◆ kanex-ai
Loading…
Sydnee Inc Legal Aug 15 7:55 PM
TEST — Veer 304E, how the Izeal reply will look
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Sydnee Inc Legal Aug 15 7:46 PM
Veer Towers 304E - furnished 1BR, corporate housing
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Kelvin Yan Aug 15 7:34 PM
Veer 304E — three drafts for review before sending
⚠ PHISHING: employee impersonation: display name matches 'kelvin yan' but sender is email.sydneeinc.com
phishing urgent
Bank of America Aug 15 5:44 PM
Your statement is available
Bank of America: Your statement is available
financial
Bank of America Aug 15 5:43 PM
Your statement is available
Bank of America: Your statement is available
financial
Sydnee Agent (AI) Aug 15 5:39 PM
[Calibration Daily] 2026-08-16
Sydnee Agent (AI): [Calibration Daily] 2026-08-16
employee high
Sydnee Inc Legal Aug 15 5:34 PM
Access test 1 of 3 - link
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Sydnee Inc Legal Aug 15 5:33 PM
Access test 3 of 3 - verified
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Sydnee Inc Legal Aug 15 5:09 PM
Access test 3 of 3 - verified
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Sydnee Inc Legal Aug 15 5:09 PM
Access test 1 of 3 - link
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Sydnee Inc Legal Aug 15 4:48 PM
Access test 1 of 3 - link (opens straight away, no code)
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Microsoft Outlook Aug 15 4:47 PM
Undeliverable: FW: Dr Cat's Video Insights on $NOW and $TEAM-Video 2 of 12 (August 16, 2026)
Microsoft Outlook: Undeliverable: FW: Dr Cat's Video Insights on $NOW and $TEAM
employee high
Microsoft Outlook Aug 15 4:46 PM
Undeliverable: FW: Dr Cat's Video Insights on $ABCL-Video 3 of 12 (August 16, 2026)
Microsoft Outlook: Undeliverable: FW: Dr Cat's Video Insights on $ABCL-Video 3
employee high
Sydnee Inc Legal Aug 15 4:26 PM
Veer 304E - all three access levels
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Sydnee Inc Legal Aug 15 4:16 PM
Veer 304E - replacement links
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Sydnee Inc Legal Aug 15 4:10 PM
Veer 304E - short links, one with a code
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Sydnee Inc Legal Aug 15 4:04 PM
Your access code
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Sydnee Inc Legal Aug 15 4:04 PM
Your access code
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Sydnee Inc Legal Aug 15 4:00 PM
Veer 304E - test of the secure file links
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Sydnee Inc Legal Aug 15 4:00 PM
Your access code
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Amazon Payments Aug 15 12:52 PM
Action requise sur le compte Amazon Payments
Fake Amazon Payments suspension threat; credential harvesting attempt.
phishing urgent
Guest Relations at The Ritz-Carlton, Laguna Niguel Aug 15 10:49 AM
Kelvin, please complete the travel request form to customize your stay at The Ritz-Carlton, Laguna Niguel
Suspicious Ritz-Carlton email with obfuscation; potential credential theft attempt.
phishing urgent
Manus Team Aug 15 7:33 AM
ACTION REQUIRED: 7 days left to back up Kelvin Yan for future restoration
⚠ PHISHING: phishing subject pattern: 'ACTION REQUIRED' from external sender privaterelay.appleid.com
phishing urgent
Benjamin & Williams Aug 15 5:02 AM
Commercial Claim Discovery Documents Our file:D-8222 Debtor: VICTORIA ROPA ELEGANTE
Fake debt collection demand with 24h payment pressure; spoofed domain.
