{"assessments":[],"deployments":[],"fuzz":[],"identity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"interpretation":"Records acceptance and evidence. Neither completion nor an AI assessment establishes correctness, safety, or independent review.","jobId":"9986e3b8-16e5-42b8-b143-87ff60fdfa3a","kind":"shape:chain","nodes":[{"acceptedSubmissionHash":"5c86e68618515b866e182ce2eea698d07bce9e5055b5ed2ee0ef3dc8d014f12f","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_economics","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"e125e3033245db21b3c55d7b52705507705c1d811451b7775ab6c69d7dfdf093","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_flow","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"e6e8dfb75773ee256f9d9ba0b94a7b29065b0040a9aa876d8eb5e6ce63374f3b","dependsOn":["build_contract_project","write_foundry_tests","manifest","audit_math","audit_permissions","audit_economics","audit_flow"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"3014f1ea5961918ca059453a484bf4c8bcbbfc2248dbe31d94ac7c5cdf8f50bd","skillId":"audit-judge","tools":[]},"key":"audit_judge","kind":"code","role":"review","skillHash":"3014f1ea5961918ca059453a484bf4c8bcbbfc2248dbe31d94ac7c5cdf8f50bd","skillId":"audit-judge","state":"accepted"},{"acceptedSubmissionHash":"a655c882a0028899f9092bc1ce2fab75b3f515a5299b15cb1e1c40d0edefe41a","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_math","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"ee8ff6b54e9af3671f32556786c940886598ddabce67d4707cb5412a049dc2c9","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_permissions","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"b572ef97900ecba05adc80b48c22470a85a8bd65ea109290ad337d99b668d500","dependsOn":[],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"47381b166d1f406a34f0ebdc740ee21bc0383e56e7ad9084b26abf1bf7570904","skillId":"build-contract-project","tools":[]},"key":"build_contract_project","kind":"code","role":"implement","skillHash":"47381b166d1f406a34f0ebdc740ee21bc0383e56e7ad9084b26abf1bf7570904","skillId":"build-contract-project","state":"accepted"},{"acceptedSubmissionHash":"f4f0f46066d74f24c01076d298b1ea6e21e04bb817daf26a72b9e5350264ae60","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"tools":[]},"key":"manifest","kind":"code","role":"integrate","skillHash":null,"skillId":null,"state":"accepted"},{"acceptedSubmissionHash":"42df588cc344e6efb219a4c2b54f0ef7bd254c9c19e201d28ac00d0ec4e2653f","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"73431852439ad3a343f3d2b7db1c43cd363b9f48f9bb51497374a0cf6d50b223","skillId":"write-foundry-tests","tools":[]},"key":"write_foundry_tests","kind":"code","role":"tests","skillHash":"73431852439ad3a343f3d2b7db1c43cd363b9f48f9bb51497374a0cf6d50b223","skillId":"write-foundry-tests","state":"accepted"}],"objective":"A custom token: Meme Witness Protection (ALIBI).\nToken name: Meme Witness Protection\nToken symbol: ALIBI\nToken supply: 1,000,000,000 with 18 decimals, all minted once to the deployer in the constructor.\n\nTransfer rules: no fee","parentJobId":null,"planHash":"eb5720a470b80d56a919dd1cf5a7d8f27c86b735aab83d3732560a1d37c3cda6","previousHash":"0000000000000000000000000000000000000000000000000000000000000000","projectId":"9986e3b8-16e5-42b8-b143-87ff60fdfa3a","publication":{"commit":null,"deliveredAt":null,"repoUrl":"https://github.com/identity-md-launches/launch-559-custom-token-meme-witness"},"receiptIdentity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"registry":"0xb6d0a187b050fa5bb0b87033a203f37becf4a775","research":[],"schema":"identitymd-work-v1","signals":[{"agentId":"51331","feedbackHash":"d90a885e256d77b374f0ef3608d72421ac08fada6c1a1e7cbf312775a05f216d","nodeKey":"audit_economics","submissionHash":"5c86e68618515b866e182ce2eea698d07bce9e5055b5ed2ee0ef3dc8d014f12f","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51340","feedbackHash":"350875dabac049c0f091cc3a76ae7191c0b64008823cc61771710786a5ea0171","nodeKey":"audit_flow","submissionHash":"e125e3033245db21b3c55d7b52705507705c1d811451b7775ab6c69d7dfdf093","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"50955","feedbackHash":"567ee8c2a0885e5cf5e0635e3fc158e2d497ee9d6848a4f7ab994c1b3ba54b7b","nodeKey":"audit_judge","submissionHash":"e6e8dfb75773ee256f9d9ba0b94a7b29065b0040a9aa876d8eb5e6ce63374f3b","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51334","feedbackHash":"1a078bbf15575c47c3dce9cad0414b4d74839e589dea17d0e2bd5236e72f8fe0","nodeKey":"audit_math","submissionHash":"a655c882a0028899f9092bc1ce2fab75b3f515a5299b15cb1e1c40d0edefe41a","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51430","feedbackHash":"c0c5108cd864ee12423ca66f6465a7dced92f2132a7e9479b1c771fdcec39717","nodeKey":"audit_permissions","submissionHash":"ee8ff6b54e9af3671f32556786c940886598ddabce67d4707cb5412a049dc2c9","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"50957","feedbackHash":"9e0cb22279aaac5d9c44a02005fe7eed020f72bbae5550a3ae06e15a53cfffc4","nodeKey":"build_contract_project","submissionHash":"b572ef97900ecba05adc80b48c22470a85a8bd65ea109290ad337d99b668d500","tag1":"verification:checks","tag2":"acceptance-v2","value":1},{"agentId":"50957","feedbackHash":"a684b422e89da9ef4dcde85cfd1a5885cc007176258c7caa01ba3966e14df600","nodeKey":"manifest","submissionHash":"f4f0f46066d74f24c01076d298b1ea6e21e04bb817daf26a72b9e5350264ae60","tag1":"verification:checks","tag2":"acceptance-v2","value":1},{"agentId":"50962","feedbackHash":"07a41564402a574781ce813e63077d7511e3fda08e8a69db9de14ae03eccd155","nodeKey":"write_foundry_tests","submissionHash":"42df588cc344e6efb219a4c2b54f0ef7bd254c9c19e201d28ac00d0ec4e2653f","tag1":"verification:checks","tag2":"acceptance-v2","value":1}],"site":null,"snapshotHash":"e2fc9807b3a3562658c06cf8f43e8823a223848bce8cd51a708026bc21f9fd12","state":"completed","submissions":[{"artifacts":[],"attempt":1,"bundleHash":"7486e37cd7a4ff1aedf26f75c3dff75e5e850671f89f2554ce32f335d7cd6206","device":"3f6a9bdd601cb99f","findings":[],"hash":"42df588cc344e6efb219a4c2b54f0ef7bd254c9c19e201d28ac00d0ec4e2653f","nodeId":"94289e6e-f7b5-4c98-a811-053a3d7bc98c","outcome":"completed","summary":"Expanded the tests with allowance lifecycle, arithmetic boundary, failure-path, and randomized invariant coverage.\n\n`forge build` and `forge test` pass offline: **44 tests passed**, including **32,768 invariant calls**.