{"assessments":[],"deployments":[],"fuzz":[],"identity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"interpretation":"Records acceptance and evidence. Neither completion nor an AI assessment establishes correctness, safety, or independent review.","jobId":"1acbfd68-ebfd-4673-86ef-f84c5b0254ea","kind":"shape:chain","nodes":[{"acceptedSubmissionHash":"c02333ab94c6b06abaaa0bd61956e75678b05002087f8c8e4689060f8b880b62","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_economics","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"776d97c630c7e65b9a967e7dab557fd44c7cbef2d2e5ffc2bf782c3b6f66061a","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_flow","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"3cae0de0ad8e674b9b1a8b46ef358239390d03d7facac830c9f5995158b85376","dependsOn":["build_contract_project","write_foundry_tests","manifest","audit_math","audit_permissions","audit_economics","audit_flow"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"3014f1ea5961918ca059453a484bf4c8bcbbfc2248dbe31d94ac7c5cdf8f50bd","skillId":"audit-judge","tools":[]},"key":"audit_judge","kind":"code","role":"review","skillHash":"3014f1ea5961918ca059453a484bf4c8bcbbfc2248dbe31d94ac7c5cdf8f50bd","skillId":"audit-judge","state":"accepted"},{"acceptedSubmissionHash":"9ddc799c8ed86ff76822b6796d0b343ff4050163db5b1b2a49d3560e39ad6696","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_math","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"12b0e34cbc45bc6553337fc836cfca5392e92808d775822f4f1d0ee287d9e09f","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_permissions","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"de04953d43a4e77c1c929c409bf202a3323f38020cf9994e40d38ec32d5ef81d","dependsOn":[],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"587567a5ef71546b5973ceaf6ef1dbbd590f49503b5ac9a6973ed86b89584857","skillId":"build-contract-project","tools":[]},"key":"build_contract_project","kind":"code","role":"implement","skillHash":"587567a5ef71546b5973ceaf6ef1dbbd590f49503b5ac9a6973ed86b89584857","skillId":"build-contract-project","state":"accepted"},{"acceptedSubmissionHash":"dfbaa64367161785ae5b7efd94f3bd2e0a3a92115d475524d202d1b4fd04eff9","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"tools":[]},"key":"manifest","kind":"code","role":"integrate","skillHash":null,"skillId":null,"state":"accepted"},{"acceptedSubmissionHash":"0d275f178f09934c60f4a03f8e9d095696a0ac9d5a1832b932484dea28a7d561","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"73431852439ad3a343f3d2b7db1c43cd363b9f48f9bb51497374a0cf6d50b223","skillId":"write-foundry-tests","tools":[]},"key":"write_foundry_tests","kind":"code","role":"tests","skillHash":"73431852439ad3a343f3d2b7db1c43cd363b9f48f9bb51497374a0cf6d50b223","skillId":"write-foundry-tests","state":"accepted"}],"objective":"A custom token: Swarms Launchpad Official token (SPAD).\nToken name: Swarms Launchpad Official token\nToken symbol: SPAD\nToken supply: 1,000,000,000 with 18 decimals, all minted once to the deployer in the constructor.","parentJobId":null,"planHash":"2e7790e43a03ddcf64c92af044a839f2b95cf225648cf9346899b7f5d7ea4755","previousHash":"0000000000000000000000000000000000000000000000000000000000000000","projectId":"1acbfd68-ebfd-4673-86ef-f84c5b0254ea","publication":{"commit":null,"deliveredAt":null,"repoUrl":"https://github.com/identity-md-launches/launch-1104-swarms-launchpad-official-token"},"receiptIdentity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"registry":"0xb6d0a187b050fa5bb0b87033a203f37becf4a775","research":[],"schema":"identitymd-work-v1","signals":[{"agentId":"51040","feedbackHash":"d5b14b4079598240c280385fafc8208473e1d6eb9c05ac4733a3f9ae3fe769e8","nodeKey":"audit_economics","submissionHash":"c02333ab94c6b06abaaa0bd61956e75678b05002087f8c8e4689060f8b880b62","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51315","feedbackHash":"ca382e1de828ff5d87f88b56b666a04f1db3f73f46b55c470690244f06ba6899","nodeKey":"audit_flow","submissionHash":"776d97c630c7e65b9a967e7dab557fd44c7cbef2d2e5ffc2bf782c3b6f66061a","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51511","feedbackHash":"4086f58717368f2b58f9ec34ee4915678edcac6b9dc31cadffd0839b3e81de71","nodeKey":"audit_judge","submissionHash":"3cae0de0ad8e674b9b1a8b46ef358239390d03d7facac830c9f5995158b85376","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"52011","feedbackHash":"cc325cef7df733df2e15606f2c3f26fa2809540b2c6313baf69ae8c64efe1a39","nodeKey":"audit_math","submissionHash":"9ddc799c8ed86ff76822b6796d0b343ff4050163db5b1b2a49d3560e39ad6696","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51566","feedbackHash":"bec7b5ee17ef1ebf110718a3047eed1bd879a64ed7472e616f46d3cc66ad74ea","nodeKey":"audit_permissions","submissionHash":"12b0e34cbc45bc6553337fc836cfca5392e92808d775822f4f1d0ee287d9e09f","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51459","feedbackHash":"2302cd6ee9e5c707a0d124c6c1ef7dc4ff02324fd78186e59d2faa2fc77f38ff","nodeKey":"build_contract_project","submissionHash":"de04953d43a4e77c1c929c409bf202a3323f38020cf9994e40d38ec32d5ef81d","tag1":"verification:checks","tag2":"acceptance-v2","value":1},{"agentId":"51318","feedbackHash":"2673ee45316aac692b3f3c3b8f8d6f45948a61491120f2c8cad97343723db334","nodeKey":"manifest","submissionHash":"dfbaa64367161785ae5b7efd94f3bd2e0a3a92115d475524d202d1b4fd04eff9","tag1":"verification:checks","tag2":"acceptance-v2","value":1},{"agentId":"51525","feedbackHash":"0f7b2442ef3bdde2927493d7dd481f03839b9ca7e6f410377b68cd59db7af84e","nodeKey":"write_foundry_tests","submissionHash":"0d275f178f09934c60f4a03f8e9d095696a0ac9d5a1832b932484dea28a7d561","tag1":"verification:checks","tag2":"acceptance-v2","value":1}],"site":null,"snapshotHash":"c7d70e0e3a30ba05f40bf72626eadea8810f5677dd4a94fac568cdb15c2b7377","state":"completed","submissions":[{"artifacts":[],"attempt":1,"bundleHash":"bb48c45b64dcbd8787c5a0d3e40d2b6948748b51c59596fc26ab5c567348e5f4","device":"c2c5d7ad583481d5","findings":[],"hash":"0d275f178f09934c60f4a03f8e9d095696a0ac9d5a1832b932484dea28a7d561","nodeId":"2ba60bff-52e6-4f4e-bea3-90086294c5a4","outcome":"completed","summary":"Added 14 edge-case and fuzz tests, plus stronger invariants tracking balances, allowances, and failed-call rollback.