T09 · Insecure Skill Coding Practices
- Location
trader.py:339- Finding
Configured Minimum-Volume Safeguard Is Not Enforced
- Content
View full analysis
= MAX_POSITIONS: break side, size, reasoning = compute_signal(m) if not side: print(f" [skip] {reasoning}") continue ok, why = context_ok(client, m.id) if not ok: print(f" [skip] {why}") continue try: r = client.trade( market_id=m.id, side=side, amount=size, source=TRADE_SOURCE, skill_slug=SKILL_SLUG, reasoning=reasoning, ) tag = "(sim)" if r.simulated else "(live)" status = "OK" if r.success else f"FAIL:{r.error}" print(f" [trade] {side.upper()} ${size} {tag} {status} — {reasoning[:70]}") if r.success: placed += 1 except Exception as e: print(f" [error] {m.id}: {e}") ``` ### Technical Analysis `SIMMER_MIN_VOLUME` is loaded into `MIN_VOLUME`, exposed as a tunable, printed at runtime, and documented as a market-volume filter. However, neither `compute_signal()` nor `run()` compares a candidate market's volume against that value. Consequently, market eligibility depends on probability, spread, resolution date, and context checks, but not liquidity. This creates a fail-open condition in a financial safety control. Operators may reasonably rely on the configured minimum-volume value when enabling live trading, even though it has no effect on order placement. ### Attack Path 1. The process is launched with `--live`, enabling real Polymarket o ...[truncated 1015 chars]- Remediation
View remediation
