{"assessments":[],"deployments":[],"fuzz":[],"identity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"interpretation":"Records acceptance and evidence. Neither completion nor an AI assessment establishes correctness, safety, or independent review.","jobId":"657f07c4-a49b-49c9-b2e6-e262cac49f32","kind":"shape:chain","nodes":[{"acceptedSubmissionHash":"780e8b7db6345f4258efea74a3035f820d5f483be305b8a871450c91bf1e7d1b","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_economics","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"3ecbef12b5f683d6fcff6413ba19f69f402c40fa99cee65488558cf9c9820976","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_flow","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"0e53a513340f1cefb3f411e6b98cac4a207fb319f3140afcd70d7d99f7f23a27","dependsOn":["build_contract_project","write_foundry_tests","manifest","audit_math","audit_permissions","audit_economics","audit_flow"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"af3aa01159bbf354f621cafa5c0006f6169e0938a8b015be508b7377dbf165bc","skillId":"audit-judge","tools":[]},"key":"audit_judge","kind":"code","role":"review","skillHash":"af3aa01159bbf354f621cafa5c0006f6169e0938a8b015be508b7377dbf165bc","skillId":"audit-judge","state":"accepted"},{"acceptedSubmissionHash":"db425d08543ee2836681c9f6c28b98c397559ca550f6824f9edc8e1dc83e9fdd","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_math","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"f3deb8d359930f670294e0ab066e77f9398e5932e53c9557e7651b19992137b5","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_permissions","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"3b5a78b504f818be1c1c36e904142bb1bf6d40e98bee9bb8a24fe5d90534057a","dependsOn":[],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"6e3e328aa196f6965a2821b098b101e9ff09eef55cdaafaec1d6ea18007b96f6","skillId":"build-contract-project","tools":[]},"key":"build_contract_project","kind":"code","role":"implement","skillHash":"6e3e328aa196f6965a2821b098b101e9ff09eef55cdaafaec1d6ea18007b96f6","skillId":"build-contract-project","state":"accepted"},{"acceptedSubmissionHash":"3158d3b85a937983f049e6a6ee1d7ad13b48c03e4ba035febcfa27269c38b4ac","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"tools":[]},"key":"manifest","kind":"code","role":"integrate","skillHash":null,"skillId":null,"state":"accepted"},{"acceptedSubmissionHash":"6e5dd757c5a13eb8e147f8e07a6dab941c7fa647c230177c2072de7063ac0608","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"73431852439ad3a343f3d2b7db1c43cd363b9f48f9bb51497374a0cf6d50b223","skillId":"write-foundry-tests","tools":[]},"key":"write_foundry_tests","kind":"code","role":"tests","skillHash":"73431852439ad3a343f3d2b7db1c43cd363b9f48f9bb51497374a0cf6d50b223","skillId":"write-foundry-tests","state":"accepted"}],"objective":"A custom token: SwarmCore (CORE).\nToken name: SwarmCore\nToken symbol: CORE\nToken supply: 1,000,000,000 with 18 decimals, all minted once to the deployer in the constructor.","parentJobId":null,"planHash":"b03d9dd43ac7c2954b7822b3777b67d6dc73d46a54230ad543f381b4b8cb9ac6","previousHash":"0000000000000000000000000000000000000000000000000000000000000000","projectId":"657f07c4-a49b-49c9-b2e6-e262cac49f32","publication":{"commit":null,"deliveredAt":null,"repoUrl":"https://github.com/identity-md-launches/launch-1202-swarmcore"},"receiptIdentity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"registry":"0xb6d0a187b050fa5bb0b87033a203f37becf4a775","research":[],"schema":"identitymd-work-v1","signals":[{"agentId":"50988","feedbackHash":"1b5bbe003663fa68c5094bb39a03a496a4a3e4784eea85fd638caaa1bbb82f40","nodeKey":"audit_economics","submissionHash":"780e8b7db6345f4258efea74a3035f820d5f483be305b8a871450c91bf1e7d1b","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51473","feedbackHash":"4d9b4acecea37a4e12340c5f22af92755254e37879adf9ddd27ea5c75aac42c4","nodeKey":"audit_flow","submissionHash":"3ecbef12b5f683d6fcff6413ba19f69f402c40fa99cee65488558cf9c9820976","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51214","feedbackHash":"c53f2aaf17296ed6c541e3827226fe0809d947c929b837111180be6cd926f62b","nodeKey":"audit_judge","submissionHash":"0e53a513340f1cefb3f411e6b98cac4a207fb319f3140afcd70d7d99f7f23a27","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51530","feedbackHash":"5b993094e99f58e3847f1a1f2fadd08c62ed47d7f6bc9c0b1a05b924de1144dc","nodeKey":"audit_math","submissionHash":"db425d08543ee2836681c9f6c28b98c397559ca550f6824f9edc8e1dc83e9fdd","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"52145","feedbackHash":"42f6217ad1c9aacf04da0d750eea00a6fabec9aa2dc65210132998079e832944","nodeKey":"audit_permissions","submissionHash":"f3deb8d359930f670294e0ab066e77f9398e5932e53c9557e7651b19992137b5","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51070","feedbackHash":"72014739bc64e30ab51d60eb34a86e1c9378cc677405518a44024983a70613e4","nodeKey":"build_contract_project","submissionHash":"3b5a78b504f818be1c1c36e904142bb1bf6d40e98bee9bb8a24fe5d90534057a","tag1":"verification:checks","tag2":"acceptance-v2","value":1},{"agentId":"51325","feedbackHash":"90ea397f06ca55af859935c2da528ee0c5300b32fa6e3e54099117c63ba2d78b","nodeKey":"manifest","submissionHash":"3158d3b85a937983f049e6a6ee1d7ad13b48c03e4ba035febcfa27269c38b4ac","tag1":"verification:checks","tag2":"acceptance-v2","value":1},{"agentId":"50970","feedbackHash":"b471ce7bdaaf86141fa6bd204f2fed5c1fd44f0e72dcd2e77fdc111c32c3bc41","nodeKey":"write_foundry_tests","submissionHash":"6e5dd757c5a13eb8e147f8e07a6dab941c7fa647c230177c2072de7063ac0608","tag1":"verification:checks","tag2":"acceptance-v2","value":1}],"site":null,"snapshotHash":"4f1125ba2d405aa71a67c104f72a03acd85d36a3d9576ab05c92f32df5b74c5a","state":"completed","submissions":[{"artifacts":[],"attempt":1,"bundleHash":null,"device":"dd2ee4882a1be950","findings":[{"citation":"resolved","description":"Merged from audit_permissions (its only finding) and the slither missing-zero-check lead; reproduced. The constructor stores poolManager_ into an immutable without validation, and beforeInitialize's first check is `if (msg.sender != poolManager) revert NotPoolManager();`. A guard built with address(0) therefore deploys fine but rejects the real PoolManager and every other caller, so a pool key naming it can never be initialized, including by the launcher that deployed it; there is no setter. Impact is confined to the harness: launch.json lists no application contracts (`\"contracts\": []`), the README states the factory supplies its own guard, and the token itself does not reference this contract, so nothing deployed by this launch is affected. Severity is informational and non-blocking. Minimal fix if the author wants the lead closed: `if (poolManager_ == address(0)) revert NotPoolManager();` (or a dedicated error) in the constructor.","line":19,"path":"src/PoolInitializationGuard.sol","reproduction":"Scratch test test/scratch/GuardZero.t.sol (run with `forge test --match-path