\n\nOnly files under `test/` changed. No implementation defects found.","treeHash":"4f05663a588e8d56787a078dccae3213e4f13c2f","usage":{"cachedInputTokens":582656,"inputTokens":65121,"model":"gpt-6-astra","outputTokens":9290,"runtime":"codex","turns":5,"wallClockMs":338923}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"d2d5a117dd72f6b4","findings":[{"citation":"resolved","description":"README.md (line 79) says DEPENDENCIES.json records the SHA-256 hashes of the vendored files so a reader can verify the vendored tree against the upstream release without a network. Seven forge-std entries do not match the files actually committed: StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IMulticall3.sol and mocks/MockERC721.sol. All six OpenZeppelin entries and the remaining forge-std entries match. Diffing the mismatched files against the upstream v1.9.4 archive (whose archive_sha256 does match the recorded 9bf19180...) shows the only difference is whitespace: the vendored copies were reformatted (multi-line signatures joined, as forge fmt does). No semantic change, and forge-std is a test-only dependency, so no production code or token behaviour is affected. The defect is that the integrity record is wrong: a verifier that checks DEPENDENCIES.json against the tree gets seven failures and cannot distinguish reformatting from tampering without fetching upstream, which is exactly what the record exists to avoid. This is outside the economics area; it is reported because it is concretely reproducible and bears on supply-chain provenance of the submission. Fix: either re-vendor the seven files byte-for-byte from the archive, or recompute and record the digests of the files as committed (and state in README that they are formatted copies).","line":26,"path":"DEPENDENCIES.json","reproduction":"In the repository root run: sha256sum lib/forge-std/src/StdAssertions.sol lib/forge-std/src/Vm.sol. Expected (DEPENDENCIES.json lines 26 and 38): d4c89eec70d267dec6188461fbc74d3dc8c47e518d176a23417533a232ed9780 and 9ed10705966cec6d7e92a705659039aa8859c8d34bf2e6ba83de7165e984ea91. Actual: 3fbf4a025b4fc94eaca4c38c1f3dacb37bee10f12ee81994cfaf365ac1ce7384 and a97ae3a5a13313815470d8b06bc6352c75ecde73761606567872f98cf0d51391. Checking every files_sha256 entry the same way yields 7 mismatches (all under lib/forge-std/src/) and 27 matches. tr -d ' \\n\\t' on each mismatched vendored file and on the corresponding file from the v1.9.4 archive gives identical bytes, so the difference is whitespace only.","severity":"low","snippet":"      \"lib/forge-std/src/StdAssertions.sol\": \"d4c89eec70d267dec6188461fbc74d3dc8c47e518d176a23417533a232ed9780\",","title":"DEPENDENCIES.json records SHA-256 digests that do not match seven vendored forge-std files"}],"hash":"5c86e68618515b866e182ce2eea698d07bce9e5055b5ed2ee0ef3dc8d014f12f","nodeId":"439f3e7b-1cba-438c-bb3b-dd1a1440caa6","outcome":"completed","summary":"The review is complete. The findings file is written at the repository root, is excluded from git by the repo's own info/exclude as intended, and no tracked file was changed.\n\n**Outcome.** The ALIBI token has no economic defect I could substantiate. It is an unmodified OpenZeppelin v5.1.0 ERC-20 whose only mint is in the constructor, with no owner, fee, hook, callback, or privileged path. I reported one low-severity provenance defect outside my area.\n\n**What I checked in the Economic Security, Invariant and Flow Gap areas**\n\n- Verified the six vendored OpenZeppelin files match the digests recorded in DEPENDENCIES.json, so the ERC-20 under review is the real v5.1.0 code.\n- Traced approve, transfer and transferFrom through the vendored implementation for fee, rebasing, blacklist, pause, void-return, sentinel-address and callback behaviour. None exist. Transfers to the zero address revert rather than silently burning.\n- Wrote and ran a scratch test simulating the launch flows: CREATE2 deploy from a factory contract, the swarm share to a distributor, a seed credited through a sync-and-settle delta like the Uniswap v4 PoolManager, the remainder to the requester, a claim, and a buy and sell-back through approve plus transferFrom. Every leg moved exactly the amount paid and the fuzzed settle credit equalled the amount sent for all values from zero to the full supply.\n- Confirmed the full supply fits in a signed 128-bit delta, so pool accounting cannot overflow.\n- Confirmed the compiled ABI exposes only the standard ERC-20 surface plus the INITIAL_SUPPLY getter, and that mint, burn and burnFrom probes from the factory and from strangers all revert with supply unchanged.\n- Ran the existing suite: 30 tests pass including 128 invariant runs holding sum of balances equal to total supply.\n\n**The one finding (low).** DEPENDENCIES.json records SHA-256 digests for seven forge-std files that do not match the committed files. I downloaded the v1.9.4 archive, whose digest does match the recorded archive hash, and diffed the files. The difference is whitespace-only reformatting, and forge-std is a test-only dependency, so token behaviour is unaffected. The record is still wrong and would fail any offline integrity check. The reproduction gives the exact command, the recorded digests, and the actual digests.\n\n**Coverage.** All three listed entry points are marked holds with reasons, plus rows for the fixed-supply invariant, the mint-to-factory invariant, the token-misbehaviour classes, and the provenance finding.\n\n**Static-analysis leads.** Slither reported nothing. Aderyn's large-numeric-literal note on line 10 is the supply constant, which uses the standard underscore-separated form and equals the manifest supply exactly, so it is not a defect.","treeHash":null,"usage":{"cachedInputTokens":762671,"inputTokens":290,"model":"claude-fable-5-1","outputTokens":15210,"runtime":"claude","turns":30,"wallClockMs":207385}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"433c37ef2c9c708d","findings":[{"citation":"resolved","description":"Outside the assigned math area; recorded because it is substantiated. Seven vendored forge-std files (StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IMulticall3.sol, mocks/MockERC721.sol) have SHA-256 digests different from the ones DEPENDENCIES.json records for tag v1.9.4. Diffing against the upstream v1.9.4 archive shows only line-wrapping differences (forge fmt style), no semantic change. All six OpenZeppelin v5.1.0 files that the production token depends on match their recorded digests exactly, so this does not affect src/ALIBI.sol or its compiled bytecode. The lock file's claim is nevertheless false for the test harness, which weakens its value as provenance evidence. Fix: either re-vendor the exact upstream files or regenerate the digests from the committed files.","line":26,"path":"DEPENDENCIES.json","reproduction":"Run in repo root: python3 -c \"import json,hashlib;[print(p, hashlib.sha256(open(p,'rb').read()).hexdigest()==h) for d in json.load(open('DEPENDENCIES.json')) for p,h in d['files_sha256'].items()]\". Expected: every line True. Actual: seven lib/forge-std/src/* lines print False; all lib/openzeppelin-contracts/* lines print True. `diff -w -B` of each mismatched file against the v1.9.4 archive shows only whitespace/line-break differences.","severity":"info","snippet":"      \"lib/forge-std/src/StdAssertions.sol\": \"d4c89eec70d267dec6188461fbc74d3dc8c47e518d176a23417533a232ed9780\",","title":"DEPENDENCIES.json records forge-std v1.9.4 file hashes that do not match the vendored files (formatting-only drift, test tooling only)"}],"hash":"a655c882a0028899f9092bc1ce2fab75b3f515a5299b15cb1e1c40d0edefe41a","nodeId":"5dc5d6a9-aacd-41e3-9c1c-57b4bcb088f9","outcome":"completed","summary":"The review is complete and the findings file is written. The git status shows no tracked changes; the findings file is the only untracked addition.