{
  "version": 1,
  "sharedInterfaces": "Serial graph: contracts -> generated launch.json -> independent review -> verified deployment -> frontend integration. The control plane inserts the manifest integrate-role node; review directly depends on it and contracts. No parallel writers or pre-invented ABI. Contracts hand off artifacts/abi/VolatilityGuardHook.json, artifacts/abi/VolatilityGuardToken.json, docs/architecture.md, docs/threat-model.md, docs/integration.md and docs/contract-validation.md; review consumes these and launch.json. Frontend consumes these plus .imd/reads/deployment.json only after live launch validation. Services alone publish source, attest, admit and broadcast; workers never receive keys, broadcast, deploy helpers or spend funds. Permissions: Sepolia 11155111 only, univ4_hook policy v2, never mainnet; existing deployer gas ceiling 0.3 Sepolia ETH, no additional funding. GitHub uses signed publisher configured org/automatic launch repository naming; IPFS uses configured Pinata/automatic naming, authorized. Service completion requires real source, receipts/test evidence, live seeded contracts, verified handoff, frontend source, pinned CID and named ENS site. Assign post-publication HTTP/IPFS reachability and read-only functional smoke validation to publisher/hosting validation; record actual results before overall completion. No live signed swap testing is authorized. Workers finish before their subsequent services; mocks never establish live integration. No research or repair nodes.",
  "steps": [
    {
      "key": "contracts",
      "skill": "build-contract-project",
      "dependsOn": [],
      "references": [
        "uniswap-v4-hooks",
        "uniswap-v4-security",
        "defi-native",
        "public-rpcs"
      ],
      "objective": "From the empty source, create the entire standalone pinned/vendored Foundry project, setup/configuration (including foundry.toml with bytecode_hash=none), ordinary-file dependencies without submodules, VolatilityGuardHook, VolatilityGuardToken, tests, ABI exports and docs. This first complete-project writer owns initial setup; subsequent workers preserve accepted source/configuration/dependencies. Implement the requested guard and launch behavior, with no discretionary admin powers or total-MEV-protection claims. Supply manifest-ready deployment parameters and local factory/pool integration simulations, not broadcasts. Verify the canonical Sepolia PoolManager 0xe03a1074c86cfedd5c142c4f04f1a1536e203543 and existing verified periphery; deploy no new helper. Export implementation-derived ABI JSON to artifacts/abi/VolatilityGuardHook.json and artifacts/abi/VolatilityGuardToken.json. Deliver docs/architecture.md, docs/threat-model.md, docs/integration.md and docs/contract-validation.md plus a usable README with offline build/test commands, assumptions, deployment parameters and operational responsibilities. Docs define actual getters/events, units, decoded errors, exact pool key and executable quote/swap/liquidity recipes for the later frontend; do not guess interfaces before implementation.",
      "acceptanceCriteria": [
        "Hook isolates every PoolId, supports arbitrary currencies and bounded observation ring/TWAP plus EWMA volatility, adaptive price-deviation limits and rolling volume budgets resistant to split swaps. Implement NORMAL/WARMUP/GUARDED/RECOVERY, stale/low-liquidity handling and deterministic recovery; LP exits and initialization/warmup stay possible. Explain how recovery works when reverts cannot persist breaker transitions.",
        "Authenticate canonical PoolManager callbacks and accounting; never trust sender/hookData identity. Specify/test both directions, exact input/output, units, signed amounts, rounding, bounded execution and caps; prevent unauthorized callbacks/reentrancy and accounting inconsistencies. No extra admin behavior. Every token/hookAdmin/treasury/LP owner is 0x09ec38170e94532eddb57c69dfc4f1fdcd0d4a60.",
        "VolatilityGuardToken is Volatility Guard Lab (VGL), 18 decimals, no constructor args; fixed 10^27 base units minted to deployer with no mint backdoor. Preserve 80% LP, 10% treasury, 10% contributors, 1h contributor lock and 30% per-wallet cap; document allocation enforcement and units for policy/manifest review.",