test/scratch/GuardZero.t.sol`, passes, i.e. observes the behaviour): (1) `new PoolInitializationGuard(address(0))` succeeds; `poolManager()` returns address(0) and `launcher()` returns the deployer. (2) `vm.prank(0x000000000004444c5dc75cB358380D2e3dE08A90)` (the real v4 PoolManager) then `guard.beforeInitialize(deployer, key, 0)` reverts with NotPoolManager(). Expected if the constructor validated its input: deployment reverts. Actual: deployment succeeds and the hook is permanently unusable; only msg.sender == address(0) passes the first check, which no transaction can produce.","severity":"info","snippet":"        poolManager = poolManager_;","title":"PoolInitializationGuard accepts a zero pool manager and then refuses every initializer (harness contract, not deployed by this launch)"}],"hash":"0e53a513340f1cefb3f411e6b98cac4a207fb319f3140afcd70d7d99f7f23a27","nodeId":"ac83182a-f08c-4dd1-810c-2c7ee07fef41","outcome":"completed","summary":"The findings file is in place, excluded from git by the repository's own exclude list, and the working tree is otherwise clean. No tracked file was changed.\n\n**Outcome:** the token holds. The review found no defect in SwarmCoreToken and kept one informational finding about an undeployed harness contract.\n\n**What I verified**\n\n- The token is OpenZeppelin ERC-20 v5.4.0 plus a constructor mint. The five vendored files it imports are byte-identical to upstream v5.4.0, so no backdoor hides in the library.\n- The ABI has only approve, transfer and transferFrom as state-changing entry points. No receive or fallback, no mint, burn, owner, pause or blacklist, and no DELEGATECALL, CALLCODE or SELFDESTRUCT in the runtime code.\n- I ran the protected floor test against the token's own creation code, with the IMD pair, fee 12500, spacing 60 and the 88% pool share. It passed 8 of 8 both with the token sorting below IMD and above it.\n- The project's own suite passes: 55 tests including fuzz and invariant runs, and the tracked files pass the format check.\n- launch.json uses only schema keys, matches name, symbol, decimals and the constructor mint, and has lowercase addresses and empty constructor arguments as the contract requires.\n\n**Specialist findings**\n\n- The permissions specialist's single finding reproduces: a PoolInitializationGuard built with a zero pool manager deploys and then refuses every initializer. I kept it at info, merged with the matching slither lead, because the manifest deploys no application contracts and the factory supplies its own guard.\n- The other three specialists and the test writer reported nothing, and I found nothing they missed.\n- The remaining static-analysis lines on LaunchLiquidity do not reproduce as defects. The library is harness-only, the transfer bool is checked, and PoolManager.unlock reverts on any unsettled delta.\n\n**Coverage:** all three entry points answered as holds, plus rows for the fixed-supply invariant, the manifest and the static-analysis leads. One note for the author: the README still says the repository has no launch.json, which is stale now that the manifest step has written one.","treeHash":null,"usage":{"cachedInputTokens":1046327,"inputTokens":322,"model":"claude-fable-5-1","outputTokens":17246,"runtime":"claude","turns":30,"wallClockMs":286115}},{"artifacts":[],"attempt":1,"bundleHash":"47fcd6a66964c2cf3e0ee2d11012923231e3d5608ae3fd3be8c64df5bc184889","device":"33ce0bb3dec09f0b","findings":[],"hash":"3158d3b85a937983f049e6a6ee1d7ad13b48c03e4ba035febcfa27269c38b4ac","nodeId":"86770aa0-d01e-4325-8346-9a5c1dd89771","outcome":"completed","summary":"Created `launch.json` matching SwarmCoreToken’s constructor, exact supply, and required pool/economics values.\n\n`forge build` succeeded; all 26 tests passed. Only `launch.json` is included in the submission changes.","treeHash":"234c657a566584365bd5ff3506e9bd935c4bb744","usage":{"cachedInputTokens":263040,"inputTokens":36580,"model":"gpt-6-astra","outputTokens":2451,"runtime":"codex","turns":4,"wallClockMs":84298}},{"artifacts":[],"attempt":1,"bundleHash":"37db2dcdd67c3097c35cdb81caa2b94ba6b62443aaa80ac75ab09c963a371892","device":"89214b73ec1e0b7b","findings":[],"hash":"3b5a78b504f818be1c1c36e904142bb1bf6d40e98bee9bb8a24fe5d90534057a","nodeId":"6d21adc0-66c2-4027-8b9f-97082e4ea825","outcome":"completed","summary":"SwarmCore (CORE) is built and tested at the repository root. `forge build`, `forge test` (26/26 passing) and `forge fmt --check` all pass with the pinned compiler, solc 0.8.26, and I re-ran all three on a clean build with the scratch folder removed.\n\n**The token** (`src/SwarmCoreToken.sol`, contract `SwarmCoreToken`)\n- It is OpenZeppelin's standard ERC-20 with name `SwarmCore`, symbol `CORE` and 18 decimals.\n- 1,000,000,000 × 10^18 tokens are minted once, in the constructor, to the deployer. At launch the deployer is the launch factory.\n- It has no constructor arguments, no owner and no admin functions: nothing can mint, pause, blacklist, burn, charge a fee or move someone else's balance. Every launch transfer arrives in full, so the token needs no exemptions.\n\n**Tests**\n- **`test/SwarmCoreToken.t.sol` (18 tests):** normal use, the standard ERC-20 error cases, two randomised (fuzz) tests showing transfers never change the supply, rejected ETH, and common mint/owner/pause/blacklist/seize calls all failing with no balance change.\n- **`test/SwarmCoreLaunch.t.sol` (8 tests):** runs the launch against a real Uniswap v4 PoolManager. The 10% swarm share arrives in full and can be claimed in full. The pool is opened behind a guard that refuses anyone else, 88% of the supply goes into it at the 2,500 IMD starting value, and the remaining 2% goes to the requester. An ordinary trader then buys and sells back. This works with IMD sorted on either side of the token and at IMD's real address. A seed the factory can't pay for fails.\n- I also ran the protected launch test locally against the token's actual creation code, using this launch's settings. It passed 8/8.\n\n**Things you should know**\n- **Helper files in `src/`:** the protected test imports `src/LaunchLiquidity.sol`, `src/PoolInitializationGuard.sol` and `src/HookFlags.sol`. I wrote these so it compiles. They are test support, not launch contracts, and the README says so; if the verifier brings its own copies, theirs replace mine.\n- **Dependencies:** OpenZeppelin v5.4.0, forge-std, Uniswap v4-core and solmate are copied into `lib/` as ordinary files, with their commits listed in the README. The token itself only uses OpenZeppelin. I removed their nested Foundry configs (v4-core's turns on ffi) and kept v4-core's upstream `.env` out of the tree.\n- **`via_ir = true`:** set in `foundry.toml` along with `bytecode_hash = \"none\"` and `evm_version = \"cancun\"`, because the tests need it to compile v4's PoolManager. It also applies to the token's build.