{
  "version": 1,
  "sharedInterfaces": "Sequential workflow. Contract handoff: abi/VolatilityGuardHook.json and abi/VolatilityGuardToken.json, docs/integration.md defining typed reads/events, units, rounding, decoded errors and canonical periphery quote/swap/exit recipes. Live dashboard reads expose per-PoolId tick/TWAP, EWMA volatility, adaptive deviation limit, rolling volume, state and history freshness. Frontend consumes these actual ABIs and the verified deployment handoff: chainId, addresses, runtime verification, pool key/id, start block, seeded position and real transaction receipts. No invented addresses. Mocks implement the documented ABI/errors and wallet lifecycle, remain labeled simulation/test fixtures, and never supply production quotes, receipts or dashboard success. Dependencies need actual outputs. Control plane adds the sole integrate-role launch manifest (sixth assignment); do not add integrate-project. Review both code and manifest, regenerate/review manifest after fixes, and block deployment until findings are closed. Only authorized services deploy/publish: Sepolia 11155111, existing signed publisher configured GitHub org with automatic repository naming, configured Pinata with automatic naming. Workers never receive keys or broadcast. Verified factory deployment precedes frontend execution; final frontend acceptance joins all actual outputs and service publication evidence. No new destination, funding, mainnet, helper deployment or discretionary admin authority.",
  "steps": [
    {
      "key": "contracts_and_tests",
      "skill": "build-contract-project",
      "dependsOn": [],
      "paths": [
        "src/**",
        "test/**",
        "script/**",
        "abi/**",
        "docs/**",
        "README.md",
        "artifacts/contracts/**",
        ".gas-snapshot"
      ],
      "references": [
        "uniswap-v4-hooks",
        "uniswap-v4-security",
        "defi-native",
        "public-rpcs"
      ],
      "objective": "Implement and test VolatilityGuardHook and VolatilityGuardToken as a complete Foundry deliverable using the accepted pinned/vendored dependencies and configuration, bytecode_hash=none. Do not rewrite protected configuration, foundry.toml, remappings.txt, lib/ or .github/; flag an incompatible/missing base as a blocker. Produce actual offline build/test/fmt evidence, ABI JSON, architecture/threat-model/integration documentation and factory launch inputs for the automatically added manifest. References are background, not a research assignment. Scripts only simulate; workers never receive keys or broadcast. Preserve all operator settings and Sepolia-only authorization. Define explicit bounded mathematical formulas, units, rounding, thresholds and deterministic state transitions, with no extra admin powers.",
      "acceptanceCriteria": [
        "VGL is Volatility Guard Lab, 18 decimals, no constructor arguments, exactly 10^27 base units minted to deployer, fixed supply with no mint backdoor. All token/hookAdmin/treasury/LP owners are 0x09ec38170e94532eddb57c69dfc4f1fdcd0d4a60. Allocation: 80% LP, 10% treasury, 10% contributors with 1h lock and 30% per-wallet cap; no additional ownership powers.",
        "Hook supports arbitrary currencies and isolates every PoolId; bounded observation ring/TWAP and EWMA volatility drive adaptive price-deviation limits and a rolling volume budget resistant to split swaps. Specify both directions and exact-input/output accounting, currency units, conservative rounding, bounded execution and caps.",
        "NORMAL/WARMUP/GUARDED/RECOVERY handle stale history and low liquidity with deterministic recovery. Initialization/warmup cannot brick the pool, LP exits remain possible, and breaker logic never relies on reverted writes persisting. Authenticate canonical PoolManager callbacks/accounting; sender/hookData never establish trusted identity. No discretionary administration or total-MEV-protection claims.",
        "Verify Sepolia chain 11155111 PoolManager 0xe03a1074c86cfedd5c142c4f04f1a1536e203543. ETH currency is zero address; canonical sorted ETH/VGL pool uses static fee 3000, tickSpacing 60, sqrtPriceX96 792281625142643375935439503360000 (0.00000001 ETH/VGL). Hook permission address bits and factory deployment parameters match actual bytecode and callbacks.",
        "Factory seeds at most 8e26 VGL base units and ZERO ETH. Derive widest aligned token-only range from opening price/spacing and round liquidity down; simulate actual pool initialization, allocation and seeded position wiring. Use only existing verified periphery and no new deployed helper. Gas uses configured deployer within existing 0.3 Sepolia ETH ceiling; no additional funds/spending authorization.",
        "Pinned/vendored project builds without network or submodules. Run forge build, forge test, forge fmt --check offline; meaningful success/failure, fuzz/invariant/stress coverage includes accounting, isolation, manipulation/split volume, unauthorized callbacks, reentrancy, stale history, edge values, recovery and LP exits. Record actual test counts, gas, failures and limitations; deployed size above 24576 bytes is a blocker.",
        "Export real ABI JSON and document architecture, threat model, exact pool key, quote/swap/liquidity/position-exit recipes, decoded errors, deployment parameters/defaults, operational responsibilities and reproducible commands. Provide local nonbroadcast deployment simulation and wiring test; retain test evidence and gas snapshot in the owned paths.",
        "Launch inputs expose exact bytecode/ABI, constructor and factory parameters, allocations/locks, ownership, hook permissions, zero-ETH seed math and budget for automatic manifest generation. No manufactured deployment receipts or addresses; source and evidence are ready for authorized publication, with unsafe/unfinished aspects explicit."
