{"assessments":[],"deployments":[],"fuzz":[],"identity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"interpretation":"Records acceptance and evidence. Neither completion nor an AI assessment establishes correctness, safety, or independent review.","jobId":"69a15e8f-defa-40d1-819e-1394cc27e660","kind":"shape:chain","nodes":[{"acceptedSubmissionHash":"828947b53d2ec86fb0d70c1888e39b323a0c3cdb6b4acfad5e48dbaa4cbb349c","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_economics","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"9d4b85b491f7234be46e5d37201f2cb8f25529e8da636575bfcc5f246e3146a0","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_flow","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"c6ebc94d28c2d3817aff72fa421b319035128967af2aafc375a9a3c5680df0fe","dependsOn":["build_contract_project","write_foundry_tests","manifest","audit_math","audit_permissions","audit_economics","audit_flow"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"3014f1ea5961918ca059453a484bf4c8bcbbfc2248dbe31d94ac7c5cdf8f50bd","skillId":"audit-judge","tools":[]},"key":"audit_judge","kind":"code","role":"review","skillHash":"3014f1ea5961918ca059453a484bf4c8bcbbfc2248dbe31d94ac7c5cdf8f50bd","skillId":"audit-judge","state":"accepted"},{"acceptedSubmissionHash":"0fa9f4c94855d66f98e31c3ea9ee2ece190d91f83a33fa9372692beef636e0e0","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_math","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"d89ea1eeaf1ae993037b2910df5e93b868e596e082e00661e9b16488fc2f858f","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_permissions","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"88240e634acd8fc175c3ee5d4e2684bc1d877c6607232c3be0b29ebb385b2d5e","dependsOn":[],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"b6503de65ad02f845827887c23da4c3b56ccc5df7a459db263bae6e549d92f7f","skillId":"build-contract-project","tools":[]},"key":"build_contract_project","kind":"code","role":"implement","skillHash":"b6503de65ad02f845827887c23da4c3b56ccc5df7a459db263bae6e549d92f7f","skillId":"build-contract-project","state":"accepted"},{"acceptedSubmissionHash":"d515024048bf5e3795956f88389cf0ddae236efa1a956d35fcfa0409cb2a38de","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"tools":[]},"key":"manifest","kind":"code","role":"integrate","skillHash":null,"skillId":null,"state":"accepted"},{"acceptedSubmissionHash":"8c26e2685a7fa1e6d180179abf3dbf1e6f22e1b9323145caa6c145fbd092f0ad","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"73431852439ad3a343f3d2b7db1c43cd363b9f48f9bb51497374a0cf6d50b223","skillId":"write-foundry-tests","tools":[]},"key":"write_foundry_tests","kind":"code","role":"tests","skillHash":"73431852439ad3a343f3d2b7db1c43cd363b9f48f9bb51497374a0cf6d50b223","skillId":"write-foundry-tests","state":"accepted"}],"objective":"A custom token: imdUSD (IMDUSD).\nToken name: imdUSD\nToken symbol: IMDUSD\nToken supply: 1,000,000,000 with 18 decimals, all minted once to the deployer in the constructor.","parentJobId":null,"planHash":"91049498082a7497790bff8b6813bbc15922c0a44067ab2967a89ac3079952d4","previousHash":"0000000000000000000000000000000000000000000000000000000000000000","projectId":"69a15e8f-defa-40d1-819e-1394cc27e660","publication":{"commit":null,"deliveredAt":null,"repoUrl":"https://github.com/identity-md-launches/launch-882-imdusd"},"receiptIdentity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"registry":"0xb6d0a187b050fa5bb0b87033a203f37becf4a775","research":[],"schema":"identitymd-work-v1","signals":[{"agentId":"52287","feedbackHash":"8b951963c7a40fffa858ece97bc23e1e3ffdfbf5fdfdc9c15241162f711d654e","nodeKey":"audit_economics","submissionHash":"828947b53d2ec86fb0d70c1888e39b323a0c3cdb6b4acfad5e48dbaa4cbb349c","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"52286","feedbackHash":"8f634f02a3fbfb0fa4369ea7f4a164fa4ee065fcbce852ff4267ef4bd805ecf6","nodeKey":"audit_flow","submissionHash":"9d4b85b491f7234be46e5d37201f2cb8f25529e8da636575bfcc5f246e3146a0","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51566","feedbackHash":"10543e95c1e67fad07b5b1627729fd34cbdca8eae70a35acedb1f41248551e10","nodeKey":"audit_judge","submissionHash":"c6ebc94d28c2d3817aff72fa421b319035128967af2aafc375a9a3c5680df0fe","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51251","feedbackHash":"29440677fbc3409827c08c0bf2432a4145ae7e3cf9747f7ef4a3273bcff3d9a9","nodeKey":"audit_math","submissionHash":"0fa9f4c94855d66f98e31c3ea9ee2ece190d91f83a33fa9372692beef636e0e0","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51139","feedbackHash":"23e34f5144b8794ebf559fb367dfd815fc8145788600bb88753cafd0a43f76ea","nodeKey":"audit_permissions","submissionHash":"d89ea1eeaf1ae993037b2910df5e93b868e596e082e00661e9b16488fc2f858f","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51416","feedbackHash":"e1663c1e39e1992a601cae21bccc7c00abb58593e3ef3fff89bfdce810d9fa4c","nodeKey":"build_contract_project","submissionHash":"88240e634acd8fc175c3ee5d4e2684bc1d877c6607232c3be0b29ebb385b2d5e","tag1":"verification:checks","tag2":"acceptance-v2","value":1},{"agentId":"50975","feedbackHash":"c76943fc0cfbc3d46a0a2af71c7a9f9fa8e863e8875c8573ad17e7b7def3f1f9","nodeKey":"manifest","submissionHash":"d515024048bf5e3795956f88389cf0ddae236efa1a956d35fcfa0409cb2a38de","tag1":"verification:checks","tag2":"acceptance-v2","value":1},{"agentId":"50960","feedbackHash":"c8d18acb077e6cac8073c3d7af7dd3d5fd82f16b024d5a57b16d7e35c6964f9e","nodeKey":"write_foundry_tests","submissionHash":"8c26e2685a7fa1e6d180179abf3dbf1e6f22e1b9323145caa6c145fbd092f0ad","tag1":"verification:checks","tag2":"acceptance-v2","value":1}],"site":null,"snapshotHash":"5134fdfb91e9e519dd9c69083bc9f59e38fff4d97ae5d1f22754cff7123b56f9","state":"completed","submissions":[{"artifacts":[],"attempt":1,"bundleHash":null,"device":"723b11f958c65250","findings":[],"hash":"0fa9f4c94855d66f98e31c3ea9ee2ece190d91f83a33fa9372692beef636e0e0","nodeId":"dc26ab5e-5520-4181-a43e-a0c639b56426","outcome":"completed","summary":"The