\n\n`forge build` and `forge test` pass: 45 tests, including 256 invariant sequences and 16,384 handler calls.\n\nOnly `test/` changed. No implementation defects found.","treeHash":"dc8c090a8e7c04d075e90b735c8d130b0785ffaa","usage":{"cachedInputTokens":382336,"inputTokens":82738,"model":"gpt-6-astra","outputTokens":9678,"runtime":"codex","turns":5,"wallClockMs":261028}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"d0653dc91b6e2259","findings":[{"citation":"resolved","description":"Asymmetry guide, pair approve <-> transferFrom (set <-> pull). approve() overwrites the allowance slot unconditionally (ERC20.sol:291) while transferFrom() decrements it (ERC20.sol:312). A spender who observes a pending approve(spender, lower) can spend the old allowance first and then the new one, so the owner's intended cap is exceeded. SPAD inherits this unchanged (src/SPAD.sol:8 `contract SPAD is ERC20 {`) and adds no increaseAllowance/decreaseAllowance or permit. This is conformant ERC-20 behaviour, is documented in README.md ('revoke it to zero and confirm that transaction before setting the replacement'), and no token-level change is recommended; it is recorded so the judge has the asymmetry check on file. Not a loss-of-funds path for the launch: the factory, distributor and PoolManager flows use transfer()/settle paths, not reduced allowances.","line":291,"path":"lib/openzeppelin-contracts/contracts/token/ERC20/ERC20.sol","reproduction":"State: owner O holds >=150 SPAD. 1) O calls approve(S, 100). 2) O broadcasts approve(S, 50); S front-runs with transferFrom(O, S, 100) (allowance 100 -> 0). 3) O's approve(S, 50) lands (allowance 0 -> 50). 4) S calls transferFrom(O, S, 50). Expected by O: S can move at most 100 in total (or 50 after the reduction). Actual: S moved 150. Verified with test/scratch/AccessProbe.t.sol::test_approveRaceIsStandardERC20Behaviour, which asserts balanceOf(S) == 150.","severity":"info","snippet":"        _allowances[owner][spender] = value;","title":"approve/transferFrom allowance race is the standard ERC-20 asymmetry (by design, no change required)"}],"hash":"12b0e34cbc45bc6553337fc836cfca5392e92808d775822f4f1d0ee287d9e09f","nodeId":"1bcdbcad-c167-4947-b303-2f4b713e4f69","outcome":"completed","summary":"The review is complete and `.imd-findings.json` is written. No tracked files were changed.\n\n**Outcome: the SPAD permission model holds.** The token is an unmodified OpenZeppelin v5.0.2 ERC20 plus one constructor mint. There is no owner, initializer, pause, blocklist, seize, burn, permit, receive or fallback path. The only state-changing entry points are the three ERC-20 ones, each scoped to the caller or to an allowance the holder set.\n\nWhat I checked in my area, each against the Access Control, Trust Gap and Asymmetry guides:\n\n- **Access control.** Enumerated every ABI function. The constructor hands out no roles and mints the full supply to the deployer, which is the factory under CREATE2. The deployer cannot pull a single wei from a holder without approval. Unknown selectors and any ETH value revert.\n- **Trust gap.** No privileged actor exists, so no access-times-economics seam exists. The one trust assumption is by design: the factory holds the whole supply after construction and the launch economics are enforced by the factory, not the token.\n- **Asymmetry.** Compared transfer against transferFrom and approve against spend. Validation, writes and revert rollback mirror correctly. The known approve-overwrite race remains, which I recorded as an info item since it is standard behaviour and the README already documents the mitigation.\n- **Supply chain.** All five vendored OpenZeppelin files are byte-identical to the upstream v5.0.2 tag. No submodules. Build, the 31 existing tests and format check pass.\n- **Static analysis lead.** The aderyn large-literal note resolves to exactly 10^27, matching the brief.\n\nThe findings file holds one info-level item with its reproduction and eight coverage rows covering all three listed entry points plus the constructor and the invariants above. My scratch probes live under test/scratch and are ignored by git.","treeHash":null,"usage":{"cachedInputTokens":500273,"inputTokens":226,"model":"claude-fable-5-1","outputTokens":13847,"runtime":"claude","turns":26,"wallClockMs":201035}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"fbcdfc017217af1f","findings":[{"citation":"resolved","description":"Reproduced the audit_economics finding. The six vendored OpenZeppelin v5.0.2 files are byte-identical to the upstream archive (sha256 18c7b7e9...925a, as recorded). The forge-std v1.9.7 archive (sha256 45157353...ee94, as recorded) is not: lib/forge-std/src/StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IERC7540.sol and interfaces/IMulticall3.sol differ from upstream. Every difference disappears when all whitespace is stripped, so the change is formatting only (line-wrapping of long signatures). It has no effect on SPAD, which imports nothing from forge-std, and no effect on tests. It is a provenance-statement inaccuracy: a byte-for-byte comparison of lib/forge-std against the recorded archive fails. Fix: restore the upstream bytes for those seven files, or amend the sentence to say forge-std was reformatted with forge fmt. Merged duplicate: none (only audit_economics reported it).","line":19,"path":"DEPENDENCIES.md","reproduction":"Download https://codeload.github.com/foundry-rs/forge-std/tar.gz/refs/tags/v1.9.7 (sha256sum = 45157353ab49eab01d294565866731e599b32401757229689ee459aa26b7ee94, matching DEPENDENCIES.md), extract, then for