T09 · Insecure Skill Coding Practices
- Location
momentum_trader.py:169- Finding
Dry-Run Mode Performs Real Auto-Redemption Operations
- Content
View full analysis
Dict: """ Execute one trading cycle Returns: Dictionary containing execution summary """ client = get_client() print(f"\n{'='*70}") print(f"Skill: {SKILL_SLUG}") print(f"Venue: {VENUE}") print(f"Mode: {'DRY-RUN (simulation)' if dry_run else 'LIVE TRADING ⚠️'}") print(f"{'='*70}\n") # 1. Auto-redeem resolved positions print("🔄 Checking for positions to redeem...") redeemed = auto_redeem_positions() ``` ### Technical Analysis The `dry_run` argument protects order placement inside `execute_trade()`, but it is not passed to or evaluated by `auto_redeem_positions()`. Consequently, `run_once(dry_run=True)` still calls `client.auto_redeem()` using an authenticated `AionClient`. Auto-redemption is an account or blockchain state-changing financial operation rather than a read-only simulation. The default command is documented as dry-run mode, so users can reasonably expect i ...[truncated 2079 chars]- Remediation
View remediation
