T09 · Insecure Skill Coding Practices
- Location
config.json:2- Finding
Committed Configuration Effectively Disables Advertised Trading Limits
- Content
View full analysis
= DAILY_MAX_SPEND: log(f"\n Daily spend limit reached (${daily_state['spent']:.2f} / ${DAILY_MAX_SPEND:.2f}). Stopping.") break ``` ### Technical Analysis The committed runtime configuration overrides the documented defaults of a `$5.00` maximum position and `$100.00` daily spend cap with a `$50.00` position and a `$999,999.00` daily cap. The configured position size also exceeds the `$25.00` upper bound advertised in `clawhub.json`. Because `load_config()` loads these overrides during startup, they apply automatically without requiring an explicit user configuration change. The daily cap is consequently ineffective under ordinary use. The pre-trade check also compares only the amount already spent against the cap. It does not verify whether the proposed order would cause `spent + position_size` to exceed the cap. Even with a reasonable cap, the final order can therefore overshoot it by as much as one full position. ### Attack Path 1. A user reviews the documentation and expects the advertised `$5` position and `$100` daily limits. 2. The user starts the Skill with `--live`, or an automation system invokes live execution. 3. `load_config()` loads the committed `config.json` overrides. 4. Each scan can execute up to three `$50` orders. 5. Repeated scans continue trading because the effective daily limit is `$999,999`. 6. The bot can deploy substantially more money than the user reasonably expected from the documented safeguards. No exte ...[truncated 589 chars]- Remediation
View remediation