phishing urgent
Sydnee Agent (AI) Aug 15 4:15 AM
Sydnee nightly — PERFORMANCE audit 2026-08-15 — 0P0 2P1 13R
Sydnee Agent (AI): Sydnee nightly — PERFORMANCE audit 2026-08-15 — 0P0 2P1 13R
employee high
The Ritz-Carlton Reservations Aug 15 4:12 AM
Plan for your upcoming stay at The Ritz-Carlton, Laguna Niguel on Monday, August 17, 2026
Ritz-Carlton reservation confirmation for August 17 stay at Laguna Niguel.
personal
Tesla Aug 15 12:55 AM
Full Self-Driving (Supervised) Subscription Renewed
Tesla FSD subscription auto-renewed for Model Y, $107.29/month.
financial low
Sydnee.ai Legal Aug 14 9:22 PM
Jiao 移民案件最新进展说明(好消息,请放心)
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydnee.ai
phishing urgent
KuCoin Aug 14 6:38 PM
Dormancy Fee Deduction Notice
KuCoin dormancy fee deducted from account this month.
financial
Tommy Wang (Wang IP Law) Aug 14 6:30 PM
Re: I-485 Application (IOE0934359789 and IOE0934359788)
Tommy Wang (Wang IP Law): Re: I-485 Application (IOE0934359789 and IOE0934359788)
legal-ip high
Bank of America Aug 14 6:16 PM
We've sent your payment to SOUTHERN CALIFORNIA EDISON SCE as requested
Bank of America: We've sent your payment to SOUTHERN CALIFORNIA EDISON SCE as
financial high
Sydnee Agent (AI) Aug 14 5:42 PM
[Calibration Daily] 2026-08-15
Sydnee Agent (AI): [Calibration Daily] 2026-08-15
employee high
Sydnee Agent (AI) Aug 14 5:30 PM
Sydnee algo daily — dev $-2,239 · prod $+0 · 6d window
Sydnee Agent (AI): Sydnee algo daily — dev $-2,239 · prod $+0 · 6d window
employee high
Laguna Road Area Community Message Aug 14 2:39 PM
1 New School Flyer for Your Child
School flyer: Congressional App Challenge signup opportunity.
family
Anthony Patino in Teams Aug 14 2:34 PM
Anthony Patino sent a message
⚠ PHISHING: employee impersonation: display name matches 'anthony' but sender is teams.mail.microsoft
phishing urgent
TAnthony Patino Aug 14 1:34 PM
[Teams oneOnOne] (Teams DM)
Anthony Patino flagging ~$20k air shipment payment for approval.
employee
Amy Burghardt Aug 14 1:19 PM
RE: Meeting
Amy Burghardt: RE: Meeting
personal high
Mary Chmelka Aug 14 1:07 PM
Survey invite to Ameritas California Language Assistance Program Survey
Ameritas requesting language preference survey for insurance benefits.
vendor low
TAnthony Patino Aug 14 12:47 PM
[Teams oneOnOne] (Teams DM)
Anthony Patino requesting updated HDCVT statement.
employee
TAnthony Patino Aug 14 12:45 PM
[Teams oneOnOne] (Teams DM)
Teams DM acknowledgment from Anthony Patino.
employee
TAnthony Patino Aug 14 12:45 PM
[Teams oneOnOne] (Teams DM)
Anthony Patino confirms E-like assessment via Teams DM.
employee low
TAnthony Patino Aug 14 12:08 PM
[Teams oneOnOne] (Teams DM)
Anthony found something; not due for ~30 days.
employee
TAnthony Patino Aug 14 12:05 PM
[Teams oneOnOne] (Teams DM)
SAVLink payment $15,915 awaiting approval
financial high
TAnthony Patino Aug 14 11:59 AM
[Teams oneOnOne] (Teams DM)
Anthony Patino internal Teams message about communications or notes.
employee
TAnthony Patino Aug 14 11:56 AM
[Teams oneOnOne] (Teams DM)
Anthony Patino confirming he will set something up now.
employee
TAnthony Patino Aug 14 11:56 AM
[Teams oneOnOne] (Teams DM)
Anthony Patino Teams DM about something that just came due recently.