each of the 30 vendored files run `cmp forge-std-1.9.7/<f> lib/forge-std/<f>`. Expected per line 19: all 30 identical. Actual: 23 identical, 7 differ (src/StdAssertions.sol, src/StdJson.sol, src/StdToml.sol, src/Vm.sol, src/console.sol, src/interfaces/IERC7540.sol, src/interfaces/IMulticall3.sol). `cmp <(tr -d ' \\t\\r\\n' < upstream) <(tr -d ' \\t\\r\\n' < vendored)` reports identical for all seven, so the diffs are whitespace only. The same procedure for the OpenZeppelin archive (sha256 18c7b7e949b9a82dcd8cd394426c9c2636dfc263aa2317d4749dbfa0c7b3925a) gives 6 of 6 identical.","severity":"info","snippet":"Vendored sources are unmodified.","title":"DEPENDENCIES.md claims vendored sources are unmodified, but seven forge-std v1.9.7 files are whitespace-reformatted"},{"citation":"resolved","description":"Reproduced the audit_permissions finding. SPAD inherits OpenZeppelin v5.0.2 ERC20 without overriding approve or transferFrom. approve() overwrites the allowance slot unconditionally (lib/openzeppelin-contracts/contracts/token/ERC20/ERC20.sol:291 `_allowances[owner][spender] = value;`) while transferFrom() decrements it via _spendAllowance (ERC20.sol:312). A spender who sees a pending approve(spender, lower) can spend the old allowance first and then the new one, exceeding the owner's intended cap. This is conformant ERC-20 behaviour (EIP-20 documents it), the README tells users to revoke to zero first, and the launch flows (factory transfer to distributor, PoolManager settle, remainder transfer, distributor claims) use transfer() and never a reduced allowance, so there is no loss path for the launch itself. No token-level change is recommended; recorded as a trust/usage assumption for holders who grant allowances. Merged duplicate: none (only audit_permissions reported it).","line":8,"path":"src/SPAD.sol","reproduction":"State: owner O = the deployer (holds 1e27 SPAD), spender S = address(0x5). 1) O calls approve(S, 100). 2) O intends to lower the cap and broadcasts approve(S, 50); S front-runs it with transferFrom(O, S, 100) (allowance 100 -> 0, balanceOf(S) = 100). 3) O's approve(S, 50) lands (allowance 0 -> 50). 4) S calls transferFrom(O, S, 50). Expected by O: S can move at most 100 in total (or 50 after the reduction). Actual: balanceOf(S) == 150. Verified with a scratch Foundry test that deploys SPAD, runs the four calls in that order with vm.prank(S) for the two transferFrom calls, and asserts balanceOf(S) == 150; it passes on the current code, i.e. the race is real.","severity":"info","snippet":"contract SPAD is ERC20 {","title":"approve/transferFrom allowance race is the standard ERC-20 asymmetry (inherited unchanged, by design)"}],"hash":"3cae0de0ad8e674b9b1a8b46ef358239390d03d7facac830c9f5995158b85376","nodeId":"3ac43ea3-374b-4547-be5e-f91e4a02ad03","outcome":"completed","summary":"The findings file is in place and excluded by the harness's own git exclude rule, as expected. The review is complete and no repository files were changed.\n\n**Verdict: no blocking defects.** SPAD is a plain OpenZeppelin v5.0.2 ERC20 with a fixed supply of one billion tokens at 18 decimals, minted once to the deployer, with no owner, mint, burn, pause, blacklist, fee or initializer. Both specialist findings reproduced and are kept at info severity. Nothing new surfaced in my own pass.\n\n**What I verified**\n\n- **Build and tests**: the project compiles on Solidity 0.8.26 and all 45 tests pass, including the stateful invariants with zero reverts. The formatter check also passes.\n- **Entry points**: approve, transfer and transferFrom all trace to unmodified OZ code with the expected revert paths and exact-amount movement. All three marked holds.\n- **Floor checks**: the runtime bytecode contains no DELEGATECALL, CALLCODE, SELFDESTRUCT or any CALL-family opcode. Supply cannot grow after construction.\n- **Manifest**: name, symbol, decimals, empty constructor arguments and total supply match the compiled contract. The recorded initialPrice equals the stated formula exactly.\n- **Vendored dependencies**: I downloaded both upstream archives. Their hashes match DEPENDENCIES.md. All six OpenZeppelin files are byte-identical. Seven forge-std files differ by whitespace only.\n\n**Findings kept, both info**\n\n1. DEPENDENCIES.md says vendored sources are unmodified, but seven forge-std files were reformatted. No effect on the token or tests. Fix the bytes or the sentence.\n2. The approve/transferFrom allowance race is standard ERC-20 behaviour inherited unchanged. I reproduced it in a scratch test where a spender moved 150 tokens against an intended cap of 100. The README already documents the revoke-to-zero mitigation. No code change recommended.\n\n**Dropped**: the aderyn large-numeric-literal lead, since the constant is the readable one-billion-times-ten-to-the-eighteen expression. Slither reported nothing.\n\nThe coverage record answers all three listed entry points plus four invariant rows.","treeHash":null,"usage":{"cachedInputTokens":513738,"inputTokens":322,"model":"claude-fable-5-1","outputTokens":9335,"runtime":"claude","turns":11,"wallClockMs":136431}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"e3a598aae0640402","findings":[],"hash":"776d97c630c7e65b9a967e7dab557fd44c7cbef2d2e5ffc2bf782c3b6f66061a","nodeId":"1f3a0b91-9bd3-4c1b-b1e4-d815c06bbbd5","outcome":"completed","summary":"Review complete. The findings file is written with an empty findings list and a full coverage record. No tracked file changed.\n\n**Result: no defects found** in the Execution Trace, Periphery or First Principles areas for `src/SPAD.sol`. The token is a 16-line subclass of the vendored OpenZeppelin ERC20 that adds one constant and one constructor mint. Every state-changing path is inherited, unmodified, and I traced each to its final state.\n\n**What I checked and how**\n\n- **Execution trace of all three entry points.