T09 · Insecure Skill Coding Practices
- Location
trader.py:232- Finding
Market safety checks fail open when context retrieval or validation raises an exception
- Content
View full analysis
tuple[bool, str]: """Check flip-flop and slippage safeguards.""" try: ctx = client.get_market_context(market_id) if not ctx: return True, "no context" if ctx.get("discipline", {}).get("is_flip_flop"): reason = ctx["discipline"].get("flip_flop_reason", "recent reversal") return False, f"Flip-flop: {reason}" slip = ctx.get("slippage", {}) if isinstance(slip, dict) and slip.get("slippage_pct", 0) > 0.15: return False, f"Slippage {slip['slippage_pct']:.1%}" for w in ctx.get("warnings", []): safe_print(f" [warn] {w}") except Exception as e: safe_print(f" [ctx] {market_id}: {e}") return True, "ok" ``` The result is then used to authorize the trade: ```python ok, why = context_ok(client, bo3_market.id) if not ok: safe_print(f" [skip] {why}") continue try: r = client.trade( market_id=bo3_market.id, side=side, amount=size, source=TRADE_SOURCE, skill_slug=SKILL_SLUG, reasoning=reasoning, ) ``` ### Technical Analysis `context_ok()` is intended to prevent trades when the SDK reports flip-flop behavior or excessive slippage. However, it returns approval in both of these unsafe states: 1. `get_market_context()` returns no context. 2. Context retrieval or parsing raises any exception. The broad `except Exception` handler records the error but then falls through to `return True, "ok"`. This is a fail-open authorization design. Network errors, authentication failures, SDK response changes, malformed context objects, or unexpected field types therefore disable the safeguards instead of stopping the ...[truncated 1295 chars]- Remediation
View remediation
