T09 · Insecure Skill Coding Practices
- Location
trader.py:354- Finding
Advertised liquidity and concurrent-position safeguards are not enforced
- Content
View full analysis
= MAX_POSITIONS: break ``` Orders are then submitted without checking market volume or existing account positions: ```python try: r = client.trade( market_id=matched_market.id, side=side, amount=size, source=TRADE_SOURCE, skill_slug=SKILL_SLUG, reasoning=whale_reasoning, ) tag = "(sim)" if r.simulated else "(live)" status = "OK" if r.success else f"FAIL:{r.error}" safe_print(f" [trade] {side.upper()} ${size} {tag} {status} -- {whale_reasoning[:120]}") if r.success: placed += 1 except Exception as e: safe_print(f" [error] {matched_market.id}: {e}") ``` ### Technical Analysis `MIN_VOLUME` is initialized and refreshed from configuration, but it is never used to reject illiquid markets. This conflicts with the documented minimum market-volume safeguard. Likewise, `MAX_POSITIONS` does not represent the number of concurrent open positions. It only limits success ...[truncated 1548 chars]- Remediation
View remediation