employee
TAnthony Patino Aug 14 11:55 AM
[Teams oneOnOne] (Teams DM)
Anthony Patino confirms document dated 6/04 with net60 terms.
employee
TAnthony Patino Aug 14 11:54 AM
[Teams oneOnOne] (Teams DM)
SmartAV Link requesting payment of $15,915.
vendor
TAnthony Patino Aug 14 11:47 AM
[Teams oneOnOne] (Teams DM)
Anthony reports received Iolo Capital invoice, needs approval to add to CC.
employee
TAnthony Patino Aug 14 11:25 AM
[Teams oneOnOne] (Teams DM)
Anthony Patino initiating a Teams call.
employee

Sydnee nightly — PERSISTENCE audit 2026-08-13 — 0P0 4P1 7R

Sydnee Agent (AI) <[email protected]>
To: Kelvin Yan <[email protected]>
Thursday Aug 13, 2026 · 4:15 AM PT · in [email protected]
AI verdict  employee high · confidence: high · by internal-exempt
“Sydnee Agent (AI): Sydnee nightly — PERSISTENCE audit 2026-08-13 — 0P0 4P1 7R”
Reasoning: @sydnee.ai is a protected domain — hard exemption
Sydnee nightly — PERSISTENCE audit — 2026-08-13 P0 findings: 0 P1 findings: 4 Risks: 7 - Area: Persistence (Thursday theme) - Branch: `dev` (cda5ab3 — docs(peak-monitor): hourly log 2026-08-12 13:09 PT) - Files scanned: `bot.py` (24,173 lines), `core/database.py` (2,553 lines), `core/risk.py` (150 lines), `core/persistence.py` (153 lines), `core/schema.sql` (104 tables), `docs/strategy_decisions.md`, `docs/audit_2026-08-06_PERSISTENCE.md`, `git log --oneline -30` - **Bugs found (P0 / P1): 0 / 4 (all carried — no new bugs)** - **Risks noted: 7 (all carried; 2 corrections to prev audit code excerpts noted below)** **Cross-check:** `git log --oneline --since=2026-08-06` returns zero results for `bot.py`, `core/database.py`, `core/risk.py`, `core/persistence.py`. All commits since 2026-08-06 are audit docs + peak-monitor hourly logs. All 4 P1 bugs and all 7 risks from the 2026-08-06 PERSISTENCE audit re-verified at current line numbers — all present and unchanged. **Two corrections to 2026-08-06 audit excerpts (no code changes — prior auditor misquoted):** - `_safe()` (database.py:82) logs at `logger.warning`, NOT `logger.debug` as stated in the 2026-08-06 RISK. Partially reduces RISK-4 (write swallowing is still silent in terms of propagation, but operator-visible at warning level). - `_update_trade_field` (bot.py:1313) uses `setattr(t, k, v)`, NOT the `setattr(t, t, v)` typo claimed in RISK-3. The `hasattr` gate risk still applies (non-dataclass flags skip in-memory update) but the typo was never in the code. --- Full report (dev branch): https://github.com/kanex1/sydnee.signals/blob/dev/docs/audit_2026-08-13_PERSISTENCE.md Reply FROM [email protected] to [email protected] to request fixes, e.g.: "code_task on sydnee-signals-dev: apply fix for the P0 about RVOL threshold in bot.py" Sydnee Agent will propose + you APPROVE (or plain 'approve') + auto-push to dev. --- Full audit below (first 12 KB) --- # Nightly Audit 2026-08-13 — PERSISTENCE ## Summary - Area: Persistence (Thursday theme) - Branch: `dev` (cda5ab3 — docs(peak-monitor): hourly log 2026-08-12 13:09 PT) - Files scanned: `bot.py` (24,173 lines), `core/database.py` (2,553 lines), `core/risk.py` (150 lines), `core/persistence.py` (153 lines), `core/schema.sql` (104 tables), `docs/strategy_decisions.md`, `docs/audit_2026-08-06_PERSISTENCE.md`, `git log --oneline -30` - **Bugs found (P0 / P1): 0 / 4 (all carried — no new bugs)** - **Risks noted: 7 (all carried; 2 corrections to prev audit code excerpts noted below)** **Cross-check:** `git log --oneline --since=2026-08-06` returns zero results for `bot.py`, `core/database.py`, `core/risk.py`, `core/persistence.py`. All commits since 2026-08-06 are audit docs + peak-monitor hourly logs. All 4 P1 bugs and all 7 risks from the 2026-08-06 PERSISTENCE audit re-verified at current line numbers — all present and unchanged. **Two corrections to 2026-08-06 audit excerpts (no code changes — prior auditor misquoted):** - `_safe()` (database.py:82) logs at `logger.warning`, NOT `logger.debug` as stated in the 2026-08-06 RISK. Partially reduces RISK-4 (write swallowing is still silent in terms of propagation, but operator-visible at warning level). - `_update_trade_field` (bot.py:1313) uses `setattr(t, k, v)`, NOT the `setattr(t, t, v)` typo claimed in RISK-3. The `hasattr` gate risk still applies (non-dataclass flags skip in-memory update) but the typo was never in the code. --- ## Findings ### BUG [P1] (carried ×3 persistence audits, unfixed since 2026-07-14): `exit_reason` blank in DB — crash window between `_close_trade_in_store` and exit-reason write **File:** `bot.py:1383` (`_close_trade_in_store`); call sites `bot.py:8795`, `8900`, `8921`, `13279`, `2515`, `2528`, `5758` **Evidence:** ```python # bot.py:1380-1384 — _close_trade_in_store() always passes exit_reason="": self.db.close_trade( trade_id=trade_id, exit_price=exit_price, exit_time=datetime.now(ET).isoformat(), pnl=pnl, exit_reason="", ) # bot.py:8795-8798 — main exit path: reason written in a separate update_trade() call: pnl = self._close_trade_in_store(trade.trade_id, exit_price) self.db.update_trade(trade.trade_id, exit_reason=reason, ...) # bot.py:2515, 2528 — reconcile path: close_trade_in_store() with NO follow-up # update_trade(exit_reason=...) call at all — exit_reason is always "" for these. self._close_trade_in_store(t.trade_id, exit_px) ``` For the main exit path (lines 8795–8928), a crash between `_close_trade_in_store` and the subsequent `update_trade(exit_reason=...)` leaves the row permanently blank. For the reconcile path (lines 2515, 2528) there is no follow-up at all — those trades are always closed with `exit_reason=""` regardless of crash. **Impact:** All `CASE WHEN exit_reason ~* 'TRIM'` analytics queries misclassify reconcile-driven closes. Any crash in the exit path produces the same result for main-loop closes. **Fix:** Pass `exit_reason` as a parameter to `_close_trade_in_store()` and include it in the `close_trade()` call. Eliminates the two-step write and the race window. --- ### BUG [P1] (carried ×3 persistence audits, unfixed since 2026-07-14): `RiskManager.DailyState` (`trade_count`, `realized_pnl`) not restored on restart — daily caps reset to zero **File:** `bot.py:23458–23461` (startup restore); `core/risk.py:29` **Evidence:** ```python # core/risk.py:29-34 — DailyState always starts zeroed: @dataclass class DailyState: date: date = field(default_factory=date.today) realized_pnl: float = 0.0 trade_count: int = 0 open_positions: int = 0 # bot.py:23458-23461 — startup only calls set_open_positions(): open_count = len(self.open_trades()) if open_count > 0: self.risk.set_open_positions(open_count) logger.info("Restored %d open positions", open_count) # No restore of trade_count or realized_pnl from DB # core/risk.py:112-120 — caps that rely on these values: if self.state.realized_pnl <= -self.cfg.daily_loss_limit: return False, "Daily loss limit hit: ..." if self.state.trade_count >= self.cfg.max_daily_trades: return False, "Max daily trades reached: ..." ``` `RiskManager` has no `restore_daily_state()` method. After any restart mid-session, `trade_count` resets to 0 and `realized_pnl` resets to 0.0. **Impact:** Real-money risk. A bot at 10/10 max daily trades that restarts places new trades freely. A bot past the daily loss limit