      ]
    },
    {
      "key": "independent_review",
      "skill": "adversarial-review",
      "dependsOn": [
        "contracts_and_tests"
      ],
      "objective": "Independently review all contract, test, script and documentation output plus the control-plane-generated launch manifest against the original request and resolved Sepolia univ4_hook policy v2. This is read-only and must receive the actual implementation and generated manifest before starting. Attack the implementation and launch configuration; do not deploy. Return concrete ranked findings and a blocking/nonblocking disposition.",
      "acceptanceCriteria": [
        "Every finding names a concrete failing input or state and is ranked by severity; inspect code AND launch manifest, including actual tests and evidence rather than trusting claimed success.",
        "Check PoolManager authenticity, hook address permissions, accounting and rounding for both directions/exact modes, arbitrary currencies, per-pool isolation, bounded execution, manipulated observations, split volume, reentrancy, stale/low liquidity, recovery, revert persistence and LP exits.",
        "Check supply, contributor lock/cap and allocations, fixed ownership/no extra powers, exact pool price/fee/spacing, verified existing periphery, token-only widest aligned rounded-down seed, zero ETH, configured deployer gas ceiling, chain 11155111 and no keys/broadcast/helper/mainnet permissions.",
        "Review offline build/test/fmt and fuzz/invariant/stress evidence, actual counts/gas/limitations, ABI and integration recipes. Blocking findings prevent verified deployment and frontend handoff."
      ]
    },
    {
      "key": "repair_findings",
      "skill": "fix-findings",
      "dependsOn": [
        "contracts_and_tests",
        "independent_review"
      ],
      "paths": [
        "src/**",
        "test/**",
        "script/**",
        "abi/**",
        "docs/**",
        "README.md",
        "artifacts/contracts/**",
        ".gas-snapshot"
      ],
      "objective": "Resolve exactly the independent review findings requiring changes, preserving original behavior and launch permissions. Fix blocking findings with regression tests or provide concrete evidence that a finding does not hold. If none require fixes, record the no-change disposition without unrelated edits. Refresh affected ABI, evidence and launch inputs; have the control plane regenerate the manifest for re-review. Never modify protected configuration/dependencies or deploy.",
      "acceptanceCriteria": [
        "Every blocking finding is fixed with a regression test or answered with a substantiated reason; unresolved blockers remain deployment blockers, never silently waived.",
        "Diff touches only what findings named and remains inside the assigned scope. No new admin behavior, authorization, helper deployment or destination is introduced.",
        "forge test passes including regressions; rerun offline build and fmt checks and relevant fuzz/invariant/stress checks for changed behavior, recording actual outcomes and updated gas/limitations.",
        "Updated ABI/docs/launch inputs remain consistent with repaired code; regenerated manifest is an explicit input to final independent review."
