T09 · Insecure Skill Coding Practices
- Location
api-orders.md:9- Finding
Order Cancellation Lacks an Explicit User Confirmation Checkpoint
- Content
View full analysis
Only orders with status `open` or `partial` can be cancelled. > If the order is already filled or cancelled, the API returns 400. ``` ### Technical Analysis The Skill defines an explicit confirmation control only for `POST /orders`. The wording “Before calling POST /orders” excludes the `DELETE /orders/{order_id}` operation from those safeguards. Order cancellation is a state-changing and financially consequential action. Nevertheless, its documented workflow does not require the agent to: - Retrieve and display the target order before cancellation. - Verify the order identifier supplied by the user. - Show the symbol, side, price, and unfilled quantity. - Obtain explicit confirmation immediately before issuing the DELETE request. - Revalidate that the order remains open or partially filled after confirmation. Consequently, the agent can follow the documented can ...[truncated 1624 chars]- Remediation
View remediation
