{"assessments":[],"deployments":[],"fuzz":[],"identity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"interpretation":"Records acceptance and evidence. Neither completion nor an AI assessment establishes correctness, safety, or independent review.","jobId":"2f955667-815b-4915-88d0-49df5f273845","kind":"shape:chain","nodes":[{"acceptedSubmissionHash":"2044526e19988e9f496cfb6dc9da8b7e8e07230f9600405aac0ff78943871837","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_economics","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"bc94b6fa5671a3623bd59822c17d341c8c649ec99d6d647a3fb4b2eca657e4c9","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_flow","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"bcd6a76dd8e90816051717a054b5a746bbba85ccb008a9634ed80a906feaaeaa","dependsOn":["build_contract_project","write_foundry_tests","manifest","audit_math","audit_permissions","audit_economics","audit_flow"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"3014f1ea5961918ca059453a484bf4c8bcbbfc2248dbe31d94ac7c5cdf8f50bd","skillId":"audit-judge","tools":[]},"key":"audit_judge","kind":"code","role":"review","skillHash":"3014f1ea5961918ca059453a484bf4c8bcbbfc2248dbe31d94ac7c5cdf8f50bd","skillId":"audit-judge","state":"accepted"},{"acceptedSubmissionHash":"129c5663b4f3c0a01022cd46c104b8849b9d22fbf656c416cd5cf4dee829db87","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_math","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"871e1be558fdf874f66c67497b363f522929c51d85880fd394701a1d94dd48a2","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_permissions","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"a264f3ddbeac824c39fd60926e2f07c5f6a91b14f0b3899eec757fd29e5e365e","dependsOn":[],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"47381b166d1f406a34f0ebdc740ee21bc0383e56e7ad9084b26abf1bf7570904","skillId":"build-contract-project","tools":[]},"key":"build_contract_project","kind":"code","role":"implement","skillHash":"47381b166d1f406a34f0ebdc740ee21bc0383e56e7ad9084b26abf1bf7570904","skillId":"build-contract-project","state":"accepted"},{"acceptedSubmissionHash":"2cf163ffc847cf1545a7bf256b8e2291c9eea7718dcff32e61d4e853d4413235","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"tools":[]},"key":"manifest","kind":"code","role":"integrate","skillHash":null,"skillId":null,"state":"accepted"},{"acceptedSubmissionHash":"af1e7edbc5cfd65459514ae22ea83f2d3410976f7991f41eb92c681fbd9c196c","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"73431852439ad3a343f3d2b7db1c43cd363b9f48f9bb51497374a0cf6d50b223","skillId":"write-foundry-tests","tools":[]},"key":"write_foundry_tests","kind":"code","role":"tests","skillHash":"73431852439ad3a343f3d2b7db1c43cd363b9f48f9bb51497374a0cf6d50b223","skillId":"write-foundry-tests","state":"accepted"}],"objective":"A custom token: Swarm Sticker (STICK).\nToken name: Swarm Sticker\nToken symbol: STICK\nToken supply: 1,000,000,000 with 18 decimals, all minted once to the deployer in the constructor.\nWhat it does: Name: Swarm Sticker\nSymbol: STICK\nSupply: 1000000000\nWhat it does: A plain community token for the IMD swarm sticker pack. No fees, no minting after launch, no owner powers.\nPool: 88% (default)   Starting market cap: 10 ETH (default)   Rest of supply to: your wallet (the page fills it in)","parentJobId":null,"planHash":"20ca3dbf5f13071c30b61904f1e62756ebeef0072ad9bf96545c7bd52ed73955","previousHash":"0000000000000000000000000000000000000000000000000000000000000000","projectId":"2f955667-815b-4915-88d0-49df5f273845","publication":{"commit":null,"deliveredAt":null,"repoUrl":"https://github.com/identity-md-launches/launch-578-custom-token-swarm-sticker"},"receiptIdentity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"registry":"0xb6d0a187b050fa5bb0b87033a203f37becf4a775","research":[],"schema":"identitymd-work-v1","signals":[{"agentId":"51331","feedbackHash":"4e0c4d799f02baa8a71a85c5a6b9bb9823fde57ddaa2f6397ca26e60be33d105","nodeKey":"audit_economics","submissionHash":"2044526e19988e9f496cfb6dc9da8b7e8e07230f9600405aac0ff78943871837","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"50939","feedbackHash":"ccefef98177a936fdbc20e0295b7ea0f511121ffd8dfa0bd1f5ce07d4d236554","nodeKey":"audit_flow","submissionHash":"bc94b6fa5671a3623bd59822c17d341c8c649ec99d6d647a3fb4b2eca657e4c9","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51504","feedbackHash":"f45724ff1fc5d1c18edba10d62274f14470985ea5e74f099b225d7822fafc4bf","nodeKey":"audit_judge","submissionHash":"bcd6a76dd8e90816051717a054b5a746bbba85ccb008a9634ed80a906feaaeaa","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51334","feedbackHash":"ba769265c2dc5558731a086f7d7b418a2df86684ea29bbc4fee2d28b701e8809","nodeKey":"audit_math","submissionHash":"129c5663b4f3c0a01022cd46c104b8849b9d22fbf656c416cd5cf4dee829db87","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51430","feedbackHash":"ca61dc0684584b66f8dbf5cb874d8997d343ae15272a9aaf7edc40ecae66a3d7","nodeKey":"audit_permissions","submissionHash":"871e1be558fdf874f66c67497b363f522929c51d85880fd394701a1d94dd48a2","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"50971","feedbackHash":"ad75d7b7d58750f1749c6b21af87ead0fcedd24e59a35f41234e352156c5c284","nodeKey":"build_contract_project","submissionHash":"a264f3ddbeac824c39fd60926e2f07c5f6a91b14f0b3899eec757fd29e5e365e","tag1":"verification:checks","tag2":"acceptance-v2","value":1},{"agentId":"51046","feedbackHash":"b8022e991456ddf28f92107c1200c5cd56120007e03d5a63e7a766ead1d488de","nodeKey":"manifest","submissionHash":"2cf163ffc847cf1545a7bf256b8e2291c9eea7718dcff32e61d4e853d4413235","tag1":"verification:checks","tag2":"acceptance-v2","value":1},{"agentId":"50971","feedbackHash":"66e620d9a0da8ab6582f578e8352e0325894ee870274cb5bbe3949961cd9e0ea","nodeKey":"write_foundry_tests","submissionHash":"af1e7edbc5cfd65459514ae22ea83f2d3410976f7991f41eb92c681fbd9c196c","tag1":"verification:checks","tag2":"acceptance-v2","value":1}],"site":null,"snapshotHash":"eb075d9ed74a29b940efcfd5e394c46a7f8ab805b437eed0ef480f26a4e081bd","state":"completed","submissions":[{"artifacts":[],"attempt":1,"bundleHash":null,"device":"433c37ef2c9c708d","findings":[{"citation":"resolved","description":"Outside the math area, reported because it is reproducible and contradicts a documented verification step. DEPENDENCIES.md states the vendored forge-std v1.9.4 files are byte-for-byte upstream and tells the reader to confirm that with `sha256sum --check lib/forge-std/SHA256SUMS`. That command fails for seven files: src/StdAssertions.sol, src/StdJson.sol, src/StdToml.sol, src/Vm.sol, src/console.sol, src/interfaces/IMulticall3.sol and src/mocks/MockERC721.sol. The SHA256SUMS entries match upstream commit 1eea5bae12ae557d589f9f0f0edae2faa47cb262 (e.g. StdAssertions.sol upstream sha256 d4c89eec... is what SHA256SUMS lists), but the committed files were reflowed to the project's `line_length = 120` by `forge fmt`. Comparing each file with all whitespace stripped, the vendored copies are identical to upstream, so this is formatting only and has no effect on the token, the tests, or production bytecode (forge-std is test-only). The OpenZeppelin checksums all pass. Fix: either restore the seven files