{"workflow":null,"planning":null,"id":"abea5e14-4681-4e2c-9e23-e2081557514d","state":"completed","template":"skill:build-contract-project","objective":"SOURCE-ONLY Foundry prototype. GitHub contracts/tests/docs; NO deployment. ALL values/assets/wallets are LOCAL FIXTURES, not launch decisions.\n\nToken name: IMDAO\nToken symbol: IMDAO\nTotal supply: 1,000,000 whole IMDAO, 18 decimals.\nMinting after launch: None; fixture mint/distribution/delegation to multiple voters, valueless liquidity.\nTransfer rules: OpenZeppelin ERC20Votes, block-number checkpoints; no tax/rebase/blacklist/pause/later mint.\nWhat each contract does: IMDAO/mock IMD Votes, restricted governor/timelock, v4 hook, treasury/recipient registry, V1/V2 policies, mock oracle.\nWho can call what: Anyone swaps/removes own liquidity; delegates propose/vote; governor queues/cancels; open execution. Timelock alone authorizes payout/enrollment/policy/oracle. Guardian ONLY suspends recipients. No admin/AI bypass.\nNumbers the contracts enforce: Fee/cap 25 bps additional to LP fee. Development/reserve V1 80/20, V2 60/40. Proposal threshold 10,000 base IMDAO at prior block; vote delay 1 block, duration 100 blocks; quorum 40,000 unboosted IMDAO FOR+ABSTAIN; weighted FOR>AGAINST. Timelock 3600 seconds. Per asset, lifetime gross payout caps: 10,000 whole units/recipient, 100,000 globally. One action/proposal. Oracle one pending, 3600-second timeout, zero payment.\nUpgrades and pausing: Only policy/recipient changes. No proxy/other upgrade/delegatecall/arbitrary call/trading pause. Suspension blocks payouts only. Token/hook/treasury/PoolId fixed.\nOutside services and values: Real local Uniswap v4 PoolManager/router; IMDAO/mock ERC20 pair, both 18 decimals. Separate mock IMD Votes: 18 decimals, not treasury asset. Fixture guardian; no live API/IMD/keys/ETH.\n\nVOTING\nSame past proposal snapshot: C=IMDAO.getPastVotes, I=mockIMD.getPastVotes; weight=C+min(floor(C/4),I). 18-decimal units; max 25% bonus, IMD alone zero. Threshold/quorum use C; base/weighted tallies separate. Both delegated; one vote/delegate/proposal, no current balances. Immutable fixture formula; delegated IMD power, NOT verified live holdings. Production checkpoints/escrow/chain/decimals/borrowing risk unresolved.\n\nAUTHORITY\nProposal binds fixed target, zero value, canonical calldata and descriptionHash of frozen purpose/text/source links. ONLY allow hook.activatePolicy(candidate,codeHash), treasury.setRecipient(recipient,expectedVersion,enabled,metadataHash), treasury.pay(paymentId,asset,bucket,recipient,version,amount,purposeHash), oracle.request(questionHash). Reject other targets/selectors, batches, malformed/trailing data, timelock self-calls/role/delay changes. Governor sole proposer/canceller; execution open; timelock sole admin; remove bootstrap roles. Freeze/verify wiring; no reinitialization/cyclic constructors. Social/oracle confer no votes. Expose proposal/snapshot/deadline/tally/state events/views. Original proposer may cancel any unexecuted proposal. Direct timelock execution and governor wrappers share all checks/accounting.\n\nRECIPIENTS\nStart unapproved. Timelocked setRecipient requires current expectedVersion; each change increments version, clears acceptance and binds operator/purpose metadataHash. Enable creates PendingAcceptance; only recipient may accept current version to become Active. Disable blocks on execution. Guardian suspend increments version/blocks immediately; no enable/spend powers. Re-enable requires fresh governance/acceptance; stale enrollment proposals fail version check. Payment proposal/queue/execution require Active matching version, nonzero non-system recipient. Enroll BEFORE payment proposal; replacements need fresh enrollment, never edit payouts. Allowlisting proves no honesty/signer continuity; real operator/multisig verification deferred.\n\nFEES\nAuthenticate manager/PoolId. afterSwap return-delta surcharge=floor(abs(unspecified delta)*25/10000), paid in unspecified currency. Prove signs/currency/slippage in both directions, exact-input/output. NOT verified IMD creator fees. manager.take sends settled cash to immutable treasury; hook alone credits exact receipt, never estimates/ERC6909 claims. Insufficient manager cash reverts; disclose limitation. development=floor(receipt*developmentBps/10000), remainder reserve; policy affects future FEES only. Raw transfers=unallocated surplus, not spendable income. No conversion/sweep/LP-principal claim.