T09 · Insecure Skill Coding Practices
- Location
trader.py:23- Finding
Declared Trading Risk Controls Are Not Fully Enforced
- Content
View full analysis
= MAX_POSITIONS: break ``` ### Technical Analysis Several configuration values are documented as trading safeguards but are not enforced according to their declared semantics: 1. `MIN_VOLUME` is read from the environment but never checked against a market's volume before an order is submitted. This permits orders in markets below the configured liquidity threshold. 2. `detect_engulfing` assumes that adjacent entries after sorting are consecutive five-minute intervals. It does not verify that the previous interval ends when the current one starts or that the current interval ends when the target interval starts. Missing intervals can therefore create a false engulfing signal. 3. Position size is computed with `max(MIN_TRADE, calculated_size)`. If `MIN_TRADE` is configured above `MA ...[truncated 1930 chars]- Remediation
View remediation
MAX_POSITION: raise ValueError("SIMMER_MIN_TRADE must not exceed SIMMER_MAX_POSITION") ``` 4. Enforce an absolute upper bound when calculating every order: ```python size = min(MAX_POSITION, max(MIN_TRADE, round(conviction * MAX_POSITION, 2))) ``` 5. Query the account's current open positions before placing an order. Calculate remaining capacity using existing positions plus orders placed during the current run. 6. Recheck volume, spread, position count, and market identity immediately before calling `client.trade` to reduce time-of-check/time-of-use inconsistencies. 7. Add tests covering missing intervals, low-volume markets, repeated executions, contradictory tunables, and boundary position sizes. ]]>