bypasses the circuit breaker for the remainder of the session. DB has all necessary data to restore via `SELECT COUNT(*), SUM(pnl) FROM trades WHERE trade_date = today AND exit_time IS NOT NULL`. **Fix:** Query completed trades for today at startup and call `self.risk.record_exit(pnl)` for each closed trade, or add `restore_daily_state(trade_count, realized_pnl)` to `RiskManager` and call it during `start()`. --- ### BUG [P1] (carried ×3 persistence audits, unfixed since 2026-07-14): `_ab_live_state` memory-only — Asian Breakout executor loses all state on restart, pending force-flat never fires **File:** `bot.py:20237–20238` **Evidence:** ```python # bot.py:20237-20238 — lazy-init, no DB restore: if not hasattr(self, "_ab_live_state"): self._ab_live_state = {} ``` `_ab_live_state` is a dict keyed by symbol holding bracket metadata (`side`, `qty`, `entry`, `stop`, `target`, `bracket_id`, `state`). On restart it is empty. The force-flat path (`bot.py:20126–20140`, `_ab_close_market`) reads `_ab_live_state[sym]` to construct the cancel+market-close order — with empty state the force-flat silently skips. The AB position continues as an untracked IBKR position. **Impact:** Live AB positions (low — `AB_EXECUTE` dev-paper only) become orphaned on restart. Real risk if `AB_EXECUTE` is promoted to production. **Fix:** Persist `_ab_live_state` to DB or Redis on each state change; restore at startup from `asian_breakout_signals` table (schema entry created via `ensure_trade_state_columns()` scope per prior audits). --- ### BUG [P1] (carried ×3 persistence audits, unfixed since 2026-07-14): AB bracket fills and closes not written to DB **File:** `bot.py:20109–20140` (`_ab_place_bracket`, `_ab_close_market`) **Evidence:** ```python # bot.py:20109-20124 — _ab_place_bracket(): places IBKR bracket, no DB write # bot.py:20126-20140 — _ab_close_market(): places IBKR market close, no DB write # Both functions only read/write _ab_live_state (memory) ``` Neither `_ab_place_bracket()` nor `_ab_close_market()` calls `db.insert_trade()` or `db.close_trade()`. AB P&L is invisible to `realized_pnl` in `RiskManager.DailyState` (compounding P1 bug #2 above — daily loss limit ignores AB losses). **Impact:** Risk double-counting (risk manager unaware of AB position size) + analytics blind spot. **Fix:** Insert a trade row on bracket fill confirmation; close it on `_ab_close_market`. --- ## Risks ### RISK (carried from 2026-08-06): `_tv_scale_state` memory-only — TV-BXt active scale-in window abandoned on restart **File:** `bot.py:4378–4379` (init); `bot.py:4144–4158` (scale logic) ```python # bot.py:4378-4379 — lazy-init, no Redis restore: if not hasattr(self, "_tv_scale_state"): self._tv_scale_state = {} ``` On restart during an active 10-slot (600s) scale-in window, `_tv_scale_state` is empty, `_scale_active=False` causes early return — remaining slots abandoned silently. No duplicate orders placed; parent trade continues normally. **Impact:** Position undersized if restart occurs during the 600s scale-in window. Silent — no log message on abandoned-slot path. --- ### RISK (carried since 2026-07-14): `TradeStore._load_today()` only loads today's date file — silently loses overnight-open trades **File:** `core/persistence.py:80–88` ```python def _load_today(self) -> None: path = self._file_for_date() # always date.today() ... ``` `TradeStore` is not used by `bot.py` (zero imports), so this is latent. If any future consumer uses it, positions opened before midnight are silently absent after the date rolls. --- ### RISK (carried since 2026-07-14, code excerpt