\n- **Nothing is committed:** no git identity is configured here and committing would write into `.git/`, which I'm not allowed to touch. All files are untracked in the working tree; I staged them once and then reset the staging area back to how it was.\n- **No `launch.json`:** I didn't write one, as the brief requires.\n\nThe README covers the token details, the launch settings, assumptions, operational responsibilities and an empty \"After launch\" section, since there's nothing for the owner to set. Passing tests are not a security audit, and I didn't run Slither or Mythril.","treeHash":"3be222186438ec03016f4fab6145ecf033d60e4d","usage":{"cachedInputTokens":1397133,"inputTokens":50,"model":"claude-opus-5-5","outputTokens":35240,"runtime":"claude","turns":26,"wallClockMs":452106}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"dc34db8e17664ebd","findings":[],"hash":"3ecbef12b5f683d6fcff6413ba19f69f402c40fa99cee65488558cf9c9820976","nodeId":"5926675a-29ef-4c14-bcee-d0461c5926d8","outcome":"completed","summary":"The review is complete and the findings file is in place. The tree is otherwise unchanged.\n\n**Result: no defects found.** `.imd-findings.json` holds an empty findings list and 11 coverage rows, one for each of the three entry points plus the invariants and periphery I checked.\n\n**What I verified in my area (Execution Trace, Periphery, First Principles):**\n\n- **Entry points.** `approve`, `transfer` and `transferFrom` are OpenZeppelin v5.4.0 code with no overrides. I traced every guard and state write: zero-address reverts, insufficient balance and allowance reverts, exact amount movement, infinite allowance left untouched. Nothing is exempted, taxed, burned or limited.\n- **Constructor.** It takes no arguments and mints exactly 1,000,000,000 × 10^18 once to msg.sender. There is no `_update` override, mint, burn, owner, pause, receive or fallback. The compiled ABI contains only the nine ERC-20 functions and three view constants.\n- **Bytecode.** An opcode scan of creation and runtime code found no DELEGATECALL, CALLCODE or SELFDESTRUCT, no link references and no immutables. None of the five solc bugs still open for 0.8.26 touches a construct this contract uses.\n- **Periphery integrity.** The five OpenZeppelin files the token compiles are byte-identical to upstream commit c64a1edb. The test-only libraries forge-std, v4-core and solmate differ from their pinned commits only by forge-fmt re-wrapping, confirmed by a whitespace-stripped comparison, so the passing tests are not produced by a tampered harness. There are no git submodules.\n- **Launch floor.** I ran the verifier's protected test from a scratch copy against this token's actual creation code with the README's terms: chain 1, IMD pair, fee 12500, spacing 60, 88% pool share, 2,500 IMD cap. All 8 tests passed, reproducing the README's claim. The project's own 26 tests also pass.\n- **Harness contracts.** The three slither and aderyn leads on `LaunchLiquidity` and `PoolInitializationGuard` are benign. The PoolManager reverts on any unsettled delta, the transfer bool is checked, and the missing zero-check could only brick the harness's own guard, which the manifest does not deploy.\n\n**Not verified.** The README's pool and economics values are said to be copied from the job, but the job text was not supplied, so I could not confirm them. launch.json does not exist yet, which is expected at this stage.","treeHash":null,"usage":{"cachedInputTokens":1111167,"inputTokens":354,"model":"claude-fable-5-1","outputTokens":22886,"runtime":"claude","turns":39,"wallClockMs":369492}},{"artifacts":[],"attempt":1,"bundleHash":"e1c846b2c0e99b75b8fff09fb7164d4979fc67f9d92ddba89504bfd6a6c9fb96","device":"c2a0c6e1f08b5974","findings":[],"hash":"6e5dd757c5a13eb8e147f8e07a6dab941c7fa647c230177c2072de7063ac0608","nodeId":"c24bc4e2-7e1c-4214-b9c2-78fb552282cc","outcome":"completed","summary":"Added tests under `test/` covering failure rollback, allowance revocation, boundary values, and fuzz properties, plus four-actor invariants for supply, balances, and allowances.\n\n`forge build` and `forge test` pass: **55 tests**, including **32,768 invariant handler calls**.\n\nNo reproducible defects found. Only test files were added.","treeHash":"e04988108db32bfa95817edce39b81efeb82b2c5","usage":{"cachedInputTokens":578432,"inputTokens":64528,"model":"gpt-6-astra","outputTokens":11994,"runtime":"codex","turns":5,"wallClockMs":268856}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"fa2b0b9c7ebc1547","findings":[],"hash":"780e8b7db6345f4258efea74a3035f820d5f483be305b8a871450c91bf1e7d1b","nodeId":"5060d86b-813f-4d01-b7c5-a063a145ca5e","outcome":"completed","summary":"The review is complete. The findings file is written at the repository root, is excluded from git by the harness's own exclude rule, and the working tree is otherwise unchanged.\n\n**Result: no defects found in the assigned area.** `.imd-findings.json` holds an empty findings list and ten coverage rows, one for each of the three state-changing entry points plus the invariants and launch flows I checked.\n\n**What I verified**\n\n- **Economic Security.** The token has no external dependencies, no fee, burn, tax, rebase, pause or blacklist, and returns `true` from every ERC-20 mutator. Transfers to the zero address and approvals of the zero spender revert with ERC-6093 errors. The approve race is the inherent ERC-20 caveat the README already documents, not a defect of this code.\n- **Invariant.** The compiled ABI contains exactly the standard ERC-20 surface and three constants. The only mint is in the constructor, so supply is fixed at 1e27. A 2,000-run fuzz of random transfer, approve and transferFrom sequences across six actors kept the sum of balances equal to totalSupply and every successful move exact.\n- **Flow Gap.** I ran the pinned launch-floor test against this token's actual creation code with this launch's terms (IMD pair, fee 12500, spacing 60, 88% pool at a 2,500 IMD cap). All 8 checks passed: supply minted to the factory, swarm share arrives and is claimable whole, single-sided seed and buy and sell each way succeed, no admin call grows supply or freezes a holder, and no DELEGATECALL, CALLCODE or SELFDESTRUCT in runtime code.\n- **Dependency integrity.** The vendored OpenZeppelin matches the upstream v5.4.0 tag exactly once formatted with the repo's forge fmt settings; only the mocks directory was removed. No git submodules are present.\n- **Static-analysis leads.** All four Slither lines and the Aderyn lines point at the test-harness contracts that are not deployed with the token. The ignored `settle()` return cannot leave a short seed because the pool manager reverts on any unsettled delta at the end of `unlock`. None are defects.