\n\n**Outcome: no math, boundary, or numerical-gap defect found in the token.** The report at `.imd-findings.json` holds one info-level note and seven coverage rows, all `holds`.\n\n**What I checked**\n\n- **Math precision.** The supply constant is a compile-time expression that evaluates exactly to one billion times ten to the eighteenth, matching the manifest and the inherited 18-decimal default. The token has no division, scaling, fee term, rate, or narrowing cast anywhere in its value path. Every unchecked block in the vendored OpenZeppelin `_update` and `_spendAllowance` is bounded by the preceding check or by the fixed supply, which sits far below the uint256 ceiling. The aderyn large-literal lead resolves to this exact constant and is not a defect.\n- **Boundary.** The token makes no external calls, has no payable, receive, or fallback path, and decodes no bytes. Sending ETH with or without calldata reverts. The only sentinel branches are the zero-address mint and burn arms, unreachable after construction. I exercised exact-balance, balance plus one, zero-value, self-transfer, zero-recipient, and max-uint inputs on all three entry points.\n- **Numerical gap.** With no arithmetic beyond exact add and subtract of caller-supplied amounts, no seam between precision, invariant, and boundary exists to exploit. The allowance sentinel is only triggered at exactly the max value. A value one below it decrements normally.\n\n**Verification run**\n\n- The existing suite passed: 29 unit and fuzz tests plus the invariant run of 8192 calls with zero reverts.\n- My scratch tests under `test/scratch/` passed on every real corner case and were removed afterwards. One scratch assertion failed only because I guessed the wrong OpenZeppelin error name for a zero-address sender. The contract reverts correctly either way.\n\n**One info note outside my area.** The OpenZeppelin hashes in `DEPENDENCIES.json` all match the vendored files. Seven forge-std hashes do not. I diffed them against the upstream v1.9.4 archive and the differences are formatter line-wrapping only, so the test tooling is semantically unchanged. The note gives a one-line Python reproduction so the author can regenerate the digests or re-vendor the exact files.","treeHash":null,"usage":{"cachedInputTokens":787207,"inputTokens":418,"model":"claude-fable-5-1","outputTokens":11965,"runtime":"claude","turns":21,"wallClockMs":186086}},{"artifacts":[],"attempt":1,"bundleHash":"4f18fa4c658c59866c1410e66a39e12e96421135c51ddf42d652d52d24b02ff4","device":"0256823ae36e7900","findings":[],"hash":"b572ef97900ecba05adc80b48c22470a85a8bd65ea109290ad337d99b668d500","nodeId":"1dffd973-2721-4717-a436-c3f4e47059b8","outcome":"completed","summary":"Implemented Meme Witness Protection (ALIBI): 1 billion tokens, 18 decimals, minted once to the deployer, with zero transfer fees.\n\nAdded vendored dependencies, deployment documentation, and 30 passing tests covering success, failure, fuzzing, and invariants.\n\n`forge build`, `forge test`, and `forge fmt --check` pass, including clean offline verification with an empty environment.","treeHash":"f04fda1d08df416ab1ae46dda5e382cc4410f4a9","usage":{"cachedInputTokens":1290112,"inputTokens":54930,"model":"gpt-6-astra","outputTokens":9065,"runtime":"codex","turns":6,"wallClockMs":518900}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"3b260b68e9ad6a37","findings":[{"citation":"resolved","description":"README.md lines 78-79 state that DEPENDENCIES.json 'records the release archive URLs, archive hashes, and SHA-256 hashes of the vendored files', and the file is the only provenance record for the dependencies committed as plain files under lib/. For the forge-std v1.9.4 entry, 7 of the 29 recorded hashes do not match the committed files: StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IMulticall3.sol and mocks/MockERC721.sol. I fetched the upstream v1.9.4 files and confirmed the committed copies differ from upstream only in whitespace (line reflows of long signatures, e.g. Vm.sol lines 783-786 `parseJsonAddressArray` collapsed to one line); token streams are identical, so no behaviour changed. The recorded hashes are the upstream originals, meaning the files were reformatted (consistent with `forge fmt` having been run over lib/) after the record was produced. All 6 OpenZeppelin v5.1.0 files and the remaining 22 forge-std files match both the record and upstream byte-for-byte; ERC20.sol, Context.sol, IERC20.sol, IERC20Metadata.sol and draft-IERC6093.sol are therefore exactly upstream, which is the Periphery conclusion that matters for the token. Impact: anyone following the README to verify provenance of the vendored test harness gets 7 mismatches and cannot distinguish reformatting from tampering without re-fetching upstream; the record contradicts the tree it describes. Runtime token code is unaffected (forge-std is a test-only dependency). Fix: either restore the 7 files to their upstream bytes (so the recorded hashes become true) or regenerate the 7 hashes from the committed files and note the reformatting.","line":38,"path":"DEPENDENCIES.json","reproduction":"State: the committed tree at HEAD (040e19d). Run from the repository root:\n\npython3 - <<'EOF'\nimport json,hashlib\nfor dep in json.load(open('DEPENDENCIES.json')):\n    for p,h in dep['files_sha256'].items():\n        a=hashlib.sha256(open(p,'rb').read()).hexdigest()\n        if a!