corrected): `_update_trade_field` `hasattr` gate skips non-dataclass attribute updates in memory **File:** `bot.py:1306–1318` ```python def _update_trade_field(self, trade_id: str, **kwargs) -> None: with self._trades_lock: for t in self._trades: if t.trade_id == trade_id: for k, v in kwargs.items(): if hasattr(t, k): # ← skips attrs not on Trade dataclass setattr(t, k, v) # (correctly uses k, not t — prior audit had typo) break self.db.update_trade(trade_id, **kwargs) ``` The `hasattr` gate means DB and in-memory state diverge for any field not declared on the `Trade` dataclass. DB is updated correctly; in-memory `Trade` object is not. **Note:** The `setattr(t, t, v)` typo claimed in the 2026-08-06 audit does NOT exist in the current code — current code correctly uses `setattr(t, k, v)`. That part of the prior risk was a misquote. --- ### RISK (carried since 2026-07-14, log level corrected): `_safe()` swallows all write exceptions — DB failures are `warning` logged only, never re-raised **File:** `core/database.py:77–87` ```python def _safe(self, func, *args, default=None, **kwargs): try: return func(*args, **kwargs) except Exception as e: logger.warning("DB operation failed: %s", e) # WARNING level (not debug) try: self._local.conn = None except Exception: pass return default ``` All write operations (`insert_trade`, `close_trade`, `update_trade` at lines 127, 138, 146) go through `_safe()`. Failures return `None` and continue execution. **Note:** The 2026-08-06 audit stated `logger.debug` — current code uses `logger.warning`, which is operator-visible. The core risk remains: DB divergence accumulates without exception propagation or a metric counter. **Remaining fix:** Re-raise on critical write operations (`insert_trade`, `close_trade`, `update_trade`) so callers can detect and surface DB outages. --- ### RISK (carried since 2026-07-14): Schema drift — 7 columns and 7 tables in runtime `ensure_*` methods are absent from `core/schema.sql` **File:** `core/database.py:222` (`ensure_trade_state_columns`), `core/database.py:364` (`ensure_scalp_signal_log_table`); `core/schema.sql` Columns in `ensure_trade_state_columns()` not in `schema.sql` trades table: `obv_be_applied_at`, `order_lmt_price`, `tape_metadata`, `tick_peak_signed_vol`, `fri_ah_close_queued`, `fri_flat_queued` (6 of 7 from prior audit — `order_type` is in `orders` table in schema.sql, not in `trades`; confirmed absent from `trades` definition via grep). Tables created at runtime but absent from `schema.sql`: `nlv_snapshots`, `rrod_signal_log`, `asian_breakout_signals`, `stock_strategy`, `scalp_signal_log`, `futures_bars`, `futures_l2_snapshots` A fresh `psql -f schema.sql` deploy misses all of these. DR restore from schema alone silently fails on first write to missing columns/tables. --- ### RISK (carried since 2026-07-14): `_deferred_closes` memory-only — crash between trim-flag persist and order submit loses deferred close **File:** `bot.py:23276` ```python self._deferred_closes: list[tuple] = [] ``` Plain list, no Redis or DB backing. 15+ call sites append to this list (trim-1/2/3, Friday EOD, Friday AH, reversal, etc.). If the process crashes after persisting a trim flag to DB but before `_process_deferred_orders()` drains the list, the close order is lost — position remains open with trim flags set, misleading analytics. --- ### RISK (carried since 2026-07-14): `insert_bar()` omits `source` column **File:** `core/database.py:1110–1119` `insert_bar()` inserts into `bar_data (symbol, timeframe, timestamp, open, high, low, close, volume)` with no `source` field distinguishing IBKR vs Polygon bars. With sp