T09 · Insecure Skill Coding Practices
- Location
scripts/trader.py:17- Finding
Documented Position Limits, Stop-Loss, and Take-Profit Controls Are Not Enforced
- Content
View full analysis
= 10: # Binance minimum place_order(symbol, "BUY", qty) else: log.info(f" Skip: trade size ${trade_usdt:.2f} below $10 minimum") elif signal == "SELL": # Check if we hold this asset base_asset = symbol.replace("USDT", "") held = get_balance(base_asset) if held * current_price > 10: place_order(symbol, "SELL", held) else: log.info(f" No {base_asset} position to sell") ``` ### Technical Analysis The application parses configuration values for maximum concurrent positions, take-profit percentage, and stop-loss percentage, but those values are never used in the trading decision or order-placement paths. Buy orders are submitted as unprotected market orders. No check counts existing positions before a purchase, and no linked protective orders are created after execution. This conflicts with the controls documented in `SKILL.md`, where `MAX_POSITIONS`, `TAKE_PROFIT_PCT`, and `STOP_LOSS_PCT` are presented ...[truncated 1376 chars]- Remediation
View remediation