findings file is in place at the repository root, excluded from git by the repository's own exclude rules as the harness intends, and no tracked file changed. The review is complete.\n\n**Result: no defects in the Math Precision, Boundary or Numerical Gap areas.** The findings file holds an empty list and nine coverage rows, all `holds`.\n\n**What the token is.** `src/Token.sol` is a 15-line wrapper over the vendored OpenZeppelin v5.5.0 ERC20. Its only logic is a constructor that mints a compile-time constant to the deployer. The four vendored OpenZeppelin files match upstream text, and the build and the existing 34 tests pass offline.\n\n**What I checked, with executed evidence.** I ran a scratch suite of nine probes (deleted afterward, as the task allows) covering every edge the three guides name that the code can reach:\n\n- **Supply constant.** The literal evaluates to exactly 10^27 and equals the manifest string and 1,000,000,000 times 10 to the `decimals()` power. The aderyn large-literal line is a style note, not a defect.\n- **Overflow and ordering.** `transfer` with `type(uint256).max` and with supply plus one both revert with the exact balance numbers before any unchecked arithmetic runs.\n- **Allowance sentinel.** An allowance of max minus one decrements normally; only exactly max is treated as infinite, and infinite allowance still cannot overdraw a balance.\n- **Exact-boundary and self-transfer paths.** Full-balance transfer, full-balance self-transfer and self-transferFrom leave balances and supply unchanged with the allowance consumed as intended.\n- **Zero-value fast paths.** Zero-value calls still hit every zero-address revert, so no early return bypasses a guard.\n- **Launch share arithmetic.** The swarm's ten percent is exactly 10^26 with no remainder, and the pool share is exact for every poolBps from 1 to 9000, checked exhaustively. No intermediate product approaches the uint256 limit.\n- **Conservation.** 1,024 fuzz runs of delegated transfers and a 1-wei hop loop keep the sum of balances equal to supply, on top of the project's 8,192-call invariant run.\n\n**What is outside my area and not asserted here.** I did not run the protected Uniswap v4 harness, since it needs the network's launch contracts and resolved deployment parameters. The token has no formulas, external calls or payable paths, so the Numerical Gap seams and the Boundary agent's external-call questions have nothing to attach to, which I recorded as coverage rows rather than silence.","treeHash":null,"usage":{"cachedInputTokens":782559,"inputTokens":322,"model":"claude-fable-5-1","outputTokens":11581,"runtime":"claude","turns":18,"wallClockMs":192848}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"99c6d0bcc495ad61","findings":[],"hash":"828947b53d2ec86fb0d70c1888e39b323a0c3cdb6b4acfad5e48dbaa4cbb349c","nodeId":"94b3900a-8198-432d-b4b4-3c0c6b0cd5ff","outcome":"completed","summary":"Review complete. `.imd-findings.json` is written at the repository root (valid JSON, 0 findings, 9 coverage rows), the scratch test is removed, and the tree is otherwise untouched.\n\n## Result: no substantiated defects in the Economic Security / Invariant / Flow Gap area\n\n**What the code is.** `src/Token.sol` is a 15-line contract: unmodified OpenZeppelin v5.5.0 `ERC20`, name `imdUSD`, symbol `IMDUSD`, 18 decimals, and a single constructor `_mint(msg.sender, 1_000_000_000 * 10**18)`. No constructor arguments, no owner, no hooks, no external calls, no exemptions.\n\n**What I checked and how.**\n- **Dependency integrity** — cloned the upstream `v5.5.0` tag and diffed all five vendored files: byte-identical except import ordering and the `draft-IERC6093.sol` → `IERC6093.sol` rename (header comment only). No silent edit to `_update`, `_approve` or `_spendAllowance`.\n- **Launch-flow economics (Flow Gap seams 1–3)** — a scratch Foundry test deployed the token through a CREATE2 factory probe and drove every flow the protected harness depends on: 10% to the distributor, `poolBps` pulled by a PoolManager-style `transferFrom`, remainder to the requester, claim out of the distributor, buy (manager push) and sell (trader approve + manager pull). Every amount arrived exactly, `totalSupply` stayed `1e27`, and the sum of all balances equalled supply at every step. A fuzz round-trip over `0..1e27` returned the exact amount.\n- **Invariants** — supply can't grow: 14 common mint/burn/owner/upgrade/pause/freeze selectors called from both a stranger and the factory all revert with no state change; direct Ether payment reverts. Allowance accounting: finite decreases exactly, `type(uint256).max` is unlimited, insufficient allowance/balance reverts atomically.