T09 · Insecure Skill Coding Practices
- Location
trader.py:300- Finding
Declared Minimum-Volume Safeguard Is Not Enforced
- Content
View full analysis
tuple[bool, str]: p = getattr(market, "current_probability", None) if not isinstance(p, (int, float)): return False, "missing probability" spread_cents = getattr(market, "spread_cents", None) if isinstance(spread_cents, (int, float)) and spread_cents / 100 > MAX_SPREAD: return False, f"Spread {spread_cents/100:.1%} > {MAX_SPREAD:.1%}" resolves_at = getattr(market, "resolves_at", None) if resolves_at: try: resolves = datetime.fromisoformat(resolves_at.replace("Z", "+00:00")) days = (resolves - datetime.now(timezone.utc)).days if days < MIN_DAYS: return False, f"Only {days} days to resolve" except Exception: pass return True, "ok" ``` ### Technical Analysis The `SIMMER_MIN_VOLUME` setting is loaded into `MIN_VOLUME` and documented as a minimum market-volume filter, but `valid_market()` never reads or validates a market's volume. Consequently, the configured threshold has no effect. This is a missing security and financial-risk control rather than a direct code-execution vulnerability. A low-liquidity market can pass validation as long as its probability, spread, and resolution-time checks pass. Low-volume markets are generally easier to manipulate and may have inadequate executable liquidity even where a displayed spread appears acceptable. ### Attack Path 1. An attacker identifies or creates activity in a low-volume over/under market. 2. The attacker moves its quoted probability enough to produce an apparent curve violation. 3. The skill discovers the market and constructs a trading opportunity. 4. `valid ...[truncated 709 chars]- Remediation
View remediation