=h: print('MISMATCH',p,'actual',a,'recorded',h)\nEOF\n\nExpected: no output (every recorded hash equals the committed file's hash, as README.md:78-79 claims). Actual: 7 MISMATCH lines, e.g. lib/forge-std/src/Vm.sol actual a97ae3a5a13313815470d8b06bc6352c75ecde73761606567872f98cf0d51391 recorded 9ed10705966cec6d7e92a705659039aa8859c8d34bf2e6ba83de7165e984ea91. Cross-check: `curl -sL https://raw.githubusercontent.com/foundry-rs/forge-std/v1.9.4/src/Vm.sol | sha256sum` gives 9ed10705... (the recorded value), and `diff -w` of that download against lib/forge-std/src/Vm.sol still shows 45 changed lines that are pure line reflows, while stripping all whitespace from both yields identical bytes.","severity":"low","snippet":"      \"lib/forge-std/src/Vm.sol\": \"9ed10705966cec6d7e92a705659039aa8859c8d34bf2e6ba83de7165e984ea91\",","title":"DEPENDENCIES.json records wrong SHA-256 hashes for 7 vendored forge-std files (whitespace-reformatted after hashing)"}],"hash":"e125e3033245db21b3c55d7b52705507705c1d811451b7775ab6c69d7dfdf093","nodeId":"b5d37266-65f3-4917-86c1-f1789ba6cbd1","outcome":"completed","summary":"Review complete. The findings file is written and validated.\n\n**Outcome:** The token is a plain, unmodified OpenZeppelin v5.1.0 ERC-20 with a single constructor mint, and nothing in the Execution Trace, Periphery or First Principles checklists fails against it. I found one low-severity defect, in the provenance record rather than the token.\n\n**What I checked**\n- **Execution flow.** The three entry points, their sentinel paths (zero addresses, max allowance), allowance residuals, and atomicity of the allowance-spend-then-transfer sequence. A scratch test under test/scratch drove the launch flows the floor demands: factory mint via CREATE2 with a different tx.origin, transfer to the distributor, claim, approval-and-pull by a pool manager stand-in, remainder forwarding, and buy/sell transfers. Every flow moved exactly the stated amount and supply stayed fixed.\n- **Periphery.** All five vendored OpenZeppelin files are byte-identical to upstream v5.1.0. The compiled ABI has only the three listed state-changing functions, no fallback or receive, no owner, and the project's opcode test confirms no DELEGATECALL, CALLCODE or SELFDESTRUCT.\n- **First principles.** The only path that increases supply is the constructor's mint. Decimals, name, symbol and supply match the brief. The constructor uses the immediate caller, not tx.origin, so the factory receives the whole supply.\n\n**Finding (low):** DEPENDENCIES.json records SHA-256 hashes for 7 forge-std files that do not match the committed files. The committed copies differ from upstream v1.9.4 only by whitespace reflows, so the test harness is semantically upstream, but the record the README points to for provenance is wrong. Reproduction is a short hash-check script included in the finding.\n\n**Coverage:** 8 rows. All three entry points hold, plus rows for the constructor, the supply invariant, the OpenZeppelin and forge-std periphery, and one unreached row for the live Uniswap v4 seed-and-swap test, which cannot compile here because v4-core is not vendored.","treeHash":null,"usage":{"cachedInputTokens":787328,"inputTokens":418,"model":"claude-fable-5-1","outputTokens":16345,"runtime":"claude","turns":21,"wallClockMs":232790}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"3c7630b22a73c1fb","findings":[{"citation":"resolved","description":"Merged from three specialist reports (audit_math, audit_flow, audit_economics) that each reproduced the same root cause; audit_permissions and the independent tester reported nothing. README.md lines 77-79 state that DEPENDENCIES.json records the SHA-256 hashes of the vendored files so the tree can be verified against the upstream release without network access. For the forge-std v1.9.4 entry, 7 of the 29 recorded file hashes do not match the committed files: src/StdAssertions.sol (line 26), src/StdJson.sol (31), src/StdToml.sol (35), src/Vm.sol (38), src/console.sol (39), src/interfaces/IMulticall3.sol and src/mocks/MockERC721.sol. I re-fetched each file from the foundry-rs/forge-std v1.9.4 tag: every upstream file hashes to exactly the recorded value, and after stripping all whitespace the upstream and committed files are byte-identical, so the committed copies are forge-fmt reflows of the genuine upstream files with no token-level change. All six OpenZeppelin v5.1.0 files match their recorded hashes and ERC20.sol is byte-identical to upstream v5.1.0 (be0df7e4...), so the production token src/ALIBI.sol and its compiled bytecode are unaffected; forge-std is a test-only dependency. Impact: the integrity record contradicts the tree it describes, so a verifier that follows the README gets seven failures and cannot distinguish reformatting from tampering without fetching upstream, which is what the record exists to avoid. Not a runtime or funds defect. Fix (either): restore the seven files to their upstream bytes so the recorded digests become true, or regenerate the seven digests from the committed files and note in README that forge-std is a formatted copy.","line":26,"path":"DEPENDENCIES.json","reproduction":"State: the committed tree at HEAD (527ccc9). From the repository root run:\n\npython3 - <<'EOF'\nimport json,hashlib\nfor dep in json.load(open('DEPENDENCIES.json')):\n    for p,h in dep['files_sha256'].items():\n        a=hashlib.sha256(open(p,'rb').read()).hexdigest()\n        if a!=h: print('MISMATCH',p,'actual',a,'recorded',h)\nEOF\n\nExpected (per README.md:77-79): no output. Actual: 7 MISMATCH lines, e.g. lib/forge-std/src/StdAssertions.sol actual 3fbf4a025b4fc94eaca4c38c1f3dacb37bee10f12ee81994cfaf365ac1ce7384 recorded d4c89eec70d267dec6188461fbc74d3dc8c47e518d176a23417533a232ed9780; lib/forge-std/src/Vm.sol actual a97ae3a5a13313815470d8b06bc6352c75ecde73761606567872f98cf0d51391 recorded 9ed10705966cec6d7e92a705659039aa8859c8d34bf2e6ba83de7165e984ea91. Cross-check: `curl -sL https://raw.githubusercontent.com/foundry-rs/forge-std/v1.9.4/src/Vm.sol | sha256sum` prints 9ed10705... (the recorded value), and `tr -d ' \\n\\t\\r'` applied to both that download and lib/forge-std/src/Vm.sol yields identical bytes. All lib/openzeppelin-contracts/* entries print nothing (they match).","severity":"low","snippet":"      \"lib/forge-std/src/StdAssertions.sol\": \"d4c89eec70d267dec6188461fbc74d3dc8c47e518d176a23417533a232ed9780\",","title":"DEPENDENCIES.json records SHA-256 digests that do not match seven vendored forge-std v1.9.4 files (files were whitespace-reformatted after hashing)"}],"hash":"e6e8dfb75773ee256f9d9ba0b94a7b29065b0040a9aa876d8eb5e6ce63374f3b","nodeId":"933be3a1-d49e-4adb-b971-94c32632b30d","outcome":"completed","summary":"The review is complete and the findings file is written. The token itself is clean.\n\n**Outcome:** one low finding, three entry points all hold, no code changes made. The file `.imd-findings.json` is in the repository root and no tracked file was touched.\n\n**What I verified on the token**\n- The vendored OpenZeppelin ERC20 is byte-identical to upstream v5.1.0, so approve, transfer and transferFrom are the stock implementations. I traced each path, including zero-address, insufficient balance and insufficient allowance reverts, and the fixed-supply behaviour.