{
  "steps": [
    {
      "key": "contracts",
      "skill": "build-contract-project",
      "dependsOn": [],
      "objective": "From the empty source, create the complete standalone Foundry project: initial configuration including foundry.toml with bytecode_hash=none, pinned ordinary-file vendored dependencies without submodules, src/VolatilityGuardHook.sol, src/VolatilityGuardToken.sol and test/ suites. This serial complete-project writer supplies all missing setup; later stages preserve accepted setup. Implement and locally simulate the requested guard, factory launch and seeded-pool interactions without broadcasting. Verify canonical Sepolia PoolManager 0xe03a1074c86cfedd5c142c4f04f1a1536e203543 and existing verified periphery; no deployed helper or discretionary admin powers. Export implementation-derived ABIs to docs/abi/VolatilityGuardHook.json and docs/abi/VolatilityGuardToken.json. Produce docs/architecture.md, docs/threat-model.md, docs/integration.md, docs/contract-validation.md and README.md. Document actual APIs, errors, units, pool key, verified periphery ABIs/addresses and quote/swap/liquidity recipes; docs/integration.md also supplies reproducible deployment parameters for the generated manifest. README covers offline commands and operational responsibilities. Review consumes these files and the system-generated launch.json; the later frontend consumes the same pinned source/docs and verified deployment handoff. Do not pre-invent ABIs.",
      "references": [
        "uniswap-v4-hooks",
        "uniswap-v4-security",
        "defi-native",
        "public-rpcs"
      ],
      "acceptanceCriteria": [
        "Hook isolates every PoolId, supports arbitrary currencies and bounded observation ring/TWAP plus EWMA volatility, adaptive price-deviation limits and rolling volume budgets resistant to split swaps. Implement NORMAL/WARMUP/GUARDED/RECOVERY, stale/low-liquidity handling and deterministic recovery; LP exits and initialization/warmup stay possible. Explain how recovery works when reverts cannot persist breaker transitions.",
        "Authenticate canonical PoolManager callbacks and accounting; never trust sender/hookData identity. Specify/test both directions, exact input/output, units, signed amounts, rounding, bounded execution and caps; prevent unauthorized callbacks/reentrancy and accounting inconsistencies. No extra admin behavior. Every token/hookAdmin/treasury/LP owner is 0x09ec38170e94532eddb57c69dfc4f1fdcd0d4a60.",
        "VolatilityGuardToken is Volatility Guard Lab (VGL), 18 decimals, no constructor args; fixed 10^27 base units minted to deployer with no mint backdoor. Preserve 80% LP, 10% treasury, 10% contributors, 1h contributor lock and 30% per-wallet cap; document allocation enforcement and units for policy/manifest review.",
        "Pool pairs VGL with native ETH (zero address), static fee 3000, tickSpacing 60, initial sqrtPriceX96 792281625142643375935439503360000 (0.00000001 ETH/VGL). Factory seeds up to 8e26 VGL units and ZERO ETH; derive widest aligned token-only range from opening price/spacing and round liquidity down. Simulate initialization, seeding, ETH-first buys, reverse trades after ETH accrual and LP exits through actual contract interactions.",
        "Run offline forge build, forge test and forge fmt --check with pinned/vendored ordinary dependencies. Include meaningful success/failure, fuzz, invariant and stress tests covering accounting, isolation, manipulation, split volume, unauthorized callbacks, reentrancy, stale history, edge values, recovery and LP exits. Record actual test counts, fuzz/invariant settings, gas, contract sizes, failures and limitations; surface undeployable bytecode as blocking.",
        "ABI exports match implemented contracts. Architecture/threat-model/integration docs specify real public actions, telemetry/events, exact ordered pool key, existing verified quote/router/position-manager addresses and ABIs, allowances, slippage, native-value handling, liquidity/exit recipes, permissions, decoded errors, assumptions and operational risks. Document supported position discovery without assuming a position ID in the later handoff.",
        "Provide reproducible factory deployment inputs and evidence suitable for generated launch.json review under Sepolia univ4_hook policy v2; validate hook address permission bits, constructor/code hashes, owners, supply/allocation/lock/cap, token-only range, liquidity rounding and configured gas ceiling. No keys, broadcasts, extra helper deployment, discretionary powers, new funding or mainnet authorization.",
        "The generated launch.json is a later control-plane deliverable, not this worker's output. Supply contract names, getHookPermissions values, pool and decimal sqrtPriceX96 for kind=univ4_hook; notes must fit 4000 characters. Supply/allocation/ownership are policy inputs, not extra manifest fields; document their implementation and policy assumptions separately in docs/integration.md."