\n- **Economic Security** — no oracle, no fee, no rebase, no sentinel-address branch, no shared cap, no ERC the code claims beyond ERC-20 itself; nothing for an actor with unlimited capital to lean on. The standard ERC-20 approve race is inherent to the interface, documented in the README, and falls under the guide's Do-Not-Report list.\n- **Static-analysis leads** — Slither: none. Aderyn's `large-numeric-literal` at `src/Token.sol:10` is `10^27`, exactly the manifest supply; style, not a defect.\n- **Outside my area** — `script/Deploy.s.sol` mints to the broadcaster rather than the factory; the README explicitly states this is not the launch path, so it's a documented trust assumption, not a finding.\n\n**Not reached.** The pinned protected harness (`Token.protected.t.sol`) imports `v4-core` and the network's `LaunchLiquidity`, which are not vendored here, so I could not run a live PoolManager seed/swap; my scratch test reproduces the token-side transfers that the harness exercises, which for a token with no transfer logic is the whole surface. Coverage rows record this.","treeHash":null,"usage":{"cachedInputTokens":838545,"inputTokens":401,"model":"claude-fable-5-1","outputTokens":11313,"runtime":"claude","turns":15,"wallClockMs":170233}},{"artifacts":[],"attempt":1,"bundleHash":"1b5deb460a740f843bb05b019b7a32c526fa91338a26bf883a1ec0093f78168a","device":"f3c310dfe443399d","findings":[],"hash":"88240e634acd8fc175c3ee5d4e2684bc1d877c6607232c3be0b29ebb385b2d5e","nodeId":"0dd80924-cdb2-4011-9848-59aad4f6c0fb","outcome":"completed","summary":"Implemented imdUSD (IMDUSD): 1 billion tokens with 18 decimals, minted once to the deployer.\n\nIncluded vendored dependencies, deployment script, tests, and operational documentation.\n\nValidation passed: build, formatting, all 34 tests, expanded fuzz testing, and offline deployment simulation. No transactions broadcast. Full network launch integration remains for the external verifier.","treeHash":"db88d2f0d14d90126f9f9c56fcf75a47494681c1","usage":{"cachedInputTokens":355072,"inputTokens":50712,"model":"gpt-6-astra","outputTokens":13439,"runtime":"codex","turns":5,"wallClockMs":379416}},{"artifacts":[],"attempt":1,"bundleHash":"a5d1e905f4abe74bb00afb1f6b53629b22cd6039992dc7a5ea7b89786c2fb8b4","device":"e4a4ecf9fefd4a46","findings":[],"hash":"8c26e2685a7fa1e6d180179abf3dbf1e6f22e1b9323145caa6c145fbd092f0ad","nodeId":"75ccd4c8-fec1-467f-a80d-2ff76e200b07","outcome":"completed","summary":"Expanded the existing tests with failure paths, allowance edge cases, and three-actor stateful invariants.\n\n`forge build` and `forge test` pass: 44 tests, 1,000 runs per fuzz test, and 16,384 invariant calls.\n\nNo implementation defects found. Only two files under `test/` changed.","treeHash":"9583f624a647a533861a8e38b623e551128f33d5","usage":{"cachedInputTokens":688768,"inputTokens":85425,"model":"gpt-6-astra","outputTokens":9980,"runtime":"codex","turns":6,"wallClockMs":308835}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"fcb71e606c933181","findings":[],"hash":"9d4b85b491f7234be46e5d37201f2cb8f25529e8da636575bfcc5f246e3146a0","nodeId":"7c7da547-8577-499c-9f88-08953066db85","outcome":"completed","summary":"The review is complete. No defects were found, and the findings file records that with a full coverage record.\n\n**Outcome:** `.imd-findings.json` holds an empty findings list and seven coverage rows, one for each of the three listed entry points plus four invariants I checked. No repository files were changed.\n\n**What I checked, by area**\n\n- **Execution Trace.** Traced approve, transfer and transferFrom from entry to final storage through the unchanged OpenZeppelin paths. Zero recipient, zero spender, insufficient balance and insufficient allowance all revert with ERC-6093 errors and leave state intact. A finite allowance is decremented before the balance check, so a failing delegated transfer rolls both back. The unlimited allowance never decreases. There are no external calls, callbacks, sentinel paths or fee deductions, so no value leak or stale read is possible.\n- **Periphery.** Fetched the five OpenZeppelin files from upstream and diffed them byte for byte. All match upstream master. The only difference from the v5.5.0 tag is the upstream rename of the draft IERC6093 file, which does not change any code. The vendor claim of \"unchanged\" holds.\n- **First Principles.** The constructor mints exactly 10^27 base units to the deploying caller, with no arguments and no second mint path. The compiled ABI exposes only the standard ERC-20 surface plus the supply getter. The 1815-byte runtime contains no DELEGATECALL, CALLCODE or SELFDESTRUCT, and there is no receive or fallback. The launch flows the protected harness exercises all move the exact amount.\n\n**Verification run**\n\n| Check | Result |\n| --- | --- |\n| forge build, offline | passed |\n| forge test, 34 tests, default seed | passed |\n| forge test, seed 0x20261007, 2048 fuzz runs | passed |\n| forge fmt --check | passed |\n| Invariant suite | 8192 handler calls, 0 reverts |\n\n**Leads examined and not reported.