\n- The constructor mints exactly one billion tokens with 18 decimals to msg.sender once. The ABI exposes no mint, burn, pause, blacklist or owner function, which satisfies every probe in the protected launch harness.\n- An opcode walk of the compiled runtime found no DELEGATECALL, CALLCODE, SELFDESTRUCT or any external call.\n- The manifest's sqrtPriceX96 recomputes exactly from the supply and the opening cap, and the paired currency is the zero address.\n- Build, format check and all 44 local tests pass. Slither reported nothing and the aderyn large-literal note is the intended supply constant.\n\n**The one kept finding**\nAll three specialists who reported something hit the same root cause, so I merged them into one low finding. Seven forge-std files under lib/ have whitespace-reformatted contents, but DEPENDENCIES.json still records the upstream digests. I re-fetched the v1.9.4 files myself: the recorded hashes match upstream exactly, and stripping whitespace makes upstream and committed files identical. This is a provenance-record defect only, test tooling only, and does not affect the token or its bytecode. The fix is either to restore the upstream bytes or to regenerate the seven digests.\n\n**Coverage record:** seven rows, three for the listed entry points plus rows for the constructor, runtime opcodes, manifest provenance and dependency provenance.","treeHash":null,"usage":{"cachedInputTokens":467915,"inputTokens":290,"model":"claude-fable-5-1","outputTokens":6805,"runtime":"claude","turns":10,"wallClockMs":114481}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"2a5d68f89de314cb","findings":[],"hash":"ee8ff6b54e9af3671f32556786c940886598ddabce67d4707cb5412a049dc2c9","nodeId":"4c7a52b9-4edc-4de6-a284-0d339b8ff0df","outcome":"completed","summary":"The review is complete. The findings file is written and the scratch test is removed, so the working tree holds only the review record.\n\n**Result: no defects found in the Access Control, Trust Gap, or Asymmetry areas.** The findings file at `.imd-findings.json` carries an empty findings list and nine coverage rows, all marked `holds`.\n\nWhat I checked and how:\n\n- **Permission model.** The compiled ABI exposes only approve, transfer and transferFrom as state-changing entry points, plus views. There is no owner, role, initializer, proxy, receive, fallback, pause, blacklist, mint, burn or upgrade path. A scratch Foundry test confirmed that ETH sends and unknown selectors revert, that the deployer cannot pull or approve on a holder's behalf, and that allowances are scoped exactly to one owner and spender pair.\n- **Constructor and roles after deployment.** The constructor takes no arguments and mints the full supply once to the immediate caller. Under a CREATE2 factory the factory receives everything and the transaction originator receives nothing. No roles are handed out.\n- **Library integrity.** The vendored OpenZeppelin files are byte-identical to the upstream v5.1.0 release archive, whose hash also matches the repository's dependency record. There are no git submodules and the runtime has no DELEGATECALL, CALLCODE or SELFDESTRUCT.\n- **Asymmetry pairs.** transfer and transferFrom share the same validation and storage writes, differing only in the allowance debit. The burn branch of the internal update function is unreachable because nothing calls the burn helper and transfers to the zero address revert. The approve-emits but spend-does-not asymmetry is standard documented OpenZeppelin v5 behaviour.\n- **Trust-gap seams.** With no fee, exemption list, recipient setter, oracle or privileged actor, no caller class is priced or treated differently, so the launch flows move exact amounts.\n- **Static-analysis leads.** Slither reported nothing. The aderyn large-numeric-literal note points at a compile-time constant equal to one billion tokens in 18-decimal units, which cannot overflow. It is recorded as a note, not a finding.\n- **Tests run.** The full suite passed (30 tests including 512-run fuzz and a 128 by 64 invariant run), formatting is clean, and my four scratch checks passed before being deleted.\n\nTrust assumptions recorded for the judge rather than as defects: the factory holds the entire supply after construction and is the sole distributor, and holders carry the standard ERC-20 approve front-running race the README already documents. Uniswap v4 seeding and swaps were not executed locally because the protected harness needs launch-environment variables, but the token has no transfer hook or fee that could affect them.","treeHash":null,"usage":{"cachedInputTokens":451032,"inputTokens":194,"model":"claude-fable-5-1","outputTokens":10509,"runtime":"claude","turns":23,"wallClockMs":149697}},{"artifacts":[],"attempt":1,"bundleHash":"7ea88c4c8a7e55ccaa1d595400f11a56a84f009768f1d88b9cbd6bf56e903679","device":"0256823ae36e7900","findings":[],"hash":"f4f0f46066d74f24c01076d298b1ea6e21e04bb817daf26a72b9e5350264ae60","nodeId":"5c9b81a4-2358-4d02-90de-02af4ea2af8f","outcome":"completed","summary":"Created [launch.json](/home/imd-worker/.identitymd/work/9986e3b8-16e5-42b8-b143-87ff60fdfa3a/5c9b81a4-2358-4d02-90de-02af4ea2af8f/launch.json) matching ALIBI’s constructor, exact supply, and requested economics.\n\nValidation passed: supplied JSON Schema, compiled constructor ABI, `forge build`, and all 30 local tests.\n\nOnly `launch.json` is changed for submission.","treeHash":"6c30035787c33fe0cfb63706bef0c64813d1d2a5","usage":{"cachedInputTokens":223104,"inputTokens":22600,"model":"gpt-6-astra","outputTokens":2972,"runtime":"codex","turns":3,"wallClockMs":129071}}],"verification":[{"checks":[{"durationMs":4183,"exitCode":0,"name":"build","output":"Compiling 32 files with Solc 0.8.26\nSolc 0.8.26 finished in 3.87s\nCompiler run successful!