{"assessments":[],"deployments":[],"fuzz":[],"identity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"interpretation":"Records acceptance and evidence. Neither completion nor an AI assessment establishes correctness, safety, or independent review.","jobId":"9374a276-63e9-4fed-83b7-12e8721b1524","kind":"shape:chain","nodes":[{"acceptedSubmissionHash":"4099aef00655076fd49bd261e143260cafb918a1053a9938ece3ade5fe333a8d","dependsOn":["scaffold_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"6b037a7b6601e883cf8a906c1520c0624817d42d8310b65c2f43679204608af3","skillId":"adversarial-review","tools":[]},"key":"adversarial_review","kind":"code","role":"review","skillHash":"6b037a7b6601e883cf8a906c1520c0624817d42d8310b65c2f43679204608af3","skillId":"adversarial-review","state":"accepted"},{"acceptedSubmissionHash":"b07c9c56cec8a7a2e74c44af9cc4faece1e4789e011eee2c57104a16c87e78dd","dependsOn":[],"execution":{"network":true,"profile":"none","requires":["network"],"skillHash":"7ae2f33d07dd65f04780071437d0c74200f8f58a323bc9324fa8524f587719c6","skillId":"scaffold-project","tools":[]},"key":"scaffold_project","kind":"code","role":"implement","skillHash":"7ae2f33d07dd65f04780071437d0c74200f8f58a323bc9324fa8524f587719c6","skillId":"scaffold-project","state":"accepted"}],"objective":"Check the IMD docs (https://imd.fun/docs) against the live API using only free, public calls: GET routes and POST /requests/check, never quote, submit or anything paid. Test documented limits and refusals (lengths, step path rules, required facts, refused fields), documented response shapes and which routes send CORS headers, with no more than 300 calls at least 2 seconds apart. Publish the script, the raw results and report.md: every claim tested, pass or fail, and for each mismatch the exact request that shows it. Known mismatch to confirm: write-readme-and-docs steps are refused with paths (unplannable_steps) yet blocked at run time without them (path_violation). Do not repeat the evaluator-consistency question; this is about documented behaviour. If the network is unreachable, deliver the script and say so. Tone: a constructive bug report. Label it everywhere it is presented (README top, CLI --help, site banner) as experimental: \"Experimental, commissioned as a test of the IMD swarm. It may not work as described. Read the code, start with small amounts, no warranty.\" Add one line at the end of the README: \"Commissioned through paid IMD swarm requests.\"","parentJobId":null,"planHash":"129184d10ace646db7bb9703b3f1c99ba764c12ffc116906227891108fa65573","previousHash":"0000000000000000000000000000000000000000000000000000000000000000","projectId":"9374a276-63e9-4fed-83b7-12e8721b1524","publication":{"commit":null,"deliveredAt":null,"repoUrl":"https://github.com/identity-md-launches/launch-613-check-imd-docs-https-imd-fun-docs"},"receiptIdentity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"registry":"0xb6d0a187b050fa5bb0b87033a203f37becf4a775","research":[],"schema":"identitymd-work-v1","signals":[{"agentId":"50959","feedbackHash":"c69be1412e92c616612fb3a285d181d0e79d058512e5b61e86d12a9a803cce34","nodeKey":"adversarial_review","submissionHash":"4099aef00655076fd49bd261e143260cafb918a1053a9938ece3ade5fe333a8d","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51736","feedbackHash":"22dd53cbf369bb646fad5c7182096fb08530811de96f42639bc41e2e2064f345","nodeKey":"scaffold_project","submissionHash":"b07c9c56cec8a7a2e74c44af9cc4faece1e4789e011eee2c57104a16c87e78dd","tag1":"verification:structural","tag2":"acceptance-v2","value":1}],"site":null,"snapshotHash":"e882b676b93da75551d1134801aad77b3ec672fc0bf38e992741f8146f3b3d05","state":"completed","submissions":[{"artifacts":[],"attempt":1,"bundleHash":null,"device":"468e82a89b9bfe18","findings":[{"citation":"resolved","description":"Both launch.open probes with template impl_tests_review (launch-missing-name, launch-nonstandard-token) returned two extra blockers, bad_path_count 'expected between 1 and 16 allowed paths' on nodes impl and tests, in addition to the missing_fact / launch_token blockers the claim asserts. The docs never say a template launch needs paths or contracts: the job-level paths row (docs.txt line 511) reads 'Up to 16 repository-relative paths the job may write' with no 'Required', and