\n\n**Not reached:** nothing within the assigned area. I did not evaluate the deployer's price derivation or the real IMD token's behavior, which live outside this repository.","treeHash":null,"usage":{"cachedInputTokens":983577,"inputTokens":386,"model":"claude-fable-5-1","outputTokens":18776,"runtime":"claude","turns":32,"wallClockMs":385406}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"5ded77c3c883b7b0","findings":[],"hash":"db425d08543ee2836681c9f6c28b98c397559ca550f6824f9edc8e1dc83e9fdd","nodeId":"419bc175-2c25-4ba0-9278-017b2bca07f5","outcome":"completed","summary":"I found no math defects in SwarmCore (CORE), so `.imd-findings.json` has an empty findings list plus a coverage row for each of the three entry points. I changed no other files.\n\n**What the code is:** `SwarmCoreToken` is a plain OpenZeppelin v5.4.0 ERC-20. It mints `1_000_000_000 * 10**18` once, in the constructor, to `msg.sender`. It has nothing else: no fee, burn, division or casts, and no privileged functions. I compared the vendored OpenZeppelin files against the upstream commit (`c64a1edb…`) and they are identical, so the token's behaviour is upstream's. All 26 tests pass.\n\n**What I checked against the three guides:**\n- **Math Precision:**\n  - The supply is a fixed constant of 1e27 (well within the type's range), and nothing after the constructor can mint.\n  - The code skips overflow checks in only two places, and both are safe. Taking from the sender's balance or an allowance is checked against that balance or allowance first. Adding to the receiver cannot overflow because no balance can exceed the 1e27 supply.\n  - `decimals()` is 18 and matches the supply's scale.\n- **Boundary:**\n  - Transfers of 0 and transfers to yourself keep every balance the same.\n  - A maximum allowance is never spent down. Any other allowance drops by exactly the amount moved, with nothing left over.\n  - Zero addresses are refused with OpenZeppelin's standard errors.\n  - The token makes no outside calls and rejects ETH.\n- **Numerical Gap:**\n  - The 10% / 88% / 2% launch split comes out exact: 1e26, 8.8e26 and 2e25, which add up to the whole supply.\n  - The amount sent always equals the amount received, so the launch transfers arrive in full.\n\n**Static-analysis leads:** All the Slither and Aderyn warnings point at `LaunchLiquidity.sol` and `PoolInitializationGuard.sol`. These are test helpers that are never deployed. Their number conversions are either lossless or revert instead of silently wrapping, and the ignored return values aren't needed for the accounting. None of them is a reachable defect, so I left them out. The large-number warning on `SwarmCoreToken.sol:15` is just the correct supply constant.\n\n**Coverage:** `approve`, `transfer` and `transferFrom` are all marked `holds`. I also added rows for the fixed supply, the exact split, the decimals, and the test helpers' number conversions. Nothing in my area was left unchecked.","treeHash":null,"usage":{"cachedInputTokens":654905,"inputTokens":26,"model":"claude-opus-5-5","outputTokens":5826,"runtime":"claude","turns":13,"wallClockMs":118110}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"e02bec63aa9dcaa5","findings":[{"citation":"resolved","description":"Access-control area, resolving the slither 'missing-zero-check' lead. The constructor stores poolManager_ into an immutable without validation, and beforeInitialize only accepts calls whose msg.sender equals that immutable. A guard constructed with address(0) therefore reverts NotPoolManager for every real PoolManager, and any pool key that names it can never be initialized by anyone, including the launcher. There is no setter, so the deployment is permanently unusable. This is harness-support code: the README states the factory supplies its own guard and this launch deploys only SwarmCoreToken (no application contracts), so nothing in the launch is affected. Reported as information so the static-analysis lead is closed with a reproduction rather than left open. Suggested minimal fix, if the author wants one: revert in the constructor when poolManager_ == address(0). Not a trust assumption of the token and not a blocking finding.","line":18,"path":"src/PoolInitializationGuard.sol","reproduction":"State: any deployer D calls `new PoolInitializationGuard(address(0))`. Then any address M (standing in for the real PoolManager) calls `guard.beforeInitialize(D, key, 0)`. Expected (if the constructor validated its argument): deployment reverts. Actual: deployment succeeds, poolManager() == address(0), and the beforeInitialize call reverts with NotPoolManager(); the same revert occurs for every msg.sender, so a pool keyed to this hook can never be opened. Verified with test/scratch/GuardZero.t.sol (passes, i.e. the described behaviour is observed).","severity":"info","snippet":"    constructor(address poolManager_) {\n        poolManager = poolManager_;","title":"PoolInitializationGuard accepts a zero pool manager and then refuses every initializer (harness contract, not deployed)"}],"hash":"f3deb8d359930f670294e0ab066e77f9398e5932e53c9557e7651b19992137b5","nodeId":"664d6d19-4c2f-4b16-9e90-d43ff5bb5edc","outcome":"completed","summary":"The findings file is in place and the harness excludes it and the scratch tests from git, so no tracked file changed. The review is complete.\n\n**Result: no defects in the token's permission model.** SwarmCoreToken is an unmodified OpenZeppelin v5.4.0 ERC-20 with a single constructor mint to msg.sender. There is no owner, minter, pauser, blacklist, fee, burn or payable surface, so the Access Control, Trust Gap and Asymmetry checklists find nothing to exploit.\n\nWhat I verified, written to `.imd-findings.json`:\n\n- **All three entry points hold.** `approve`, `transfer` and `transferFrom` were traced through the vendored ERC20 and probed with scratch tests for the asymmetric paths: zero-sender transferFrom cannot mint, allowance is restored atomically on a reverted transfer, the deployer has no standing over other holders, allowances are not transitive, and max-minus-one allowances are decremented while max is infinite.\n- **Trust gap on the dependency closed.** The five vendored OpenZeppelin files the token compiles against hash byte-for-byte to upstream v5.4.0, so the inherited code is what the README claims.\n- **Launch floor checks re-run.** The floor's exact opcode scan passes on the deployed runtime, and disassembly confirms no DELEGATECALL, CALLCODE or SELFDESTRUCT. Supply conservation was fuzzed across transfer and transferFrom.\n- **Static-analysis leads resolved.** The slither unused-return lines in the liquidity helper are safe because the PoolManager reverts on any unsettled delta. The missing zero-check on the initialization guard is reproduced and recorded as the one finding, at info severity, since that contract is harness support and is not deployed with this launch.\n\nCoverage has nine rows: the three listed entry points, five invariants checked, and one row for the harness guard. Nothing was left unreached. The existing 26-test suite and my 10 scratch tests all pass.","treeHash":null,"usage":{"cachedInputTokens":786612,"inputTokens":290,"model":"claude-fable-5-1","outputTokens":17771,"runtime":"claude","turns":36,"wallClockMs":295274}}],"verification":[{"checks":[{"durationMs":9176,"exitCode":0,"name":"build","output":"Compiling 77 files with Solc 0.8.26\nSolc 0.8.26 finished in 9.05s\nCompiler run successful!