consequently returns only the month name. For example, both `April 2026` and `April 2027` become `april`. `build_distributions()` groups markets solely by normalized city and this month-only period. Contracts concerning different years can therefore be analyzed as if they were mutually exclusive bins in one probability distribution. Their probabilities may then produce an artificial sum deviation or monotonicity violation. Because the resulting opportunity can be passed directly to `client.trade()`, this is financially unsafe when the process is launched with `--live`. ### Attack Path 1. Multiple searchable precipitation contracts exist for the same city and month but different years. 2. `find_markets()` discovers those contracts. 3. `parse_period()` discards each contract's year. 4. `build_distributions()` places the unrelated contracts under the same `city|month` key. 5. `find_violations()` interprets their prices as parts of one distribution. 6. A false violation passes the probability and execution gates. 7. With `--live`, the client submits a real Polymarket order using the configured trading authority. ### Impact Assessme ...[truncated 383 chars]- Remediation
View remediation
str | None: match = _PERIOD_PATTERN.search(question) if not match: return None return f"{match.group(1).lower()}-{match.group(2)}" ``` Include the complete resolution period in the distribution key. Reject contracts without an unambiguous year unless authoritative market metadata supplies an equivalent date. Where available, group by event or series identifier rather than relying only on question text. Add tests confirming that different years, time zones, units, and resolution periods cannot be merged. ]]>
