T09 · Insecure Skill Coding Practices
- Location
scripts/market_data.py:62- Finding
Unvalidated Market Prices Can Corrupt the Simulated Trading Ledger
- Content
View full analysis
= od["price"]: should_match = True match_price = mp if should_match: result = _execute_single(conn, od, match_price) ``` The resulting negative cost is applied directly to the portfolio balance: ```python # scripts/matching.py:75-91 p = conn.execute("SELECT cash FROM portfolios WHERE id=?", (pid,)).fetchone() cost = qty * price if p["cash"] < cost: conn.execute( "UPDATE orders SET status='rejected',updated_at=datetime('now','localtime') WHERE id=?", (oid,), ) conn.commit() ...[truncated 3287 chars]- Remediation
View remediation
0) ``` Similar constraints should protect quantities, cash values, average costs, NAV values, and trade prices. 7. Perform all matching mutations in an explicit transaction. Roll back the cash, holding, order, and trade changes together if validation or any database operation fails. 8. Add regression tests for negative prices, zero, booleans, strings, missing fields, `NaN`, positive and negative infinity, excessively large values, and malformed remote responses. ]]>