to their upstream bytes (and keep lib/ out of `forge fmt`), or regenerate lib/forge-std/SHA256SUMS from the committed files and reword the 'unmodified' claim to say whitespace-only reformatting was applied.","line":12,"path":"DEPENDENCIES.md","reproduction":"In the repository root run `sha256sum --check lib/forge-std/SHA256SUMS`. Expected per DEPENDENCIES.md: every line reports OK. Actual: 7 lines report FAILED (StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IMulticall3.sol, mocks/MockERC721.sol) and the command exits non-zero. `sha256sum --check lib/openzeppelin-contracts/SHA256SUMS` passes. `diff` against the upstream file at the pinned commit shows only line-wrapping changes; `tr -d '[:space:]' | sha256sum` on upstream and local gives identical digests for all seven files.","severity":"info","snippet":"files are unmodified. Their SHA-256 checksums, using paths relative to the project","title":"DEPENDENCIES.md claims vendored forge-std files are unmodified, but seven of them fail the shipped SHA256SUMS check (reformatted by forge fmt)"}],"hash":"129c5663b4f3c0a01022cd46c104b8849b9d22fbf656c416cd5cf4dee829db87","nodeId":"f11fda16-17ba-486a-bb7c-013f8f57534b","outcome":"completed","summary":"The review is complete and written to `.imd-findings.json`. The token's math holds; the only reproducible defect is a documentation claim outside my area.\n\n**Outcome of the math, boundary and numerical-gap audit**\n\nThe contract is a single OpenZeppelin v5.1.0 ERC-20 with one constructor mint and no overrides, so there is no division, scaling, fee or cast arithmetic to go wrong. I traced each of the three entry points through the vendored OpenZeppelin code and exercised the boundaries with a scratch Foundry suite that I then removed:\n\n- **Supply constant** is exactly 10^27, matches the manifest's minor-unit string, and divides evenly by 10^18. Decimals default to 18.\n- **Launch splits** of 10%, 88% and 2% in basis points are exact with zero remainder, and the 2%/8% sub-splits of the swarm share are too.\n- **Opening price** from a 10 ETH cap over one billion tokens derives exactly to a sqrt price of 10^4 times 2^96, inside Uniswap v4's bounds, and matches the README's stated per-token price.\n- **Transfer and transferFrom** behave correctly at every edge I fed them: whole supply in one call, supply plus one, max uint, zero amount, self-transfer, allowance of max minus one versus max, and allowance exactly equal to amount. Balance sums stay at 10^27 under fuzzing.\n- **Boundary surface** is empty: no external calls, no payable paths, no bytes decoding, so no boundary corner case applies.\n\n**One info-level finding, outside my area.** The dependencies document says the vendored forge-std files are unmodified and tells readers to verify with the shipped checksum file, but that check fails for seven files. I fetched the pinned upstream commit and confirmed the differences are whitespace-only reflows from the project's formatter. This has no effect on the token or its bytecode, since forge-std is test-only, and the OpenZeppelin checksums all pass. The fix is either to restore upstream bytes or regenerate the checksum file and reword the claim.\n\n**Coverage.** All three listed entry points are marked `holds`, plus five invariant rows covering supply, splits, price derivation, boundary surface and numerical-gap seams. Nothing was left unreached. The existing suite of 32 tests and the invariant run pass, and `forge fmt --check` is clean.","treeHash":null,"usage":{"cachedInputTokens":783123,"inputTokens":322,"model":"claude-fable-5-1","outputTokens":15699,"runtime":"claude","turns":25,"wallClockMs":217580}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"d2d5a117dd72f6b4","findings":[{"citation":"resolved","description":"DEPENDENCIES.md states that the vendored files are unmodified and that `sha256sum --check lib/forge-std/SHA256SUMS` verifies them against forge-std v1.9.4 (commit 1eea5bae). In the committed tree seven forge-std sources (StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IMulticall3.sol, mocks/MockERC721.sol) no longer match the checksums recorded in lib/forge-std/SHA256SUMS. Comparing each against the upstream file at that commit shows the differences are whitespace/line-wrapping only (forge fmt was evidently run over lib/ after SHA256SUMS was generated), so the test library's behaviour is unchanged and no deployed code is affected: the production contract depends only on the OpenZeppelin files, which match both their SHA256SUMS and the upstream commit byte for byte. The defect is that the documented, offline-runnable provenance check for forge-std fails, so a verifier following the README/DEPENDENCIES instructions cannot confirm the test library is what it claims to be without network access. Fix: either restore the upstream byte-exact files (and exclude lib/ from forge fmt) or regenerate lib/forge-std/SHA256SUMS from the files as committed and say in DEPENDENCIES.md that they were reformatted. Outside the assigned economics area; reported because it is concrete and reproducible.","line":12,"path":"DEPENDENCIES.md","reproduction":"From the repository root run `sha256sum --check lib/forge-std/SHA256SUMS`. Expected (per DEPENDENCIES.md): every line reports OK. Actual: `lib/forge-std/src/StdAssertions.sol: FAILED`, `StdJson.sol: FAILED`, `StdToml.sol: FAILED`, `Vm.sol: FAILED`, `console.sol: FAILED`, `interfaces/IMulticall3.sol: FAILED`, `mocks/MockERC721.sol: FAILED`, `sha256sum: WARNING: 7 computed checksums did NOT match`. Example: SHA256SUMS line 17 records 9ed10705...ea91 for src/Vm.sol while the committed blob (git ls-files -s -> 6334dd2f...) hashes to a97ae3a5...1391. `sha256sum --check lib/openzeppelin-contracts/SHA256SUMS` reports all OK, and `diff -w` of each failing forge-std file against raw.githubusercontent.com/foundry-rs/forge-std/1eea5bae12ae557d589f9f0f0edae2faa47cb262/src/<file> is empty (whitespace-only drift).","severity":"low","snippet":"files are unmodified. Their SHA-256 checksums, using paths relative to the project","title":"DEPENDENCIES.md provenance claim is false: 7 vendored forge-std files fail their own SHA256SUMS"}],"hash":"2044526e19988e9f496cfb6dc9da8b7e8e07230f9600405aac0ff78943871837","nodeId":"2adad58d-9952-4de9-a419-e3a07dbdff3c","outcome":"completed","summary":"The review is complete and the findings file is written.\n\n**Outcome.** The token's economics hold. `src/SwarmSticker.sol` is a 13-line, unmodified OpenZeppelin v5.1.0 ERC-20 that mints the full supply once to the deployer. I found no defect in the Economic Security, Invariant or Flow Gap areas. One low-severity provenance defect outside my area is reported.\n\n**What I checked in the assigned area**\n\n- **Conservation and supply growth.** The only mint is in the constructor. No public path reaches `_mint`, `_burn` or `_update`. The existing stateful invariant suite plus a scratch fuzz confirmed sum of balances equals total supply after any sequence.\n- **Launch flows arrive whole.** Transfers move exactly the stated amount with no fee, burn, hook or callback. I modelled the PoolManager's sync-and-settle pattern in a scratch harness. The factory-to-distributor, distributor-to-claimant, factory-to-pool, pool-to-trader and trader-to-pool legs all credited exactly, and the factory ended at zero.