{
  "steps": [
    {
      "key": "contracts",
      "skill": "build-contract-project",
      "dependsOn": [],
      "objective": "Build and test the complete VolatilityGuard Lab Foundry project from the supplied empty source, including initial setup and pinned ordinary-file vendored dependencies, VolatilityGuardHook and VolatilityGuardToken, ABI exports and architecture/threat-model/integration documentation. This complete-project writer owns initial project setup; preserve any protected existing configuration/dependencies. Set bytecode_hash=none and prove offline build/test/fmt. Implement the coupled hook/token and launch-ready integration without deploying anything, new deployed helpers, factory/policy commissioning or extra admin behavior. Use the supplied DeFi references as implementation background, not a research assignment. Supply actual test/gas/size/failure/limitation evidence and all source inputs needed by the control-plane manifest. Repair blocking independent-review findings before deployment.",
      "references": [
        "uniswap-v4-hooks",
        "uniswap-v4-security",
        "defi-native",
        "public-rpcs"
      ],
      "acceptanceCriteria": [
        "Hook isolates every PoolId, supports arbitrary currencies, uses bounded observation ring/TWAP and EWMA volatility, adaptive price-deviation limits and rolling volume budgets resistant to split swaps. Define NORMAL/WARMUP/GUARDED/RECOVERY, stale/low-liquidity behavior and deterministic recovery; initialization/warmup cannot brick the pool and LP exits remain possible. Breaker transitions must not rely on reverted writes.",
        "Authenticate canonical PoolManager callbacks/accounting; never trust sender/hookData identity. Specify both directions, exact-input and exact-output, units, rounding, caps and bounded execution. No discretionary admin powers or claims of total MEV protection. Verify Sepolia PoolManager 0xe03a1074c86cfedd5c142c4f04f1a1536e203543 and existing verified periphery; no newly deployed helper.",
        "VolatilityGuardToken is Volatility Guard Lab (VGL), 18 decimals, no constructor arguments, fixed 10^27 units minted to deployer, no mint backdoor. Pair native ETH (zero address) with VGL using static fee 3000, tickSpacing 60, initial sqrtPriceX96 792281625142643375935439503360000 (0.00000001 ETH/VGL); document the exact sorted pool key and hook permissions.",
        "Preserve all token/hookAdmin/treasury/LP owners as 0x09ec38170e94532eddb57c69dfc4f1fdcd0d4a60, with no extra admin behavior. Supply allocations: 80% LP, 10% treasury, 10% contributors, 1h contributor lock and 30% per-wallet cap. Launch specification uses resolved Sepolia univ4_hook policy v2, not worker-chosen ownership or policy.",
        "Factory seeds up to 8e26 VGL units and ZERO ETH. Document/test the deployer derivation of widest aligned token-only range from opening price/spacing, rounding liquidity down. Gas comes from configured deployer under existing 0.3 Sepolia ETH ceiling; no additional funding/spending authority. No worker keys or broadcasts.",
        "Pinned/vendored ordinary files support network-free build, test and fmt with bytecode_hash=none, no submodules. Run meaningful fuzz/invariant/stress coverage for accounting, isolation, manipulation/split volume, unauthorized callbacks, reentrancy, stale history, edge values, recovery and LP exits, including swap modes/directions; record actual counts, gas, sizes, failures and limitations in docs/contract-evidence.md.",
        "Export valid ABI JSON at docs/abi/VolatilityGuardHook.json and docs/abi/VolatilityGuardToken.json. Deliver architecture/threat-model docs and docs/integration.md defining dashboard reads/events, units, exact pool key, quote/swap/liquidity recipes, supported-position exits and decoded errors. Explain token-only bootstrap and accrued-ETH limits for reverse swaps; evidence contains no fabricated receipts."
      ]
    },
    {
      "key": "contract_review",
      "skill": "adversarial-review",
      "dependsOn": [
        "contracts"
      ],
      "objective": "Independently inspect contract source, tests, ABI exports, integration documentation and the control-plane-generated launch manifest before deployment. Run the required Foundry checks and challenge the security/accounting assumptions and resolved launch parameters. Write nothing. Report blocking findings to the contracts author and independently recheck repairs; deployment is gated on clearance. Manifest generation and deployment are service operations, not worker tasks.",
      "acceptanceCriteria": [
        "Review directly covers the contracts writer and the generated manifest, checks per-pool isolation, callback authentication, units/rounding, all swap modes, manipulation/split volume, bounded execution, stale/low-liquidity recovery, reverted transitions, initialization and LP exits; assess meaningful fuzz/invariant/stress evidence and remaining limitations.",
        "Check token supply/ownership/allocations/lock/cap, canonical Sepolia PoolManager, verified periphery, hook permission bits, exact ETH/VGL pool key/opening price and token-only range/liquidity arithmetic against the approved requirements. Confirm zero ETH seed, 8e26 VGL seed ceiling, 0.3 Sepolia ETH gas ceiling and no extra admin powers, helpers, funding or mainnet authorization.",
        "Validate offline reproducibility, ABI/documentation consistency and manifest source/bytecode linkage. Clearly report findings, evidence and limitations; all blocking findings must be repaired by the author and independently cleared before the control plane deploys. The reviewer neither edits files nor broadcasts."