\n\nPAYOUTS\nPositive amount, supported asset/bucket, purpose hash. Nonzero paymentId binds one proposal forever. Queue atomically reserves asset/bucket cash AND recipient/global cap capacity and schedules timelock. Enforce grossPaid+reserved<=cap per asset across ALL buckets. No cap reset/netting on returns or re-enrollment, no cross-asset valuation. Record readyAt, expiresAt=readyAt+604800 seconds. Timelock alone pays exact reserved tuple at readyAt<=now<expiresAt; recheck recipient version/status. Consume bucket/reservation, increase gross paid, transfer once. Failure rolls back for retry/cancel. Each milestone needs a vote.\nGovernor cancellation atomically cancels timelock/releases cash/cap reservations. Anyone can cancel queued payment if expired OR recipient version/status invalid; proposer may cancel earlier. No loops/replay. Target enforces expiry/status on direct execution. Nonpayments have no expiry.\n\nBUSINESS RETURNS\nreturnUnspent(paymentId,amount,evidenceHash) and depositProceeds(paymentId,amount,evidenceHash): only original recipient of PAID payment, even if suspended. Pull positive amount of original payment asset from caller; credit exact receipt to original bucket. Cumulative returns<=original payout; proceeds uncapped, separate ledger. Unique receipt IDs/evidence hashes. Returns are recipient-declared; proceeds NOT audited profit. Never reduce gross cap usage/rewrite payments. Recipient approvals INTO treasury allowed, treasury approvals OUT forbidden. Donations stay surplus. No clawback/business/fiat/tax automation.\n\nACCOUNTING\nPer asset: fees+returns+proceeds-grossPayments=development+reserve. Reservations INCLUDED in buckets, not extra liabilities; reserved<=bucket; cash>=buckets, excess=surplus. Solvency and exact sender debit AND recipient credit on every movement; SafeERC20, CEI, reentrancy protection, atomic rollback. No unsupported tokens.\nV1/V2 direct pure non-proxy policies, no mutable/external dependencies: pin both runtime hashes; activation verifies code/hash. Two weights sum to 10000; STATICCALL 30000 gas, bounded copying, exactly 64 bytes; invalid uses built-in 80/20. Cannot raise fees/redirect custody/alter old balances.\n\nORACLE MOCK\nTimelock-only request with nonce/chain/consumer/question-bound ID; Pending/Answered/Expired; unanswered=UNKNOWN. Immutable delivery authenticates fixture responder; fixed-size boolean envelope, matching request/domain/question, Pending and now<expiry. Anyone expires at now>=expiry. Reject forged/malformed/duplicate/late answers; retries need fresh governance. Callback records evidence only, no spending/upgrades/calls; never in swap/LP paths. Not live IMD/truth proof.\n\nDELIVER/VERIFY\nOrder: governance/registry/treasury, fees/payouts/returns, policies/oracle. src/, test/, README: ABIs/roles/states/fixtures/invariants/limitations/commands. Pin dependencies/solc=0.8.26/EVM. No FFI/filesystem/env/network cheatcodes. Run forge fmt --check, forge build, forge test; report results/static-analysis availability. Unit/fuzz/invariants: four real-manager swap cases, hook permissions/LP exits, unauthorized/bootstrap routes, snapshots/redelegation/bonus/quorum/double votes, enrollment/version races/suspension, cross-bucket caps, queue/cancel/expiry/direct-execution boundaries, failed transfer/retry/replay, returns/re-spend/cap persistence, proceeds/surplus/conservation, reentrancy/nonstandard tokens, policy/oracle faults. Freeze commit for independent review. No public deploy/sign/fund, website/imports/dispatch/buybacks/rewards. Document live IMD/fee/hook/oracle gaps, production voting/budget/guardian/multisig/migration gates. No launch-ready claims.","blockedReason":null,"createdAt":"2026-10-08T01:47:22.353Z","updatedAt":"2026-10-08T03:00:48.504Z","paidBy":"0x6031ed55f29a1b8eeb49f9baf7b6897496dc5a62","parentJobId":null,"project":{"id":"abea5e14-4681-4e2c-9e23-e2081557514d","head":"abea5e14-4681-4e2c-9e23-e2081557514d","running":null,"versions":[{"jobId":"abea5e14-4681-4e2c-9e23-e2081557514d","workflowId":null,"objective":"SOURCE-ONLY Foundry prototype. GitHub contracts/tests/docs; NO deployment. ALL values/assets/wallets are LOCAL FIXTURES, not launch decisions.\n\nToken name: IMDAO\nToken symbol: IMDAO\nTotal supply: 1,000,000 whole IMDAO, 18 decimals.\nMinting after launch: None; fixture mint/distribution/delegation to multiple voters, valueless liquidity.\nTransfer rules: OpenZeppelin ERC20Votes, block-number checkpoints; no tax/rebase/blacklist/pause/later mint.