T09 · Insecure Skill Coding Practices
Error
- Location
clob_microstructure.py:28- Finding
Live Trading Proceeds When Safety Context Validation Fails
- Content
View full analysis
0.15: return False, "slippage too high" edge = ctx.get("edge_analysis", {}) if edge.get("recommendation") == "HOLD": return False, "edge below threshold" return True, "ok" except Exception: return True, "context unavailable" ``` The returned value is subsequently used to authorize live execution: ```python ok, reason = check_context(client, sig["market_id"]) if not ok: log.warning("Skipping trade: %s", reason) continue if live: try: result = client.trade( market_id=sig["market_id"], side=side, amount=size, source=TRADE_SOURCE, skill_slug=SKILL_SLUG, reasoning=reasoning, ) ``` ### Technical Analysis `check_context()` is intended to prevent trades when flip-flop behavior, excessive slippage, or insufficient edge is detected. However, every exception raised while retrieving or parsing the context is converted into a successful authorization result: ```python return True, "context unavailable" ``` Consequently, network timeouts, authentication errors, SDK failures, malformed responses, unex ...[truncated 1706 chars]- Remediation
View remediation
