T09 · Insecure Skill Coding Practices
- Location
scripts/score_company.py:323- Finding
Unvalidated Rating Scores and Weights Permit Rating Manipulation
- Content
View full analysis
- Remediation
View remediation
float: score = float(value) if not math.isfinite(score) or not 0 <= score <= 100: raise ValueError(f"{name} must be a finite number between 0 and 100") return score ``` 3. **Validate weights** Require every weight to be finite and within `0–1`. Verify that each complete weight group sums to 1 within a small floating-point tolerance: ```python def validate_weights(weights: dict[str, float], name: str) -> None: if any(not math.isfinite(v) or not 0 <= v <= 1 for v in weights.values()): raise ValueError(f"{name} weights must be finite values between 0 and 1") if not math.isclose(sum(weights.values()), 1.0, rel_tol=0, abs_tol=1e-9): raise ValueError(f"{name} weights must sum to 1.0") ``` 4. **Validate raw metrics** Reject negative quantities and counts where negative values have no valid business meaning. Require denominator fields to be strictly positive before division. 5. **Validate calculated results** Before grade mapping, require the comprehensive score to be finite and within the model's expected range. Fail closed instead of producing a rating when validation fails. 6. **Record validation failures** Return a structured no-rating or input-validation result identifying the invalid fiel ...[truncated 350 chars]