        "Pool pairs VGL with native ETH (zero address), static fee 3000, tickSpacing 60, initial sqrtPriceX96 792281625142643375935439503360000 (0.00000001 ETH/VGL). Factory seeds up to 8e26 VGL units and ZERO ETH; derive widest aligned token-only range from opening price/spacing and round liquidity down. Simulate initialization, seeding, ETH-first buys, reverse trades after ETH accrual and LP exits through actual contract interactions.",
        "Run offline forge build, forge test and forge fmt --check with pinned/vendored ordinary dependencies. Include meaningful success/failure, fuzz, invariant and stress tests covering accounting, isolation, manipulation, split volume, unauthorized callbacks, reentrancy, stale history, edge values, recovery and LP exits. Record actual test counts, fuzz/invariant settings, gas, contract sizes, failures and limitations; surface undeployable bytecode as blocking.",
        "ABI exports match implemented contracts. Architecture/threat-model/integration docs specify real public actions, telemetry/events, exact ordered pool key, existing verified quote/router/position-manager addresses and ABIs, allowances, slippage, native-value handling, liquidity/exit recipes, permissions, decoded errors, assumptions and operational risks. Document supported position discovery without assuming a position ID in the later handoff.",
        "Provide reproducible factory deployment inputs and evidence suitable for generated launch.json review under Sepolia univ4_hook policy v2; validate hook address permission bits, constructor/code hashes, owners, supply/allocation/lock/cap, token-only range, liquidity rounding and configured gas ceiling. No keys, broadcasts, extra helper deployment, discretionary powers, new funding or mainnet authorization."
      ]
    },
    {
      "key": "review",
      "skill": "adversarial-review",
      "dependsOn": [
        "contracts"
      ],
      "objective": "Independently review all accepted contract source, dependencies, tests, ABI/docs and the control-plane-generated launch.json BEFORE deployment, on a different device and wallet from authors. This read-only review directly depends on the contracts writer and generated manifest node; add no writable paths. Attack concrete accounting, guard, initialization, recovery and launch-policy states and reproduce defects where possible. Report severity-ranked findings with concrete failing inputs/states and truthful validation evidence. Use the control plane bounded repair/re-review mechanism, at most two revisions: blocking findings reopen direct source/manifest dependencies, regeneration precedes re-review, and unresolved blockers prohibit launch admission. Do not add a repair worker node or require live receipts to finish review.",
      "acceptanceCriteria": [
        "Every finding names a concrete failing input or state, impact, severity and reproduction evidence; distinguish tested properties from assumptions and limitations. Review is independent of authors by device and wallet and writes no repository files.",
        "Inspect code AND generated launch.json, ABI hashes, deployment bytecode/configuration, factory compatibility and hook permission bits. Verify canonical PoolManager and existing verified periphery, chain 11155111, native ETH/VGL key, fee 3000, spacing 60, initial sqrt price, owners, fixed supply/splits, 1h lock, 30% cap, zero ETH seed, maximum VGL seed, range/liquidity rounding and existing 0.3 ETH gas ceiling.",
        "Challenge accounting/callback authentication, sender/hookData misuse, arbitrary currencies, both swap directions and exact input/output, units/rounding/caps, isolation, TWAP/EWMA manipulation, split volume, stale/low liquidity, edge values, reentrancy, all state transitions and deterministic recovery including non-persisting revert transitions. Verify initialization, bootstrap and exits cannot brick.",
        "Inspect and run applicable offline build/test/fmt and adversarial checks; assess fuzz/invariant/stress coverage, actual counts, gas and deployability, not only successful mocks. Inspect documented swap/quote/liquidity integration and economic limitations, no mint backdoor, extra administration, helper deployment or total MEV protection claim.",
        "Publish review findings through the review result, including manifest consistency and remaining limitations. Blocking findings must be fixed and re-reviewed before service admission; unresolved blockers after two revisions stay recorded and refuse deployment. Review completion is source/manifest based and never contingent on later live deployment receipts."