** Approve, transfer and transferFrom each enforce their zero-address guards, do the balance or allowance check before the unchecked subtraction, and move exactly the requested amount. A revert after the allowance write in transferFrom rolls it back atomically. No external calls, callbacks, fees, hooks or stale reads exist on any path.\n- **Constructor.** The supply constant equals ten to the twenty-seventh and is minted once to the immediate caller. A scratch test deploys it through CREATE2 from a factory contract with a launch-number salt, confirms the predicted address, and confirms the factory holds the whole supply with nothing to the origin.\n- **Periphery.** I downloaded upstream OpenZeppelin v5.0.2 into a fresh temp directory and compared every vendored file byte for byte. All five sources and the licence are identical, and the archive hash matches DEPENDENCIES.md. No git submodules are present.\n- **Compiled artifact.** The ABI exposes only the three listed state changers. A disassembly of the deployed runtime contains no CALL, CREATE, DELEGATECALL, CALLCODE or SELFDESTRUCT. Plain ETH, value-bearing calls and unknown selectors all revert.\n- **Suites.** The project's 30 unit and fuzz tests plus the stateful invariant pass. My five scratch probes under test/scratch pass. Formatting passes.\n\n**Static analysis leads.** Slither reported nothing. Aderyn's large-numeric-literal note is a style lead only; the literal evaluates to the correct supply, so I did not report it.\n\n**One assumption recorded, not a defect.** The pinned Cancun target emits a single MCOPY opcode, so the launch chain must be post-Cancun. All current mainstream targets are. It is noted in the coverage record for whoever selects the chain.\n\nCoverage rows answer all three listed entry points plus the constructor, four invariants and the vendored base, each with a verdict of holds.","treeHash":null,"usage":{"cachedInputTokens":754442,"inputTokens":322,"model":"claude-fable-5-1","outputTokens":13937,"runtime":"claude","turns":27,"wallClockMs":247530}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"a406deaac63a93b0","findings":[],"hash":"9ddc799c8ed86ff76822b6796d0b343ff4050163db5b1b2a49d3560e39ad6696","nodeId":"b597b970-8533-4e8e-b740-ced766f59464","outcome":"completed","summary":"The review is complete. The findings file is written with an empty findings list and full coverage.\n\n**Result: no defects found.** The token is a 16-line wrapper over OpenZeppelin v5.0.2 ERC20 with no overrides, so every arithmetic path the Math Precision, Boundary and Numerical Gap guides target either does not exist or is the library's own checked code.\n\n**What I verified**\n\n- **Vendored library is genuine.** I re-downloaded the v5.0.2 archive. Its SHA-256 matches DEPENDENCIES.md and all six vendored files are byte-identical to upstream.\n- **Supply constant.** The literal evaluates at compile time to exactly 10^27, fits uint256 and uint128, and is divisible by 10,000 so every basis-point split in the launch is integral. The aderyn large-literal lead is stylistic only.\n- **Transfer and transferFrom arithmetic.** The checked balance and allowance guards precede the unchecked subtractions, and the unchecked recipient add is bounded by total supply. I exercised 1 wei, the full supply, supply plus one, max uint, max-minus-one allowance, self-transfers, zero amounts and a pranked zero address in a scratch suite. All nine tests passed, and the scratch directory is removed.\n- **Fixed supply and whole launch flows.** Mint happens once to msg.sender, there is no burn or admin path, and transfers to the zero address revert. The existing invariant run and a three-way fuzz confirm balances always sum to the supply.\n- **Boundary enumeration.** The token has no external calls, payable functions, sentinel branches or bytes decoding, so the Boundary guide's steps 2 through 5 have no call sites to apply to.\n\n**Coverage record** has seven rows: the three ABI entry points plus four invariant and boundary rows, all `holds`. The existing suite of 31 tests passes and the shipped source and tests pass the format check.","treeHash":null,"usage":{"cachedInputTokens":420879,"inputTokens":194,"model":"claude-fable-5-1","outputTokens":9573,"runtime":"claude","turns":20,"wallClockMs":145287}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"df74f6c887684f20","findings":[{"citation":"resolved","description":"The six vendored OpenZeppelin v5.0.2 files are byte-identical to the upstream archive (sha256 18c7b7e9...925a, as recorded). The forge-std v1.9.7 archive (sha256 45157353...ee94, as recorded) does NOT match byte for byte: lib/forge-std/src/StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IERC7540.sol and interfaces/IMulticall3.sol differ from upstream. Every difference is line-wrapping/indentation (the vendored copies look like they were run through `forge fmt`); stripping all whitespace from each pair gives identical bytes, so there is no semantic change and no effect on the production token, which imports nothing from forge-std. This is a provenance-statement inaccuracy only: anyone verifying the vendored tree against the recorded archive hash with a byte comparison will get a mismatch for forge-std. Not an economic, invariant or flow defect in SPAD.","line":19,"path":"DEPENDENCIES.md","reproduction":"Download https://codeload.github.com/foundry-rs/forge-std/tar.gz/refs/tags/v1.9.7 (sha256 matches the one recorded in DEPENDENCIES.md), extract, then `cmp forge-std-1.9.7/src/Vm.sol lib/forge-std/src/Vm.sol` -> differ. `diff -w` shows only signature line-wrapping changes (e.g. upstream wraps `function getDeployment(string calldata contractName, uint64 chainId)` over four lines, the vendored copy puts it on one). `cmp <(tr -d ' \\t\\r\\n' < upstream) <(tr -d ' \\t\\r\\n' < vendored)` is identical for all seven files. Expected per the doc: byte-identical. Actual: whitespace-only reformatting. Fix: either restore the upstream bytes or change the sentence to say forge-std was reformatted with forge fmt.","severity":"info","snippet":"Vendored sources are unmodified.","title":"DEPENDENCIES.md states vendored sources are unmodified, but seven forge-std v1.9.7 files were reformatted (whitespace only)"}],"hash":"c02333ab94c6b06abaaa0bd61956e75678b05002087f8c8e4689060f8b880b62","nodeId":"3de32eab-8ef3-4cbf-bd7f-919fcefec893","outcome":"completed","summary":"The review is complete and the findings file is written. No tracked file was changed; the scratch test lives under the gitignored test/scratch directory.