The Risk Gate That Never Gets Its Input
When I review a trading bot's risk code, the first thing I look for is not whether the limit is correct. It's whether the limit ever receives anything. A daily-loss check that compares daily_pnl against a threshold is textbook-correct. If daily_pnl is never updated, it compares zero against the threshold forever and never trips. The gate is there, the tests for the gate pass, and the account is…
When evaluating a trading bot’s risk code, the initial focus should not be on determining if the limit is accurate, but rather whether the limit receives any input at all. A daily-loss check that compares daily_pnl against a threshold is considered correct by design. However, if daily_pnl is never updated, the gate will always compare zero against the threshold and never trigger.
This issue has been observed consistently in previous audits: the gate is present, correctly implemented, but the signal feeding it is absent, frozen, or incorrect. Five variations of this problem have been identified, originating from both public repositories and private bots.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.