\n- **Split arithmetic.** The 10 percent, 88 percent and 2 percent shares of 10^27 minor units divide with no rounding dust.\n- **Opening price.** With ETH as currency0 the implied sqrt price and tick for a 10 ETH cap sit comfortably inside Uniswap v4 bounds, and the single-sided liquidity fits uint128. That derivation is the deployer's, and nothing in the token constrains it.\n- **Dependency integrity.** The five vendored OpenZeppelin files match both their checksum file and the upstream commit byte for byte.\n\n**The one finding (low).** DEPENDENCIES.md says the vendored forge-std files are unmodified and verifiable with its checksum file, but seven of them fail that check. Diffing against upstream v1.9.4 shows whitespace-only drift from a later `forge fmt` run. No deployed code is affected since forge-std is test-only, but the documented offline provenance check is broken. The fix is to restore the byte-exact upstream files or regenerate the checksum file and say so.\n\n**Leads not reported.** The aderyn large-numeric-literal note is style only. The standard ERC-20 approve race is documented in the README and is not a defect.\n\n**Coverage.** All three listed entry points are marked holds, with nine additional rows for the invariants and economics checks above. The scratch test directory was removed and no project file was changed.","treeHash":null,"usage":{"cachedInputTokens":614173,"inputTokens":258,"model":"claude-fable-5-1","outputTokens":15763,"runtime":"claude","turns":27,"wallClockMs":217380}},{"artifacts":[],"attempt":1,"bundleHash":"f18410d6f6a6623a7838252f5f61d42d8993f7fc0b720c22db8b912c9937d81b","device":"02ae6543274731ab","findings":[],"hash":"2cf163ffc847cf1545a7bf256b8e2291c9eea7718dcff32e61d4e853d4413235","nodeId":"213bc6b5-bd5f-4bda-b034-7db4d2ee4059","outcome":"completed","summary":"Created [launch.json](/home/imd-worker/.identitymd/work/2f955667-815b-4915-88d0-49df5f273845/213bc6b5-bd5f-4bda-b034-7db4d2ee4059/launch.json) with the exact supply, economics, and accepted constructor arguments.\n\nSchema and ABI checks passed. `forge build` succeeded; `forge test` passed all 32 tests. Only `launch.json` changed for submission.","treeHash":"51ff5326f1a94b232b42b95c139fc4bdc7bd709f","usage":{"cachedInputTokens":191744,"inputTokens":21435,"model":"gpt-6-astra","outputTokens":2748,"runtime":"codex","turns":3,"wallClockMs":110186}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"2a5d68f89de314cb","findings":[{"citation":"resolved","description":"DEPENDENCIES.md asserts that both vendored snapshots are byte-identical to upstream and directs the verifier to prove it with `sha256sum --check lib/forge-std/SHA256SUMS`. That command fails: lib/forge-std/SHA256SUMS holds the genuine upstream v1.9.4 (commit 1eea5bae) hashes (confirmed by fetching each file at that commit), but seven files in lib/forge-std/src were re-wrapped after vendoring (StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IMulticall3.sol, mocks/MockERC721.sol). The diffs are whitespace-only line re-wrapping consistent with `forge fmt` at line_length 120 having been run over lib/; stripping all whitespace from each local and upstream file yields identical content, so the assertion library and cheatcode interface are semantically intact and the passing test suite is not undermined. The OpenZeppelin snapshot verifies cleanly and matches upstream v5.1.0 byte for byte. Impact is limited to provenance: the repository's stated integrity check contradicts the tree, so a reviewer following the documented procedure gets a failed verification of the test library and must re-derive trust by hand, as done here. No production bytecode is affected (forge-std is test-only). Fix: either restore the seven upstream files byte-for-byte, or regenerate lib/forge-std/SHA256SUMS from the tree and reword DEPENDENCIES.md to say the files were reformatted; in both cases keep lib/ out of `forge fmt` (e.g. an `ignore` entry under [fmt]) so the snapshot stays stable. The protected harness and launch flows are unaffected.","line":12,"path":"DEPENDENCIES.md","reproduction":"From the repository root run `sha256sum --check lib/forge-std/SHA256SUMS`. Expected per DEPENDENCIES.md line 11-13: every line reports OK. Actual: 'sha256sum: WARNING: 7 computed checksums did NOT match' with FAILED for lib/forge-std/src/StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IMulticall3.sol and mocks/MockERC721.sol. Cross-check: `curl -sL https://raw.githubusercontent.com/foundry-rs/forge-std/1eea5bae12ae557d589f9f0f0edae2faa47cb262/src/StdAssertions.sol | sha256sum` prints d4c89eec70d267dec6188461fbc74d3dc8c47e518d176a23417533a232ed9780, which is the hash recorded in SHA256SUMS, while the local file hashes to 3fbf4a025b4fc94eaca4c38c1f3dacb37bee10f12ee81994cfaf365ac1ce7384. `diff -w` shows the only differences are line wrapping; `tr -d ' \\t\\n\\r' < file | sha256sum` is identical for local and upstream on all seven files. By contrast `sha256sum --check lib/openzeppelin-contracts/SHA256SUMS` reports all OK and every OZ file hash equals the upstream file at commit 69c8def5.","severity":"low","snippet":"files are unmodified. Their SHA-256 checksums, using paths relative to the project","title":"DEPENDENCIES.md states vendored forge-std is unmodified, but its own documented checksum verification fails on 7 files"}],"hash":"871e1be558fdf874f66c67497b363f522929c51d85880fd394701a1d94dd48a2","nodeId":"f23c1c4b-5ab8-4029-8518-fee0f7807e39","outcome":"completed","summary":"Review complete. The findings file is written at `.imd-findings.json` with one low finding and eight coverage rows, and no repository file was changed.\n\n**Outcome in my area (Access Control, Trust Gap, Asymmetry): no defects.** The token is a 13-line subclass of OpenZeppelin 5.1.0 ERC20 with no overrides, and the vendored OpenZeppelin files are byte-identical to upstream. The compiled ABI exposes exactly the nine standard ERC-20 selectors, with no constructor arguments, fallback, receive, owner, pause, blacklist or minter slot in storage, and the runtime has no DELEGATECALL, CALLCODE or SELFDESTRUCT. There is no role, modifier, initializer or branch keyed on the caller, so every holder class (factory, distributor, PoolManager, trader) takes the same transfer path and every launch flow moves exactly what it says. The deployer cannot pull a holder's balance without allowance. The only trust assumption is that the factory, which holds the whole supply after construction, performs the split off-token, which is the launch design rather than a token defect. All 32 existing unit, fuzz and invariant tests pass.\n\n**One low finding, outside my area but reproducible.** DEPENDENCIES.md says the vendored libraries are unmodified and tells the reader to prove it with the checksum file. That command fails on seven forge-std files. The checksum file records the real upstream v1.9.4 hashes, but the seven local files were re-wrapped by the formatter. I confirmed the differences are whitespace only, so the assertion library is intact and test results stand. The fix is to restore the upstream bytes or regenerate the sums and reword the claim, and to keep lib out of `forge fmt`.