the impl_tests_review example (docs.txt lines 689-690) names only contracts. The checker's 'facts' mode only looks for the expected missing_fact entries, so the rows are PASS and the narrative (line 27, 'Missing launch name/symbol appear as required missing facts and matching missing_fact blockers') omits the blocker. A reader of the report cannot learn that a template launch with neither paths nor contracts is refused for path count. Either surface it as OBSERVED/FAIL with the docs lines, or re-probe with the documented example body (template plus contracts) so the row says whether the documented example itself passes.","line":169,"path":"report.md","reproduction":"POST https://api.imd.fun/requests/check with results/requests/launch-missing-name.json ({\"action\":\"launch.open\",\"input\":{\"onchain\":\"evm_project\",\"objective\":\"Build a simple donation contract with tests and deploy it on Sepolia.\",\"template\":\"impl_tests_review\"}}). Expected per docs: only missing_fact blockers for token_name/token_symbol. Actual (results/probes/launch-missing-name.json, HTTP 200): blockers also include {\"code\":\"bad_path_count\",\"detail\":\"expected between 1 and 16 allowed paths\",\"node\":\"impl\"} and the same for node \"tests\". Same two blockers in results/probes/launch-nonstandard-token.json. report.md marks both rows PASS and neither the five numbered findings nor the 'What matched' section mentions them.","severity":"low","snippet":"| launch-missing-name | [Launch check requires token name/symbol, fixed token terms unless custom_token, and custom token economics.](https://imd.fun/docs/#job-body) | PASS | HTTP 200; blockers=[{\"code\": \"bad_path_count\", \"detail\": \"expected between 1 and 16 allowed paths\", \"node\": \"impl\"}, {\"code\": \"bad_path_count\", \"detail\": \"expected between 1 and 16 allowed paths\", \"node\": \"tests\"}, {\"code\": \"missing_fact\", \"fact\": \"token_name\", \"detail\": \"Token name: needed to mint the token.\"}, {\"code\": \"missing_fact\", \"fact\": \"token_symbol\", \"detail\": \"Token symbol: needed to mint the token.\"}] | [raw](results/probes/launch-missing-name.json) |","title":"Template launch checks carry an undocumented bad_path_count blocker that the report files as PASS and never discusses"},{"citation":"resolved","description":"The mismatch is real: results/probes/oracle-attestation.json (HTTP 200, Origin https://example.org) has no access-control-allow-origin header while oracle-list, oracle-counts, oracle-detail and oracle-pools all return '*'. But the docs are weaker than the finding states. Only docs.txt line 39 ('Enabled on selected routes only, including /swarm, oracle reads and ENS') covers the attestation route; in the per-route Oracle table (docs.txt lines 142-146) the 'Open CORS' marker appears on GET /oracle/counts (line 143) only, and the attestation row (line 145) carries none. The finding should quote both so a maintainer can decide whether the fix is a header on the route or a narrower sentence under Base URLs. Not a reason to drop the finding.","line":19,"path":"report.md","reproduction":"curl -H 'Origin: https://example.org' https://api.imd.fun/oracle/requests/6c3d808e-c038-464c-9f1b-381718ea2937/attestation returns 200 with headers Cache-Control, Content-Type, Date, Server, x-railway-request-id, Content-Length, x-hikari-trace, x-railway-edge, vary, Connection and no Access-Control-Allow-Origin (results/probes/oracle-attestation.json). docs.txt line 143 is the only oracle row that says 'Open CORS'; line 145 (attestation) does not. report.md line 19 cites only the Base URLs sentence.","severity":"info","snippet":"4. **Oracle attestation lacks the CORS header advertised for oracle reads.** [Base URLs → CORS](https://imd.fun/docs/#base) describes oracle reads as CORS-enabled. With `Origin: https://example.org`, the list, counts, detail and pools GETs send `Access-Control-Allow-Origin: *`; the successful attestation GET sends no allow-origin header. Please add it to the attestation route or explicitly document the exception. Reproduction: `oracle-attestation`. This tests an actual successful attestation, not an unknown-ID error. It does not test an OPTIONS preflight.","title":"Attestation CORS finding cites only the generic 'oracle reads' sentence; the route table marks Open CORS on /oracle/counts alone"}],"hash":"4099aef00655076fd49bd261e143260cafb918a1053a9938ece3ade5fe333a8d","nodeId":"35ac207e-dabf-4ebc-b845-157e8fb9ab0a","outcome":"completed","summary":"The review is complete. Nothing in the report had to be removed: every reported mismatch reproduces from the saved raw results and the docs snapshot. The findings file holds two low-severity notes about presentation, not about the mismatches themselves.