      ]
    },
    {
      "key": "release_review",
      "skill": "adversarial-review",
      "dependsOn": [
        "contracts_and_tests",
        "repair_findings",
        "independent_review"
      ],
      "objective": "Independently re-review the final code, tests, regression evidence and regenerated launch manifest. Depend directly on both writers and verify every blocker disposition. Provide a read-only release assessment to the authorized deployment service; do not broadcast or hold keys. Deployment must wait for this assessment and verified policy compliance, and frontend must wait for the resulting actual verified deployment handoff.",
      "acceptanceCriteria": [
        "Review directly covers every writer, final code AND final manifest. Findings identify concrete inputs/states and severity; every prior blocking finding has a verified resolution, with no outstanding blocker accepted for deployment.",
        "Confirm the exact Sepolia pool, owners, supply/allocations/lock/cap, hook permission bits, canonical PoolManager, verified periphery and factory bytecode/parameters match code and manifest. Recheck token-only zero-ETH seed and gas ceiling with no extra permissions.",
        "Gate handoff on authorized service verification of deployed source/runtime, factory deployment and seeded-pool receipts, actual addresses/pool key/start block/position details and allocation evidence. Failed or unavailable deployment remains incomplete; simulations are not live receipts.",
        "Workers never receive deployment keys or broadcast. No mainnet, unapproved funding, new helper or discretionary admin powers. Record actual review/check limitations and residual risks for frontend disclosure."
      ]
    },
    {
      "key": "frontend_and_launch",
      "skill": "frontend-for-contract",
      "dependsOn": [
        "contracts_and_tests",
        "independent_review",
        "repair_findings",
        "release_review"
      ],
      "paths": [
        "web/**",
        "dist/**",
        "README.md",
        "docs/**",
        "artifacts/launch/**"
      ],
      "objective": "Final proposed assignment joins all accepted outputs after the authorized service provides verified live Sepolia contracts and a seeded pool. Build the complete React/Vite/TypeScript + RainbowKit/wagmi/viem dapp in web/ with committed relative-base dist/ export. Use actual accepted ABIs, deployment receipts and verified existing periphery. Validate real interactions and prepare source, receipts and test evidence for the existing signed GitHub publisher and static site for configured Pinata. Only these already-authorized services publish, using configured org/service and automatic naming; no caller repo/CID is needed. Record returned real repository/IPFS URLs and verify the functional public site. No additional integrate-project step; the automatic manifest supplies the sole integrate-role assignment.",
      "acceptanceCriteria": [
        "Deliver responsive usable site, source and lockfile, dist/index.html and assets with relative URLs suitable for static/IPFS hosting. Centralize actual chain IDs, addresses, ABIs and public RPC configuration without private credentials. Injected wallets work without extra credentials; README explains install, preview, rebuild and publish.",
        "Explain hook mechanics, threat model and limitations with no total MEV protection claim. Live dashboard shows per-pool tick/TWAP, volatility, deviation, rolling volume/state/events and stale/RPC failures; simulation demos are explicitly labeled and isolated from live data.",
        "Primary ETH/VGL swaps support direction/amount, balances/max including gas needs, actual periphery quotes, slippage/minimum received, required approvals, wallet-signed swaps, pending/success/failure states, decoded errors and explorer links. All primary contract actions have appropriate controls and connected reads show live state; no fabricated quotes/receipts.",
        "Explain and enforce token-sided bootstrap: buy with ETH first; reverse trades depend on accrued ETH liquidity. Offer supported-position exits through existing verified periphery and validate position ownership/permissions. No new deployed helper, spending authority, discretionary admin controls or worker-signed user transactions.",
        "Run production build, typecheck and meaningful responsive/interaction tests for both swap directions, wallet/chain states, rejected signing, guard reverts, funds/RPC errors, approvals and exits. Document actual results and untested live-chain behavior; mocks validate components only and never prove deployed integration.",
        "Integrate actual ABIs, verified deployment handoff and seeded pool; verify reachable Sepolia reads and real quote/swap wiring against existing periphery. Exercise both directions where accrued ETH permits and inspect actual receipts where authorized transactions exist; do not invent signing/spending permission to complete tests. Any missing required live proof blocks completion.",
        "Authorized publisher publishes real source, contract/frontend test evidence, verified source and deployment receipts to its configured GitHub org with automatic repository naming; configured Pinata publishes static export with automatic naming. Record actual URLs/CID and check public repository evidence and functional reachable IPFS site with relative assets and live configuration.",
        "Final acceptance covers all preceding branches and original requirements: contracts live and verified on Sepolia with real seeded pool, blockers repaired and independently cleared, source/evidence published and functional IPFS dapp reachable. Missing/failed service handoffs or live checks remain explicit incompletion, never mock success. Preserve existing 0.3 Sepolia ETH gas ceiling and all destination permissions."
      ]
    }
  ],
  "questions": []
}
