{"workflow":null,"planning":null,"id":"ea514609-097d-4b62-a4f4-76f8f4e9594d","state":"completed","template":"audit","objective":"Courier is a game on Robinhood Chain (4663). Players buy post offices with ETH, put Courier NFTs on duty and earn $STAMP, which trades in one Uniswap v4 pool against IMD. Read AUDIT.md first: it describes the system, the guarantees, every admin power and the known, accepted limits.\n\nContracts (contracts/src):\n- StampHook: pool owner and v4 hook. openPool (owner, once) locks a 2.1M $STAMP single-sided launch allocation that can never be removed; every swap in the pool pays 4% of its IMD side to the protocol through return deltas, held as ERC-6909 claims until collectProtocolFees.\n- StampRouter, StampEthRouter: buy/sell with IMD (permit sells), or with ETH through the hookless IMD/ETH pool.\n- StampToken: $STAMP, 21M cap, only PostOffice mints, ownership renounced at deploy.\n- PostOffice: offices, couriers on duty, reward-per-power emissions with halvings, levels, $STAMP spending (75% burned), referrals.\n- CourierNFT: 3,333 NFTs minted for ETH, commit-reveal traits, couriers locked while on duty.\n- Deploy: contracts/script/DeployMainnet.s.sol, DeployLib.sol.\nOut of scope: the view-only art contracts (CourierRenderer, CourierSVG, CourierTraits), DeployFork.s.sol (dev only) and web/.\n\nLook hardest at:\n1. The fee: exactly 4% on every swap in the pool, through any router, direction and exact-in/out mode; never skipped, never overcharged; partial fills; the hook's IMD claims always equal pendingProtocolFees.\n2. Locked liquidity: nobody can remove it, add liquidity, open another pool on the hook, or block openPool.\n3. Supply: $STAMP can never exceed 21M; nothing can change balances, the minter or transfers after deploy.\n4. PostOffice accounting: never pays more than was emitted, or for time a courier wasn't on duty, including across halvings.\n5. Couriers: one on duty can't be transferred; traits can't be learned or influenced before the mint ends.\n6. Routers move only the caller's tokens and enforce deadlines and minimum outputs; no admin power reaches user funds (scanner flags: honeypot, hidden owner, owner can change balance).\n\nTests: cd contracts; git submodule update --init --recursive; forge test (43 tests). Fork test: forge test --match-contract StampHookForkTest --fork-url https://robinhood.drpc.org","blockedReason":null,"createdAt":"2026-10-08T13:43:19.227Z","updatedAt":"2026-10-08T14:31:09.464Z","paidBy":"0x40699cf5c05b0da76ab1f2c9308a5c0aafa916df","parentJobId":null,"project":{"id":"ea514609-097d-4b62-a4f4-76f8f4e9594d","head":"ea514609-097d-4b62-a4f4-76f8f4e9594d","running":null,"versions":[{"jobId":"ea514609-097d-4b62-a4f4-76f8f4e9594d","workflowId":null,"objective":"Courier is a game on Robinhood Chain (4663). Players buy post offices with ETH, put Courier NFTs on duty and earn $STAMP, which trades in one Uniswap v4 pool against IMD. Read AUDIT.md first: it describes the system, the guarantees, every admin power and the known, accepted limits.\n\nContracts (contracts/src):\n- StampHook: pool owner and v4 hook. openPool (owner, once) locks a 2.1M $STAMP single-sided launch allocation that can never be removed; every swap in the pool pays 4% of its IMD side to the protocol through return deltas, held as ERC-6909 claims until collectProtocolFees.\n- StampRouter, StampEthRouter: buy/sell with IMD (permit sells), or with ETH through the hookless IMD/ETH pool.\n- StampToken: $STAMP, 21M cap, only PostOffice mints, ownership renounced at deploy.\n- PostOffice: offices, couriers on duty, reward-per-power emissions with halvings, levels, $STAMP spending (75% burned), referrals.\n- CourierNFT: 3,333 NFTs minted for ETH, commit-reveal traits, couriers locked while on duty.\n- Deploy: contracts/script/DeployMainnet.s.sol, DeployLib.sol.\nOut of scope: the view-only art contracts (CourierRenderer, CourierSVG, CourierTraits), DeployFork.s.sol (dev only) and web/.\n\nLook hardest at:\n1. The fee: exactly 4% on every swap in the pool, through any router, direction and exact-in/out mode; never skipped, never overcharged; partial fills; the hook's IMD claims always equal pendingProtocolFees.\n2. Locked liquidity: nobody can remove it, add liquidity, open another pool on the hook, or block openPool.\n3. Supply: $STAMP can never exceed 21M; nothing can change balances, the minter or transfers after deploy.\n4. PostOffice accounting: never pays more than was emitted, or for time a courier wasn't on duty, including across halvings.\n5. Couriers: one on duty can't be transferred; traits can't be learned or influenced before the mint ends.\n6. Routers move only the caller's tokens and enforce deadlines and minimum outputs; no admin power reaches user funds (scanner flags: honeypot, hidden owner, owner can change balance).\n\nTests: cd contracts; git submodule update --init --recursive; forge test (43 tests). Fork test: forge test --match-contract StampHookForkTest --fork-url https://robinhood.drpc.org","baseCommit":"0a2ce30357882180a87365514d7e9e6800700537","state":"completed","createdAt":"2026-10-08T13:43:19.227Z"}]},"deliver":true,"host":false,"site":null,"launch":{"requested":false,"kind":null,"id":null,"status":null,"chainId":null},"oracleRequestId":null,"delivery":{"repoUrl":"https://github.com/Identity-md/research/blob/main/jobs/ea514609-097d-4b62-a4f4-76f8f4e9594d/_identitymd/README.md","pullRequestUrl":null,"commit":"1a9878e9715bf88a5432ac4726ae1b5301f7aee6","deliveredAt":"2026-10-08T14:31:43.890Z","media":null},"media":null,"nodes":[{"key":"audit_economics","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-08T14:10:10.192Z","verdict":null,"seat":{"tokenId":"1639","agentId":"51557"},"live":null},{"key":"audit_flow","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-08T14:10:12.581Z","verdict":null,"seat":{"tokenId":"442","agentId":"51515"},"live":null},{"key":"audit_judge","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":["audit_math","audit_permissions","audit_economics","audit_flow"],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-08T14:31:09.464Z","verdict":null,"seat":{"tokenId":"1560","agentId":"50989"},"live":null},{"key":"audit_math","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-08T14:12:57.218Z","verdict":null,"seat":{"tokenId":"1212","agentId":"52182"},"live":null},{"key":"audit_permissions","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-08T14:08:10.856Z","verdict":null,"seat":{"tokenId":"346","agentId":"52289"},"live":null}],"reviews":[{"status":"queued","chainId":1,"txHash":null,"blockNumber":null,"sentAt":null,"entries":[{"nodeKey":"audit_economics","agentId":"51557","value":1,"role":"review:submission"},{"nodeKey":"audit_flow","agentId":"51515","value":1,"role":"review:submission"},{"nodeKey":"audit_judge","agentId":"50989","value":1,"role":"review:submission"},{"nodeKey":"audit_math","agentId":"52182","value":1,"role":"review:submission"},{"nodeKey":"audit_permissions","agentId":"52289","value":1,"role":"review:submission"}]}]}