** The approve replacement race is standard ERC-20 behaviour and documented in the README. A stranger with zero allowance can call transferFrom for zero value and emit a zero-value Transfer event, which is also standard OpenZeppelin behaviour. The aderyn large-literal note resolves to exactly 10^27, as the tests assert. None of these is a defect in this code.\n\n**Not covered.** Live PoolManager seeding and swaps require the network's launch contracts and resolved environment, which this repository cannot run offline. The repository's own factory fixture only exercises the token-side transfer legs.","treeHash":null,"usage":{"cachedInputTokens":619913,"inputTokens":290,"model":"claude-fable-5-1","outputTokens":10381,"runtime":"claude","turns":18,"wallClockMs":155218}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"d0653dc91b6e2259","findings":[{"citation":"resolved","description":"Reproduced from the audit_permissions specialist (sole reporter; no duplicate across areas). Token.transferFrom(from, to, value) binds `from` to the caller only through _spendAllowance, whose check `currentAllowance < value` cannot fail when value == 0. Any address can therefore call transferFrom(holder, anyone, 0) with zero allowance; it returns true and the token emits Transfer(holder, anyone, 0). No balance, allowance or supply changes, so there is no loss of funds and nothing in the launch flows (factory -> distributor, pool seed, swaps, claims) is affected. The practical abuse is event-history poisoning: an attacker plants Transfer events that appear to originate from a holder, so explorers and wallets show a look-alike counterparty. This is the unchanged OpenZeppelin v5 ERC20 behaviour inherited by src/Token.sol and is permitted by ERC-20 (zero-value transfers must be treated as normal transfers). Recorded as a documented trust assumption, not a defect requiring a fix. If the requester wants to close it, the minimal change is an override of transferFrom in src/Token.sol that requires msg.sender == from or allowance(from, msg.sender) > 0 when value == 0; launch flows never send zero-value transferFrom, so they are unaffected.","line":297,"path":"lib/openzeppelin-contracts/contracts/token/ERC20/ERC20.sol","reproduction":"State: Token deployed by DEPLOYER; DEPLOYER calls transfer(VICTIM=0x1234, 1000e18). STRANGER=0xBAD holds nothing and allowance(VICTIM, STRANGER) == 0. Call: vm.prank(STRANGER); token.transferFrom(VICTIM, STRANGER, 0). Expected (if `from` were bound to the caller): revert ERC20InsufficientAllowance(STRANGER, 0, 0). Actual: returns true and emits Transfer(0x1234, 0xBAD, 0) from the token (checked with vm.expectEmit(true,true,true,true,address(token))); balanceOf(VICTIM) stays 1000e18, allowance(VICTIM, STRANGER) stays 0. Control: the same call with value 1 reverts ERC20InsufficientAllowance(STRANGER, 0, 1). Both were run in a scratch Foundry test on this tree (test/scratch/Judge.t.sol, 7 passed) and the project's own test_zeroTransferFromNeedsNoAllowance asserts the same behaviour.","severity":"info","snippet":"            if (currentAllowance < value) {","title":"Zero-value transferFrom needs no allowance, so any caller can emit a Transfer event naming any holder as sender (address-poisoning vector; standard ERC-20 behaviour, not blocking)"}],"hash":"c6ebc94d28c2d3817aff72fa421b319035128967af2aafc375a9a3c5680df0fe","nodeId":"65e6406e-dfbc-4d55-800a-7522dbe22c83","outcome":"completed","summary":"The review is complete and the findings file is written. Nothing further is needed.\n\n**Outcome:** the token is clean. The findings file at `.imd-findings.json` carries one info-level note and a full coverage record. No blocking defects, so nothing reopens the author's work.\n\n**What I verified against the code**\n\n- `src/Token.sol` is an unmodified OpenZeppelin v5 ERC20 with a single constructor mint to msg.sender. The minted amount equals the manifest's totalSupply, decimals are 18, and name and symbol match the brief.\n- The ABI exposes only approve, transfer and transferFrom. There is no owner, mint, burn, pause, blacklist or upgrade path.\n- The vendored OpenZeppelin files are ordinary committed files, not submodules, and their transfer, allowance and update logic matches upstream line by line.\n- A scratch opcode scan of the deployed runtime found no DELEGATECALL, CALLCODE or SELFDESTRUCT.\n- The full project suite passes, including the invariant run that holds total supply and the balance sum constant.\n\n**Specialist findings judged**\n\n- The audit_permissions note about zero-value transferFrom reproduced exactly as described. With zero allowance, a stranger can call transferFrom on any holder for value zero and the token emits a Transfer event naming that holder. Balances and allowances do not change. This is standard ERC-20 behaviour and I kept it at info as a documented trust assumption, not a defect.\n- The other three specialists and the independent tester reported nothing, which agrees with my own pass.\n- The aderyn large-numeric-literal lead is a style note; the literal is correct.