T09 · Insecure Skill Coding Practices
- Location
trader.py:452- Finding
Declared Minimum Market Volume Safeguard Is Not Enforced
- Content
View full analysis
= MAX_POSITIONS: break side, size, reasoning = compute_signal(m) if not side: print(f" [skip] {reasoning}") continue ok, why = context_ok(client, m.id) if not ok: print(f" [skip] {why}") continue try: r = client.trade( market_id=m.id, side=side, amount=size, source=TRADE_SOURCE, skill_slug=SKILL_SLUG, reasoning=reasoning, ) ``` ### Technical Analysis The application loads `SIMMER_MIN_VOLUME` and documents it as a minimum market-volume safety control. However, neither `compute_signal` nor the order-submission loop checks a market's volume against `MIN_VOLUME`. The implemented pre-trade controls only cover the spread, time until resolution, flip-flop detection, and reported slippage. Consequently, a market that satisfies those checks can be traded even if it has negligible liquidity. This is a fail-open financial risk-control defect. The existence of the configuration option may also cause operators to believe that low-volume markets are being rejected when the value has no effect. ### Attack Path 1. An attacker creates, promotes, or identifies a low-volume market whose question matches one of the broad OnlyFans search keywords. 2. The operator starts the skill with the `--live` option. 3. `find_markets` returns the low-volume market. 4. The market probability falls outside one of the configured YES or NO thresholds, causing `comput ...[truncated 822 chars]- Remediation
View remediation