      ]
    },
    {
      "key": "review",
      "skill": "adversarial-review",
      "dependsOn": [
        "contracts"
      ],
      "objective": "Independently review src/ contracts, vendored dependencies, test/ suites, README.md, docs/abi/*.json, docs/architecture.md, docs/threat-model.md, docs/integration.md, docs/contract-validation.md and the generated launch.json before deployment. Read-only: no writable paths or repository outputs. Use a different device and wallet from accepted-work authors. Directly depend on contracts; the control plane also inserts the generated manifest as a direct prerequisite, as in executionPreview. Attack concrete accounting, guard, initialization, recovery and launch-policy states. Return severity-ranked findings, failing inputs/states and reproducible evidence through the review result. Blocking findings reopen direct source/manifest dependencies for at most two revisions; regenerate manifest before re-review. Unresolved blockers prohibit admission. Review finishes on source/manifest evidence, without future receipts or deployed addresses.",
      "acceptanceCriteria": [
        "Every finding names a concrete failing input or state, impact, severity and reproduction evidence; distinguish tested properties from assumptions and limitations. Review is independent of authors by device and wallet and writes no repository files.",
        "Check source and schema-valid launch.json: kind=univ4_hook, notes <=4000 characters, contract names, declared permission bits, pool and initial sqrt price. Cross-check owners, fixed supply/splits, 1h lock, 30% cap, zero ETH seed, <=8e26 VGL seed, range rounding and 0.3 ETH ceiling against resolved policy and source/docs, not nonexistent manifest allocation fields. Verify chain 11155111, canonical PoolManager, verified periphery, ABI hashes and factory compatibility.",
        "Challenge accounting/callback authentication, sender/hookData misuse, arbitrary currencies, both swap directions and exact input/output, units/rounding/caps, isolation, TWAP/EWMA manipulation, split volume, stale/low liquidity, edge values, reentrancy, all state transitions and deterministic recovery including non-persisting revert transitions. Verify initialization, bootstrap and exits cannot brick.",
        "Inspect and run applicable offline build/test/fmt and adversarial checks; assess fuzz/invariant/stress coverage, actual counts, gas and deployability, not only successful mocks. Inspect documented swap/quote/liquidity integration and economic limitations, no mint backdoor, extra administration, helper deployment or total MEV protection claim.",
        "Publish review findings through the review result, including manifest consistency and remaining limitations. Blocking findings must be fixed and re-reviewed before service admission; unresolved blockers after two revisions stay recorded and refuse deployment. Review completion is source/manifest based and never contingent on later live deployment receipts."
      ]
    },
    {
      "key": "frontend",
      "paths": [
        "web/**",
        "dist/**",
        "docs/**"
      ],
      "skill": "frontend-for-contract",
      "dependsOn": [
        "review"
      ],
      "objective": "Final integration assignment joining all preceding work, after review and service-verified live launch. Consume docs/abi/VolatilityGuardHook.json, docs/abi/VolatilityGuardToken.json, docs/integration.md, architecture/threat-model/contract-validation docs and .imd/reads/deployment.json at its pinned sourceCommit. Build React/Vite/TypeScript with RainbowKit/wagmi/viem under web/ and a relative-base static export under dist/. Keep frontend package setup, lockfile and ordinary-file dependencies under web/; preserve deployed contracts, root setup and upstream dependencies. Write only web/**, dist/** and docs/**. Integrate actual verified deployed contracts and existing periphery: explanation, dashboard, ETH/VGL swaps, supported-position exits and labeled demos. Centralize public ABI/address/chain/RPC configuration and support injected wallets without credentials. Run real read-only chain integration, local contract simulations and browser interaction checks; mock signing/error states without worker spending. Deliver web/README.md, docs/frontend-validation.md and docs/site-validation.md with a public read-only smoke procedure for publisher validation after hosting/naming. Worker completion requires source/export/evidence, not future URLs/CIDs/receipts. Services publish source, pin dist/, name the site and record public reachability validation.",
      "acceptanceCriteria": [
        "Consume only promised handoff fields: version, launchId, chainId, repoUrl, sourceCommit, attestationHash, manifest, contracts and abiInstructions; contracts supply name/address/txHash/blockNumber/creationCodeHash/abiHash. Build ABIs from exact sourceCommit, compare canonicalKeccak(abi) to abiHash and verify deployed code/chain before enabling transactions. Missing/mismatched evidence disables affected actions with a useful explanation.",