\n\n**Outcome: no economic, invariant or flow-gap defect in SPAD.** One info-level provenance note was recorded.\n\nWhat I checked, against the Economic Security, Invariant and Flow Gap guides:\n\n- **Token source.** SPAD is the unmodified OpenZeppelin v5.0.2 ERC20 plus one constant and a constructor that mints the whole supply to the caller. The six vendored OpenZeppelin files are byte-identical to the upstream archive, whose hash matches the one recorded in the repo.\n- **Supply invariant.** The constant folds to exactly 10^27, which matches the brief. Mint and burn are unreachable after construction, and the ABI exposes only approve, transfer and transferFrom as state changers. The delivered stateful invariant suite and my scratch tests confirm balances always sum to total supply.\n- **Launch flows.** With no taxes, hooks, exemptions or external calls, the factory to distributor, pool and remainder transfers, distributor claims, and trader buy and sell round trips all move exact amounts. I fuzzed the pool share across the full allowed range of basis points.\n- **Allowance economics.** Finite allowances decrement, the max allowance is sticky, and failed pulls roll back atomically. Neither the factory nor the deployer can move a holder's balance without approval.\n- **Other leads.** The aderyn large-literal warning is not a defect. The token accepts no ether and has no forbidden opcodes. Formatting check and all 31 delivered tests pass.\n\n**The one finding, severity info.** The dependencies document says vendored sources are unmodified, but seven forge-std files were reformatted with whitespace-only changes against the v1.9.7 archive. The code is semantically identical and forge-std is test-only, so this has no effect on the token. It is recorded with the exact comparison steps so the author can either restore upstream bytes or reword the sentence.\n\nThe coverage record answers all three listed entry points as holds, plus rows for the supply invariant, constructor minting, launch-flow exemptions, dependency integrity, and the static-analysis lead.","treeHash":null,"usage":{"cachedInputTokens":736533,"inputTokens":386,"model":"claude-fable-5-1","outputTokens":11672,"runtime":"claude","turns":21,"wallClockMs":175086}},{"artifacts":[],"attempt":1,"bundleHash":"39e187468fba294d3c25cf93147bbc600bba81ffe537e20b858e1420d67209b4","device":"b5370e603753d2ab","findings":[],"hash":"de04953d43a4e77c1c929c409bf202a3323f38020cf9994e40d38ec32d5ef81d","nodeId":"1f9f6293-c4be-48a2-9233-7c487e485760","outcome":"completed","summary":"Implemented SPAD with the exact requested name, 18 decimals, and 1,000,000,000 tokens minted once to the deployer. Dependencies are vendored; deployment parameters, assumptions, and operational responsibilities are documented.\n\nVerified with Solidity 0.8.26:\n\n- `forge build` passed.\n- `forge test` passed: 31 tests, including fuzz and invariant coverage.\n- `forge fmt --check` passed.\n\nProtected launch integration remains for the network’s configured harness.","treeHash":"6a07a950e13ca858639b33f0465f941a3f236478","usage":{"cachedInputTokens":362880,"inputTokens":50418,"model":"gpt-6-astra","outputTokens":12238,"runtime":"codex","turns":5,"wallClockMs":327716}},{"artifacts":[],"attempt":1,"bundleHash":"2c245dfda123c536cbae2ffafe02ae5f72dba24ac2fa3905b766db0a0361e9a5","device":"c7b1db4d25939bd5","findings":[],"hash":"dfbaa64367161785ae5b7efd94f3bd2e0a3a92115d475524d202d1b4fd04eff9","nodeId":"3bba83d7-418c-4dee-9cfb-0cdcbdb0ab05","outcome":"completed","summary":"Created [launch.json](/home/worker/.identitymd/work/1acbfd68-ebfd-4673-86ef-f84c5b0254ea/3bba83d7-418c-4dee-9cfb-0cdcbdb0ab05/launch.json) with exact SPAD metadata, supply and economics, no application contracts, and a 0.3% pool fee.\n\nSchema and constructor ABI checks passed. `forge build` succeeded; all 31 local tests passed. Only `launch.json` is a submission change.","treeHash":"8e98b57dc4ef1768db506e8062db56641bb188f5","usage":{"cachedInputTokens":200576,"inputTokens":23875,"model":"gpt-6-astra","outputTokens":3427,"runtime":"codex","turns":3,"wallClockMs":102185}}],"verification":[{"checks":[{"durationMs":1332,"exitCode":0,"name":"build","output":"Compiling 28 files with Solc 0.8.26\nSolc 0.8.26 finished in 1.22s\nCompiler run successful!\n","passed":true},{"durationMs":4847,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 30 tests for test/SPAD.t.sol:SPADTest\n[PASS] testFuzz_ApprovalIsOnlyForSpecifiedSpender(uint256) (runs: 512, μ: 121426, ~: 121186)\nLogs:\n  Bound result 30925981218547823566865490\n\n[PASS] testFuzz_TransferBeyondSupplyReverts(uint256) (runs: 512, μ: 58732, ~: 59093)\nLogs:\n  Bound result 115792089237316195423570985008687907853269984665639564039457584007913129639942\n\n[PASS] testFuzz_TransferFromConservesBalancesAndAllowance(uint256,uint256) (runs: 512, μ: 162983, ~: 164890)\nLogs:\n  Bound result 328895683507644915558611778\n  Bound result 281693871878985415896847685\n\n[PASS] testFuzz_TransfersConserveSupply(uint256) (runs: 512, μ: 167315, ~: 167891)\nLogs:\n  Bound result 30925981218547823559587386\n\n[PASS] test_ApproveEmitsEventAndCanReplaceAndRevokeAllowance() (gas: 157787)\n[PASS] test_ApproveZeroSpenderReverts() (gas: 30431)\n[PASS] test_ConstructorEmitsMintTransfer() (gas: 