T09 · Insecure Skill Coding Practices
- Location
candle_momentum.py:351- Finding
Configured Maximum Position Is Not Enforced as a Hard Trade Limit
- Content
View full analysis
= 0.85 and vol_surge >= 2.5: amount = min(base * 3.0, 15.0) # very strong: up to $15 elif body_ratio >= 0.75 and vol_surge >= 2.0: amount = base * 2.0 # strong: $10 elif body_ratio >= 0.65 and vol_surge >= 1.75: amount = base * 1.4 # medium: $7 else: amount = base # baseline: $5 ``` The resulting amount is submitted directly to the trading API: ```python result = client.trade( market_id=market_id, side=side, amount=amount, venue=os.environ.get("TRADING_VENUE", "polymarket"), source=TRADE_SOURCE, skill_slug=SKILL_SLUG, reasoning=full_reasoning, ) ``` The conflicting documented setting appears in `SKILL.md:104`: ```markdown | `max_position` | 5.0 | `CM_MAX_POSITION` | Max USD per trade | ``` ### Technical Analysis A risk-control value described as a maximum must be enforced as a hard upper bound at the final transaction sink. Instead, `max_position` is used as a baseline for gradient sizing. With the default configuration of `$5`, qualifying signals can generate `$7`, `$10`, or `$15` trades. The first branch has a fixed `$15` cap, but the other multiplier branches have no independent upper bound. For example, a user-provided `CM_MAX_POSITION=100` could result in a `$200` trade in the second branch. No validation also ensures that the configured value is finite, positive, or within an account-level safety limit. The market context check does not restore the documented ma ...[truncated 1204 chars]- Remediation
View remediation