\n\n**Not reached:** the network's protected harness (pool initialization, seeding and swaps against a real Uniswap v4 PoolManager) cannot run in this tree because its dependencies and environment are not present. It is recorded as unreached in the coverage record.","treeHash":null,"usage":{"cachedInputTokens":760498,"inputTokens":290,"model":"claude-fable-5-1","outputTokens":12746,"runtime":"claude","turns":23,"wallClockMs":175801}},{"artifacts":[],"attempt":1,"bundleHash":"f94d0a1e94b43e05774be5e9769dd8b63639c67c90aea5e09e378f1e6b759c77","device":"35c52a5b502e847c","findings":[],"hash":"a264f3ddbeac824c39fd60926e2f07c5f6a91b14f0b3899eec757fd29e5e365e","nodeId":"732932ff-3b95-4d29-be77-73e8566e71ec","outcome":"completed","summary":"Implemented Swarm Sticker (STICK): 1 billion tokens, 18 decimals, minted once to the deployer, with no fees, further minting, or owner powers.\n\nAdded vendored dependencies, success/failure tests, fuzz tests, stateful invariants, and deployment documentation covering the 88% pool allocation and 10 ETH starting market cap.\n\nVerified with Solidity 0.8.26:\n\n- `forge build`\n- `forge test`\n- `forge fmt --check`\n\nAll passed, including a fresh offline build and tests with an empty environment. Actual Uniswap v4 integration remains for the independent launch verifier.","treeHash":"a23c08e6d50a30129e5ac2d867bc39b2aeadc495","usage":{"cachedInputTokens":283392,"inputTokens":50902,"model":"gpt-6-astra","outputTokens":13263,"runtime":"codex","turns":5,"wallClockMs":429883}},{"artifacts":[],"attempt":1,"bundleHash":"9ce793b3007e573c3730eb725c3a896f6d67e06f6f7756b9d9395f4ad732e546","device":"35c52a5b502e847c","findings":[],"hash":"af1e7edbc5cfd65459514ae22ea83f2d3410976f7991f41eb92c681fbd9c196c","nodeId":"99950a57-3882-40a5-8211-b0b4ee8ab3b1","outcome":"completed","summary":"Extended tests under `test/` with allowance failure paths, maximum-value cases, fuzz properties, and stateful invariants.\n\nValidation passed:\n\n- `forge build`\n- `forge test`: 46 passed, 0 failed\n- 24,576 invariant handler calls\n\nNo defects found. Protected pool integration was not run because its external launch infrastructure is absent.","treeHash":"c7998bf5744217d308261c20005559bd24a5f13b","usage":{"cachedInputTokens":710912,"inputTokens":81194,"model":"gpt-6-astra","outputTokens":11157,"runtime":"codex","turns":5,"wallClockMs":388597}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"72b617d4b615473a","findings":[{"citation":"resolved","description":"Periphery pass (vendored base contracts and libraries). DEPENDENCIES.md states that the vendored files are unmodified and gives `sha256sum --check lib/forge-std/SHA256SUMS` as the way to confirm it. That command fails on this tree. Seven forge-std files (src/StdAssertions.sol, src/StdJson.sol, src/StdToml.sol, src/Vm.sol, src/console.sol, src/interfaces/IMulticall3.sol, src/mocks/MockERC721.sol) do not match the hashes listed in lib/forge-std/SHA256SUMS. The listed hashes equal upstream forge-std at commit 1eea5bae12ae557d589f9f0f0edae2faa47cb262 (v1.9.4), so it is the committed files that were changed, not the list. I fetched the seven upstream files and compared them with all whitespace removed: every difference is whitespace only (line re-wrapping consistent with a formatter run at line_length 120), so test behaviour is not affected and production bytecode is not affected (forge-std is test-only). The defect is that the stated provenance guarantee and its documented check are false for this commit: a verifier who runs the documented command gets a non-zero exit and cannot confirm the test tooling by checksum. The OpenZeppelin half is sound: `sha256sum --check lib/openzeppelin-contracts/SHA256SUMS` passes and all five OpenZeppelin source files are byte-identical to upstream at 69c8def5f222ff96f2b5beff05dfba996368aa79 (v5.1.0). Minimal fix that preserves behaviour: restore the seven files to their upstream bytes so the existing list verifies, or regenerate the list and correct the 'unmodified' sentence to say the files were reformatted.","line":11,"path":"DEPENDENCIES.md","reproduction":"From the repository root at commit 341284c run: sha256sum --check lib/forge-std/SHA256SUMS\nExpected (per DEPENDENCIES.md lines 11-18): every line OK, exit 0.\nActual: exit 1 with 'WARNING: 7 computed checksums did NOT match' and FAILED for lib/forge-std/src/StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IMulticall3.sol, mocks/MockERC721.sol.\nExample: lib/forge-std/src/Vm.sol is listed (SHA256SUMS line 17) and upstream as 9ed10705966cec6d7e92a705659039aa8859c8d34bf2e6ba83de7165e984ea91 (108076 bytes) but the committed file hashes to a97ae3a5a13313815470d8b06bc6352c75ecde73761606567872f98cf0d51391 (107876 bytes); e.g. upstream wraps `function parseJsonAddressArray(string calldata json, string calldata key)` over four lines and the committed file has it on one.","severity":"low","snippet":"Both snapshots were obtained from GitHub archives at the commits above. Vendored\nfiles are unmodified. Their SHA-256 checksums, using paths relative to the project","title":"Documented forge-std integrity check fails: 7 vendored files differ from upstream and from the committed SHA256SUMS"}],"hash":"bc94b6fa5671a3623bd59822c17d341c8c649ec99d6d647a3fb4b2eca657e4c9","nodeId":"cd8be0c6-7296-4468-a166-9688795a88ba","outcome":"completed","summary":"The review found no defect in the token's control flow and one low-severity defect in the vendored test library. The report is in `.imd-findings.json` at the repository root, with one finding and eight coverage rows. No tracked file was changed.\n\n**The finding (low).** `DEPENDENCIES.md` line 11 says the vendored files are unmodified and tells the reader to confirm it with a checksum command. That command fails for forge-std:\n\n```\nsha256sum --check lib/forge-std/SHA256SUMS\nsha256sum: WARNING: 7 computed checksums did NOT match\n```\n\nThe listed hashes are upstream's, so the committed files are what changed. I fetched the seven upstream files and compared them with whitespace stripped. The differences are whitespace only, so tests and production bytecode are unaffected. The defect is that the stated provenance guarantee does not verify on this commit.\n\n**Coverage of the three entry points.** All three hold.\n- **`approve`** writes only the caller's own allowance, rejects a zero spender, and makes no external call.\n- **`transfer`** always debits the caller, rejects a zero recipient so the burn branch is unreachable, and moves the exact amount with no fee.\n- **`transferFrom`** checks and decrements the allowance before moving funds. Only the maximum value is treated as infinite, and only the owner can set it. A later revert restores the allowance.\n\n**Other rows I recorded.**\n- **Constructor:** mints exactly 10^27 units once to the caller and hands out no roles or approvals.\n- **Supply:** total supply is constant and cannot grow, because the mint function has no caller outside the constructor.\n- **Runtime code:** it contains no external call, delegatecall, create or selfdestruct opcodes. It does use `PUSH0` and `MCOPY`, so the target chain must support Cancun, which Uniswap v4 already requires.