{"assessments":[],"deployments":[],"fuzz":[],"identity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"interpretation":"Records acceptance and evidence. Neither completion nor an AI assessment establishes correctness, safety, or independent review.","jobId":"1405b728-d34f-45d3-844f-cde77275cd8f","kind":"shape:chain","nodes":[{"acceptedSubmissionHash":null,"dependsOn":["write_foundry_tests"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"c26edc76dc7a76e09a42c3634054429c1679c6e247747d647a03f77e5b332d7e","skillId":"adversarial-review","tools":[]},"key":"adversarial_review","kind":"code","role":"review","skillHash":"c26edc76dc7a76e09a42c3634054429c1679c6e247747d647a03f77e5b332d7e","skillId":"adversarial-review","state":"waiting"},{"acceptedSubmissionHash":null,"dependsOn":["adversarial_review"],"execution":{"network":true,"profile":"none","requires":["network"],"skillHash":"3ddca93330036359dd721585e58e67820336a0398b7927b3c89369d6134f30f6","skillId":"research-report","tools":[]},"key":"research_report","kind":"code","role":"implement","skillHash":"3ddca93330036359dd721585e58e67820336a0398b7927b3c89369d6134f30f6","skillId":"research-report","state":"waiting"},{"acceptedSubmissionHash":null,"dependsOn":[],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"ff1fad07fad3b8e08a71e9c5201fd632e161ed8163eb407676ea8b0bedbe179e","skillId":"write-foundry-tests","tools":[]},"key":"write_foundry_tests","kind":"code","role":"tests","skillHash":"ff1fad07fad3b8e08a71e9c5201fd632e161ed8163eb407676ea8b0bedbe179e","skillId":"write-foundry-tests","state":"failed"}],"objective":"INDEPENDENT REVIEW REQUEST: the IMD6900 (formerly IMDSTR) upgrade on Ethereum, before its 48h timelock batch is queued\n\nWHY THIS CHANGE\n- IMDSTR (\"Identity.MD Strategy\") is a fork of TokenWorks' NFTStrategy made for identity.md NFTs, live on Ethereum and Robinhood Chain since 2026-09-24. TokenWorks has since launched its own strategy for identity.md, so two tokens would carry the same name. Ours is renamed Identity.MD 6900 (symbol IMD6900). The token address does not change; the rename is a launcher call through the timelock.\n- With the rename come improvements the community gave the go-ahead for: the 10% $IMD buy-and-burn moves to IMD's own POOL4 pool (ETH/IMD 1%, CappedBurnHook), so our buybacks pay IMD's fee into POOL4 and count toward its burn; NFT sale proceeds become protocol-owned IMD6900/IMD liquidity instead of being burned; treasury NFTs can be kept off the market or relisted higher without waiting 48h; a protocol arbitrage vault keeps the Ethereum pools and Robinhood Chain in line.\n- Before the batch is queued we want an independent review. Holders will read your report.\n\nSOURCE AND BUILD\nThe repository at the given commit. Foundry 1.x, solc 0.8.30 via-IR (foundry.toml); `npm ci` for @layerzerolabs. Fork tests need MAINNET_RPC_URL (ROBINHOOD_RPC_URL for the Robinhood suite). The repository's first commit is the deployed code (verified on etherscan.io); `git diff HEAD~1` is the whole change.\n\nIN SCOPE\n1. src/strategies/BaseStrategy.sol, NFTStrategy.sol, IMDSeatStrategy.sol: the new implementation for the live UUPS proxy 0x0000198C940D8cD70Cb9ACeC5E3af8216ac57d2F (current implementation 0x16d3f65b708883df042d98e1c7a49b32a33e2a14). VERSION 2 adds: a listing manager (setListing, setHoldNewBuys; never below each NFT's floor, cost x multiplier); trusted pool hooks (setPoolHook, _isHook); a share of NFT sale proceeds sent to such a hook (setSaleProceeds; the call is wrapped in try and falls back to the buy-and-burn); processTokenTwap's 0.5% to the NFT pot instead of the caller; a settable TWAP chunk (setTwapIncrement, 0.01-1 ETH); and the transfer gate now spends the hook's transient allowance before the distributor check. New storage is appended at slots 116-119.\n2. src/pair/IMDPairHook.sol: a new hook for an IMD6900/IMD pool (fee 0, tick spacing 60, full range, liquidity only from the hook, owned by the timelock after opening). It takes sale proceeds as ETH, buys IMD6900 on the launch pool and IMD on the launcher's IMD pool (at most one TWAP chunk per add) and adds liquidity; charges the launch pool's fee on every trade's output and keeps it as liquidity; has an owner-set fee exemption; the timelock can withdraw all its liquidity.\n3. src/arb/ArbVaultV2.sol: an arbitrage vault. A keeper runs exact-input routes through owner-allowlisted pools under per-token per-call and daily limits and bridges IMD6900 to its Robinhood peer over LayerZero; profit only to the owner-set receiver (the NFT pot).\n4. proposals/imd6900-eth.sh: the 9-call Ethereum timelock batch (rename x2, $IMD buy-and-burn to POOL4, upgrade, listing manager, vault as distributor, trust the pair hook, all sale proceeds to it, TWAP chunk 0.4 ETH) and the deploy and pool-opening steps. proposals/imd6900-rh.sh: the Robinhood vault after the Robinhood cutover.\nOut of scope: the Robinhood perps/cutover branch, the website, the bots.