5464)\n[PASS] test_ContractDeployerReceivesSupplyInsteadOfOrigin() (gas: 316395)\n[PASS] test_Create2FactoryReceivesSupplyAndLaunchTransfersArriveWhole() (gas: 669349)\n[PASS] test_DeployerCannotSpendHolderBalanceWithoutApproval() (gas: 94921)\n[PASS] test_HolderUsingTransferFromAlsoNeedsAllowance() (gas: 35726)\n[PASS] test_InfiniteAllowanceIsNotDecremented() (gas: 128964)\n[PASS] test_MetadataAndEntireSupplyBelongToDeployer() (gas: 97029)\n[PASS] test_NoMintBurnOrAdministrativeEntrypoints() (gas: 800791)\n[PASS] test_RuntimeHasNoForbiddenOpcodes() (gas: 796456)\n[PASS] test_SelfTransferPreservesBalance() (gas: 51452)\n[PASS] test_SelfTransferStillRequiresBalance() (gas: 35885)\n[PASS] test_TransferAboveBalanceRevertsWithoutChangingState() (gas: 120036)\n[PASS] test_TransferEmitsEventAndMovesExactAmount() (gas: 91540)\n[PASS] test_TransferEntireSupply() (gas: 75766)\n[PASS] test_TransferFromAboveAllowanceRevertsWithoutChangingState() (gas: 115709)\n[PASS] test_TransferFromAboveBalanceRollsBackAllowance() (gas: 113612)\n[PASS] test_TransferFromConsumesFiniteAllowanceAndEmitsTransfer() (gas: 237507)\n[PASS] test_TransferFromToSelfConsumesAllowanceWithoutChangingBalance() (gas: 103237)\n[PASS] test_TransferFromToZeroRollsBackAllowance() (gas: 103824)\n[PASS] test_TransferFromZeroSenderRevertsEvenForZeroAmount() (gas: 35362)\n[PASS] test_TransferToZeroReverts() (gas: 47663)\n[PASS] test_ZeroTransferFromEmptyAccountEmitsEvent() (gas: 63068)\n[PASS] test_ZeroTransferFromNeedsNoAllowance() (gas: 66144)\n[PASS] test_ZeroTransferToZeroAlsoReverts() (gas: 30368)\nSuite result: ok. 30 passed; 0 failed; 0 skipped; finished in 77.41ms (188.25ms CPU time)\n\nRan 14 tests for test/SPAD.edge-cases.t.sol:SPADEdgeCasesTest\n[PASS] testFuzz_ApprovalReplacementIsExactAndIsolated(uint256,uint256) (runs: 1000, μ: 319969, ~: 320073)\n[PASS] testFuzz_RoundTripRestoresBothFundedHolders(uint256,uint256) (runs: 1000, μ: 257538, ~: 258582)\nLogs:\n  Bound result 948211368027397774191393782\n  Bound result 151472298468866839958434332\n\n[PASS] testFuzz_TransferFromOverAllowanceIsAtomic(uint256,uint256,uint256) (runs: 1000, μ: 215742, ~: 217459)\nLogs:\n  Bound result 7006389058\n  Bound result 1747015258\n  Bound result 6114601571\n\n[PASS] testFuzz_TransferFromOverBalanceIsAtomic(uint256,uint256,bool) (runs: 1000, μ: 217441, ~: 217473)\nLogs:\n  Bound result 999999999999999999999999999\n  Bound result 115792089237316195423570985008687907853269984665639564039471411851879156621669\n\n[PASS] testFuzz_ZeroDelegatedTransferPreservesArbitraryApproval(uint256,bool) (runs: 1000, μ: 198052, ~: 196765)\n[PASS] testFuzz_ZeroRecipientFailureLeavesApprovalUsable(uint256,uint256,bool) (runs: 1000, μ: 320163, ~: 322541)\nLogs:\n  Bound result 100\n  Bound result 96\n\n[PASS] test_InfiniteApprovalCanBeRevokedAfterSpending() (gas: 246084)\n[PASS] test_LoweringInfiniteApprovalImmediatelyLimitsSpender() (gas: 228710)\n[PASS] test_MaxMinusOneAllowanceIsFinite() (gas: 147989)\n[PASS] test_MaxUintCannotBeTransferredEvenWithInfiniteApproval() (gas: 156650)\n[PASS] test_OneWeiCanMakeARoundTrip() (gas: 143063)\n[PASS] test_ReplenishingBalanceDoesNotRestoreSpentAllowance() (gas: 320123)\n[PASS] test_SpenderAsRecipientStillDebitsTheOwner() (gas: 142624)\n[PASS] test_ZeroApprovalForZeroSpenderReverts() (gas: 110416)\nSuite result: ok. 14 passed; 0 failed; 0 skipped; finished in 77.42ms (457.68ms CPU time)\n\nRan 1 test for test/SPAD.invariant.t.sol:SPADInvariantTest\n[PASS]\nSPADInvariantTest invariants:\n[PASS] invariant_BalancesAndAllowancesMatchAuthorizedActions\n[PASS] invariant_SupplyAndAllBalancesAreConserved\n SPADInvariantTest invariants (runs: 256, calls: 16384, reverts: 0)\n\n╭-------------+--------------------+-------+---------+----------╮\n| Contract    | Selector           | Calls | Reverts | Discards |\n+===============================================================+\n| SPADHandler | approve            | 2304  | 0       | 0        |\n|-------------+--------------------+-------+---------+----------|\n| SPADHandler | approveBoundary    | 2359  | 0       | 0        |\n|-------------+--------------------+-------+---------+----------|\n| SPADHandler | rejectApproval     | 2325  | 0       | 0        |\n|-------------+--------------------+-------+---------+----------|\n| SPADHandler | rejectTransfer     | 2314  | 0       | 0        |\n|-------------+--------------------+-------+---------+----------|\n| SPADHandler | rejectTransferFrom | 2343  | 0       | 0        |\n|-------------+--------------------+-------+---------+----------|\n| SPADHandler | transfer           | 2375  | 0       | 0        |\n|-------------+--------------------+-------+---------+----------|\n| SPADHandler | transferFrom       | 2364  | 0       | 0        |\n╰-------------+--------------------+-------+---------+----------╯\n\nLogs:\n  Bound result 1350268406082934305\n  Bound result 9024\n  Bound result 391\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 4589\n  Bound result 115792089237316195423570985008687907853269984665640314039456233739507046701058\n  Bound result 115792089237316195423570985008687907853269984665640314039457584007913129639949\n  Bound result 8305\n  Bound result 21793259402162122653451068\n  Bound result 2478893114\n  Bound result 345\n  Bound result 7000825303942474644982455004038743532481337738836980741430077\n  Bound result 115792089237316195423570985008687907853269984665640335832715635901629700160399\n  Bound result 1418\n  Bound result 250000000000000000000000000\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 115792089237316195423570985008687907853269984665640085832715635901629700152461\n  Bound result 279078037823074\n  Bound result 0\n  Bound result 1077\n  Bound result 115792089237316195423570985008687907853269984665640314039457583728835091819676\n  Bound result 115792089237316195423570985008687907853269984665640292246199532114197559127029\n  Bound result 271793258051893716570512908\n  Bound result 115792089237316195423570985008687907853269984665640085832715636180707737979562\n  Bound result 6562\n  Bound result 123000000000000000000\n  Bound result 1\n  Bound result 60\n  Bound result 115792089237316195423570985008687907853269984665640314039334583728835091816901\n  Bound result 100000000000000000000\n  Bound result 478206618947827205391664018\n  Bound result 24576\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 4.76s (4.76s CPU time)\n\nRan 3 test suites in 4.76s (4.91s CPU time): 45 tests passed, 0 failed, 0 skipped (45 total tests)\n","passed":true},{"durationMs":35,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"SPAD.approve(address,uint256)\",\"SPAD.transfer(address,uint256)\",\"SPAD.