\n- **OpenZeppelin:** the five vendored files are byte-identical to upstream v5.1.0 at the pinned commit.\n\n**How I verified.**\n- The existing suite passes: 32 tests, including the invariant run.\n- A temporary scratch test with nine extra cases also passed and was then deleted. It covered aliased sender, recipient and spender, the allowance sentinel boundary, malformed calldata, and value sent with a call.\n- The finding's snippet was checked against the tree and matches.\n\n**Not done.**\n- I did not run the protected launch harness, because it needs the network's factory and Uniswap v4 sources, which are not in this tree. The seed and swap flows were assessed by reading the token code only.\n- No launch manifest exists yet, so constructor arguments and pool fields in it were not reviewed.\n- Math precision, economics and access-control guides were outside my assigned area and received only incidental coverage.","treeHash":null,"usage":{"cachedInputTokens":642032,"inputTokens":18,"model":"claude-fable-5-1","outputTokens":16743,"runtime":"claude","turns":19,"wallClockMs":194638}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"0238a59bba722237","findings":[{"citation":"resolved","description":"Merged from the four specialist reports (audit_economics, audit_permissions, audit_flow, audit_math): same root cause, one finding, kept at low. DEPENDENCIES.md says the vendored files are unmodified and gives `sha256sum --check lib/forge-std/SHA256SUMS` as the proof. I re-ran it: seven files fail (src/StdAssertions.sol, src/StdJson.sol, src/StdToml.sol, src/Vm.sol, src/console.sol, src/interfaces/IMulticall3.sol, src/mocks/MockERC721.sol). I fetched each of the seven from foundry-rs/forge-std at 1eea5bae12ae557d589f9f0f0edae2faa47cb262: the upstream hash equals the hash recorded in SHA256SUMS in every case, so the list is right and the committed files were changed (line re-wrapping, consistent with `forge fmt` at line_length 120 run over lib/). With all whitespace stripped, each committed file is identical to upstream, so the change is formatting only. Impact is limited to provenance of test tooling: the offline verifier cannot confirm forge-std by the documented command (non-zero exit). Production bytecode is not affected: SwarmSticker imports only OpenZeppelin, `sha256sum --check lib/openzeppelin-contracts/SHA256SUMS` passes, and all five OpenZeppelin sources are byte-identical (cmp) to upstream at 69c8def5f222ff96f2b5beff05dfba996368aa79. Fix without changing behaviour: restore the seven files to their upstream bytes (and keep lib/ out of `forge fmt`), or regenerate lib/forge-std/SHA256SUMS from the committed files and reword the sentence to say they were whitespace-reformatted.","line":12,"path":"DEPENDENCIES.md","reproduction":"From the repository root run `sha256sum --check lib/forge-std/SHA256SUMS`. Expected (DEPENDENCIES.md lines 11-18): every line OK, exit 0. Actual: `sha256sum: WARNING: 7 computed checksums did NOT match`, with FAILED for lib/forge-std/src/StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IMulticall3.sol and mocks/MockERC721.sol. Example: SHA256SUMS line 17 lists 9ed10705966cec6d... for src/Vm.sol, which is also the hash of the upstream file at commit 1eea5bae, while `sha256sum lib/forge-std/src/Vm.sol` gives a97ae3a5a1331381...; SHA256SUMS line 5 lists d4c89eec70d267de... for StdAssertions.sol, the committed file hashes to 3fbf4a025b4fc94e.... `tr -d '[:space:]' < file | sha256sum` is equal for the committed and upstream copy of all seven files. `sha256sum --check lib/openzeppelin-contracts/SHA256SUMS` reports all six lines OK.","severity":"low","snippet":"files are unmodified. Their SHA-256 checksums, using paths relative to the project","title":"Documented forge-std provenance check fails: 7 vendored test-library files were reformatted and no longer match lib/forge-std/SHA256SUMS"},{"citation":"resolved","description":"Found in my own pass; no specialist reported it. Documentation only, no effect on the token or the launch. README.md was written before the manifest and the later test work and was not updated. (a) Lines 67-71 say no requester wallet, pool fee or tick spacing was supplied and that no production manifest is included, but launch.json is in the tree with economics.remainderTo 0xcd5a046e76029fccc360ea842a1c42bc4b302c2f, pool.fee 3000 and pool.tickSpacing 60. (b) Lines 92-93 say `Fuzz tests run 512 cases each; stateful invariants run 128 sequences of up to 64 operations`, but the test files carry inline `forge-config` overrides (test/SwarmSticker.t.sol:19 and test/SwarmSticker.adversarial.t.sol:9 set fuzz runs to 1000; test/SwarmSticker.invariant.t.sol:154-155 set invariant runs 256, depth 96), which is what test/TESTING.md says. An operator following the README would look for parameters to resolve that the manifest already fixes. Fix: update those two README passages to match launch.json and test/TESTING.md.","line":70,"path":"README.md","reproduction":"(a) `ls launch.json` exists and contains \"fee\": 3000, \"tickSpacing\": 60 and economics.remainderTo, while README.md lines 67-71 state none was supplied and no manifest is included. (b) Run `forge test`: fuzz tests report `runs: 1000` and the invariant suite reports `runs: 256, calls: 24576` (256 x 96), against README's 512 cases and 128 sequences of 64.","severity":"info","snippet":"launch system, and confirm the remainder wallet before release. No placeholder\nwallet or production manifest is included. No special token exemptions or","title":"README contradicts the tree: says no manifest or pool parameters are included, and states fuzz/invariant run counts the tests override"}],"hash":"bcd6a76dd8e90816051717a054b5a746bbba85ccb008a9634ed80a906feaaeaa","nodeId":"c4d22f37-888d-4c86-99b9-b10144bd2d5e","outcome":"completed","summary":"The review is written to `.imd-findings.json`: two findings, both documentation-level, and no defect in the token itself. No tracked files were changed.\n\n**Findings**\n\n1. **Low — the documented forge-std checksum check fails** (`DEPENDENCIES.md:12`). All four specialists reported this; I merged them into one finding and reproduced it. `sha256sum --check lib/forge-std/SHA256SUMS` fails on 7 files. The recorded hashes match upstream at the pinned commit, so the committed files were changed, and the changes are whitespace-only. This affects test tooling only; the OpenZeppelin files the token compiles from are byte-identical to upstream v5.1.0.\n2. **Info — README is stale against the tree** (`README.md:70`). This is mine; no specialist reported it. The README says no manifest, pool fee or tick spacing is included, but `launch.json` has them. It also states 512 fuzz cases and 128 invariant sequences of depth 64, while the tests override these to 1000 and 256 at depth 96.\n\n**Coverage**\n\n- **`approve`, `transfer`, `transferFrom`: all hold.** The contract is unmodified OpenZeppelin `ERC20` with a single constructor mint of 1e27 to `msg.sender`. There are no fees, overrides or privileged paths.\n- **ABI and bytecode:** only the nine standard ERC-20 functions are exposed, and the runtime contains no `DELEGATECALL`, `CALLCODE` or `SELFDESTRUCT`.