\n","passed":true},{"durationMs":17269,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 13 tests for test/ALIBI.edge.t.sol:ALIBIEdgeTest\n[PASS] testAnApprovalDoesNotFollowTokensToTheirNewOwner() (gas: 171406)\n[PASS] testApprovalBeforeFundingSurvivesFailedSpendThenBecomesUsable() (gas: 268185)\n[PASS] testApprovalsAreIndependentForEachOwnerAndSpender() (gas: 513329)\n[PASS] testFuzzApprovalReplacementIsIdempotentAndDoesNotMoveFunds(uint256,uint256) (runs: 1000, μ: 192840, ~: 192899)\n[PASS] testFuzzOverdrawIsAtomic(uint256,uint256) (runs: 1000, μ: 188602, ~: 189431)\nLogs:\n  Bound result 602423746275505014485520733\n  Bound result 115792089237316195423570985008687907853269984665639961615711308502898644365994\n\n[PASS] testFuzzSplitSpendingExhaustsAllowanceAndCannotReplay(uint256,uint256) (runs: 1000, μ: 290247, ~: 292410)\nLogs:\n  Bound result 8236\n  Bound result 1\n\n[PASS] testInfiniteApprovalCanBeReducedAndRevokedAfterUse() (gas: 362327)\n[PASS] testMaximumMinusOneAllowanceIsFiniteAcrossRepeatedSpends() (gas: 224767)\n[PASS] testMaximumTransferFromRevertsWithoutConsumingInfiniteAllowance() (gas: 121881)\n[PASS] testOneWeiAndFullSupplyRoundTripsLeaveNoDust() (gas: 335719)\n[PASS] testSelfTransferStillChecksBalanceAndPreservesAllowanceOnFailure() (gas: 214202)\n[PASS] testZeroApprovalToZeroSpenderIsRejected() (gas: 58310)\n[PASS] testZeroDelegatedTransferRejectsZeroRecipientForFiniteAndInfiniteAllowances() (gas: 316201)\nSuite result: ok. 13 passed; 0 failed; 0 skipped; finished in 103.50ms (297.63ms CPU time)\n\nRan 29 tests for test/ALIBI.t.sol:ALIBITest\n[PASS] testApprovalEmitsEventAndCanBeReplacedAndRevoked() (gas: 177854)\n[PASS] testApproveRejectsZeroSpender() (gas: 37639)\n[PASS] testConstructorEmitsMintTransfer() (gas: 11404)\n[PASS] testDeployerCannotSpendHolderFundsWithoutApproval() (gas: 150719)\n[PASS] testFactoryDistributorClaimAndPoolCustodyTransfersHaveNoFee() (gas: 623518)\n[PASS] testFactoryReceivesEntireSupply() (gas: 256297)\n[PASS] testFuzzInsufficientAllowanceIsAtomic(uint256,uint256) (runs: 512, μ: 125146, ~: 126338)\nLogs:\n  Bound result 1000000000000000000000000000\n  Bound result 687773454335305604144085812\n\n[PASS] testFuzzSelfTransferCannotCreateBalance(uint256) (runs: 512, μ: 55067, ~: 54817)\nLogs:\n  Bound result 677385586343234746759253506\n\n[PASS] testFuzzTransferConservesBalancesAndSupply(address,uint256) (runs: 512, μ: 110878, ~: 111245)\nLogs:\n  Bound result 7791\n\n[PASS] testFuzzTransferFromConservesBalancesAndSpendsAllowance(uint256,uint256) (runs: 512, μ: 157314, ~: 158058)\nLogs:\n  Bound result 15997\n  Bound result 260426263924151566091989682\n\n[PASS] testMetadataAndEntireInitialSupply() (gas: 92439)\n[PASS] testNoMintOrPrivilegedBalanceControlsExist() (gas: 725224)\n[PASS] testRuntimeHasNoForbiddenOpcodes() (gas: 2259059)\n[PASS] testSelfTransferPreservesBalance() (gas: 51432)\n[PASS] testTransferEmitsEventAndDeliversExactAmount() (gas: 88974)\n[PASS] testTransferEntireSupply() (gas: 81606)\n[PASS] testTransferFromBalanceFailureRestoresSpentAllowance() (gas: 114385)\n[PASS] testTransferFromInvalidRecipientRestoresSpentAllowance() (gas: 111465)\n[PASS] testTransferFromOwnerStillRequiresAllowance() (gas: 50820)\n[PASS] testTransferFromPreservesInfiniteAllowance() (gas: 132436)\n[PASS] testTransferFromRejectsInsufficientAllowanceWithoutChangingState() (gas: 108557)\n[PASS] testTransferFromRejectsZeroSenderEvenForZeroValue() (gas: 50762)\n[PASS] testTransferFromSpendsFiniteAllowanceAndEmitsTransfer() (gas: 152941)\n[PASS] testTransferFromToOwnerSpendsAllowanceWithoutChangingBalance() (gas: 100733)\n[PASS] testTransferRejectsInsufficientBalanceWithoutChangingState() (gas: 112897)\n[PASS] testTransferRejectsMaximumAmountWithoutOverflow() (gas: 50569)\n[PASS] testTransferRejectsZeroRecipientIncludingZeroValue() (gas: 72073)\n[PASS] testZeroTransferFromNeedsNoAllowance() (gas: 67491)\n[PASS] testZeroTransferFromUnfundedAccountEmitsEvent() (gas: 66470)\nSuite result: ok. 29 passed; 0 failed; 0 skipped; finished in 103.73ms (425.52ms CPU time)\n\nRan 2 tests for test/ALIBI.invariant.t.sol:ALIBIInvariantTest\n[PASS] invariant_fixedSupplyAndExactBalancesAndAllowances() (runs: 256, calls: 32768, reverts: 0)\n\n╭--------------+--------------------+-------+---------+----------╮\n| Contract     | Selector           | Calls | Reverts | Discards |\n+================================================================+\n| ALIBIHandler | approve            | 5332  | 0       | 0        |\n|--------------+--------------------+-------+---------+----------|\n| ALIBIHandler | approveBoundary    | 5496  | 0       | 0        |\n|--------------+--------------------+-------+---------+----------|\n| ALIBIHandler | rejectTransfer     | 5516  | 0       | 0        |\n|--------------+--------------------+-------+---------+----------|\n| ALIBIHandler | rejectTransferFrom | 5421  | 0       | 0        |\n|--------------+--------------------+-------+---------+----------|\n| ALIBIHandler | transfer           | 5585  | 0       | 0        |\n|--------------+--------------------+-------+---------+----------|\n| ALIBIHandler | transferFrom       | 5418  | 0       | 0        |\n╰--------------+--------------------+-------+---------+----------╯\n\nLogs:\n  Bound result 6\n  Bound result 100000000000000000000\n  Bound result 4000000000000000000\n  Bound result 18\n  Bound result 37\n  Bound result 115792089237316195423570985008687907853269984665640314039357584007935047545925\n  Bound result 13224\n  Bound result 0\n  Bound result 1\n  Bound result 7705\n  Bound result 0\n  Bound result 123000000000000000000\n  Bound result 0\n  Bound result 242\n  Bound result 0\n  Bound result 115792089237316195423570985008687907853269984665640314039557584007913129645468\n  Bound result 115792089237316195423570985008687907853269984665640314039557584007913307002082\n  Bound result 115792089237316195423570985008687907853269984665640314039580584007913129647737\n  Bound result 115792089237316195423570985008687907853269984665640314039357584007916847489567\n  Bound result 249999900000000000000000004\n  Bound result 115792089237316195423570985008687907853269984665640314039580584007913129642372\n  Bound result 611\n  Bound result 332\n  Bound result 1000000000\n  Bound result 115792089237316195423570985008687907853269984665640314039334584007913129643005\n  Bound result 115792089237316195423570985008687907853269984665640314039557584007913129643475\n  Bound result 115792089237316195423570985008687907853269984665640314039580584007913129640768\n  Bound result 6688\n  Bound result 2908\n  Bound result 1197\n  Bound result 255\n  Bound result 66504595674442936917156351\n  Bound result 1063\n  Bound result 115792089237316195423570985008687907853269984665640380544176258450850046810830\n  Bound result 1000000000\n  Bound result 0\n  Bound result 0\n  Bound result 1000000000000000000\n  Bound result 25000000000000000000\n  Bound result 35398529637199187801337492\n  Bound result 1\n  Bound result 0\n  Bound result 53591\n  Bound result 242\n  Bound result 0\n  Bound result 15663710528249072311657798116565083107297974030461491600606240680501323\n  Bound result 1562\n  Bound result 449\n  Bound result 3600\n  Bound result 10\n  Bound result 115792089237316195423570985008687907853269984665640564039457584007913129639934\n  Bound result 1\n  Bound result 4555\n  Bound result 115792089237316195423570985008687907853269984665640282933491546764164013765368\n  Bound result 115792089237316195423570985008687907853269984665640380544176258450850046803653\n  