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":4,\"DEPENDENCIES.md\":19,\"README.md\":65,\"SECURITY.md\":20,\"foundry.toml\":18,\"remappings.txt\":2,\"src/SPAD.sol\":16,\"test/SPAD.edge-cases.t.sol\":245,\"test/SPAD.invariant.t.sol\":190,\"test/SPAD.t.sol\":350},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"0d275f178f09934c60f4a03f8e9d095696a0ac9d5a1832b932484dea28a7d561","verifiedTreeHash":"dc8c090a8e7c04d075e90b735c8d130b0785ffaa","verifierVersion":"0.1.0+ad90ce4c"},{"checks":[{"durationMs":1045,"exitCode":0,"name":"build","output":"Compiling 27 files with Solc 0.8.26\nSolc 0.8.26 finished in 944.59ms\nCompiler run successful!\n","passed":true},{"durationMs":651,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 30 tests for test/SPAD.t.sol:SPADTest\n[PASS] testFuzz_ApprovalIsOnlyForSpecifiedSpender(uint256) (runs: 512, μ: 121384, ~: 121114)\nLogs:\n  Bound result 483110906759280053267648431\n\n[PASS] testFuzz_TransferBeyondSupplyReverts(uint256) (runs: 512, μ: 58757, ~: 59093)\nLogs:\n  Bound result 115792089237316195423570985008687907853269984665639564039457584007913129654225\n\n[PASS] testFuzz_TransferFromConservesBalancesAndAllowance(uint256,uint256) (runs: 512, μ: 163056, ~: 164900)\nLogs:\n  Bound result 1000000000000000000000000000\n  Bound result 171975133946238651228457087\n\n[PASS] testFuzz_TransfersConserveSupply(uint256) (runs: 512, μ: 167705, ~: 167819)\nLogs:\n  Bound result 23953\n\n[PASS] test_ApproveEmitsEventAndCanReplaceAndRevokeAllowance() (gas: 157787)\n[PASS] test_ApproveZeroSpenderReverts() (gas: 30431)\n[PASS] test_ConstructorEmitsMintTransfer() (gas: 5464)\n[PASS] test_ContractDeployerReceivesSupplyInsteadOfOrigin() (gas: 316395)\n[PASS] test_Create2FactoryReceivesSupplyAndLaunchTransfersArriveWhole() (gas: 669349)\n[PASS] test_DeployerCannotSpendHolderBalanceWithoutApproval() (gas: 94921)\n[PASS] test_HolderUsingTransferFromAlsoNeedsAllowance() (gas: 35726)\n[PASS] test_InfiniteAllowanceIsNotDecremented() (gas: 128964)\n[PASS] test_MetadataAndEntireSupplyBelongToDeployer() (gas: 97029)\n[PASS] test_NoMintBurnOrAdministrativeEntrypoints() (gas: 800791)\n[PASS] test_RuntimeHasNoForbiddenOpcodes() (gas: 796456)\n[PASS] test_SelfTransferPreservesBalance() (gas: 51452)\n[PASS] test_SelfTransferStillRequiresBalance() (gas: 35885)\n[PASS] test_TransferAboveBalanceRevertsWithoutChangingState() (gas: 120036)\n[PASS] test_TransferEmitsEventAndMovesExactAmount() (gas: 91540)\n[PASS] test_TransferEntireSupply() (gas: 75766)\n[PASS] test_TransferFromAboveAllowanceRevertsWithoutChangingState() (gas: 115709)\n[PASS] test_TransferFromAboveBalanceRollsBackAllowance() (gas: 113612)\n[PASS] test_TransferFromConsumesFiniteAllowanceAndEmitsTransfer() (gas: 237507)\n[PASS] test_TransferFromToSelfConsumesAllowanceWithoutChangingBalance() (gas: 103237)\n[PASS] test_TransferFromToZeroRollsBackAllowance() (gas: 103824)\n[PASS] test_TransferFromZeroSenderRevertsEvenForZeroAmount() (gas: 35362)\n[PASS] test_TransferToZeroReverts() (gas: 47663)\n[PASS] test_ZeroTransferFromEmptyAccountEmitsEvent() (gas: 63068)\n[PASS] test_ZeroTransferFromNeedsNoAllowance() (gas: 66144)\n[PASS] test_ZeroTransferToZeroAlsoReverts() (gas: 30368)\nSuite result: ok. 30 passed; 0 failed; 0 skipped; finished in 14.15ms (60.48ms CPU time)\n\nRan 1 test for test/SPAD.invariant.t.sol:SPADInvariantTest\n[PASS] invariant_SupplyAndAllBalancesAreConserved() (runs: 128, calls: 8192, reverts: 0)\n\n╭-------------+--------------+-------+---------+----------╮\n| Contract    | Selector     | Calls | Reverts | Discards |\n+=========================================================+\n| SPADHandler | approve      | 2805  | 0       | 0        |\n|-------------+--------------+-------+---------+----------|\n| SPADHandler | transfer     | 2711  | 0       | 0        |\n|-------------+--------------+-------+---------+----------|\n| SPADHandler | transferFrom | 2676  | 0       | 0        |\n╰-------------+--------------+-------+---------+----------╯\n\nLogs:\n  Bound result 1000000000000000000000000000\n  Bound result 0\n  Bound result 40\n  Bound result 37\n  Bound result 0\n  Bound result 24\n  Bound result 0\n  Bound result 13\n  Bound result 1\n  Bound result 0\n  Bound result 0\n  Bound result 2\n  Bound result 538\n  Bound result 476\n  Bound result 3147\n  Bound result 129\n  Bound result 13\n  Bound result 91\n  Bound result 47\n  Bound result 1557\n  Bound result 0\n  Bound result 8\n  Bound result 0\n  Bound result 0\n  Bound result 252\n  Bound result 0\n  Bound result 6\n  Bound result 692\n  Bound result 126\n  Bound result 0\n  Bound result 149\n  Bound result 12\n  Bound result 249\n  Bound result 5\n  Bound result 8\n  Bound result 1117\n  Bound result 357\n  Bound result 116\n  Bound result 40\n  Bound result 4\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 575.60ms (574.61ms CPU time)\n\nRan 2 test suites in 576.79ms (589.75ms CPU time): 31 tests passed, 0 failed, 0 skipped (31 total tests)\n","passed":true},{"durationMs":32,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"SPAD.approve(address,uint256)\",\"SPAD.transfer(address,uint256)\",\"SPAD.