\nWhat each contract does: IMDAO/mock IMD Votes, restricted governor/timelock, v4 hook, treasury/recipient registry, V1/V2 policies, mock oracle.\nWho can call what: Anyone swaps/removes own liquidity; delegates propose/vote; governor queues/cancels; open execution. Timelock alone authorizes payout/enrollment/policy/oracle. Guardian ONLY suspends recipients. No admin/AI bypass.\nNumbers the contracts enforce: Fee/cap 25 bps additional to LP fee. Development/reserve V1 80/20, V2 60/40. Proposal threshold 10,000 base IMDAO at prior block; vote delay 1 block, duration 100 blocks; quorum 40,000 unboosted IMDAO FOR+ABSTAIN; weighted FOR>AGAINST. Timelock 3600 seconds. Per asset, lifetime gross payout caps: 10,000 whole units/recipient, 100,000 globally. One action/proposal. Oracle one pending, 3600-second timeout, zero payment.\nUpgrades and pausing: Only policy/recipient changes. No proxy/other upgrade/delegatecall/arbitrary call/trading pause. Suspension blocks payouts only. Token/hook/treasury/PoolId fixed.\nOutside services and values: Real local Uniswap v4 PoolManager/router; IMDAO/mock ERC20 pair, both 18 decimals. Separate mock IMD Votes: 18 decimals, not treasury asset. Fixture guardian; no live API/IMD/keys/ETH.\n\nVOTING\nSame past proposal snapshot: C=IMDAO.getPastVotes, I=mockIMD.getPastVotes; weight=C+min(floor(C/4),I). 18-decimal units; max 25% bonus, IMD alone zero. Threshold/quorum use C; base/weighted tallies separate. Both delegated; one vote/delegate/proposal, no current balances. Immutable fixture formula; delegated IMD power, NOT verified live holdings. Production checkpoints/escrow/chain/decimals/borrowing risk unresolved.\n\nAUTHORITY\nProposal binds fixed target, zero value, canonical calldata and descriptionHash of frozen purpose/text/source links. ONLY allow hook.activatePolicy(candidate,codeHash), treasury.setRecipient(recipient,expectedVersion,enabled,metadataHash), treasury.pay(paymentId,asset,bucket,recipient,version,amount,purposeHash), oracle.request(questionHash). Reject other targets/selectors, batches, malformed/trailing data, timelock self-calls/role/delay changes. Governor sole proposer/canceller; execution open; timelock sole admin; remove bootstrap roles. Freeze/verify wiring; no reinitialization/cyclic constructors. Social/oracle confer no votes. Expose proposal/snapshot/deadline/tally/state events/views. Original proposer may cancel any unexecuted proposal. Direct timelock execution and governor wrappers share all checks/accounting.\n\nRECIPIENTS\nStart unapproved. Timelocked setRecipient requires current expectedVersion; each change increments version, clears acceptance and binds operator/purpose metadataHash. Enable creates PendingAcceptance; only recipient may accept current version to become Active. Disable blocks on execution. Guardian suspend increments version/blocks immediately; no enable/spend powers. Re-enable requires fresh governance/acceptance; stale enrollment proposals fail version check. Payment proposal/queue/execution require Active matching version, nonzero non-system recipient. Enroll BEFORE payment proposal; replacements need fresh enrollment, never edit payouts. Allowlisting proves no honesty/signer continuity; real operator/multisig verification deferred.\n\nFEES\nAuthenticate manager/PoolId. afterSwap return-delta surcharge=floor(abs(unspecified delta)*25/10000), paid in unspecified currency. Prove signs/currency/slippage in both directions, exact-input/output. NOT verified IMD creator fees. manager.take sends settled cash to immutable treasury; hook alone credits exact receipt, never estimates/ERC6909 claims. Insufficient manager cash reverts; disclose limitation. development=floor(receipt*developmentBps/10000), remainder reserve; policy affects future FEES only. Raw transfers=unallocated surplus, not spendable income. No conversion/sweep/LP-principal claim.\n\nPAYOUTS\nPositive amount, supported asset/bucket, purpose hash. Nonzero paymentId binds one proposal forever. Queue atomically reserves asset/bucket cash AND recipient/global cap capacity and schedules timelock. Enforce grossPaid+reserved<=cap per asset across ALL buckets. No cap reset/netting on returns or re-enrollment, no cross-asset valuation. Record readyAt, expiresAt=readyAt+604800 seconds. Timelock alone pays exact reserved tuple at readyAt<=now<expiresAt; recheck recipient version/status. Consume bucket/reservation, increase gross paid, transfer once. Failure rolls back for retry/cancel. Each milestone needs a vote.