\n\n**What I verified against `results/probes/*.json` and `results/docs.txt`**\n\n- **Step-path contradiction.** Docs line 501 lists write-readme-and-docs, deploy-script and gas-and-size-report as requiring paths. All three check clean without paths and return `unplannable_steps` (\"declares its own budget\") with paths. The historical job c2ba5413 is `blocked` with `path_violation`, allowed paths `README.md` and `docs/**`, three zero-turn failures on `artifacts/SEPOLIA-GUIDE.md`. The known mismatch from the task is confirmed from both directions.\n- **16-path limit.** 8 directory-form paths pass, 9 and 16 return `bad_path_count`, 16 `.md` paths and 16 `/**` paths pass. The report's two-entries-per-directory inference is labelled as inference and is consistent with the `.git/config` probe, which expands to both `.git/config` and `.git/config/**`.\n- **Oracle list rows.** Docs line 142 promises `panelSize` and `quorum` per row. Zero of 500 rows in the limit=501 probe carry either; the detail route does.\n- **Attestation CORS.** The attestation response has no `Access-Control-Allow-Origin` header while list, counts, detail and pools return `*`.\n- **Explorer agent.** Docs line 287 promises `jobs` and `lastAcceptedAt`; the seat 42 response has neither.\n- **Report integrity.** The 88-row CORS table matches raw headers exactly. Minimum start-to-start spacing is 2.184 s and finish-to-next-start is 2.1 s. The body limit probes are exactly 16,384 and 16,385 bytes with 200 and 413. The docs footer reads `3b96b1cc`, checked 2026-10-01. The offline verifier and all 12 unit tests pass on a scratch copy. The experimental label is present in README, CLI help and the site banner.\n\n**Findings written to `.imd-findings.json`**\n\n1. **Low.** The two template launch probes also return `bad_path_count` on nodes `impl` and `tests`. The docs never mark job-level paths or contracts as required for a template, yet the report files both rows as PASS and never mentions the blocker. The probes also omit `contracts`, so they cannot say whether the documented example body passes.\n2. **Info.** The attestation CORS finding rests only on the generic \"oracle reads\" sentence in Base URLs. The per-route oracle table marks Open CORS on `/oracle/counts` alone, so the finding should cite both lines. The mismatch itself stands.\n\nNo files other than the findings file were changed.","treeHash":null,"usage":{"cachedInputTokens":973457,"inputTokens":354,"model":"claude-fable-5-1","outputTokens":17141,"runtime":"claude","turns":22,"wallClockMs":227366}},{"artifacts":[],"attempt":1,"bundleHash":"6af0fffb91160d6361c0b731286d6a822a732b5639cf1f465e58162a3154ed54","device":"080b27034220eb6f","findings":[],"hash":"b07c9c56cec8a7a2e74c44af9cc4faece1e4789e011eee2c57104a16c87e78dd","nodeId":"347f2354-caaa-479b-8884-6a51b218fbd8","outcome":"completed","summary":"Implemented the checker, claims list, raw results, and [report.md](report.md).\n\n- 234 probes; conservative budget usage: 244/300.\n- Five finding groups, including the README planning conflict and historical runtime `path_violation`.\n- Exact requests included for every mismatch.\n- All 12 offline tests passed.\n\nRun locally: `python3 scripts/audit.py --verify`. See [README.md](README.md) for instructions.","treeHash":"51aba1596bb4bcafb304d19b35d2d693a663096f","usage":{"cachedInputTokens":2379904,"inputTokens":119771,"model":null,"outputTokens":29850,"runtime":"codex","turns":10,"wallClockMs":1313782}}],"verification":[{"checks":[],"detail":"paths and tree verified; no suite was run for this kind of work","evaluation":"structural","profile":"none","status":"accepted","submissionHash":"b07c9c56cec8a7a2e74c44af9cc4faece1e4789e011eee2c57104a16c87e78dd","verifiedTreeHash":"51aba1596bb4bcafb304d19b35d2d693a663096f","verifierVersion":"0.1.0+68ddf5e4"}]}