\nwarning[missing-zero-check]: address parameter is used in a state write or value transfer without a zero-address check\n   ╭▸ src/PoolInitializationGuard.sol:18:17\n   │\n18 │     constructor(address poolManager_) {\n   │                 ━━━━━━━━━━━━━━━━━━━━\n   │\n   ╰ help: https://getfoundry.sh/forge/linting/missing-zero-check\n\nwarning[unused-return]: return value of an external call is not used\n   ╭▸ src/LaunchLiquidity.sol:31:33\n   │\n31 │           (BalanceDelta delta,) = manager.modifyLiquidity(\n   │ ┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┛\n32 │ ┃             seed.key,\n33 │ ┃             ModifyLiquidityParams({\n34 │ ┃                 tickLower: seed.tickLower,\n   ‡ ┃\n39 │ ┃             \"\"\n40 │ ┃         );\n   │ ┗━━━━━━━━━┛\n   │\n   ╰ help: https://getfoundry.sh/forge/linting/unused-return\n\nwarning[unsafe-typecast]: typecast can truncate values\n   ╭▸ src/LaunchLiquidity.sol:49:28\n   │\n49 │             uint256 owed = uint256(uint128(-amount));\n   │                            ━━━━━━━━━━━━━━━━━━━━━━━━━\n   │\n   ├ note: consider disabling this lint if you're certain the cast is safe\n   │       \n   │       // casting to 'uint256' is safe because [explain why]\n   │       // forge-lint: disable-next-line(unsafe-typecast)\n   │       \n   │       \n   ╰ help: https://getfoundry.sh/forge/linting/unsafe-typecast\n\nwarning[unsafe-typecast]: typecast can truncate values\n   ╭▸ src/LaunchLiquidity.sol:49:36\n   │\n49 │             uint256 owed = uint256(uint128(-amount));\n   │                                    ━━━━━━━━━━━━━━━━\n   │\n   ├ note: consider disabling this lint if you're certain the cast is safe\n   │       \n   │       // casting to 'uint128' is safe because [explain why]\n   │       // forge-lint: disable-next-line(unsafe-typecast)\n   │       \n   │       \n   ╰ help: https://getfoundry.sh/forge/linting/unsafe-typecast\n\nwarning[unused-return]: return value of an external call is not used\n   ╭▸ src/LaunchLiquidity.sol:51:17\n   │\n51 │                 manager.settle{value: owed}();\n   │                 ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n   │\n   ╰ help: https://getfoundry.sh/forge/linting/unused-return\n\nwarning[unused-return]: return value of an external call is not used\n   ╭▸ src/LaunchLiquidity.sol:57:17\n   │\n57 │                 manager.settle();\n   │                 ━━━━━━━━━━━━━━━━\n   │\n   ╰ help: https://getfoundry.sh/forge/linting/unused-return\n\nwarning[unsafe-typecast]: typecast can truncate values\n   ╭▸ src/LaunchLiquidity.sol:60:51\n   │\n60 │             manager.take(currency, address(this), uint256(uint128(amount)));\n   │                                                   ━━━━━━━━━━━━━━━━━━━━━━━━\n   │\n   ├ note: consider disabling this lint if you're certain the cast is safe\n   │       \n   │       // casting to 'uint256' is safe because [explain why]\n   │       // forge-lint: disable-next-line(unsafe-typecast)\n   │       \n   │       \n   ╰ help: https://getfoundry.sh/forge/linting/unsafe-typecast\n\nwarning[unsafe-typecast]: typecast can truncate values\n   ╭▸ src/LaunchLiquidity.sol:60:59\n   │\n60 │             manager.take(currency, address(this), uint256(uint128(amount)));\n   │                                                           ━━━━━━━━━━━━━━━\n   │\n   ├ note: consider disabling this lint if you're certain the cast is safe\n   │       \n   │       // casting to 'uint128' is safe because [explain why]\n   │       // forge-lint: disable-next-line(unsafe-typecast)\n   │       \n   │       \n   ╰ help: https://getfoundry.sh/forge/linting/unsafe-typecast\n\n","passed":true},{"durationMs":166,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 8 tests for test/SwarmCoreLaunch.t.sol:SwarmCoreLaunchTest\n[PASS] test_factoryHoldsTheWholeSupply() (gas: 21379)\n[PASS] test_guardRefusesDirectCalls() (gas: 18748461)\n[PASS] test_guardRefusesInitializationByAnyoneButTheLauncher() (gas: 19031858)\n[PASS] test_launchAndTradeAtImdAddress() (gas: 20370925)\n[PASS] test_launchAndTradeWithPairAsCurrency0() (gas: 20370237)\n[PASS] test_launchAndTradeWithPairAsCurrency1() (gas: 20363661)\n[PASS] test_seedFailsWithoutTheFunds() (gas: 511870)\n[PASS] test_swarmShareArrivesWholeAndIsClaimableWhole() (gas: 146542)\nSuite result: ok. 8 passed; 0 failed; 0 skipped; finished in 48.01ms (209.12ms CPU time)\n\nRan 18 tests for test/SwarmCoreToken.t.sol:SwarmCoreTokenTest\n[PASS] testFuzz_transferConservesSupply(address,uint256) (runs: 256, μ: 94898, ~: 95202)\nLogs:\n  Bound result 1000000000000000000000000000\n\n[PASS] testFuzz_transferFromSpendsAllowanceExactly(uint256,uint256) (runs: 256, μ: 142687, ~: 145166)\nLogs:\n  Bound result 511865889220616717214533614\n  Bound result 147881435324609990331718512\n\n[PASS] test_approveAndTransferFrom() (gas: 152339)\n[PASS] test_approveRevertsForZeroSpender() (gas: 32941)\n[PASS] test_constructorEmitsSingleMintTransfer() (gas: 14653)\n[PASS] test_deployScriptMintsToCaller() (gas: 1301742)\n[PASS] test_infiniteAllowanceIsNotSpent() (gas: 122936)\n[PASS] test_metadata() (gas: 28042)\n[PASS] test_noMintOwnerPauseOrSeizeEntryPoints() (gas: 264134)\n[PASS] test_rejectsEther() (gas: 39000)\n[PASS] test_selfTransferKeepsBalance() (gas: 43917)\n[PASS] test_transferFromRevertsAboveAllowance() (gas: 87904)\n[PASS] test_transferFromRevertsWithoutAllowance() (gas: 38808)\n[PASS] test_transferMovesExactAmount() (gas: 92139)\n[PASS] test_transferRevertsOnInsufficientBalance() (gas: 92945)\n[PASS] test_transferRevertsToZeroAddress() (gas: 33244)\n[PASS] test_wholeSupplyMintedOnceToDeployer() (gas: 36197)\n[PASS] test_zeroTransferSucceeds() (gas: 48111)\nSuite result: ok. 18 passed; 0 failed; 0 skipped; finished in 48.01ms (14.03ms CPU time)\n\nRan 2 test suites in 48.79ms (96.02ms CPU time): 26 tests passed, 0 failed, 0 skipped (26 total tests)\n","passed":true},{"durationMs":49,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"SwarmCoreToken.approve(address,uint256)\",\"SwarmCoreToken.transfer(address,uint256)\",\"SwarmCoreToken.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":3,\"README.md\":134,\"foundry.toml\":15,\"launch.json\":20,\"remappings.txt\":4,\"script/DeploySwarmCore.s.sol\":22,\"src/HookFlags.sol\":15,\"src/LaunchLiquidity.sol\":63,\"src/PoolInitializationGuard.sol\":28,\"src/SwarmCoreToken.sol\":20,\"test/SwarmCoreLaunch.t.sol\":294,\"test/SwarmCoreToken.t.sol\":184},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"3158d3b85a937983f049e6a6ee1d7ad13b48c03e4ba035febcfa27269c38b4ac","verifiedTreeHash":"234c657a566584365bd5ff3506e9bd935c4bb744","verifierVersion":"0.1.0+fdeb4d4a"},{"checks":[{"durationMs":8950,"exitCode":0,"name":"build","output":"Compiling 77 files with Solc 0.8.26\nSolc 0.8.26 finished in 8.83s\nCompiler run successful!