\n\n**Coverage:** all three listed entry points are answered, two as holds and transferFrom pointing at the info note, plus three invariant rows for supply, opcodes and dependency integrity. The scratch test directory was removed, so the only file I left behind is the findings JSON.","treeHash":null,"usage":{"cachedInputTokens":552095,"inputTokens":386,"model":"claude-fable-5-1","outputTokens":8686,"runtime":"claude","turns":13,"wallClockMs":136787}},{"artifacts":[],"attempt":1,"bundleHash":"1188b130a24825af4f1678800f17928ba4d4beaac20922267d19d4944da9adb7","device":"377843575071cdb1","findings":[],"hash":"d515024048bf5e3795956f88389cf0ddae236efa1a956d35fcfa0409cb2a38de","nodeId":"64dba37f-72cb-472c-b79a-0e55fa910a87","outcome":"completed","summary":"Created [launch.json](/home/worker/.identitymd/work/69a15e8f-defa-40d1-819e-1394cc27e660/64dba37f-72cb-472c-b79a-0e55fa910a87/launch.json) with the exact token supply, constructor arguments, economics, and paired currency.\n\nValidation passed against the supplied schema and compiled constructor ABI. `forge build` succeeded; `forge test` passed all 34 tests.\n\nOnly `launch.json` is changed for submission.","treeHash":"eb5db94a098e5527f60d35de7836331ff5a5e5f3","usage":{"cachedInputTokens":190976,"inputTokens":21336,"model":"gpt-6-astra","outputTokens":2957,"runtime":"codex","turns":3,"wallClockMs":92760}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"8d26cb1a4eaeb75a","findings":[{"citation":"resolved","description":"Asymmetry between the two balance-moving entry points. Token.transfer(to, value) always binds `from` to msg.sender. Token.transferFrom(from, to, value) binds `from` only through _spendAllowance, and the check at line 297 is `currentAllowance < value`, which never fails when value == 0. Any address can therefore call transferFrom(victim, anyone, 0) with zero allowance; it succeeds, returns true and emits Transfer(victim, anyone, 0) from the token. No balance or allowance changes, so there is no on-chain loss. The practical abuse is address poisoning: an attacker plants Transfer events that appear to come from a holder, so wallet and explorer history shows a look-alike counterparty the holder may later copy-paste. This is the stock OpenZeppelin v5 ERC20 behaviour inherited unchanged by src/Token.sol, it matches ERC-20 (zero-value transfers are allowed), and the project's own test test_zeroTransferFromNeedsNoAllowance asserts it. Reported as a documented trust assumption, not a blocking defect. If the requester wants to close it, the minimal change is an override of transferFrom in src/Token.sol that reverts, or requires msg.sender == from, when value == 0 and allowance(from, msg.sender) == 0; the launch flows (factory -> distributor, seed, swaps) never send zero-value transferFrom, so they are unaffected.","line":297,"path":"lib/openzeppelin-contracts/contracts/token/ERC20/ERC20.sol","reproduction":"State: Token deployed, deployer transfers 1000e18 to VICTIM=0x1234; STRANGER=0xBAD holds nothing and has allowance(VICTIM, STRANGER) == 0. Call: vm.prank(STRANGER); token.transferFrom(VICTIM, STRANGER, 0). Expected (if `from` were bound): revert ERC20InsufficientAllowance(STRANGER, 0, 0) or require msg.sender == from. Actual: returns true and emits Transfer(0x1234, 0xBAD, 0) from the token; balanceOf(VICTIM) stays 1000e18, allowance stays 0. Confirmed with vm.expectEmit in a scratch Foundry test on this tree (5 passed). With value 1 the same call reverts ERC20InsufficientAllowance(STRANGER, 0, 1), showing the binding exists only for nonzero values.","severity":"info","snippet":"            if (currentAllowance < value) {","title":"Zero-value transferFrom needs no allowance, so any caller can emit a Transfer event from any holder (address-poisoning vector)"}],"hash":"d89ea1eeaf1ae993037b2910df5e93b868e596e082e00661e9b16488fc2f858f","nodeId":"521af813-2797-4b7c-b30a-71ecd98bb8a0","outcome":"completed","summary":"The findings file exists at the repository root and is excluded from git by the harness's own exclude list, which is expected. The working tree is otherwise clean, with no scratch files left behind.\n\n**Outcome: no blocking defects in the permission model.** The review covered the Access Control, Trust Gap and Asymmetry guides against `src/Token.sol` and the vendored ERC20 it inherits.\n\n**What I checked**\n\n- **Permission map.** The compiled ABI exposes exactly three state-changing functions and no fallback, receive, owner, mint, burn, pause, blacklist, freeze, seize, initialize or upgrade selector. Unknown calldata and direct ETH revert.\n- **Inconsistent guards.** Balances are written only through `transfer` (sender bound to caller) and `transferFrom` (bound by allowance). Allowances are written only by `approve` on the caller's own row and decremented by `_spendAllowance`. No weaker writer exists.\n- **Constructor and temporal story.** The one-time mint is exactly one billion tokens at 18 decimals, to the immediate creator. A scratch test confirmed a CREATE2 factory receives everything and its caller nothing. The aderyn large-literal lead is style only.\n- **Trust gap and asymmetry.** There is no privileged actor and no economic formula, so no seam exists between them. Transfers move exactly the stated value with no caller-class branch, so the launch flows cannot arrive short.\n- **Vendored library.** The ERC20 file reads as stock OpenZeppelin v5 with no logic changes and no override of the update hook. The existing 34 tests, including the 128 by 64 invariant run, pass offline.\n\n**One info-level note recorded.