\n- **`launch.json`:** `initialPrice` recomputes exactly from the supply and the 10 ETH cap, and the supply, decimals and constructor arguments match the code.\n- **Local suite:** 46 tests pass.\n\nTwo things I could not verify:\n\n- The protected harness (real Uniswap v4 seed and swaps) is marked `unreached`: it needs v4-core and launch infrastructure that are not in this tree. A fee-free ERC-20 satisfies its checks by inspection only.\n- `economics.remainderTo` could not be compared to the job, which gives no address.\n\nNeither finding is high or critical, so no proof tests are attached.","treeHash":null,"usage":{"cachedInputTokens":475499,"inputTokens":18,"model":"claude-fable-5-1","outputTokens":9392,"runtime":"claude","turns":9,"wallClockMs":117280}}],"verification":[{"checks":[{"durationMs":1120,"exitCode":0,"name":"build","output":"Compiling 31 files with Solc 0.8.26\nSolc 0.8.26 finished in 1.02s\nCompiler run successful!\n","passed":true},{"durationMs":2194,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 31 tests for test/SwarmSticker.t.sol:SwarmStickerTest\n[PASS] testApprovalDoesNotRequireBalanceOrMoveTokens() (gas: 82388)\n[PASS] testApprovalEmitsEventAndCanBeReplacedAndRevoked() (gas: 179300)\n[PASS] testApprovalRejectsZeroSpender() (gas: 30410)\n[PASS] testConstructorEmitsMintAndMintsToImmediateCaller() (gas: 28358)\n[PASS] testCreate2FactoryReceivesEntireSupply() (gas: 273665)\n[PASS] testDeployerCannotSpendHoldersTokensWithoutApproval() (gas: 92718)\n[PASS] testEntireSupplyCanMove() (gas: 140126)\n[PASS] testFuzzExcessAllowanceSpendReverts(uint256,uint256) (runs: 512, μ: 116286, ~: 116697)\nLogs:\n  Bound result 22308\n  Bound result 13000000000000000000\n\n[PASS] testFuzzExcessTransferReverts(uint256) (runs: 512, μ: 54346, ~: 54684)\nLogs:\n  Bound result 180319948891367460030091941535420926414557573971\n\n[PASS] testFuzzTransferConservesSupply(address,uint256) (runs: 512, μ: 93105, ~: 93162)\nLogs:\n  Bound result 292428886945392280520248342\n\n[PASS] testFuzzTransferFromAccountsExactly(uint256,uint256) (runs: 512, μ: 157837, ~: 158681)\nLogs:\n  Bound result 13000000000000000000\n  Bound result 115792089237316195423570985008687907853269984665640564039444584007913129662244\n\n[PASS] testLaunchAllocationClaimsAndPoolTransfersArriveWhole() (gas: 693451)\n[PASS] testMetadataAndInitialSupply() (gas: 73856)\n[PASS] testNativeETHAndUnknownCallsAreRejected() (gas: 58946)\n[PASS] testNoAdminMintBurnOrUpgradeEntrypoints() (gas: 1734424)\n[PASS] testRuntimeHasNoForbiddenOpcodes() (gas: 1018351)\n[PASS] testSelfTransferDoesNotChangeBalance() (gas: 51442)\n[PASS] testSelfTransferStillRequiresSufficientBalance() (gas: 33344)\n[PASS] testTransferEmitsEventAndDeliversExactAmount() (gas: 89017)\n[PASS] testTransferFromBalanceFailureRestoresAllowance() (gas: 114861)\n[PASS] testTransferFromConsumesFiniteAllowance() (gas: 218430)\n[PASS] testTransferFromPreservesInfiniteAllowance() (gas: 122304)\n[PASS] testTransferFromRejectsInsufficientAllowanceWithoutMutation() (gas: 109008)\n[PASS] testTransferFromRejectsUnapprovedCaller() (gas: 98641)\n[PASS] testTransferFromRejectsZeroRecipientAndRestoresAllowance() (gas: 101600)\n[PASS] testTransferFromRejectsZeroSenderEvenForZeroAmount() (gas: 33053)\n[PASS] testTransferFromToSelfConsumesAllowanceWithoutChangingBalance() (gas: 101200)\n[PASS] testTransferFromZeroAmountNeedsNoAllowance() (gas: 49111)\n[PASS] testTransferRejectsInsufficientBalance() (gas: 50642)\n[PASS] testTransferRejectsZeroRecipientEvenForZeroAmount() (gas: 71948)\n[PASS] testZeroTransferFromEmptyAccountEmitsEvent() (gas: 56238)\nSuite result: ok. 31 passed; 0 failed; 0 skipped; finished in 13.75ms (62.49ms CPU time)\n\nRan 1 test for test/SwarmSticker.invariant.t.sol:SwarmStickerInvariantTest\n[PASS]\nSwarmStickerInvariantTest invariants:\n[PASS] invariantAllowancesMatchModel\n[PASS] invariantSupplyAndBalancesMatchModel\n SwarmStickerInvariantTest invariants (runs: 128, calls: 8192, reverts: 0)\n\n╭----------------+-------------------------+-------+---------+----------╮\n| Contract       | Selector                | Calls | Reverts | Discards |\n+=======================================================================+\n| StickerHandler | approve                 | 2051  | 0       | 0        |\n|----------------+-------------------------+-------+---------+----------|\n| StickerHandler | move                    | 2035  | 0       | 0        |\n|----------------+-------------------------+-------+---------+----------|\n| StickerHandler | rejectUnauthorizedSpend | 2093  | 0       | 0        |\n|----------------+-------------------------+-------+---------+----------|\n| StickerHandler | spend                   | 2013  | 0       | 0        |\n╰----------------+-------------------------+-------+---------+----------╯\n\nLogs:\n  Bound result 1439\n  Bound result 0\n  Bound result 0\n  Bound result 15\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 1\n  Bound result 2\n  Bound result 6050\n  Bound result 0\n  Bound result 0\n  Bound result 3261\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 3961\n  Bound result 35\n  Bound result 0\n  Bound result 0\n  Bound result 11\n  Bound result 18\n  Bound result 3261\n  Bound result 67\n  Bound result 127\n  Bound result 5116\n  Bound result 1385\n  Bound result 95\n  Bound result 289\n  Bound result 1278\n  Bound result 1220\n  Bound result 0\n  Bound result 0\n  Bound result 2942\n  Bound result 116\n  Bound result 4942\n  Bound result 1044\n  Bound result 42\n  Bound result 522\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 2.12s (2.12s CPU time)\n\nRan 2 test suites in 2.12s (2.14s CPU time): 32 tests passed, 0 failed, 0 skipped (32 total tests)\n","passed":true},{"durationMs":31,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"SwarmSticker.approve(address,uint256)\",\"SwarmSticker.transfer(address,uint256)\",\"SwarmSticker.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":3,\"DEPENDENCIES.md\":22,\"README.md\":130,\"foundry.toml\":24,\"launch.json\":20,\"remappings.txt\":2,\"src/SwarmSticker.sol\":13,\"test/SwarmSticker.invariant.t.sol\":103,\"test/SwarmSticker.t.sol\":397},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"2cf163ffc847cf1545a7bf256b8e2291c9eea7718dcff32e61d4e853d4413235","verifiedTreeHash":"51ff5326f1a94b232b42b95c139fc4bdc7bd709f","verifierVersion":"0.1.0+61e9b7ca"},{"checks":[{"durationMs":1277,"exitCode":0,"name":"build","output":"Compiling 31 files with Solc 0.8.26\nSolc 0.8.26 finished in 1.16s\nCompiler run successful!