\nwarning[missing-zero-check]: address parameter is used in a state write or value transfer without a zero-address check\n   ╭▸ src/PoolInitializationGuard.sol:18:17\n   │\n18 │     constructor(address poolManager_) {\n   │                 ━━━━━━━━━━━━━━━━━━━━\n   │\n   ╰ help: https://getfoundry.sh/forge/linting/missing-zero-check\n\nwarning[unused-return]: return value of an external call is not used\n   ╭▸ src/LaunchLiquidity.sol:31:33\n   │\n31 │           (BalanceDelta delta,) = manager.modifyLiquidity(\n   │ ┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┛\n32 │ ┃             seed.key,\n33 │ ┃             ModifyLiquidityParams({\n34 │ ┃                 tickLower: seed.tickLower,\n   ‡ ┃\n39 │ ┃             \"\"\n40 │ ┃         );\n   │ ┗━━━━━━━━━┛\n   │\n   ╰ help: https://getfoundry.sh/forge/linting/unused-return\n\nwarning[unsafe-typecast]: typecast can truncate values\n   ╭▸ src/LaunchLiquidity.sol:49:28\n   │\n49 │             uint256 owed = uint256(uint128(-amount));\n   │                            ━━━━━━━━━━━━━━━━━━━━━━━━━\n   │\n   ├ note: consider disabling this lint if you're certain the cast is safe\n   │       \n   │       // casting to 'uint256' is safe because [explain why]\n   │       // forge-lint: disable-next-line(unsafe-typecast)\n   │       \n   │       \n   ╰ help: https://getfoundry.sh/forge/linting/unsafe-typecast\n\nwarning[unsafe-typecast]: typecast can truncate values\n   ╭▸ src/LaunchLiquidity.sol:49:36\n   │\n49 │             uint256 owed = uint256(uint128(-amount));\n   │                                    ━━━━━━━━━━━━━━━━\n   │\n   ├ note: consider disabling this lint if you're certain the cast is safe\n   │       \n   │       // casting to 'uint128' is safe because [explain why]\n   │       // forge-lint: disable-next-line(unsafe-typecast)\n   │       \n   │       \n   ╰ help: https://getfoundry.sh/forge/linting/unsafe-typecast\n\nwarning[unused-return]: return value of an external call is not used\n   ╭▸ src/LaunchLiquidity.sol:51:17\n   │\n51 │                 manager.settle{value: owed}();\n   │                 ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n   │\n   ╰ help: https://getfoundry.sh/forge/linting/unused-return\n\nwarning[unused-return]: return value of an external call is not used\n   ╭▸ src/LaunchLiquidity.sol:57:17\n   │\n57 │                 manager.settle();\n   │                 ━━━━━━━━━━━━━━━━\n   │\n   ╰ help: https://getfoundry.sh/forge/linting/unused-return\n\nwarning[unsafe-typecast]: typecast can truncate values\n   ╭▸ src/LaunchLiquidity.sol:60:51\n   │\n60 │             manager.take(currency, address(this), uint256(uint128(amount)));\n   │                                                   ━━━━━━━━━━━━━━━━━━━━━━━━\n   │\n   ├ note: consider disabling this lint if you're certain the cast is safe\n   │       \n   │       // casting to 'uint256' is safe because [explain why]\n   │       // forge-lint: disable-next-line(unsafe-typecast)\n   │       \n   │       \n   ╰ help: https://getfoundry.sh/forge/linting/unsafe-typecast\n\nwarning[unsafe-typecast]: typecast can truncate values\n   ╭▸ src/LaunchLiquidity.sol:60:59\n   │\n60 │             manager.take(currency, address(this), uint256(uint128(amount)));\n   │                                                           ━━━━━━━━━━━━━━━\n   │\n   ├ note: consider disabling this lint if you're certain the cast is safe\n   │       \n   │       // casting to 'uint128' is safe because [explain why]\n   │       // forge-lint: disable-next-line(unsafe-typecast)\n   │       \n   │       \n   ╰ help: https://getfoundry.sh/forge/linting/unsafe-typecast\n\n","passed":true},{"durationMs":149,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 18 tests for test/SwarmCoreToken.t.sol:SwarmCoreTokenTest\n[PASS] testFuzz_transferConservesSupply(address,uint256) (runs: 256, μ: 94865, ~: 95202)\nLogs:\n  Bound result 160026082952199424853765\n\n[PASS] testFuzz_transferFromSpendsAllowanceExactly(uint256,uint256) (runs: 256, μ: 143089, ~: 145094)\nLogs:\n  Bound result 1000\n  Bound result 454\n\n[PASS] test_approveAndTransferFrom() (gas: 152339)\n[PASS] test_approveRevertsForZeroSpender() (gas: 32941)\n[PASS] test_constructorEmitsSingleMintTransfer() (gas: 14653)\n[PASS] test_deployScriptMintsToCaller() (gas: 1301742)\n[PASS] test_infiniteAllowanceIsNotSpent() (gas: 122936)\n[PASS] test_metadata() (gas: 28042)\n[PASS] test_noMintOwnerPauseOrSeizeEntryPoints() (gas: 264134)\n[PASS] test_rejectsEther() (gas: 39000)\n[PASS] test_selfTransferKeepsBalance() (gas: 43917)\n[PASS] test_transferFromRevertsAboveAllowance() (gas: 87904)\n[PASS] test_transferFromRevertsWithoutAllowance() (gas: 38808)\n[PASS] test_transferMovesExactAmount() (gas: 92139)\n[PASS] test_transferRevertsOnInsufficientBalance() (gas: 92945)\n[PASS] test_transferRevertsToZeroAddress() (gas: 33244)\n[PASS] test_wholeSupplyMintedOnceToDeployer() (gas: 36197)\n[PASS] test_zeroTransferSucceeds() (gas: 48111)\nSuite result: ok. 18 passed; 0 failed; 0 skipped; finished in 5.88ms (11.83ms CPU time)\n\nRan 8 tests for test/SwarmCoreLaunch.t.sol:SwarmCoreLaunchTest\n[PASS] test_factoryHoldsTheWholeSupply() (gas: 21379)\n[PASS] test_guardRefusesDirectCalls() (gas: 18748461)\n[PASS] test_guardRefusesInitializationByAnyoneButTheLauncher() (gas: 19031858)\n[PASS] test_launchAndTradeAtImdAddress() (gas: 20370925)\n[PASS] test_launchAndTradeWithPairAsCurrency0() (gas: 20370237)\n[PASS] test_launchAndTradeWithPairAsCurrency1() (gas: 20363661)\n[PASS] test_seedFailsWithoutTheFunds() (gas: 511870)\n[PASS] test_swarmShareArrivesWholeAndIsClaimableWhole() (gas: 146542)\nSuite result: ok. 8 passed; 0 failed; 0 skipped; finished in 55.00ms (219.60ms CPU time)\n\nRan 2 test suites in 55.65ms (60.88ms CPU time): 26 tests passed, 0 failed, 0 skipped (26 total tests)\n","passed":true},{"durationMs":55,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"SwarmCoreToken.approve(address,uint256)\",\"SwarmCoreToken.transfer(address,uint256)\",\"SwarmCoreToken.