** A zero-value `transferFrom` needs no allowance, so any caller can emit a Transfer event that appears to come from any holder. No balance changes. This is standard ERC-20 behaviour, the project's own tests assert it, and it is reported as a documented trust assumption with an optional fix, not a blocking defect.\n\n**Coverage record** has eight rows: the three listed entry points plus the constructor and four invariants. All hold except `transferFrom`, which points at the info note.\n\n**Not reached.** The pinned protected harness needs Uniswap v4 core, which is not vendored, so the live PoolManager seed and swap were not executed here. The token-side legs of those flows were traced instead.","treeHash":null,"usage":{"cachedInputTokens":729932,"inputTokens":322,"model":"claude-fable-5-1","outputTokens":15030,"runtime":"claude","turns":31,"wallClockMs":222113}}],"verification":[{"checks":[{"durationMs":1178,"exitCode":0,"name":"build","output":"Compiling 30 files with Solc 0.8.26\nSolc 0.8.26 finished in 1.08s\nCompiler run successful!\n","passed":true},{"durationMs":533,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 6 tests for test/Deploy.t.sol:DeployTest\n[PASS] test_localDeploymentWithExplicitChain() (gas: 540175)\n[PASS] test_localDeploymentWithZeroExpectation() (gas: 540158)\n[PASS] test_rejectsMismatchedChain() (gas: 30760)\n[PASS] test_rejectsUnsupportedChain() (gas: 30550)\n[PASS] test_sepoliaDeploymentWithExplicitChain() (gas: 540113)\n[PASS] test_sepoliaRequiresExplicitExpectation() (gas: 30759)\nSuite result: ok. 6 passed; 0 failed; 0 skipped; finished in 6.58ms (1.78ms CPU time)\n\nRan 27 tests for test/Token.t.sol:TokenTest\n[PASS] testFuzz_allowanceCannotBeExceeded(uint256) (runs: 256, μ: 100702, ~: 100900)\n[PASS] testFuzz_delegatedTransferConservesSupply(uint256,uint256) (runs: 256, μ: 138235, ~: 139796)\n[PASS] testFuzz_overdrawReverts(uint256) (runs: 256, μ: 53301, ~: 53647)\n[PASS] testFuzz_transferConservesSupply(address,uint256) (runs: 256, μ: 78191, ~: 78564)\n[PASS] test_approvalEmitsEventAndCanBeReplacedOrRevoked() (gas: 168142)\n[PASS] test_approvalRejectsZeroSpender() (gas: 30550)\n[PASS] test_constructorEmitsFullMint() (gas: 5562)\n[PASS] test_directEtherPaymentReverts() (gas: 36092)\n[PASS] test_emptyHolderCannotTransferPositiveAmount() (gas: 37638)\n[PASS] test_factoryReceivesSupplyAndLaunchTransfersArriveWhole() (gas: 599274)\n[PASS] test_fullBalanceTransfer() (gas: 62700)\n[PASS] test_infiniteAllowanceRemainsUnchanged() (gas: 120639)\n[PASS] test_insufficientAllowanceRevertsWithoutChangingState() (gas: 100323)\n[PASS] test_insufficientBalanceRollsBackAllowanceSpend() (gas: 98468)\n[PASS] test_metadataAndEntireInitialSupply() (gas: 81092)\n[PASS] test_noMintBurnFreezeOrUpgradeEntryPoints() (gas: 1062817)\n[PASS] test_runtimeHasNoForbiddenOpcodes() (gas: 473987)\n[PASS] test_selfTransferPreservesBalance() (gas: 42818)\n[PASS] test_transferEmitsEventAndMovesExactAmount() (gas: 79989)\n[PASS] test_transferFromConsumesFiniteAllowanceAndEmitsTransfer() (gas: 133725)\n[PASS] test_transferFromRejectsZeroSender() (gas: 33223)\n[PASS] test_transferFromToSelfConsumesAllowanceWithoutChangingBalance() (gas: 94687)\n[PASS] test_transferFromZeroRecipientRollsBackAllowanceSpend() (gas: 95709)\n[PASS] test_transferRejectsZeroRecipientEvenForZeroAmount() (gas: 66531)\n[PASS] test_unapprovedCallerCannotMoveHolderFunds() (gas: 97091)\n[PASS] test_zeroTransferFromNeedsNoAllowance() (gas: 51016)\n[PASS] test_zeroValueTransferFromEmptyAccountEmitsEvent() (gas: 49953)\nSuite result: ok. 27 passed; 0 failed; 0 skipped; finished in 9.23ms (37.02ms CPU time)\n\nRan 1 test for test/Token.invariant.t.sol:TokenInvariantTest\n[PASS] invariant_supplyAndBalancesAreConserved() (runs: 128, calls: 8192, reverts: 0)\n\n╭--------------+--------------+-------+---------+----------╮\n| Contract     | Selector     | Calls | Reverts | Discards |\n+==========================================================+\n| TokenHandler | approve      | 2688  | 0       | 0        |\n|--------------+--------------+-------+---------+----------|\n| TokenHandler | transfer     | 2762  | 0       | 0        |\n|--------------+--------------+-------+---------+----------|\n| TokenHandler | transferFrom | 2742  | 0       | 0        |\n╰--------------+--------------+-------+---------+----------╯\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 437.45ms (436.31ms CPU time)\n\nRan 3 test suites in 440.26ms (453.26ms CPU time): 34 tests passed, 0 failed, 0 skipped (34 total tests)\n","passed":true},{"durationMs":36,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"Token.approve(address,uint256)\",\"Token.transfer(address,uint256)\",\"Token.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":3,\"README.md\":108,\"REVIEW.md\":64,\"foundry.toml\":22,\"remappings.txt\":2,\"script/Deploy.s.sol\":29,\"src/Token.sol\":15,\"test/Deploy.t.sol\":65,\"test/Token.invariant.t.sol\":69,\"test/Token.t.sol\":326},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true},{"durationMs":372,"exitCode":0,"name":"slither","output":"slither: no results at low impact or above","passed":true},{"durationMs":248,"exitCode":0,"name":"aderyn","output":"[low] large-numeric-literal at src/Token.sol:10: Large Numeric Literal","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"88240e634acd8fc175c3ee5d4e2684bc1d877c6607232c3be0b29ebb385b2d5e","verifiedTreeHash":"db88d2f0d14d90126f9f9c56fcf75a47494681c1","verifierVersion":"0.1.0+be003835"},{"checks":[{"durationMs":1322,"exitCode":0,"name":"build","output":"Compiling 30 files with Solc 0.8.26\nSolc 0.8.26 finished in 1.22s\nCompiler run successful!