T09 · Insecure Skill Coding Practices
- Location
trader.py:167- Finding
Documented Minimum-Volume Safeguard Is Not Enforced
- Content
View full analysis
= MAX_POSITIONS: break side, size, reasoning = compute_signal(m) if not side: print(f" [skip] {reasoning}") continue ok, why = context_ok(client, m.id) if not ok: print(f" [skip] {why}") continue try: r = client.trade( market_id=m.id, side=side, amount=size, source=TRADE_SOURCE, skill_slug=SKILL_SLUG, reasoning=reasoning, ) tag = "(sim)" if r.simulated else "(live)" status = "OK" if r.success else f"FAIL:{r.error}" print(f" [trade] {side.upper()} ${size} {tag} {status} — {reasoning[:70]}") if r.success: placed += 1 except Exception as e: print(f" [error] {m.id}: {e}") ``` ### Technical Analysis The skill loads `SIMMER_MIN_VOLUME` into `MIN_VOLUME` and describes it as a market-liquidity risk control. However, neither `compute_signal()` nor the trading loop compares a market's volume with this value. The variable is only displayed in status output. Consequently, every discovered market that passes the probability, spread, resolution-date, flip-flop, and slippage checks remains eligible for trading regardless of its actual volume. This is a fail-open implementation of a documented financial safeguard. Low-volume markets may have inadequate order-book depth even if the reported bid-ask spread appears acceptable. The spread check therefore does not replace a volume or liquidity check. ### Attack Path 1. A user provides a live-capable `SIMMER_API_K ...[truncated 1176 chars]- Remediation
View remediation
tuple[bool, str]: try: volume = float(market.volume) except (AttributeError, TypeError, ValueError): return False, "Market volume unavailable or invalid" if volume < MIN_VOLUME: return False, f"Volume ${volume:,.2f} below minimum ${MIN_VOLUME:,.2f}" return True, "ok" ``` Invoke this check before `compute_signal()` and again before a live trade if refreshed market information is available. ]]>