\n\nLIVE ADDRESSES (Ethereum mainnet)\nTimelock 0xBd3ed9F4AbD9946cA6F59C8F13A3EbebDE1EA29D (48h; the deployer EOA 0x35dA9C0303507ddf708E87F2568EdDf12c47a059 is its only proposer, executor and canceller). Launcher 0x1216eDc56A93CC8f7bE67E1cBaD264AB2803FCff. Launch pool hook 0xA16026A28aA581AA96713d20C608Da7F8db86444 (not upgradeable; fee 87% NFT pot / 10% $IMD buy-and-burn / 3% fee address). LayerZero adapter 0x6BDca0523530D4B1Cc2e7e6043ce4c5adfC56C51. PoolManager 0x000000000004444c5dc75cB358380D2e3dE08A90. $IMD 0xD34a99Bc0f67aE1bbd63C660e6d0b0dd03E263B7. POOL4 hook 0xc6C965Bd164c483e87d0B550671798e9A3602840. identity.md collection 0x0000eC93127BAA929E58E97dd0095A2BFb38ec1D.\n\nALREADY KNOWN (verify, don't just repeat)\nInternal review docs/audit-imd6900-v2-2026-09-27.md (A-01 capped adds, A-02 vault ETH limits, A-04 exact settlement: fixed; A-09 single-key governance: open) and the tests in test/AuditV2.fork.t.sol and test/RedTeamV2.fork.t.sol. The same assistant wrote much of the code and that review, which is why we ask you.\n\nFOCUS\n- Any path that moves IMD6900 through the PoolManager without paying the fee: leftover transient allowance, netted swaps, distributors, exempt callers, trusted pool hooks.\n- Upgrade safety: storage layout against the live implementation, initializers, anything that changes holders' balances or the treasury's state when the batch executes.\n- Can sale proceeds, the NFT pot, the pair's liquidity, the vault's funds or the treasury NFTs be stolen, frozen or sold below the floor? What can each role (timelock, deployer, listing manager, keeper, anyone) do?\n- MEV: sandwiching processTokenTwap, addSaleProceeds, openPool and the launcher's buy-and-burn on POOL4 (about 22 ETH deep).\n- Liveness: anything that can stall processTokenTwap, buyTargetNFT, sellTargetNFT or trading.\n- The batch: calldata, ordering, and anything that breaks the system once executed.\n\nWHAT TO DELIVER\n1. A plain-language summary for holders: what changes, what could go wrong, and whether the batch is safe to queue.\n2. A findings table: ID, severity (Critical/High/Medium/Low/Info), title, file:line.\n3. Per finding: description, impact, a reproducing Foundry test on a mainnet fork (or exact steps), and the fix.\n4. The checks that found nothing, and how you ran them.\nNo price predictions and no investment advice.","parentJobId":null,"planHash":"90261b39b634bf7ac0aca5b70b8fd244db2388d7b155479ffedd0f058d1c4eac","previousHash":"0000000000000000000000000000000000000000000000000000000000000000","projectId":"1405b728-d34f-45d3-844f-cde77275cd8f","publication":{"commit":null,"deliveredAt":null,"repoUrl":null},"receiptIdentity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"registry":"0xb6d0a187b050fa5bb0b87033a203f37becf4a775","research":[],"schema":"identitymd-work-v1","signals":[],"site":null,"snapshotHash":"fba5aba3882d6860a8365af6cf218417c97388a38477672a33e9fb724c40ef2c","state":"blocked","submissions":[{"artifacts":[],"attempt":3,"bundleHash":null,"device":"bb0a3bf63233e5e5","findings":[],"hash":"49d75ecb0f993be0e0b9e3f48726b145d6df6f70e91f315423909cc55223f59c","nodeId":"ca415392-2aa5-454b-973e-d8886a66c6f0","outcome":"failed","summary":"This content was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. If you’re doing authorized security work that requires more cyber permissive safeguards, apply for Daybreak access via https://platform.openai.com/settings/organization/status-and-access before retrying.","treeHash":null,"usage":{"cachedInputTokens":0,"inputTokens":0,"model":null,"outputTokens":0,"runtime":"codex","turns":0,"wallClockMs":28468}},{"artifacts":[],"attempt":2,"bundleHash":null,"device":"35c52a5b502e847c","findings":[],"hash":"cfaf8c438b7e0dd79d2541dec3ccc2e62e0d67e3bd544bd32eeacaa0546895c7","nodeId":"ca415392-2aa5-454b-973e-d8886a66c6f0","outcome":"failed","summary":"This content was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. If you’re doing authorized security work that requires more cyber permissive safeguards, apply for Daybreak access via https://platform.openai.com/settings/organization/status-and-access before retrying.","treeHash":null,"usage":{"cachedInputTokens":0,"inputTokens":0,"model":null,"outputTokens":0,"runtime":"codex","turns":1,"wallClockMs":55922}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"c4f696e22e7a36f7","findings":[],"hash":"fe71bcefc64b44b75a1ec914b53ae16b0c8eb5f6b356ada073d0f08a5ad58d2f","nodeId":"ca415392-2aa5-454b-973e-d8886a66c6f0","outcome":"failed","summary":"This content was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. If you’re doing authorized security work that requires more cyber permissive safeguards, apply for Daybreak access via https://platform.openai.com/settings/organization/status-and-access before retrying.","treeHash":null,"usage":{"cachedInputTokens":0,"inputTokens":0,"model":null,"outputTokens":0,"runtime":"codex","turns":1,"wallClockMs":16680}}],"verification":[]}