T09 · Insecure Skill Coding Practices
- Location
scripts/polymarket.py:26- Finding
Unsanitized Remote API Content Is Rendered in the Terminal
- Content
View full analysis
str: """Format a single market for display.""" q = m.get("question", "Unknown")[:80] prices = json.loads(m.get("outcomePrices", '["0","0"]')) yes_pct = float(prices[0]) * 100 if prices else 0 no_pct = float(prices[1]) * 100 if len(prices) > 1 else 0 vol24h = m.get("volume24hr", 0) or 0 vol_total = m.get("volumeNum", 0) or 0 closed = "🔒" if m.get("closed") else "" return f"{closed}{q}\n Yes: {yes_pct:.1f}% | No: {no_pct:.1f}% | 24h: ${vol24h:,.0f} | Total: ${vol_total:,.0f}" ``` ```python m = markets[0] print(f"📊 {m.get('question', 'Unknown')}\n") prices = json.loads(m.get("outcomePrices", '["0","0"]')) outcomes = json.loads(m.get("outcomes", '["Yes","No"]')) for i, (outcome, price) in enumerate(zip(outcomes, prices)): pct = float(price) * 100 print(f" {outcome}: {pct:.1f}%") ``` ```python if m.get("description"): desc = m.get("description", "")[:500] print(f"\n {desc}{'...' if len(m.get('description', '')) > 500 else ''}") ``` ```python for e in events: title = e.get("title", "Unknown")[:70] vol = e.get("volume", 0) or 0 markets_count = len(e.get("markets", [])) print(f"• {title}") print(f" Volume: ${vol:,.0f} | Markets: {markets_count}") print() ``` ### Technical Analysis The `question`, `description`, `outcomes`, and event `title` values originate in responses from `https://gamma-api.polymarket.com`. Although the responses are decoded as JSON, JSON parsing does n ...[truncated 2442 chars]- Remediation
View remediation
str: text = str(value) text = ANSI_ESCAPE_RE.sub("", text) return CONTROL_RE.sub("", text) ``` Use the helper before truncation and display: ```python q = terminal_safe(m.get("question", "Unknown"))[:80] desc = terminal_safe(m.get("description", ""))[:500] outcome = terminal_safe(outcome) title = terminal_safe(e.get("title", "Unknown"))[:70] ``` Where feasible, use a maintained terminal-rendering or escaping library rather than relying solely on a custom regular expression, because terminal escape syntax has multiple forms. ]]>