\n","passed":true},{"durationMs":3029,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 6 tests for test/Deploy.t.sol:DeployTest\n[PASS] test_localDeploymentWithExplicitChain() (gas: 540175)\n[PASS] test_localDeploymentWithZeroExpectation() (gas: 540158)\n[PASS] test_rejectsMismatchedChain() (gas: 30760)\n[PASS] test_rejectsUnsupportedChain() (gas: 30550)\n[PASS] test_sepoliaDeploymentWithExplicitChain() (gas: 540113)\n[PASS] test_sepoliaRequiresExplicitExpectation() (gas: 30759)\nSuite result: ok. 6 passed; 0 failed; 0 skipped; finished in 599.31µs (1.07ms CPU time)\n\nRan 37 tests for test/Token.t.sol:TokenTest\n[PASS] testFuzz_allowanceCannotBeExceeded(uint256) (runs: 1000, μ: 100775, ~: 100936)\n[PASS] testFuzz_approvalsAreIsolatedByOwnerAndSpender(uint256,uint256) (runs: 1000, μ: 311876, ~: 312558)\n[PASS] testFuzz_delegatedOverdrawIsAtomic(uint256,uint256) (runs: 1000, μ: 174516, ~: 175144)\n[PASS] testFuzz_delegatedTransferConservesSupply(uint256,uint256) (runs: 1000, μ: 138011, ~: 139818)\n[PASS] testFuzz_overdrawReverts(uint256) (runs: 1000, μ: 53374, ~: 53692)\n[PASS] testFuzz_partialSpendsExhaustExactlyOneApproval(uint256,uint256) (runs: 1000, μ: 309303, ~: 311248)\n[PASS] testFuzz_transferConservesSupply(address,uint256) (runs: 1000, μ: 75485, ~: 75723)\n[PASS] test_approvalEmitsEventAndCanBeReplacedOrRevoked() (gas: 168164)\n[PASS] test_approvalRejectsZeroSpender() (gas: 30594)\n[PASS] test_constructorEmitsFullMint() (gas: 5562)\n[PASS] test_directEtherPaymentReverts() (gas: 36114)\n[PASS] test_emptyHolderCannotTransferPositiveAmount() (gas: 37638)\n[PASS] test_factoryReceivesSupplyAndLaunchTransfersArriveWhole() (gas: 599307)\n[PASS] test_fullBalanceTransfer() (gas: 62700)\n[PASS] test_fullSupplyDelegatedTransferCannotReuseAllowanceAfterRoundTrip() (gas: 230368)\n[PASS] test_infiniteAllowanceCanBeReducedAndRevoked() (gas: 314938)\n[PASS] test_infiniteAllowanceRemainsUnchanged() (gas: 120573)\n[PASS] test_insufficientAllowanceRevertsWithoutChangingState() (gas: 100324)\n[PASS] test_insufficientBalanceRollsBackAllowanceSpend() (gas: 98512)\n[PASS] test_largestFiniteAllowanceIsConsumed() (gas: 197708)\n[PASS] test_maximumTransferRevertsWithInfiniteApproval() (gas: 138171)\n[PASS] test_metadataAndEntireInitialSupply() (gas: 81092)\n[PASS] test_noMintBurnFreezeOrUpgradeEntryPoints() (gas: 1062839)\n[PASS] test_oneWeiCanRoundTripWithoutRoundingOrFees() (gas: 123316)\n[PASS] test_runtimeHasNoForbiddenOpcodes() (gas: 474031)\n[PASS] test_selfTransferPreservesBalance() (gas: 42818)\n[PASS] test_transferEmitsEventAndMovesExactAmount() (gas: 80011)\n[PASS] test_transferFromConsumesFiniteAllowanceAndEmitsTransfer() (gas: 133681)\n[PASS] test_transferFromRejectsZeroSender() (gas: 33223)\n[PASS] test_transferFromToSelfConsumesAllowanceWithoutChangingBalance() (gas: 94709)\n[PASS] test_transferFromZeroRecipientRollsBackAllowanceSpend() (gas: 95731)\n[PASS] test_transferRejectsZeroRecipientEvenForZeroAmount() (gas: 66531)\n[PASS] test_unapprovedCallerCannotMoveHolderFunds() (gas: 97202)\n[PASS] test_zeroApprovalStillRejectsZeroSpender() (gas: 42575)\n[PASS] test_zeroCallerCannotTransferOrApprove() (gas: 75156)\n[PASS] test_zeroTransferFromNeedsNoAllowance() (gas: 51060)\n[PASS] test_zeroValueTransferFromEmptyAccountEmitsEvent() (gas: 49975)\nSuite result: ok. 37 passed; 0 failed; 0 skipped; finished in 67.79ms (448.61ms CPU time)\n\nRan 1 test for test/Token.invariant.t.sol:TokenInvariantTest\n[PASS]\nTokenInvariantTest invariants:\n[PASS] invariant_allowancesMatchAuthorizations\n[PASS] invariant_supplyAndBalancesAreConserved\n TokenInvariantTest invariants (runs: 256, calls: 16384, reverts: 0)\n\n╭--------------+---------------------+-------+---------+----------╮\n| Contract     | Selector            | Calls | Reverts | Discards |\n+=================================================================+\n| TokenHandler | approve             | 1608  | 0       | 0        |\n|--------------+---------------------+-------+---------+----------|\n| TokenHandler | approveAndSpend     | 1602  | 0       | 0        |\n|--------------+---------------------+-------+---------+----------|\n| TokenHandler | approveInfinite     | 1660  | 0       | 0        |\n|--------------+---------------------+-------+---------+----------|\n| TokenHandler | delegatedOverdraw   | 1696  | 0       | 0        |\n|--------------+---------------------+-------+---------+----------|\n| TokenHandler | overdraw            | 1658  | 0       | 0        |\n|--------------+---------------------+-------+---------+----------|\n| TokenHandler | overspendAllowance  | 1608  | 0       | 0        |\n|--------------+---------------------+-------+---------+----------|\n| TokenHandler | rejectZeroRecipient | 1654  | 0       | 0        |\n|--------------+---------------------+-------+---------+----------|\n| TokenHandler | revoke              | 1648  | 0       | 0        |\n|--------------+---------------------+-------+---------+----------|\n| TokenHandler | transfer            | 1616  | 0       | 0        |\n|--------------+---------------------+-------+---------+----------|\n| TokenHandler | transferFrom        | 1634  | 0       | 0        |\n╰--------------+---------------------+-------+---------+----------╯\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 2.94s (2.94s CPU time)\n\nRan 3 test suites in 2.95s (3.01s CPU time): 44 tests passed, 0 failed, 0 skipped (44 total tests)\n","passed":true},{"durationMs":34,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"Token.approve(address,uint256)\",\"Token.transfer(address,uint256)\",\"Token.