\n","passed":true},{"durationMs":2276,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 31 tests for test/SwarmSticker.t.sol:SwarmStickerTest\n[PASS] testApprovalDoesNotRequireBalanceOrMoveTokens() (gas: 82388)\n[PASS] testApprovalEmitsEventAndCanBeReplacedAndRevoked() (gas: 179300)\n[PASS] testApprovalRejectsZeroSpender() (gas: 30410)\n[PASS] testConstructorEmitsMintAndMintsToImmediateCaller() (gas: 28358)\n[PASS] testCreate2FactoryReceivesEntireSupply() (gas: 273665)\n[PASS] testDeployerCannotSpendHoldersTokensWithoutApproval() (gas: 92718)\n[PASS] testEntireSupplyCanMove() (gas: 140126)\n[PASS] testFuzzExcessAllowanceSpendReverts(uint256,uint256) (runs: 512, μ: 116391, ~: 116698)\nLogs:\n  Bound result 3000000000000000000\n  Bound result 999999997000000000127714937\n\n[PASS] testFuzzExcessTransferReverts(uint256) (runs: 512, μ: 54342, ~: 54684)\nLogs:\n  Bound result 988837720444643369728694435671136161\n\n[PASS] testFuzzTransferConservesSupply(address,uint256) (runs: 512, μ: 92688, ~: 93078)\nLogs:\n  Bound result 21970269567462\n\n[PASS] testFuzzTransferFromAccountsExactly(uint256,uint256) (runs: 512, μ: 157964, ~: 158621)\nLogs:\n  Bound result 39869432909668629544540635\n  Bound result 115792089237316195423570985008687907853269984665640524170024674339283587893434\n\n[PASS] testLaunchAllocationClaimsAndPoolTransfersArriveWhole() (gas: 693451)\n[PASS] testMetadataAndInitialSupply() (gas: 73856)\n[PASS] testNativeETHAndUnknownCallsAreRejected() (gas: 58946)\n[PASS] testNoAdminMintBurnOrUpgradeEntrypoints() (gas: 1734424)\n[PASS] testRuntimeHasNoForbiddenOpcodes() (gas: 1018351)\n[PASS] testSelfTransferDoesNotChangeBalance() (gas: 51442)\n[PASS] testSelfTransferStillRequiresSufficientBalance() (gas: 33344)\n[PASS] testTransferEmitsEventAndDeliversExactAmount() (gas: 89017)\n[PASS] testTransferFromBalanceFailureRestoresAllowance() (gas: 114861)\n[PASS] testTransferFromConsumesFiniteAllowance() (gas: 218430)\n[PASS] testTransferFromPreservesInfiniteAllowance() (gas: 122304)\n[PASS] testTransferFromRejectsInsufficientAllowanceWithoutMutation() (gas: 109008)\n[PASS] testTransferFromRejectsUnapprovedCaller() (gas: 98641)\n[PASS] testTransferFromRejectsZeroRecipientAndRestoresAllowance() (gas: 101600)\n[PASS] testTransferFromRejectsZeroSenderEvenForZeroAmount() (gas: 33053)\n[PASS] testTransferFromToSelfConsumesAllowanceWithoutChangingBalance() (gas: 101200)\n[PASS] testTransferFromZeroAmountNeedsNoAllowance() (gas: 49111)\n[PASS] testTransferRejectsInsufficientBalance() (gas: 50642)\n[PASS] testTransferRejectsZeroRecipientEvenForZeroAmount() (gas: 71948)\n[PASS] testZeroTransferFromEmptyAccountEmitsEvent() (gas: 56238)\nSuite result: ok. 31 passed; 0 failed; 0 skipped; finished in 27.41ms (74.54ms CPU time)\n\nRan 1 test for test/SwarmSticker.invariant.t.sol:SwarmStickerInvariantTest\n[PASS]\nSwarmStickerInvariantTest invariants:\n[PASS] invariantAllowancesMatchModel\n[PASS] invariantSupplyAndBalancesMatchModel\n SwarmStickerInvariantTest invariants (runs: 128, calls: 8192, reverts: 0)\n\n╭----------------+-------------------------+-------+---------+----------╮\n| Contract       | Selector                | Calls | Reverts | Discards |\n+=======================================================================+\n| StickerHandler | approve                 | 2007  | 0       | 0        |\n|----------------+-------------------------+-------+---------+----------|\n| StickerHandler | move                    | 2026  | 0       | 0        |\n|----------------+-------------------------+-------+---------+----------|\n| StickerHandler | rejectUnauthorizedSpend | 2083  | 0       | 0        |\n|----------------+-------------------------+-------+---------+----------|\n| StickerHandler | spend                   | 2076  | 0       | 0        |\n╰----------------+-------------------------+-------+---------+----------╯\n\nLogs:\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 451\n  Bound result 1779\n  Bound result 0\n  Bound result 4\n  Bound result 361315426016778749494872900\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 5367\n  Bound result 162881115996791776622635623\n  Bound result 2169\n  Bound result 72\n  Bound result 6616\n  Bound result 0\n  Bound result 746\n  Bound result 115833595285032134052730560\n  Bound result 417775229677623218024774697\n  Bound result 20000000000000000000000000\n  Bound result 245481830731746615442142411\n  Bound result 5091\n  Bound result 318\n  Bound result 2\n  Bound result 663257060409369833466916791\n  Bound result 999999999999999999999999997\n  Bound result 0\n  Bound result 3008\n  Bound result 746\n  Bound result 5072\n  Bound result 2\n  Bound result 21\n  Bound result 1000000000000000000\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 2.20s (2.19s CPU time)\n\nRan 2 test suites in 2.20s (2.22s CPU time): 32 tests passed, 0 failed, 0 skipped (32 total tests)\n","passed":true},{"durationMs":49,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"SwarmSticker.approve(address,uint256)\",\"SwarmSticker.transfer(address,uint256)\",\"SwarmSticker.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":3,\"DEPENDENCIES.md\":22,\"README.md\":130,\"foundry.toml\":24,\"remappings.txt\":2,\"src/SwarmSticker.sol\":13,\"test/SwarmSticker.invariant.t.sol\":103,\"test/SwarmSticker.t.sol\":397},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true},{"durationMs":592,"exitCode":0,"name":"slither","output":"slither: no results at low impact or above","passed":true},{"durationMs":297,"exitCode":0,"name":"aderyn","output":"[low] large-numeric-literal at src/SwarmSticker.sol:11: Large Numeric Literal","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"a264f3ddbeac824c39fd60926e2f07c5f6a91b14f0b3899eec757fd29e5e365e","verifiedTreeHash":"a23c08e6d50a30129e5ac2d867bc39b2aeadc495","verifierVersion":"0.1.0+61e9b7ca"},{"checks":[{"durationMs":1918,"exitCode":0,"name":"build","output":"Compiling 32 files with Solc 0.8.26\nSolc 0.8.26 finished in 1.76s\nCompiler run successful!\n","passed":true},{"durationMs":7238,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 31 tests for test/SwarmSticker.t.sol:SwarmStickerTest\n[PASS] testApprovalDoesNotRequireBalanceOrMoveTokens() (gas: 82388)\n[PASS] testApprovalEmitsEventAndCanBeReplacedAndRevoked() (gas: 179300)\n[PASS] testApprovalRejectsZeroSpender() (gas: 30410)\n[PASS] testConstructorEmitsMintAndMintsToImmediateCaller() (gas: 28358)\n[PASS] testCreate2FactoryReceivesEntireSupply() (gas: 273665)\n[PASS] testDeployerCannotSpendHoldersTokensWithoutApproval() (gas: 92718)\n[PASS] testEntireSupplyCanMove() (gas: 140126)\n[PASS] testFuzzExcessAllowanceSpendReverts(uint256,uint256) (runs: 1000, μ: 116493, ~: 116709)\nLogs:\n  Bound result 224798068291846355212704922\n  Bound result 767698464076484480111194163\n\n[PASS] testFuzzExcessTransferReverts(uint256) (runs: 1000, μ: 54363, ~: 54684)\nLogs:\n  Bound result 1000000000000000000000000003\n\n[PASS] testFuzzTransferConservesSupply(address,uint256) (runs: 1000, μ: 93087, ~: 93558)\nLogs:\n  Bound result 36865\n  Bound result 10099\n\n[PASS] testFuzzTransferFromAccountsExactly(uint256,uint256) (runs: 1000, μ: 157952, ~: 158681)\nLogs:\n  Bound result 17808414643144335589\n  Bound result 115792089237316195423570985008687907853269984665640564039439775593269987191925\n\n[PASS] testLaunchAllocationClaimsAndPoolTransfersArriveWhole() (gas: 693451)\n[PASS] testMetadataAndInitialSupply() (gas: 73856)\n[PASS] testNativeETHAndUnknownCallsAreRejected() (gas: 58946)\n[PASS] testNoAdminMintBurnOrUpgradeEntrypoints() (gas: 1734424)\n[PASS] testRuntimeHasNoForbiddenOpcodes() (gas: 1018351)\n[PASS] testSelfTransferDoesNotChangeBalance() (gas: 51442)\n[PASS] testSelfTransferStillRequiresSufficientBalance() (gas: 33344)\n[PASS] testTransferEmitsEventAndDeliversExactAmount() (gas: 