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":4,\"DEPENDENCIES.md\":19,\"README.md\":65,\"SECURITY.md\":20,\"foundry.toml\":18,\"remappings.txt\":2,\"src/SPAD.sol\":16,\"test/SPAD.invariant.t.sol\":73,\"test/SPAD.t.sol\":350},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true},{"durationMs":389,"exitCode":0,"name":"slither","output":"slither: no results at low impact or above","passed":true},{"durationMs":219,"exitCode":0,"name":"aderyn","output":"[low] large-numeric-literal at src/SPAD.sol:10: Large Numeric Literal","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"de04953d43a4e77c1c929c409bf202a3323f38020cf9994e40d38ec32d5ef81d","verifiedTreeHash":"6a07a950e13ca858639b33f0465f941a3f236478","verifierVersion":"0.1.0+ad90ce4c"},{"checks":[{"durationMs":1105,"exitCode":0,"name":"build","output":"Compiling 27 files with Solc 0.8.26\nSolc 0.8.26 finished in 1.00s\nCompiler run successful!\n","passed":true},{"durationMs":692,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 30 tests for test/SPAD.t.sol:SPADTest\n[PASS] testFuzz_ApprovalIsOnlyForSpecifiedSpender(uint256) (runs: 512, μ: 121364, ~: 121090)\nLogs:\n  Bound result 1596\n\n[PASS] testFuzz_TransferBeyondSupplyReverts(uint256) (runs: 512, μ: 58783, ~: 59093)\nLogs:\n  Bound result 115792089237316195423570985008687907853269984665639564039457584007913129641531\n\n[PASS] testFuzz_TransferFromConservesBalancesAndAllowance(uint256,uint256) (runs: 512, μ: 162454, ~: 164876)\nLogs:\n  Bound result 1000000000000000000000000000\n  Bound result 22956\n\n[PASS] testFuzz_TransfersConserveSupply(uint256) (runs: 512, μ: 166976, ~: 167819)\nLogs:\n  Bound result 449855155487451607012051703\n\n[PASS] test_ApproveEmitsEventAndCanReplaceAndRevokeAllowance() (gas: 157787)\n[PASS] test_ApproveZeroSpenderReverts() (gas: 30431)\n[PASS] test_ConstructorEmitsMintTransfer() (gas: 5464)\n[PASS] test_ContractDeployerReceivesSupplyInsteadOfOrigin() (gas: 316395)\n[PASS] test_Create2FactoryReceivesSupplyAndLaunchTransfersArriveWhole() (gas: 669349)\n[PASS] test_DeployerCannotSpendHolderBalanceWithoutApproval() (gas: 94921)\n[PASS] test_HolderUsingTransferFromAlsoNeedsAllowance() (gas: 35726)\n[PASS] test_InfiniteAllowanceIsNotDecremented() (gas: 128964)\n[PASS] test_MetadataAndEntireSupplyBelongToDeployer() (gas: 97029)\n[PASS] test_NoMintBurnOrAdministrativeEntrypoints() (gas: 800791)\n[PASS] test_RuntimeHasNoForbiddenOpcodes() (gas: 796456)\n[PASS] test_SelfTransferPreservesBalance() (gas: 51452)\n[PASS] test_SelfTransferStillRequiresBalance() (gas: 35885)\n[PASS] test_TransferAboveBalanceRevertsWithoutChangingState() (gas: 120036)\n[PASS] test_TransferEmitsEventAndMovesExactAmount() (gas: 91540)\n[PASS] test_TransferEntireSupply() (gas: 75766)\n[PASS] test_TransferFromAboveAllowanceRevertsWithoutChangingState() (gas: 115709)\n[PASS] test_TransferFromAboveBalanceRollsBackAllowance() (gas: 113612)\n[PASS] test_TransferFromConsumesFiniteAllowanceAndEmitsTransfer() (gas: 237507)\n[PASS] test_TransferFromToSelfConsumesAllowanceWithoutChangingBalance() (gas: 103237)\n[PASS] test_TransferFromToZeroRollsBackAllowance() (gas: 103824)\n[PASS] test_TransferFromZeroSenderRevertsEvenForZeroAmount() (gas: 35362)\n[PASS] test_TransferToZeroReverts() (gas: 47663)\n[PASS] test_ZeroTransferFromEmptyAccountEmitsEvent() (gas: 63068)\n[PASS] test_ZeroTransferFromNeedsNoAllowance() (gas: 66144)\n[PASS] test_ZeroTransferToZeroAlsoReverts() (gas: 30368)\nSuite result: ok. 30 passed; 0 failed; 0 skipped; finished in 16.36ms (69.83ms CPU time)\n\nRan 1 test for test/SPAD.invariant.t.sol:SPADInvariantTest\n[PASS] invariant_SupplyAndAllBalancesAreConserved() (runs: 128, calls: 8192, reverts: 0)\n\n╭-------------+--------------+-------+---------+----------╮\n| Contract    | Selector     | Calls | Reverts | Discards |\n+=========================================================+\n| SPADHandler | approve      | 2675  | 0       | 0        |\n|-------------+--------------+-------+---------+----------|\n| SPADHandler | transfer     | 2756  | 0       | 0        |\n|-------------+--------------+-------+---------+----------|\n| SPADHandler | transferFrom | 2761  | 0       | 0        |\n╰-------------+--------------+-------+---------+----------╯\n\nLogs:\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 6\n  Bound result 4\n  Bound result 127\n  Bound result 0\n  Bound result 0\n  Bound result 489780387011462679285655666\n  Bound result 319\n  Bound result 1\n  Bound result 95\n  Bound result 255\n  Bound result 3963891462\n  Bound result 5295234177902\n  Bound result 5\n  Bound result 1\n  Bound result 1\n  Bound result 0\n  Bound result 1939271983223\n  Bound result 0\n  Bound result 118\n  Bound result 40692442031407889801704852\n  Bound result 1\n  Bound result 348\n  Bound result 255\n  Bound result 18\n  Bound result 3471\n  Bound result 3\n  Bound result 266800410505\n  Bound result 18\n  Bound result 1629482294208\n  Bound result 1589\n  Bound result 0\n  Bound result 1652\n  Bound result 8\n  Bound result 100\n  Bound result 0\n  Bound result 12\n  Bound result 1\n  Bound result 156380048498\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 607.29ms (601.76ms CPU time)\n\nRan 2 test suites in 608.79ms (623.65ms CPU time): 31 tests passed, 0 failed, 0 skipped (31 total tests)\n","passed":true},{"durationMs":32,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"SPAD.approve(address,uint256)\",\"SPAD.transfer(address,uint256)\",\"SPAD.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":4,\"DEPENDENCIES.md\":19,\"README.md\":65,\"SECURITY.md\":20,\"foundry.toml\":18,\"launch.json\":20,\"remappings.txt\":2,\"src/SPAD.sol\":16,\"test/SPAD.invariant.t.sol\":73,\"test/SPAD.t.sol\":350},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"dfbaa64367161785ae5b7efd94f3bd2e0a3a92115d475524d202d1b4fd04eff9","verifiedTreeHash":"8e98b57dc4ef1768db506e8062db56641bb188f5","verifierVersion":"0.1.0+ad90ce4c"}]}