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":3,\"README.md\":134,\"foundry.toml\":15,\"remappings.txt\":4,\"script/DeploySwarmCore.s.sol\":22,\"src/HookFlags.sol\":15,\"src/LaunchLiquidity.sol\":63,\"src/PoolInitializationGuard.sol\":28,\"src/SwarmCoreToken.sol\":20,\"test/SwarmCoreLaunch.t.sol\":294,\"test/SwarmCoreToken.t.sol\":184},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true},{"durationMs":793,"exitCode":0,"name":"slither","output":"[medium/medium] unused-return at src/LaunchLiquidity.sol:29: LaunchLiquidity.settleSeed(IPoolManager,bytes) (src/LaunchLiquidity.sol#29-43) ignores return value by (delta,None) = manager.modifyLiquidity(seed.key,ModifyLiquidityParams({tickLower:seed.tickLower,tickUpper:seed.tickUpper,liquidityDelta:int256(uint256(seed.liquidity)),salt:bytes32(0)}),) (src/LaunchLiquidity.sol#31-40)\n[medium/medium] unused-return at src/LaunchLiquidity.sol:47: LaunchLiquidity.settle(IPoolManager,Currency,int128) (src/LaunchLiquidity.sol#47-62) ignores return value by manager.settle{value: owed}() (src/LaunchLiquidity.sol#51)\n[medium/medium] unused-return at src/LaunchLiquidity.sol:47: LaunchLiquidity.settle(IPoolManager,Currency,int128) (src/LaunchLiquidity.sol#47-62) ignores return value by manager.settle() (src/LaunchLiquidity.sol#57)\n[low/medium] missing-zero-check at src/PoolInitializationGuard.sol:18: PoolInitializationGuard.constructor(address).poolManager_ (src/PoolInitializationGuard.sol#18) lacks a zero-check on :","passed":true},{"durationMs":284,"exitCode":0,"name":"aderyn","output":"[low] large-numeric-literal at src/SwarmCoreToken.sol:15: Large Numeric Literal\n[low] unchecked-return at src/LaunchLiquidity.sol:57: Unchecked Return\n[low] unsafe-erc20-operation at src/LaunchLiquidity.sol:54: Unsafe ERC20 Operation","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"3b5a78b504f818be1c1c36e904142bb1bf6d40e98bee9bb8a24fe5d90534057a","verifiedTreeHash":"3be222186438ec03016f4fab6145ecf033d60e4d","verifierVersion":"0.1.0+fdeb4d4a"},{"checks":[{"durationMs":15068,"exitCode":0,"name":"build","output":"Compiling 79 files with Solc 0.8.26\nSolc 0.8.26 finished in 14.95s\nCompiler run successful!\nwarning[missing-zero-check]: address parameter is used in a state write or value transfer without a zero-address check\n   ╭▸ src/PoolInitializationGuard.sol:18:17\n   │\n18 │     constructor(address poolManager_) {\n   │                 ━━━━━━━━━━━━━━━━━━━━\n   │\n   ╰ help: https://getfoundry.sh/forge/linting/missing-zero-check\n\nwarning[unused-return]: return value of an external call is not used\n   ╭▸ src/LaunchLiquidity.sol:31:33\n   │\n31 │           (BalanceDelta delta,) = manager.modifyLiquidity(\n   │ ┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┛\n32 │ ┃             seed.key,\n33 │ ┃             ModifyLiquidityParams({\n34 │ ┃                 tickLower: seed.tickLower,\n   ‡ ┃\n39 │ ┃             \"\"\n40 │ ┃         );\n   │ ┗━━━━━━━━━┛\n   │\n   ╰ help: https://getfoundry.sh/forge/linting/unused-return\n\nwarning[unsafe-typecast]: typecast can truncate values\n   ╭▸ src/LaunchLiquidity.sol:49:28\n   │\n49 │             uint256 owed = uint256(uint128(-amount));\n   │                            ━━━━━━━━━━━━━━━━━━━━━━━━━\n   │\n   ├ note: consider disabling this lint if you're certain the cast is safe\n   │       \n   │       // casting to 'uint256' is safe because [explain why]\n   │       // forge-lint: disable-next-line(unsafe-typecast)\n   │       \n   │       \n   ╰ help: https://getfoundry.sh/forge/linting/unsafe-typecast\n\nwarning[unsafe-typecast]: typecast can truncate values\n   ╭▸ src/LaunchLiquidity.sol:49:36\n   │\n49 │             uint256 owed = uint256(uint128(-amount));\n   │                                    ━━━━━━━━━━━━━━━━\n   │\n   ├ note: consider disabling this lint if you're certain the cast is safe\n   │       \n   │       // casting to 'uint128' is safe because [explain why]\n   │       // forge-lint: disable-next-line(unsafe-typecast)\n   │       \n   │       \n   ╰ help: https://getfoundry.sh/forge/linting/unsafe-typecast\n\nwarning[unused-return]: return value of an external call is not used\n   ╭▸ src/LaunchLiquidity.sol:51:17\n   │\n51 │                 manager.settle{value: owed}();\n   │                 ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n   │\n   ╰ help: https://getfoundry.sh/forge/linting/unused-return\n\nwarning[unused-return]: return value of an external call is not used\n   ╭▸ src/LaunchLiquidity.sol:57:17\n   │\n57 │                 manager.settle();\n   │                 ━━━━━━━━━━━━━━━━\n   │\n   ╰ help: https://getfoundry.sh/forge/linting/unused-return\n\nwarning[unsafe-typecast]: typecast can truncate values\n   ╭▸ src/LaunchLiquidity.sol:60:51\n   │\n60 │             manager.take(currency, address(this), uint256(uint128(amount)));\n   │                                                   ━━━━━━━━━━━━━━━━━━━━━━━━\n   │\n   ├ note: consider disabling this lint if you're certain the cast is safe\n   │       \n   │       // casting to 'uint256' is safe because [explain why]\n   │       // forge-lint: disable-next-line(unsafe-typecast)\n   │       \n   │       \n   ╰ help: https://getfoundry.sh/forge/linting/unsafe-typecast\n\nwarning[unsafe-typecast]: typecast can truncate values\n   ╭▸ src/LaunchLiquidity.sol:60:59\n   │\n60 │             manager.take(currency, address(this), uint256(uint128(amount)));\n   │                                                           ━━━━━━━━━━━━━━━\n   │\n   ├ note: consider disabling this lint if you're certain the cast is safe\n   │       \n   │       // casting to 'uint128' is safe because [explain why]\n   │       // forge-lint: disable-next-line(unsafe-typecast)\n   │       \n   │       \n   ╰ help: https://getfoundry.sh/forge/linting/unsafe-typecast\n\n","passed":true},{"durationMs":8049,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 8 tests for test/SwarmCoreLaunch.t.sol:SwarmCoreLaunchTest\n[PASS] test_factoryHoldsTheWholeSupply() (gas: 21379)\n[PASS] test_guardRefusesDirectCalls() (gas: 18748461)\n[PASS] test_guardRefusesInitializationByAnyoneButTheLauncher() (gas: 19031858)\n[PASS] test_launchAndTradeAtImdAddress() (gas: 20370925)\n[PASS] test_launchAndTradeWithPairAsCurrency0() (gas: 20370237)\n[PASS] test_launchAndTradeWithPairAsCurrency1() (gas: 20363661)\n[PASS] test_seedFailsWithoutTheFunds() (gas: 511870)\n[PASS] test_swarmShareArrivesWholeAndIsClaimableWhole() (gas: 146542)\nSuite result: ok. 8 passed; 0 failed; 0 skipped; finished in 85.96ms (308.65ms CPU time)\n\nRan 18 tests for test/SwarmCoreToken.t.sol:SwarmCoreTokenTest\n[PASS] testFuzz_transferConservesSupply(address,uint256) (runs: 256, μ: 94845, ~: 95190)\nLogs:\n  Bound result 7\n\n[PASS] testFuzz_transferFromSpendsAllowanceExactly(uint256,uint256) (runs: 256, μ: 142763, ~: 145094)\nLogs:\n  Bound result 1\n  Bound result 0\n\n[PASS] test_approveAndTransferFrom() (gas: 152339)\n[PASS] test_approveRevertsForZeroSpender() (gas: 32941)\n[PASS] test_constructorEmitsSingleMintTransfer() (gas: 14653)\n[PASS] test_deployScriptMintsToCaller() (gas: 1301742)\n[PASS] test_infiniteAllowanceIsNotSpent() (gas: 122936)\n[PASS] test_metadata() (gas: 28042)\n[PASS] test_noMintOwnerPauseOrSeizeEntryPoints() (gas: 264134)\n[PASS] test_rejectsEther() (gas: 39000)\n[PASS] test_selfTransferKeepsBalance() (gas: 43917)\n[PASS] test_transferFromRevertsAboveAllowance() (gas: 87904)\n[PASS] test_transferFromRevertsWithoutAllowance() (gas: 38808)\n[PASS] test_transferMovesExactAmount() (gas: 92139)\n[PASS] test_transferRevertsOnInsufficientBalance() (gas: 92945)\n[PASS] test_transferRevertsToZeroAddress() (gas: 33244)\n[PASS] test_wholeSupplyMintedOnceToDeployer() (gas: 36197)\n[PASS] test_zeroTransferSucceeds() (gas: 48111)\nSuite result: ok. 18 passed; 0 failed; 0 skipped; finished in 87.91ms (104.76ms CPU time)\n\nRan 27 tests for