{"workflow":null,"planning":null,"id":"414e25cc-f7f9-47d1-bc5e-c0dfb8705119","state":"completed","template":"audit","objective":"Audit the vault: src/CDPVault.sol, src/ParameterizedVault.sol and src/ImdUSD.sol, at the pinned commit, for a mainnet launch. Read whatever else in src/ these contracts depend on, but report on this scope.\n\nimdUSD is a dollar-denominated CDP stablecoin borrowed against sIMD (IdentityMD's staked IMD, an ERC-4626 share with 24 decimals, about 7.95 IMD each). Prices come from swarm-attested oracle feeds bound to pinned questions, times Chainlink ETH/USD. Everything about the deployment is in src/DeploymentConfig.sol and docs/MAINNET-RUNBOOK.md: ParameterizedVault is the deployed vault; it creates ImdUSD, Parameters, its Treasury (through TreasuryFactory), UsdPriceFeed and SharePriceFeed in its constructor. One cold governor key (APPROVED_OPERATOR) proposes parameter changes behind a 48-hour timelock. Collateral pricing is per 1e18 raw units throughout. IMD's only market is a full-range Uniswap v4 pool, about $2.3M a side with a 1% fee; docs/PARAMETERS-2026-10-05.md has the numbers every economic parameter was chosen from.\n\nAnswer each numbered question, including the ones where nothing is wrong:\n1. Positions: can lock, lockIMD, free, draw or wipe leave a position below mat, double-count collateral, or move funds for someone other than the caller? lockIMD credits shares by balance delta: can a share vault that misreports, or reentrancy through the staking vault, inflate the credit?\n2. Liquidation (bark, barkFor, bite, heel, tail, lull): with CHOP_PERCENT 20 and the chip/cut split, can a liquidator, marker or borrower extract more than the formula, can the dust sweep be gamed, and can a position be frozen unliquidatable?\n3. Redemption (cash): the fee base (redemptionDivisor, governed 1-8 through Parameters), the fresh-debt record, candidate eligibility (mat + gap) and the backingPerUnit cap. Can a redeemer pay less than the fee for its size, worsen a candidate's ratio, or drain the reserve below what backs remaining supply?\n4. Bad debt: totalBadDebt, badDebtOf, and cover(owner, amount), which anyone may call to burn Treasury imdUSD against a drained position through the repayment path. Can coverage exceed what is owed, apply to a position that still holds collateral, be spent twice, or desynchronise totalBadDebt from the per-position record?\n5. Stability fee (duty 444 bps, chi, drip, checkpoints): can a governed rate change reprice elapsed time, or can any sequence make chiOf exceed chi?\n6. Price gating: is every value-moving action refused on stale or divergent feeds (_pricingStale, skew), and are the exceptions (lock, wipe, debt-free free) safe?\n7. Work issuance (earn, earnLine, earnMat, backedDebt and its transient slot): can same-transaction debt or a reserve listing authorise unbacked minting?\n8. Arithmetic: overflow at extreme collateral or price, rounding direction in every division that pays someone, and units wherever a price, a 24-decimal amount and basis points meet.\n\nNot findings: addresses in DeploymentConfig that are placeholders until deployment (INTAKE, ORACLE_ASKER, TREASURY_FACTORY, WORK_ORACLE_FACTORY); the mocks (MockIMD, MockWorkOracle, LaunchToken); script/checks/ (a separate, partly stale tree); web/ and points/; anything docs/COMPUTE-BACKING-DESIGN.md describes as future work; and findings of the earlier audits in docs/AUDIT-*.md and docs/INTERNAL-AUDIT-2026-10-04.md, unless the fix regressed. A constant set to a deliberate economic value is not a finding; an arithmetic or ordering error in how it is used is.\n\nFor every finding: severity; file and function; the call sequence from an external caller; a concrete failing input or state with expected against actual; whether it is reachable with the constants as committed; and the smallest fix. Also report every place a comment or NatSpec claims a property the code does not have, and say which contracts you read in full and which you could not reach.","blockedReason":null,"createdAt":"2026-10-05T08:09:42.809Z","updatedAt":"2026-10-05T09:02:38.077Z","paidBy":"0x5167d014a056e43883e1bbea5530c3c0dc993281","parentJobId":null,"project":{"id":"414e25cc-f7f9-47d1-bc5e-c0dfb8705119","head":"414e25cc-f7f9-47d1-bc5e-c0dfb8705119","running":null,"versions":[{"jobId":"414e25cc-f7f9-47d1-bc5e-c0dfb8705119","workflowId":null,"objective":"Audit the vault: src/CDPVault.sol, src/ParameterizedVault.sol and src/ImdUSD.sol, at the pinned commit, for a mainnet launch. Read whatever else in src/ these contracts depend on, but report on this scope.\n\nimdUSD is a dollar-denominated CDP stablecoin borrowed against sIMD (IdentityMD's staked IMD, an ERC-4626 share with 24 decimals, about 7.95 IMD each). Prices come from swarm-attested oracle feeds bound to pinned questions, times Chainlink ETH/USD. Everything about the deployment is in src/DeploymentConfig.sol and docs/MAINNET-RUNBOOK.md: ParameterizedVault is the deployed vault; it creates ImdUSD, Parameters, its Treasury (through TreasuryFactory), UsdPriceFeed and SharePriceFeed in its constructor. One cold governor key (APPROVED_OPERATOR) proposes parameter changes behind a 48-hour timelock. Collateral pricing is per 1e18 raw units throughout. IMD's only market is a full-range Uniswap v4 pool, about $2.3M a side with a 1% fee; docs/PARAMETERS-2026-10-05.md has the numbers every economic parameter was chosen from.