T09 · Insecure Skill Coding Practices
- Location
scripts/kalshi_commands.py:331- Finding
Advertised Daily-Loss and Aggregate Position Limits Are Not Enforced
- Content
View full analysis
MAX_SINGLE_TRADE_COST: return f"❌ Trade cost ${cost:.2f} exceeds max ${MAX_SINGLE_TRADE_COST:.2f} per trade." if quantity > MAX_POSITION_SIZE: return f"❌ Quantity {quantity} exceeds max {MAX_POSITION_SIZE} contracts per trade." return None ``` The incomplete risk check is invoked before buy orders at `scripts/kalshi_commands.py:933-941`: ```python amount = quantity * price_cents / 100.0 if action == "buy": risk_err = _check_risk(amount, quantity) if risk_err: _trade_audit("trade_blocked", { "ticker": ticker, "side": side, "quantity": quantity, "price_cents": price_cents, "reason": risk_err, }) return risk_err ``` ### Technical Analysis `MAX_DAILY_LOSS` is declared as a kill switch but is never evaluated by `_check_risk()`. The function only checks the estimated cost and quantity of the current order. The quantity check is also a per-order limit rather than an aggregate position limit. It does not obtain the existing position or include resting orders when determining projected exposure. Consequently, multiple individually valid orders can create a position substantially larger than 100 contracts. This conflicts with the hard-limit claims in `SKILL.md:218-224` and `references/risk-limits.md:5-14`. Users or agents may therefore authorize trades under the incorrect assumption that cumulative loss and position controls ...[truncated 1600 chars]- Remediation
View remediation
