T09 · Insecure Skill Coding Practices
- Location
bin/earn-api.ts:22- Finding
State-Changing Binance Clients Do Not Enforce Authorization Controls
- Content
View full analysis
{ if (typeof args.productId !== "string") die("Missing --productId"); if (typeof args.amount !== "string") die("Missing --amount"); out(await signedRequest("POST", "/sapi/v1/simple-earn/flexible/subscribe", { productId: args.productId, amount: args.amount, })); }, "redeem-flexible": async (args) => { if (typeof args.productId !== "string") die("Missing --productId"); const params: Record = { productId: args.productId }; if (args.all === true) params.redeemAll = "true"; else if (typeof args.amount === "string") params.amount = args.amount; else die("Missing --amount or --all"); out(await signedRequest("POST", "/sapi/v1/simple-earn/flexible/redeem", params)); }, "subscribe-locked": async (args) => { if (typeof args.projectId !== "string") die("Missing --projectId"); if (typeof args.amount !== "string") die("Missing --amount"); out(await signedRequest("POST", "/sapi/v1/simple-earn/locked/subscribe", { projectId: args.projectId, amount: args.amount, })); }, "redeem-locked": async (args) => { if (typeof args.positionId !== "string") die("Missing --positionId"); out(await signedRequest("POST", "/sapi/v1/simple-earn/locked/redeem", { positionId: args.positionId, })); }, ``` `bin/margin-api.ts:33-53`: ```ts borrow: async (args) => { if (typeof args.asset !== "string") die("Missing --asset"); if (typeof args.amount !== "string") die("Missing --amount"); out(await signedRequest("POST", "/sapi/v1/margin/borrow-repay", { asset: args.asset, ...[truncated 4011 chars]- Remediation
View remediation