        "Derive receipts and supported positions from supplied transaction hashes, public logs and chain reads; derive allocation evidence from policy/source and public state where possible, leaving gaps explicit. The technical manifest has no supply/ownership/allocation fields. Handoff promises no full receipts, position IDs, allocation proofs, live swap receipts or site URLs. Exits require verified supported positions and connected-wallet ownership/authorization, never assumed deployer authority.",
        "Responsive UI explains hook behavior, all states, bootstrap, risks and limitations without claiming total MEV protection. Live dashboard reads tick/TWAP, EWMA volatility, deviation, volume budget/state and events from real deployed interfaces, clearly marking unavailable/stale/RPC-error states and keeping simulation data explicitly labeled.",
        "Primary ETH/VGL swap controls cover amounts, both directions, balances/max with gas allowance, real periphery quotes, slippage/minimum received and exact-input/output semantics supported by contract recipes, approvals and visitor-wallet-signed swaps. Show pending/success/reverted/rejected states, decoded errors and Sepolia explorer links. Explain token-only bootstrap: buy with ETH first; reverse trades depend on accrued ETH liquidity.",
        "Expose every primary supported contract action, including supported-position exits, with live connected-wallet reads and configured chain checks. Integrate actual ABIs, pool key, router/quote/liquidity recipes and decoded errors; validate live code/state and read-only quote behavior. Do not deploy helpers, request service keys, invent worker spending authority or fabricate successful live interactions.",
        "Run production build, TypeScript checks and meaningful responsive/interaction validation for both directions, wallet disconnected/connected, wrong chain, rejected signing, approvals, pending/success/reverted transactions, guard errors, insufficient funds, RPC failures, bootstrap/reverse-liquidity constraints and exits. Signing/error mocks follow actual ABI/provider interfaces and are labeled; validate real integration separately with public reads and local simulations without spending.",
        "Commit dist/index.html and relative assets alongside source and web/ lockfile; ensure reproducible dependencies are ordinary files available offline where needed, not submodules. Document install/preview/rebuild/publish commands in web/README.md and integration/evidence in docs/. Record actual results and untested live-chain behavior in docs/frontend-validation.md; static export/source/evidence finish this worker, publication/CID/naming/reachability finish services.",
        "docs/site-validation.md defines post-publication read-only checks for the publisher: fetch named/IPFS URL, index and relative assets; check delivered chain/address configuration against the handoff and public RPC reads. Record actual reachability/functionality evidence after pinning/naming. This is a later service completion gate, not a frontend submission gate; local browser tests cover wallet interactions without claiming live signed swaps."
      ]
    }
  ],
  "version": 1,
  "questions": [],
  "sharedInterfaces": "Serial: contracts -> generated launch.json -> review -> source publication -> attestation -> admission -> deployment -> frontend -> publication/pinning -> naming/validation. Frontend is the sole final integration assignment; no concurrent writers or guessed ABI. Contracts own initial setup/src/test and docs/abi/{VolatilityGuardHook,VolatilityGuardToken}.json plus architecture, threat-model, integration and contract-validation docs. Review consumes these and generated launch.json; control plane adds its direct manifest dependency. Frontend consumes the same pinned files plus .imd/reads/deployment.json; writes only web/**, dist/**, docs/** after all earlier writers. Signing/error mocks follow actual ABI/provider interfaces, are labeled and prove no live execution. Services own receipts, broadcast, publication and naming; workers receive no keys. Sepolia 11155111, univ4_hook policy v2 only; existing 0.3 Sepolia ETH gas ceiling, no extra funding or worker spending, never mainnet. Authorized GitHub uses signed publisher's configured org/automatic launch name; IPFS uses configured Pinata/automatic naming. Overall completion requires live seeded contracts, published source/test evidence/real receipts, verified handoff, frontend source/export, pinned CID and named ENS site. Publisher owns post-hosting read-only public reachability/smoke validation per docs/site-validation.md and records results before completion. Visitor signs user transactions; no live worker-signed swap tests."
}
