T09 · Insecure Skill Coding Practices
- Location
trader.js:78- Finding
Bearish Signals Submit SELL Orders Instead of Buying NO Tokens
- Content
View full analysis
- Remediation
View remediation
1) { throw new Error(`Invalid ask price for token ${tokenId}`); } const size = parseFloat(maxUsdc) / bestAsk; const order = await client.createAndPostOrder({ tokenID: tokenId, price: bestAsk, side: 'BUY', size, feeRateBps: 0, nonce: 0, expiration: 0, }); ``` Additional hardening should include: 1. Add unit tests asserting `BUY signal -> BUY YES` and `SELL signal -> BUY NO`. 2. Validate token ordering against explicit outcome labels rather than assuming array index zero is YES and index one is NO. 3. Reject missing, non-finite, zero, negative, or out-of-range prices instead of falling back to `0.5`. 4. Validate `MAX_TRADE_USDC` and enforce a positive upper bound before calculating order size. 5. Display the exact token outcome, exchange side, price, and maximum spend before submission. 6. Consider requiring explicit confirmation for the first live order after configuration changes. 7. Perform billing after preflight validation, or refund cycles where no documented operation can be attempted. ]]>