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":3,\"README.md\":108,\"REVIEW.md\":64,\"foundry.toml\":22,\"remappings.txt\":2,\"script/Deploy.s.sol\":29,\"src/Token.sol\":15,\"test/Deploy.t.sol\":65,\"test/Token.invariant.t.sol\":203,\"test/Token.t.sol\":494},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"8c26e2685a7fa1e6d180179abf3dbf1e6f22e1b9323145caa6c145fbd092f0ad","verifiedTreeHash":"9583f624a647a533861a8e38b623e551128f33d5","verifierVersion":"0.1.0+be003835"},{"checks":[{"durationMs":1175,"exitCode":0,"name":"build","output":"Compiling 30 files with Solc 0.8.26\nSolc 0.8.26 finished in 1.07s\nCompiler run successful!\n","passed":true},{"durationMs":530,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 6 tests for test/Deploy.t.sol:DeployTest\n[PASS] test_localDeploymentWithExplicitChain() (gas: 540175)\n[PASS] test_localDeploymentWithZeroExpectation() (gas: 540158)\n[PASS] test_rejectsMismatchedChain() (gas: 30760)\n[PASS] test_rejectsUnsupportedChain() (gas: 30550)\n[PASS] test_sepoliaDeploymentWithExplicitChain() (gas: 540113)\n[PASS] test_sepoliaRequiresExplicitExpectation() (gas: 30759)\nSuite result: ok. 6 passed; 0 failed; 0 skipped; finished in 581.91µs (1.00ms CPU time)\n\nRan 27 tests for test/Token.t.sol:TokenTest\n[PASS] testFuzz_allowanceCannotBeExceeded(uint256) (runs: 256, μ: 100650, ~: 100894)\n[PASS] testFuzz_delegatedTransferConservesSupply(uint256,uint256) (runs: 256, μ: 137899, ~: 139796)\n[PASS] testFuzz_overdrawReverts(uint256) (runs: 256, μ: 53291, ~: 53647)\n[PASS] testFuzz_transferConservesSupply(address,uint256) (runs: 256, μ: 78234, ~: 78594)\n[PASS] test_approvalEmitsEventAndCanBeReplacedOrRevoked() (gas: 168142)\n[PASS] test_approvalRejectsZeroSpender() (gas: 30550)\n[PASS] test_constructorEmitsFullMint() (gas: 5562)\n[PASS] test_directEtherPaymentReverts() (gas: 36092)\n[PASS] test_emptyHolderCannotTransferPositiveAmount() (gas: 37638)\n[PASS] test_factoryReceivesSupplyAndLaunchTransfersArriveWhole() (gas: 599274)\n[PASS] test_fullBalanceTransfer() (gas: 62700)\n[PASS] test_infiniteAllowanceRemainsUnchanged() (gas: 120639)\n[PASS] test_insufficientAllowanceRevertsWithoutChangingState() (gas: 100323)\n[PASS] test_insufficientBalanceRollsBackAllowanceSpend() (gas: 98468)\n[PASS] test_metadataAndEntireInitialSupply() (gas: 81092)\n[PASS] test_noMintBurnFreezeOrUpgradeEntryPoints() (gas: 1062817)\n[PASS] test_runtimeHasNoForbiddenOpcodes() (gas: 473987)\n[PASS] test_selfTransferPreservesBalance() (gas: 42818)\n[PASS] test_transferEmitsEventAndMovesExactAmount() (gas: 79989)\n[PASS] test_transferFromConsumesFiniteAllowanceAndEmitsTransfer() (gas: 133725)\n[PASS] test_transferFromRejectsZeroSender() (gas: 33223)\n[PASS] test_transferFromToSelfConsumesAllowanceWithoutChangingBalance() (gas: 94687)\n[PASS] test_transferFromZeroRecipientRollsBackAllowanceSpend() (gas: 95709)\n[PASS] test_transferRejectsZeroRecipientEvenForZeroAmount() (gas: 66531)\n[PASS] test_unapprovedCallerCannotMoveHolderFunds() (gas: 97091)\n[PASS] test_zeroTransferFromNeedsNoAllowance() (gas: 51016)\n[PASS] test_zeroValueTransferFromEmptyAccountEmitsEvent() (gas: 49953)\nSuite result: ok. 27 passed; 0 failed; 0 skipped; finished in 8.38ms (32.54ms CPU time)\n\nRan 1 test for test/Token.invariant.t.sol:TokenInvariantTest\n[PASS] invariant_supplyAndBalancesAreConserved() (runs: 128, calls: 8192, reverts: 0)\n\n╭--------------+--------------+-------+---------+----------╮\n| Contract     | Selector     | Calls | Reverts | Discards |\n+==========================================================+\n| TokenHandler | approve      | 2747  | 0       | 0        |\n|--------------+--------------+-------+---------+----------|\n| TokenHandler | transfer     | 2731  | 0       | 0        |\n|--------------+--------------+-------+---------+----------|\n| TokenHandler | transferFrom | 2714  | 0       | 0        |\n╰--------------+--------------+-------+---------+----------╯\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 444.06ms (443.16ms CPU time)\n\nRan 3 test suites in 445.41ms (453.02ms CPU time): 34 tests passed, 0 failed, 0 skipped (34 total tests)\n","passed":true},{"durationMs":35,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"Token.approve(address,uint256)\",\"Token.transfer(address,uint256)\",\"Token.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":3,\"README.md\":108,\"REVIEW.md\":64,\"foundry.toml\":22,\"launch.json\":20,\"remappings.txt\":2,\"script/Deploy.s.sol\":29,\"src/Token.sol\":15,\"test/Deploy.t.sol\":65,\"test/Token.invariant.t.sol\":69,\"test/Token.t.sol\":326},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"d515024048bf5e3795956f88389cf0ddae236efa1a956d35fcfa0409cb2a38de","verifiedTreeHash":"eb5db94a098e5527f60d35de7836331ff5a5e5f3","verifierVersion":"0.1.0+be003835"}]}