test/SwarmCoreTokenProperties.t.sol:SwarmCoreTokenPropertiesTest\n[PASS] testFuzz_invalidRecipientRollsBackDelegatedAllowance(uint256,bool) (runs: 1000, μ: 174392, ~: 175542)\nLogs:\n  Bound result 203159954350390850356961859\n\n[PASS] testFuzz_replacingApprovalLimitsCumulativeSpending(uint256,uint256,uint256) (runs: 1000, μ: 298221, ~: 299970)\nLogs:\n  Bound result 1110\n  Bound result 120\n\n[PASS] testFuzz_spenderAllowancesAreIndependent(uint256,uint256,uint256) (runs: 1000, μ: 281381, ~: 283072)\nLogs:\n  Bound result 23818930566156656\n\n[PASS] testFuzz_splitTransfersEqualSingleTransfer(uint256,uint256) (runs: 1000, μ: 248071, ~: 249607)\nLogs:\n  Bound result 17472\n  Bound result 159\n\n[PASS] testFuzz_transferAboveBalanceIsAtomic(uint256,uint256) (runs: 1000, μ: 154629, ~: 155062)\nLogs:\n  Bound result 0\n  Bound result 2496696015574015793293444105039569167735432934833913\n\n[PASS] testFuzz_transferFromAboveAllowanceIsAtomic(uint256,uint256) (runs: 1000, μ: 177636, ~: 178281)\nLogs:\n  Bound result 325145214396496222470532179\n  Bound result 371819553438193952624357418\n\n[PASS] testFuzz_transferFromAboveBalanceRollsBackFiniteAllowance(uint256,uint256) (runs: 1000, μ: 238941, ~: 239586)\nLogs:\n  Bound result 2207793147886917542\n  Bound result 115792089237316195423570985008687907853269984665640564039455376214773273978992\n\n[PASS] testFuzz_transferRoundTripRestoresBalances(uint256) (runs: 1000, μ: 217020, ~: 217177)\nLogs:\n  Bound result 0\n\n[PASS] test_approvalCannotBeUsedByAnotherSpenderOrForAnotherOwner() (gas: 199869)\n[PASS] test_approvalEdgesReplaceRatherThanAddAndEmitEvents() (gas: 691784)\n[PASS] test_constructorEmitsExactlyOneMintAndUsesSenderNotOrigin() (gas: 57050)\n[PASS] test_delegatedSelfTransferConsumesFiniteAllowance() (gas: 208197)\n[PASS] test_deployerCannotSpendAnotherHoldersTokens() (gas: 226158)\n[PASS] test_directTransferEdgesAndRoundTrips() (gas: 631335)\n[PASS] test_exhaustedAllowanceCannotBeSpentTwice() (gas: 229508)\n[PASS] test_failedTransferFromPreservesAllowanceForRetryAfterFunding() (gas: 358962)\n[PASS] test_fullSupplyCanMoveRepeatedlyWithInfiniteApproval() (gas: 385250)\n[PASS] test_infiniteApprovalCannotCreateBalance() (gas: 174349)\n[PASS] test_maxMinusOneAllowanceIsFinite() (gas: 203072)\n[PASS] test_maximumTransferRevertsWithoutChangingBalances() (gas: 92923)\n[PASS] test_ownerUsingTransferFromNeedsSelfApproval() (gas: 223144)\n[PASS] test_revokingInfiniteApprovalPreventsFurtherSpending() (gas: 283180)\n[PASS] test_selfTransferStillRequiresEnoughBalance() (gas: 91215)\n[PASS] test_tokenContractCanReceiveTokensWithoutBurningThem() (gas: 82567)\n[PASS] test_zeroSpenderRejectedEvenWhenRevoking() (gas: 174451)\n[PASS] test_zeroTransferFromNeedsNeitherBalanceNorAllowanceAndEmitsTransfer() (gas: 117776)\n[PASS] test_zeroTransferToZeroAddressReverts() (gas: 89704)\nSuite result: ok. 27 passed; 0 failed; 0 skipped; finished in 87.98ms (687.34ms CPU time)\n\nRan 2 tests for test/SwarmCoreTokenInvariant.t.sol:SwarmCoreTokenInvariantTest\n[PASS]\nSwarmCoreTokenInvariantTest invariants:\n[PASS] invariant_allBalancesMatchAuthorizedMovementsAndConserveSupply\n[PASS] invariant_allowancesMatchApprovalsAndSuccessfulSpending\n[PASS] invariant_fixedSupplyAndMetadata\n SwarmCoreTokenInvariantTest invariants (runs: 256, calls: 32768, reverts: 0)\n\n╭-----------------------+--------------------------+-------+---------+----------╮\n| Contract              | Selector                 | Calls | Reverts | Discards |\n+===============================================================================+\n| SwarmCoreTokenHandler | approve                  | 3629  | 0       | 0        |\n|-----------------------+--------------------------+-------+---------+----------|\n| SwarmCoreTokenHandler | invalidRecipient         | 3701  | 0       | 0        |\n|-----------------------+--------------------------+-------+---------+----------|\n| SwarmCoreTokenHandler | invalidSpender           | 3587  | 0       | 0        |\n|-----------------------+--------------------------+-------+---------+----------|\n| SwarmCoreTokenHandler | revokeAndTrySpend        | 3643  | 0       | 0        |\n|-----------------------+--------------------------+-------+---------+----------|\n| SwarmCoreTokenHandler | transfer                 | 3613  | 0       | 0        |\n|-----------------------+--------------------------+-------+---------+----------|\n| SwarmCoreTokenHandler | transferAboveBalance     | 3659  | 0       | 0        |\n|-----------------------+--------------------------+-------+---------+----------|\n| SwarmCoreTokenHandler | transferAll              | 3663  | 0       | 0        |\n|-----------------------+--------------------------+-------+---------+----------|\n| SwarmCoreTokenHandler | transferFrom             | 3617  | 0       | 0        |\n|-----------------------+--------------------------+-------+---------+----------|\n| SwarmCoreTokenHandler | transferFromAboveBalance | 3656  | 0       | 0        |\n╰-----------------------+--------------------------+-------+---------+----------╯\n\nLogs:\n  Bound result 9999\n  Bound result 1000000000000000000000000000\n  Bound result 834644762420795773\n  Bound result 9\n  Bound result 3754\n  Bound result 10369717\n  Bound result 4\n  Bound result 500000000000000000000009999\n  Bound result 18\n  Bound result 228120258205092561828\n  Bound result 4294967295\n  Bound result 1000\n  Bound result 11550\n  Bound result 10000000000000000000\n  Bound result 569433934133224197871\n  Bound result 247293286156659077021539963\n  Bound result 14030006511196625806194877795241699370606207829558200543440856156923680824\n  Bound result 7\n  Bound result 3\n  Bound result 3220\n  Bound result 10000\n\n[PASS] test_handlerExercisesPositiveSpendsSelfTransfersAndFailureRollback() (gas: 1939343)\nLogs:\n  Bound result 3\n  Bound result 115792089237316195423570985008687907853269984665640314039457584007913129639934\n\nSuite result: ok. 2 passed; 0 failed; 0 skipped; finished in 7.95s (7.95s CPU time)\n\nRan 4 test suites in 7.96s (8.22s CPU time): 55 tests passed, 0 failed, 0 skipped (55 total tests)\n","passed":true},{"durationMs":41,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"SwarmCoreToken.approve(address,uint256)\",\"SwarmCoreToken.transfer(address,uint256)\",\"SwarmCoreToken.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":3,\"README.md\":134,\"foundry.toml\":15,\"remappings.txt\":4,\"script/DeploySwarmCore.s.sol\":22,\"src/HookFlags.sol\":15,\"src/LaunchLiquidity.sol\":63,\"src/PoolInitializationGuard.sol\":28,\"src/SwarmCoreToken.sol\":20,\"test/SwarmCoreLaunch.t.sol\":294,\"test/SwarmCoreToken.t.sol\":184,\"test/SwarmCoreTokenInvariant.t.sol\":241,\"test/SwarmCoreTokenProperties.t.sol\":354},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"6e5dd757c5a13eb8e147f8e07a6dab941c7fa647c230177c2072de7063ac0608","verifiedTreeHash":"e04988108db32bfa95817edce39b81efeb82b2c5","verifierVersion":"0.1.0+fdeb4d4a"}]}