      ]
    },
    {
      "key": "frontend",
      "skill": "frontend-for-contract",
      "dependsOn": [
        "review"
      ],
      "paths": [
        "web/**",
        "dist/**",
        "docs/**"
      ],
      "objective": "Final integration step joining the serial workflow: after independent review and service-verified live deployment, consume the contract ABI/docs and .imd/reads/deployment.json pinned sourceCommit; build React/Vite/TypeScript with RainbowKit/wagmi/viem in web/ and commit a relative-base static export in dist/. Keep package configuration, lockfile and needed dependencies in web/; preserve accepted contracts, root configuration/dependencies and lockfiles. Write instructions/evidence only in docs/ or web/, never root README.md or artifacts/. Integrate actual deployed contracts and verified existing periphery; include explanatory information, live dashboard, primary ETH/VGL swaps, supported-position exits and explicitly labeled simulation demos. Centralize public addresses/chain/ABI/RPC configuration without credentials; support injected wallets without extra credentials. Submit source, export and docs/frontend-validation.md before publication. Services subsequently publish source and pin/name the site; post-publication validation owns reachability and functional smoke evidence. Do not require a published URL/CID or contributor-signed live swap receipt for worker completion.",
      "acceptanceCriteria": [
        "Consume only promised handoff fields: version, launchId, chainId, repoUrl, sourceCommit, attestationHash, manifest, contracts and abiInstructions; contracts supply name/address/txHash/blockNumber/creationCodeHash/abiHash. Build ABIs from exact sourceCommit, compare canonicalKeccak(abi) to abiHash and verify deployed code/chain before enabling transactions. Missing/mismatched evidence disables affected actions with a useful explanation.",
        "Fetch receipts and derive position/allocation data from manifest, transaction hashes, logs and public chain reads where needed. Handoff does not promise full receipts, seeded position IDs, allocation proofs, live swap receipts or frontend URLs. Never fabricate them. Position exits require discovered/entered verified supported positions and connected-wallet ownership/authorization; do not assume deployer authority.",
        "Responsive UI explains hook behavior, all states, bootstrap, risks and limitations without claiming total MEV protection. Live dashboard reads tick/TWAP, EWMA volatility, deviation, volume budget/state and events from real deployed interfaces, clearly marking unavailable/stale/RPC-error states and keeping simulation data explicitly labeled.",
        "Primary ETH/VGL swap controls cover amounts, both directions, balances/max with gas allowance, real periphery quotes, slippage/minimum received and exact-input/output semantics supported by contract recipes, approvals and visitor-wallet-signed swaps. Show pending/success/reverted/rejected states, decoded errors and Sepolia explorer links. Explain token-only bootstrap: buy with ETH first; reverse trades depend on accrued ETH liquidity.",
        "Expose every primary supported contract action, including supported-position exits, with live connected-wallet reads and configured chain checks. Integrate actual ABIs, pool key, router/quote/liquidity recipes and decoded errors; validate live code/state and read-only quote behavior. Do not deploy helpers, request service keys, invent worker spending authority or fabricate successful live interactions.",
        "Run production build, TypeScript checks and meaningful responsive/interaction validation for both directions, wallet disconnected/connected, wrong chain, rejected signing, approvals, pending/success/reverted transactions, guard errors, insufficient funds, RPC failures, bootstrap/reverse-liquidity constraints and exits. Signing/error mocks follow actual ABI/provider interfaces and are labeled; validate real integration separately with public reads and local simulations without spending.",
        "Commit dist/index.html and relative assets alongside source and web/ lockfile; ensure reproducible dependencies are ordinary files available offline where needed, not submodules. Document install/preview/rebuild/publish commands in web/README.md and integration/evidence in docs/. Record actual results and untested live-chain behavior in docs/frontend-validation.md; static export/source/evidence finish this worker, publication/CID/naming/reachability finish services."
      ]
    }
  ],
  "questions": []
}