Bound result 220166628555673435534511805863\n  Bound result 1000000000\n  Bound result 115792089237316195423570985008687907853269984665640314039357584007913129695443\n  Bound result 50604499611179302247456164\n  Bound result 53769638671599898028915189\n  Bound result 5112\n  Bound result 449\n  Bound result 1200137770842609444058179855066657684274736596538254\n  Bound result 1\n  Bound result 115792089237316195423570985008687907853269984665640380544176258450850046803325\n  Bound result 4176\n  Bound result 10000000000000000000\n  Bound result 0\n  Bound result 0\n  Bound result 8423\n  Bound result 4000000000000000000\n  Bound result 0\n  Bound result 95\n  Bound result 2\n  Bound result 1000000000000000000\n  Bound result 95\n  Bound result 115792089237316195423570985008687907853269984665640380544166258450850046806141\n  Bound result 7332\n  Bound result 529\n  Bound result 0\n  Bound result 25000000000000000000\n  Bound result 115792089237316195423570985008687907853269984665640278640804946808725328311356\n  Bound result 3\n  Bound result 3999999999999999999\n  Bound result 158217934184884509984802273\n  Bound result 5404580052049861610050476217027731030936592810153662716340362509729815516063\n  Bound result 17653396521591315352170582\n  Bound result 4179\n\n[PASS] testMixedSequencePreservesLedgerAndTransferability() (gas: 10535181)\nLogs:\n  Bound result 1\n  Bound result 1\n  Bound result 1\n  Bound result 115792089237316195423570985008687907853269984665640564039457584007913129639935\n  Bound result 0\n  Bound result 1\n  Bound result 1\n  Bound result 250000000000000000000000000\n  Bound result 250000000000000000000000000\n  Bound result 1\n  Bound result 1\n  Bound result 0\n  Bound result 1\n  Bound result 1\n  Bound result 1\n  Bound result 1\n\nSuite result: ok. 2 passed; 0 failed; 0 skipped; finished in 17.05s (17.05s CPU time)\n\nRan 3 test suites in 17.05s (17.26s CPU time): 44 tests passed, 0 failed, 0 skipped (44 total tests)\n","passed":true},{"durationMs":129,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"ALIBI.approve(address,uint256)\",\"ALIBI.transfer(address,uint256)\",\"ALIBI.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":3,\"DEPENDENCIES.json\":52,\"LICENSE\":21,\"README.md\":125,\"foundry.toml\":20,\"remappings.txt\":2,\"src/ALIBI.sol\":17,\"test/ALIBI.edge.t.sol\":253,\"test/ALIBI.invariant.t.sol\":209,\"test/ALIBI.t.sol\":360},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"42df588cc344e6efb219a4c2b54f0ef7bd254c9c19e201d28ac00d0ec4e2653f","verifiedTreeHash":"4f05663a588e8d56787a078dccae3213e4f13c2f","verifierVersion":"0.1.0+da6bdbe5"},{"checks":[{"durationMs":3803,"exitCode":0,"name":"build","output":"Compiling 31 files with Solc 0.8.26\nSolc 0.8.26 finished in 3.39s\nCompiler run successful!\n","passed":true},{"durationMs":5401,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 29 tests for test/ALIBI.t.sol:ALIBITest\n[PASS] testApprovalEmitsEventAndCanBeReplacedAndRevoked() (gas: 177854)\n[PASS] testApproveRejectsZeroSpender() (gas: 37639)\n[PASS] testConstructorEmitsMintTransfer() (gas: 11404)\n[PASS] testDeployerCannotSpendHolderFundsWithoutApproval() (gas: 150719)\n[PASS] testFactoryDistributorClaimAndPoolCustodyTransfersHaveNoFee() (gas: 623518)\n[PASS] testFactoryReceivesEntireSupply() (gas: 256297)\n[PASS] testFuzzInsufficientAllowanceIsAtomic(uint256,uint256) (runs: 512, μ: 124644, ~: 126346)\nLogs:\n  Bound result 1000000000\n  Bound result 0\n\n[PASS] testFuzzSelfTransferCannotCreateBalance(uint256) (runs: 512, μ: 55067, ~: 54817)\nLogs:\n  Bound result 15061\n\n[PASS] testFuzzTransferConservesBalancesAndSupply(address,uint256) (runs: 512, μ: 110664, ~: 111269)\nLogs:\n  Bound result 9252\n\n[PASS] testFuzzTransferFromConservesBalancesAndSpendsAllowance(uint256,uint256) (runs: 512, μ: 157160, ~: 158059)\nLogs:\n  Bound result 4000000000000000000\n  Bound result 123000000000000000000\n\n[PASS] testMetadataAndEntireInitialSupply() (gas: 92439)\n[PASS] testNoMintOrPrivilegedBalanceControlsExist() (gas: 725224)\n[PASS] testRuntimeHasNoForbiddenOpcodes() (gas: 2259059)\n[PASS] testSelfTransferPreservesBalance() (gas: 51432)\n[PASS] testTransferEmitsEventAndDeliversExactAmount() (gas: 88974)\n[PASS] testTransferEntireSupply() (gas: 81606)\n[PASS] testTransferFromBalanceFailureRestoresSpentAllowance() (gas: 114385)\n[PASS] testTransferFromInvalidRecipientRestoresSpentAllowance() (gas: 111465)\n[PASS] testTransferFromOwnerStillRequiresAllowance() (gas: 50820)\n[PASS] testTransferFromPreservesInfiniteAllowance() (gas: 132436)\n[PASS] testTransferFromRejectsInsufficientAllowanceWithoutChangingState() (gas: 108557)\n[PASS] testTransferFromRejectsZeroSenderEvenForZeroValue() (gas: 50762)\n[PASS] testTransferFromSpendsFiniteAllowanceAndEmitsTransfer() (gas: 152941)\n[PASS] testTransferFromToOwnerSpendsAllowanceWithoutChangingBalance() (gas: 100733)\n[PASS] testTransferRejectsInsufficientBalanceWithoutChangingState() (gas: 112897)\n[PASS] testTransferRejectsMaximumAmountWithoutOverflow() (gas: 50569)\n[PASS] testTransferRejectsZeroRecipientIncludingZeroValue() (gas: 72073)\n[PASS] testZeroTransferFromNeedsNoAllowance() (gas: 67491)\n[PASS] testZeroTransferFromUnfundedAccountEmitsEvent() (gas: 66470)\nSuite result: ok. 29 passed; 0 failed; 0 skipped; finished in 31.08ms (150.01ms CPU time)\n\nRan 1 test for test/ALIBI.invariant.t.sol:ALIBIInvariantTest\n[PASS] invariant_fixedSupplyAndExactBalancesAndAllowances() (runs: 128, calls: 8192, reverts: 0)\n\n╭--------------+--------------+-------+---------+----------╮\n| Contract     | Selector     | Calls | Reverts | Discards |\n+==========================================================+\n| ALIBIHandler | approve      | 2719  | 0       | 0        |\n|--------------+--------------+-------+---------+----------|\n| ALIBIHandler | transfer     | 2656  | 0       | 0        |\n|--------------+--------------+-------+---------+----------|\n| ALIBIHandler | transferFrom | 2817  | 0       | 0        |\n╰--------------+--------------+-------+---------+----------╯\n\nLogs:\n  Bound result 96\n  Bound result 0\n  Bound result 123000000000000000001\n  Bound result 1118\n  Bound result 0\n  Bound result 0\n  Bound result 4092\n  Bound result 18\n  Bound result 0\n  Bound result 20383769980278273336938961\n  Bound result 10000000000000000000\n  Bound result 0\n  Bound result 0\n  Bound result 250000000000000000000001118\n  Bound result 2738\n  Bound result 244\n  Bound result 0\n  Bound result 0\n  Bound result 340\n  Bound result 66318542287327142857998423\n  Bound result 0\n  Bound result 0\n  Bound result 26\n  Bound result 6\n  Bound result 24301\n  Bound result 3390\n  Bound result 152611103042707842360541219\n  Bound result 233\n  Bound result 15495667691657047350990164\n  Bound result 228\n  Bound result 1789\n  Bound result 242\n  Bound result 3\n  Bound result 0\n  Bound result 0\n  Bound result 302\n  Bound result 1411\n  Bound result 6000000000000000000\n  Bound result 695983099786731\n  Bound result 2671\n  Bound result 2514000705\n  Bound result 18\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 5.09s (5.08s CPU time)\n\nRan 2 test suites in 5.09s (5.12s CPU time): 30 tests passed, 0 failed, 0 skipped (30 total tests)\n","passed":true},{"durationMs":156,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"ALIBI.approve(address,uint256)\",\"ALIBI.transfer(address,uint256)\",\"ALIBI.