\nGovernor cancellation atomically cancels timelock/releases cash/cap reservations. Anyone can cancel queued payment if expired OR recipient version/status invalid; proposer may cancel earlier. No loops/replay. Target enforces expiry/status on direct execution. Nonpayments have no expiry.\n\nBUSINESS RETURNS\nreturnUnspent(paymentId,amount,evidenceHash) and depositProceeds(paymentId,amount,evidenceHash): only original recipient of PAID payment, even if suspended. Pull positive amount of original payment asset from caller; credit exact receipt to original bucket. Cumulative returns<=original payout; proceeds uncapped, separate ledger. Unique receipt IDs/evidence hashes. Returns are recipient-declared; proceeds NOT audited profit. Never reduce gross cap usage/rewrite payments. Recipient approvals INTO treasury allowed, treasury approvals OUT forbidden. Donations stay surplus. No clawback/business/fiat/tax automation.\n\nACCOUNTING\nPer asset: fees+returns+proceeds-grossPayments=development+reserve. Reservations INCLUDED in buckets, not extra liabilities; reserved<=bucket; cash>=buckets, excess=surplus. Solvency and exact sender debit AND recipient credit on every movement; SafeERC20, CEI, reentrancy protection, atomic rollback. No unsupported tokens.\nV1/V2 direct pure non-proxy policies, no mutable/external dependencies: pin both runtime hashes; activation verifies code/hash. Two weights sum to 10000; STATICCALL 30000 gas, bounded copying, exactly 64 bytes; invalid uses built-in 80/20. Cannot raise fees/redirect custody/alter old balances.\n\nORACLE MOCK\nTimelock-only request with nonce/chain/consumer/question-bound ID; Pending/Answered/Expired; unanswered=UNKNOWN. Immutable delivery authenticates fixture responder; fixed-size boolean envelope, matching request/domain/question, Pending and now<expiry. Anyone expires at now>=expiry. Reject forged/malformed/duplicate/late answers; retries need fresh governance. Callback records evidence only, no spending/upgrades/calls; never in swap/LP paths. Not live IMD/truth proof.\n\nDELIVER/VERIFY\nOrder: governance/registry/treasury, fees/payouts/returns, policies/oracle. src/, test/, README: ABIs/roles/states/fixtures/invariants/limitations/commands. Pin dependencies/solc=0.8.26/EVM. No FFI/filesystem/env/network cheatcodes. Run forge fmt --check, forge build, forge test; report results/static-analysis availability. Unit/fuzz/invariants: four real-manager swap cases, hook permissions/LP exits, unauthorized/bootstrap routes, snapshots/redelegation/bonus/quorum/double votes, enrollment/version races/suspension, cross-bucket caps, queue/cancel/expiry/direct-execution boundaries, failed transfer/retry/replay, returns/re-spend/cap persistence, proceeds/surplus/conservation, reentrancy/nonstandard tokens, policy/oracle faults. Freeze commit for independent review. No public deploy/sign/fund, website/imports/dispatch/buybacks/rewards. Document live IMD/fee/hook/oracle gaps, production voting/budget/guardian/multisig/migration gates. No launch-ready claims.","baseCommit":"0243d7da4a4337ae8b16bcdf15bb4ead736fd68f","state":"completed","createdAt":"2026-10-08T01:47:22.353Z"}]},"deliver":true,"host":false,"site":null,"launch":{"requested":false,"kind":null,"id":null,"status":null,"chainId":null},"oracleRequestId":null,"delivery":{"repoUrl":"https://github.com/identity-md-launches/launch-968-imdao","pullRequestUrl":"https://github.com/identity-md-launches/launch-968-imdao/pull/1","commit":"2e7c4f5f0489a0b1d4eedf38d59c70951803f7b2","deliveredAt":"2026-10-08T03:01:07.459Z","media":null},"media":null,"nodes":[{"key":"build_contract_project","role":"implement","state":"accepted","attempt":2,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-08T03:00:48.504Z","verdict":{"status":"accepted","profile":"foundry","evaluation":"checks","rejectionCode":null,"detail":"all checks passed","verifierVersion":"0.1.0+ad90ce4c","verifiedTreeHash":"fd2332c7013e06b5b504a2c52835982c7fd5465c","at":"2026-10-08T03:00:48.504Z","failedChecks":[]},"seat":{"tokenId":"686","agentId":"51496"},"live":null}],"reviews":[{"status":"queued","chainId":1,"txHash":null,"blockNumber":null,"sentAt":null,"entries":[{"nodeKey":"build_contract_project","agentId":"51727","value":0,"role":"verification:checks"},{"nodeKey":"build_contract_project","agentId":"51496","value":1,"role":"verification:checks"}]}]}