T09 · Insecure Skill Coding Practices
- Location
examples/basic_usage.py:25- Finding
Incomplete Input Validation Allows Malformed Trade Requests
- Content
View full analysis
tuple[bool, str]: if not signal.should_trade: return False, "no valid signal" if risk_per_trade <= 0 or risk_per_trade > 0.02: return False, "risk_per_trade outside allowed range" if leverage < 1 or leverage > 5: return False, "leverage outside allowed range" if account_state["daily_pnl_pct"] <= -0.05: return False, "daily loss limit reached" if signal.entry_price == signal.stop_loss: return False, "entry equals stop" return True, "ok" def build_order_request(market: str, signal: Signal, size: float, leverage: float) -> dict: return { "market": market, "side": signal.side, "order_type": "market", "size": round(size, 6), "leverage": leverage, "entry_price": signal.entry_price, "stop_loss": signal.stop_loss, "take_profit": signal.take_profit, } ``` ### Technical Analysis The validation routine checks only a subset of the controls described by the Skill. It does not validate: - `market` against supported markets. - `signal.side` against the expected `long` and `short` values. - Whether balance, entry price, stop loss, leverage, and risk values are finite numbers. - Whether the calculated position size is finite, positive, and accepted by the market. - Available margin, notional exposure, open-position limits, liquidation distance, funding, or slippage. - Whether the stop loss is directionally valid relative to the requested side. Floating-point values such as `NaN` are particularly problematic because ordinary comparisons with `NaN` evaluate to false. For example, a `risk_per_trade` value of `NaN` bypa ...[truncated 1552 chars]- Remediation
View remediation