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":3,\"DEPENDENCIES.json\":52,\"LICENSE\":21,\"README.md\":125,\"foundry.toml\":20,\"remappings.txt\":2,\"src/ALIBI.sol\":17,\"test/ALIBI.invariant.t.sol\":91,\"test/ALIBI.t.sol\":360},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true},{"durationMs":1172,"exitCode":0,"name":"slither","output":"slither: no results at low impact or above","passed":true},{"durationMs":325,"exitCode":0,"name":"aderyn","output":"[low] large-numeric-literal at src/ALIBI.sol:10: Large Numeric Literal","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"b572ef97900ecba05adc80b48c22470a85a8bd65ea109290ad337d99b668d500","verifiedTreeHash":"f04fda1d08df416ab1ae46dda5e382cc4410f4a9","verifierVersion":"0.1.0+da6bdbe5"},{"checks":[{"durationMs":1296,"exitCode":0,"name":"build","output":"Compiling 31 files with Solc 0.8.26\nSolc 0.8.26 finished in 1.20s\nCompiler run successful!\n","passed":true},{"durationMs":2247,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 29 tests for test/ALIBI.t.sol:ALIBITest\n[PASS] testApprovalEmitsEventAndCanBeReplacedAndRevoked() (gas: 177854)\n[PASS] testApproveRejectsZeroSpender() (gas: 37639)\n[PASS] testConstructorEmitsMintTransfer() (gas: 11404)\n[PASS] testDeployerCannotSpendHolderFundsWithoutApproval() (gas: 150719)\n[PASS] testFactoryDistributorClaimAndPoolCustodyTransfersHaveNoFee() (gas: 623518)\n[PASS] testFactoryReceivesEntireSupply() (gas: 256297)\n[PASS] testFuzzInsufficientAllowanceIsAtomic(uint256,uint256) (runs: 512, μ: 124949, ~: 126334)\nLogs:\n  Bound result 999999999999999999999999998\n  Bound result 289358849247603028912595608\n\n[PASS] testFuzzSelfTransferCannotCreateBalance(uint256) (runs: 512, μ: 55069, ~: 54817)\nLogs:\n  Bound result 336210811562527848\n\n[PASS] testFuzzTransferConservesBalancesAndSupply(address,uint256) (runs: 512, μ: 110841, ~: 111257)\nLogs:\n  Bound result 0\n\n[PASS] testFuzzTransferFromConservesBalancesAndSpendsAllowance(uint256,uint256) (runs: 512, μ: 157365, ~: 158035)\nLogs:\n  Bound result 1000000000000000000000000000\n  Bound result 1000000000000000000000000000\n\n[PASS] testMetadataAndEntireInitialSupply() (gas: 92439)\n[PASS] testNoMintOrPrivilegedBalanceControlsExist() (gas: 725224)\n[PASS] testRuntimeHasNoForbiddenOpcodes() (gas: 2259059)\n[PASS] testSelfTransferPreservesBalance() (gas: 51432)\n[PASS] testTransferEmitsEventAndDeliversExactAmount() (gas: 88974)\n[PASS] testTransferEntireSupply() (gas: 81606)\n[PASS] testTransferFromBalanceFailureRestoresSpentAllowance() (gas: 114385)\n[PASS] testTransferFromInvalidRecipientRestoresSpentAllowance() (gas: 111465)\n[PASS] testTransferFromOwnerStillRequiresAllowance() (gas: 50820)\n[PASS] testTransferFromPreservesInfiniteAllowance() (gas: 132436)\n[PASS] testTransferFromRejectsInsufficientAllowanceWithoutChangingState() (gas: 108557)\n[PASS] testTransferFromRejectsZeroSenderEvenForZeroValue() (gas: 50762)\n[PASS] testTransferFromSpendsFiniteAllowanceAndEmitsTransfer() (gas: 152941)\n[PASS] testTransferFromToOwnerSpendsAllowanceWithoutChangingBalance() (gas: 100733)\n[PASS] testTransferRejectsInsufficientBalanceWithoutChangingState() (gas: 112897)\n[PASS] testTransferRejectsMaximumAmountWithoutOverflow() (gas: 50569)\n[PASS] testTransferRejectsZeroRecipientIncludingZeroValue() (gas: 72073)\n[PASS] testZeroTransferFromNeedsNoAllowance() (gas: 67491)\n[PASS] testZeroTransferFromUnfundedAccountEmitsEvent() (gas: 66470)\nSuite result: ok. 29 passed; 0 failed; 0 skipped; finished in 16.22ms (75.48ms CPU time)\n\nRan 1 test for test/ALIBI.invariant.t.sol:ALIBIInvariantTest\n[PASS] invariant_fixedSupplyAndExactBalancesAndAllowances() (runs: 128, calls: 8192, reverts: 0)\n\n╭--------------+--------------+-------+---------+----------╮\n| Contract     | Selector     | Calls | Reverts | Discards |\n+==========================================================+\n| ALIBIHandler | approve      | 2721  | 0       | 0        |\n|--------------+--------------+-------+---------+----------|\n| ALIBIHandler | transfer     | 2765  | 0       | 0        |\n|--------------+--------------+-------+---------+----------|\n| ALIBIHandler | transferFrom | 2706  | 0       | 0        |\n╰--------------+--------------+-------+---------+----------╯\n\nLogs:\n  Bound result 495790613314\n  Bound result 0\n  Bound result 255\n  Bound result 96\n  Bound result 123000000000000000000\n  Bound result 120209876281281145568259942\n  Bound result 0\n  Bound result 3963891462\n  Bound result 134340507881134979136017368\n  Bound result 244\n  Bound result 49239\n  Bound result 17\n  Bound result 12380947365977654703358746\n  Bound result 127\n  Bound result 1879\n  Bound result 1283\n  Bound result 358\n  Bound result 1392\n  Bound result 142329976341462984815779306\n  Bound result 114142783024305074059030786\n  Bound result 624764351\n  Bound result 48654891484800337341767268\n  Bound result 0\n  Bound result 79\n  Bound result 51729\n  Bound result 1240\n  Bound result 3579\n  Bound result 1\n  Bound result 1000000000\n  Bound result 93646153543565049174381702\n  Bound result 195\n  Bound result 59618333\n  Bound result 34\n  Bound result 1000000000\n  Bound result 10000000000000000000\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 2.16s (2.16s CPU time)\n\nRan 2 test suites in 2.16s (2.18s CPU time): 30 tests passed, 0 failed, 0 skipped (30 total tests)\n","passed":true},{"durationMs":47,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"ALIBI.approve(address,uint256)\",\"ALIBI.transfer(address,uint256)\",\"ALIBI.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":3,\"DEPENDENCIES.json\":52,\"LICENSE\":21,\"README.md\":125,\"foundry.toml\":20,\"launch.json\":20,\"remappings.txt\":2,\"src/ALIBI.sol\":17,\"test/ALIBI.invariant.t.sol\":91,\"test/ALIBI.t.sol\":360},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"f4f0f46066d74f24c01076d298b1ea6e21e04bb817daf26a72b9e5350264ae60","verifiedTreeHash":"6c30035787c33fe0cfb63706bef0c64813d1d2a5","verifierVersion":"0.1.0+da6bdbe5"}]}