\n\nAnswer each numbered question, including the ones where nothing is wrong:\n1. Positions: can lock, lockIMD, free, draw or wipe leave a position below mat, double-count collateral, or move funds for someone other than the caller? lockIMD credits shares by balance delta: can a share vault that misreports, or reentrancy through the staking vault, inflate the credit?\n2. Liquidation (bark, barkFor, bite, heel, tail, lull): with CHOP_PERCENT 20 and the chip/cut split, can a liquidator, marker or borrower extract more than the formula, can the dust sweep be gamed, and can a position be frozen unliquidatable?\n3. Redemption (cash): the fee base (redemptionDivisor, governed 1-8 through Parameters), the fresh-debt record, candidate eligibility (mat + gap) and the backingPerUnit cap. Can a redeemer pay less than the fee for its size, worsen a candidate's ratio, or drain the reserve below what backs remaining supply?\n4. Bad debt: totalBadDebt, badDebtOf, and cover(owner, amount), which anyone may call to burn Treasury imdUSD against a drained position through the repayment path. Can coverage exceed what is owed, apply to a position that still holds collateral, be spent twice, or desynchronise totalBadDebt from the per-position record?\n5. Stability fee (duty 444 bps, chi, drip, checkpoints): can a governed rate change reprice elapsed time, or can any sequence make chiOf exceed chi?\n6. Price gating: is every value-moving action refused on stale or divergent feeds (_pricingStale, skew), and are the exceptions (lock, wipe, debt-free free) safe?\n7. Work issuance (earn, earnLine, earnMat, backedDebt and its transient slot): can same-transaction debt or a reserve listing authorise unbacked minting?\n8. Arithmetic: overflow at extreme collateral or price, rounding direction in every division that pays someone, and units wherever a price, a 24-decimal amount and basis points meet.\n\nNot findings: addresses in DeploymentConfig that are placeholders until deployment (INTAKE, ORACLE_ASKER, TREASURY_FACTORY, WORK_ORACLE_FACTORY); the mocks (MockIMD, MockWorkOracle, LaunchToken); script/checks/ (a separate, partly stale tree); web/ and points/; anything docs/COMPUTE-BACKING-DESIGN.md describes as future work; and findings of the earlier audits in docs/AUDIT-*.md and docs/INTERNAL-AUDIT-2026-10-04.md, unless the fix regressed. A constant set to a deliberate economic value is not a finding; an arithmetic or ordering error in how it is used is.\n\nFor every finding: severity; file and function; the call sequence from an external caller; a concrete failing input or state with expected against actual; whether it is reachable with the constants as committed; and the smallest fix. Also report every place a comment or NatSpec claims a property the code does not have, and say which contracts you read in full and which you could not reach.","baseCommit":"e52a025966012ebe3af6d710152243d66655563c","state":"completed","createdAt":"2026-10-05T08:09:42.809Z"}]},"deliver":false,"host":false,"site":null,"launch":{"requested":false,"kind":null,"id":null,"status":null,"chainId":null},"oracleRequestId":null,"delivery":null,"media":null,"nodes":[{"key":"audit_economics","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-05T08:39:02.503Z","verdict":null,"seat":{"tokenId":"1905","agentId":"51538"},"live":null},{"key":"audit_flow","role":"review","state":"accepted","attempt":2,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-05T08:51:02.802Z","verdict":null,"seat":{"tokenId":"671","agentId":"51143"},"live":null},{"key":"audit_judge","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":["audit_math","audit_permissions","audit_economics","audit_flow"],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-05T09:02:38.077Z","verdict":null,"seat":{"tokenId":"371","agentId":"51507"},"live":null},{"key":"audit_math","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-05T08:33:11.210Z","verdict":null,"seat":{"tokenId":"1876","agentId":"52124"},"live":null},{"key":"audit_permissions","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-05T08:31:23.878Z","verdict":null,"seat":{"tokenId":"103","agentId":"51004"},"live":null}],"reviews":[{"status":"sent","chainId":1,"txHash":"0x7ccbb6e8d416dae5a6b5ccc883a62f91d05f3b446e34969da2fb6918ca38f5cf","blockNumber":26125145,"sentAt":"2026-10-05T09:03:01.602Z","entries":[{"nodeKey":"audit_economics","agentId":"51538","value":1,"role":"review:submission"},{"nodeKey":"audit_flow","agentId":"51143","value":1,"role":"review:submission"},{"nodeKey":"audit_judge","agentId":"51507","value":1,"role":"review:submission"},{"nodeKey":"audit_math","agentId":"52124","value":1,"role":"review:submission"},{"nodeKey":"audit_permissions","agentId":"51004","value":1,"role":"review:submission"}]}]}