T09 · Insecure Skill Coding Practices
- Location
providers/okx_provider.py:102- Finding
Invalid order amounts are silently converted into positive live orders
- Content
View full analysis
Dict[str, Any]: """ OKX 市价单: - side = 'buy' 时,如果 ccy='USDT',sz 代表购买用的 USDT 金额 - side = 'sell' 时,sz 代表卖出的基础货币数量 """ inst_id = self._normalize_symbol(symbol) side = side.lower() body = { 'instId': inst_id, 'tdMode': 'cash', 'side': side, 'ordType': 'market', } if side == 'buy': body['ccy'] = 'USDT' body['sz'] = f"{size:.2f}" if float(body['sz']) < 10: body['sz'] = "10.00" else: body['sz'] = f"{size:.8f}".rstrip('0').rstrip('.') if not body['sz'] or float(body['sz']) < 0.00001: body['sz'] = "0.00001" ``` ```python # providers/okx_provider.py ...[truncated 2673 chars]- Remediation
View remediation
float: if value is None or not math.isfinite(value) or value <= 0: raise ValueError(f"{name} must be a finite number greater than zero") return value ``` 2. Apply validation before creating the provider request: ```python size = require_positive_finite(args.size, "size") price = require_positive_finite(args.price, "price") ``` 3. Replace truthiness-based checks with explicit checks: ```python if args.symbol is None or args.side is None or args.size is None: ... ``` 4. Never increase an order to an exchange minimum automatically. If an amount is below the supported minimum, reject it with a clear error that includes the applicable constraint. 5. Validate symbols against the intended instrument format and validate order parameters against OKX instrument metadata, including minimum order size, lot size, tick size, and quote-currency rules. 6. Add automated tests covering zero, negative values, `NaN`, positive and negative infinity, values below the exchange minimum, and unusually large values. Verify that none of these invalid inputs reaches `OKXClient.request()`. 7. Consider requiring an explicit confirmation or configurable notional limit for `okx_live` orders to reduce the impact of compromised or malformed upstream requests. ]]>