89017)\n[PASS] testTransferFromBalanceFailureRestoresAllowance() (gas: 114861)\n[PASS] testTransferFromConsumesFiniteAllowance() (gas: 218430)\n[PASS] testTransferFromPreservesInfiniteAllowance() (gas: 122304)\n[PASS] testTransferFromRejectsInsufficientAllowanceWithoutMutation() (gas: 109008)\n[PASS] testTransferFromRejectsUnapprovedCaller() (gas: 98641)\n[PASS] testTransferFromRejectsZeroRecipientAndRestoresAllowance() (gas: 101600)\n[PASS] testTransferFromRejectsZeroSenderEvenForZeroAmount() (gas: 33053)\n[PASS] testTransferFromToSelfConsumesAllowanceWithoutChangingBalance() (gas: 101200)\n[PASS] testTransferFromZeroAmountNeedsNoAllowance() (gas: 49111)\n[PASS] testTransferRejectsInsufficientBalance() (gas: 50642)\n[PASS] testTransferRejectsZeroRecipientEvenForZeroAmount() (gas: 71948)\n[PASS] testZeroTransferFromEmptyAccountEmitsEvent() (gas: 56238)\nSuite result: ok. 31 passed; 0 failed; 0 skipped; finished in 116.50ms (343.54ms CPU time)\n\nRan 13 tests for test/SwarmSticker.adversarial.t.sol:SwarmStickerAdversarialTest\n[PASS] testApprovalsAreNotTransitive() (gas: 220045)\n[PASS] testDelegatedZeroTransferToZeroRecipientRevertsWithoutLosingApproval() (gas: 119467)\n[PASS] testFuzzFailedSpendCanBeRetriedAfterFunding(uint256,uint256,uint256) (runs: 1000, μ: 320334, ~: 321067)\nLogs:\n  Bound result 562043726635995994278199186\n  Bound result 943488720409927117073254620\n  Bound result 211106155464482137738551908368408415227213139927\n\n[PASS] testFuzzRepeatedRoundTripsAreFeeFree(uint256,uint256,uint256,uint256) (runs: 1000, μ: 660717, ~: 598844)\nLogs:\n  Bound result 192875045980069811918425448\n  Bound result 2\n  Bound result 159612859\n  Bound result 8\n\n[PASS] testFuzzReplacingAllowanceIsIdempotentAndIsolated(uint256,uint256,uint256) (runs: 1000, μ: 324966, ~: 326216)\nLogs:\n  Bound result 11284\n\n[PASS] testFuzzSpendingOneOwnersApprovalDoesNotSpendAnothers(uint256) (runs: 1000, μ: 384099, ~: 383832)\nLogs:\n  Bound result 15282391656020695690\n\n[PASS] testFuzzSplitSpendsCannotExceedCumulativeBudget(uint256,uint256) (runs: 1000, μ: 259336, ~: 261168)\nLogs:\n  Bound result 573609885987127330493142940\n  Bound result 389174766054442772123101268\n\n[PASS] testInfiniteAllowanceCanBeRevokedAndReplacedWithFiniteBudget() (gas: 301771)\n[PASS] testLargestFiniteAllowanceIsConsumed() (gas: 226786)\n[PASS] testMaximumTransferCannotWrapBalancesOrSpendUnlimitedFunds() (gas: 149268)\n[PASS] testReplayingAnExhaustedAllowanceCannotSpendAgain() (gas: 162998)\n[PASS] testSelfSpenderNeedsItsOwnAllowanceAndConsumesIt() (gas: 242685)\n[PASS] testZeroSpenderRejectedAtBothApprovalExtremes() (gas: 72653)\nSuite result: ok. 13 passed; 0 failed; 0 skipped; finished in 116.78ms (546.50ms CPU time)\n\nRan 2 tests for test/SwarmSticker.invariant.t.sol:SwarmStickerInvariantTest\n[PASS]\nSwarmStickerInvariantTest invariants:\n[PASS] invariantAllowancesMatchModel\n[PASS] invariantMetadataDoesNotChange\n[PASS] invariantSupplyAndBalancesMatchModel\n SwarmStickerInvariantTest invariants (runs: 256, calls: 24576, reverts: 0)\n\n╭----------------+-------------------------+-------+---------+----------╮\n| Contract       | Selector                | Calls | Reverts | Discards |\n+=======================================================================+\n| StickerHandler | approve                 | 2669  | 0       | 0        |\n|----------------+-------------------------+-------+---------+----------|\n| StickerHandler | move                    | 2730  | 0       | 0        |\n|----------------+-------------------------+-------+---------+----------|\n| StickerHandler | moveFullBalanceAndBack  | 2698  | 0       | 0        |\n|----------------+-------------------------+-------+---------+----------|\n| StickerHandler | rejectExcessAllowance   | 2651  | 0       | 0        |\n|----------------+-------------------------+-------+---------+----------|\n| StickerHandler | rejectExcessBalance     | 2764  | 0       | 0        |\n|----------------+-------------------------+-------+---------+----------|\n| StickerHandler | rejectUnauthorizedSpend | 2690  | 0       | 0        |\n|----------------+-------------------------+-------+---------+----------|\n| StickerHandler | rejectZeroRecipient     | 2813  | 0       | 0        |\n|----------------+-------------------------+-------+---------+----------|\n| StickerHandler | revoke                  | 2756  | 0       | 0        |\n|----------------+-------------------------+-------+---------+----------|\n| StickerHandler | spend                   | 2805  | 0       | 0        |\n╰----------------+-------------------------+-------+---------+----------╯\n\nLogs:\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 9280\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 15\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 482\n  Bound result 0\n  Bound result 0\n  Bound result 1953\n  Bound result 0\n  Bound result 0\n  Bound result 5547\n  Bound result 645326474426547203313410069153905908525362434350\n  Bound result 9353\n  Bound result 4224\n  Bound result 28979884934604844\n  Bound result 659918\n  Bound result 4024465510511102366299098504\n  Bound result 0\n  Bound result 20000000000000000000\n  Bound result 0\n  Bound result 10000\n  Bound result 0\n  Bound result 14156453979135213186503102059795389090579586967354570453358534299053859756180\n  Bound result 0\n  Bound result 4424\n  Bound result 10545\n  Bound result 24301\n  Bound result 21455212015041\n  Bound result 3793\n  Bound result 19\n  Bound result 0\n  Bound result 244\n  Bound result 0\n  Bound result 413\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 2547247313\n  Bound result 0\n  Bound result 3660\n  Bound result 115792089237316195423570985008687907853269984665639564039457584007913129650871\n  Bound result 395127614396935425117564229\n  Bound result 8223\n  Bound result 2909\n  Bound result 0\n  Bound result 0\n  Bound result 4099\n\n[PASS] testHandlerBoundarySequence() (gas: 1714966)\nLogs:\n  Bound result 1\n  Bound result 1\n  Bound result 115792089237316195423570985008687907853269984665640564039457584007913129639935\n  Bound result 115792089237316195423570985008687907853269984665640564039457584007913129639935\n  Bound result 115792089237316195423570985008687907853269984665640564039457584007913129639934\n  Bound result 1\n  Bound result 0\n  Bound result 1\n\nSuite result: ok. 2 passed; 0 failed; 0 skipped; finished in 7.13s (7.13s CPU time)\n\nRan 3 test suites in 7.13s (7.36s CPU time): 46 tests passed, 0 failed, 0 skipped (46 total tests)\n","passed":true},{"durationMs":44,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"SwarmSticker.approve(address,uint256)\",\"SwarmSticker.transfer(address,uint256)\",\"SwarmSticker.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":3,\"DEPENDENCIES.md\":22,\"README.md\":130,\"foundry.toml\":24,\"remappings.txt\":2,\"src/SwarmSticker.sol\":13,\"test/SwarmSticker.adversarial.t.sol\":251,\"test/SwarmSticker.invariant.t.sol\":245,\"test/SwarmSticker.t.sol\":399,\"test/TESTING.md\":41},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"af1e7edbc5cfd65459514ae22ea83f2d3410976f7991f41eb92c681fbd9c196c","verifiedTreeHash":"c7998bf5744217d308261c20005559bd24a5f13b","verifierVersion":"0.1.0+61e9b7ca"}]}