      ]
    },
    {
      "key": "frontend",
      "paths": [
        "web/**",
        "dist/**",
        "docs/**"
      ],
      "skill": "frontend-for-contract",
      "dependsOn": [
        "contracts",
        "contract_review"
      ],
      "objective": "After independent contract clearance AND actual verified deployment handoff at .imd/reads/deployment.json, build the complete responsive public VolatilityGuard Lab swap dapp using React/Vite/TypeScript and RainbowKit/wagmi/viem. Keep all frontend source, package.json, lockfiles and build configuration in web/, committed relative-base static export in root dist/, and documentation in docs/ or web/. Root configuration/lockfiles remain protected. Use pinned deployed addresses and ABI hashes with verified existing periphery. Deliver source, export and meaningful tests/evidence; the control plane publishes and validates the live site. Finish by validating the integrated dapp against the reviewed contracts, manifest and actual deployment; repair frontend integration failures within this scope.",
      "acceptanceCriteria": [
        "Validate deployment handoff chainId 11155111, addresses, pinned source and ABI hashes against docs/abi and integration docs; use actual deployments only. Injected wallets work without extra credentials. No worker keys, broadcasting deployments, new helpers, fabricated quotes or fabricated receipts.",
        "Provide hook explanation and candid risk/limitation information without total-MEV-protection claims; live pool dashboard shows tick/TWAP, volatility, deviation, rolling volume, state and events with accurate units and unavailable/stale/RPC states.",
        "Primary ETH/VGL swap UI supports amounts, direction, balances/max, real quotes, slippage/minimum received, necessary approvals, wallet-signed swaps, transaction progress/errors and explorer links. Implement against documented verified periphery and actual pool; expose actionable decoded guard errors.",
        "Explain and handle token-sided bootstrap: buy with ETH first and allow reverse trades according to accrued ETH liquidity. Provide supported-position exits and clearly labeled simulation demos, distinct from actual quotes/transactions.",
        "Test both swap directions, wallet connection and chain states, rejected signing, guard reverts, insufficient funds/RPC failures and responsive UI. Record actual results/limitations in docs/frontend-evidence.md; validate production build and relative asset paths for the committed dist/ export. No service publication receipts or live URL are worker prerequisites.",
        "Final integration checks join reviewed contract ABIs/docs and actual deployment with web/ and dist/: verify manifest/source/address/ABI linkage, quote and wallet transaction construction, approvals/slippage, dashboard units/events and supported exits. Resolve frontend failures; contract blockers require author repair and independent pre-deployment review again. Submit real source, static export and evidence for service publication."
      ]
    }
  ],
  "version": 1,
  "questions": [],
  "sharedInterfaces": "Sequential handoffs: contracts produces a complete offline Foundry project, docs/abi/VolatilityGuardHook.json, docs/abi/VolatilityGuardToken.json, and docs/integration.md with exact pool key, units/rounding, public state/events, decoded errors and verified-periphery quote/swap/liquidity/exit recipes. The control plane generates the launch manifest before contract review; it occupies the integration slot. Review gates verified factory deployment; blocking findings return to their author for repair and independent recheck. Frontend also waits for actual .imd/reads/deployment.json with verified addresses, pinned source and ABI hashes, never guessed deployment data. Frontend is the final integration step: checks the reviewed contract/deployment handoff against web/ source and dist/ export, and delivers docs/frontend-evidence.md. Writers are sequential; review is read-only. Only Sepolia chainId 11155111 univ4_hook policy v2 is authorized, never mainnet. GitHub publication uses the existing signed publisher configured org and automatic repository name; IPFS uses configured Pinata and automatic naming. No caller repository/CID or new credentials are required. Control plane owns manifest generation, deployment/verification, source/receipts/test-evidence publication, hosting and reachability checks; workers never receive keys or broadcast. Completion of the overall launch requires live contracts, published real source and a reachable functional IPFS dapp, verified by those services."
}
