T09 · Insecure Skill Coding Practices
- Location
clawhub.json:32- Finding
Managed automation defaults conflict with documented trading safeguards
- Content
View full analysis
Vulnerability Details
File Location:
clawhub.json:32-81
Additional Relevant Locations:SKILL.md:4,SKILL.md:50-54,mert_sniper.py:40-43,mert_sniper.py:511-522
Vulnerability Type: Unsafe financial automation configuration
Risk Level: HighVulnerable Code
json { "env": "SIMMER_MERT_MAX_BET_USD", "type": "number", "default": 50, "range": [ 1, 200 ], "step": 5, "label": "Max bet per trade" }, { "env": "SIMMER_MERT_EXPIRY_MINUTES", "type": "number", "default": 30, "range": [ 5, 120 ], "step": 5, "label": "Order expiry (minutes)" }, { "env": "SIMMER_MERT_MIN_SPLIT", "type": "number", "default": 0.1, "range": [ 0.01, 0.5 ], "step": 0.01, "label": "Minimum probability split" }, { "env": "SIMMER_MERT_MAX_TRADES_PER_RUN", "type": "number", "default": 5, "range": [ 1, 20 ], "step": 1, "label": "Max trades per run" }, { "env": "SIMMER_MERT_SIZING_PCT", "type": "number", "default": 0.1, "range": [ 0.01, 1.0 ], "step": 0.01, "label": "Position sizing percentage" }The conflicting implementation defaults and affected selection logic are:
python CONFIG_SCHEMA = { "market_filter": {"env": "SIMMER_MERT_FILTER", "default": "", "type": str}, "max_bet_usd": {"env": "SIMMER_MERT_MAX_BET_USD", "default": 10.00, "type": float}, "expiry_window_mins": {"env": "SIMMER_MERT_EXPIRY_MINUTES", "default": 8, "type": int}, "min_split": {"env": "SIMMER_MERT_MIN_SPLIT", "default": 0.60, "type": float}, "max_trades_per_run": {"env": "SIMMER_MERT_MAX_TRADES_PER_RUN", "default": 5, "type": int}, "sizing_pct": {"env": "SIMMER_MERT_SIZING_PCT", "default": 0.05, "type": float}, }python # Check split threshold if price < MIN_SPLIT and price > (1 - MIN_SPLIT): ...[truncated 3345 chars]- Remediation
View remediation
Remediation Suggestions
-
Align all metadata defaults with the documented and implementation defaults:
SIMMER_MERT_MAX_BET_USD:10SIMMER_MERT_EXPIRY_MINUTES:8SIMMER_MERT_MIN_SPLIT:0.60SIMMER_MERT_SIZING_PCT:0.05
-
Change the minimum-split range to
[0.5, 1.0], or to a narrower reviewed range such as[0.5, 0.95]. -
Reject unsafe values after configuration loading rather than relying solely on UI metadata:
python if not 0.5 <= MIN_SPLIT < 1.0: raise ValueError("min_split must be between 0.5 and 1.0") if MAX_BET_USD <= 0: raise ValueError("max_bet_usd must be positive") if EXPIRY_WINDOW_MINS <= 0: raise ValueError("expiry_window_mins must be positive") -
Determine the favored side independently of the threshold:
python if max(price, 1 - price) < MIN_SPLIT: continue side = "yes" if price >= 0.5 else "no" side_price = max(price, 1 - price) -
Add tests covering boundary and invalid values, including
0.10,0.49,0.50,0.60, and values outside[0, 1]. -
Add an integration test confirming that
clawhub.json,SKILL.md, andCONFIG_SCHEMAexpose identical defaults. -
Require an explicit confirmation when metadata increases live exposure beyond the documented default.
-
