{"assessments":[],"deployments":[],"fuzz":[],"identity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"interpretation":"Records acceptance and evidence. Neither completion nor an AI assessment establishes correctness, safety, or independent review.","jobId":"4def1c1e-df96-4235-ae88-218ba1c5c337","kind":"shape:chain","nodes":[{"acceptedSubmissionHash":"309c0da86b606db1f4ca1099739a7816208f1d1dbc5272c56022d3089c44e0c3","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_economics","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"6fe89647eaae509fec54a2a6e2845b05eec8f579dafec2c9a66676c050be2452","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_flow","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"40ad0e9164ee7cea8240dc29efe46b35b10a3f488fe9be0d4338ff4c08a7c09a","dependsOn":["build_contract_project","write_foundry_tests","manifest","audit_math","audit_permissions","audit_economics","audit_flow"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"3014f1ea5961918ca059453a484bf4c8bcbbfc2248dbe31d94ac7c5cdf8f50bd","skillId":"audit-judge","tools":[]},"key":"audit_judge","kind":"code","role":"review","skillHash":"3014f1ea5961918ca059453a484bf4c8bcbbfc2248dbe31d94ac7c5cdf8f50bd","skillId":"audit-judge","state":"accepted"},{"acceptedSubmissionHash":"ee4bfed87436442452d7cba78916a22ac15af3c42f567fe082edb2fac1e7efb6","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_math","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"72c3d65dfe0942c5c41b2ff2cb4c7f5409cd5062acb05986de4a9d158669788b","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_permissions","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"ff06c124bca817e0ec1d07d17d454f30a71fc375f320d6946352b4c8ee9423af","dependsOn":[],"execution":{"mustProduce":["src/LaunchToken.sol"],"network":false,"profile":"foundry","requires":[],"skillHash":"b6503de65ad02f845827887c23da4c3b56ccc5df7a459db263bae6e549d92f7f","skillId":"build-contract-project","tools":[]},"key":"build_contract_project","kind":"code","role":"implement","skillHash":"b6503de65ad02f845827887c23da4c3b56ccc5df7a459db263bae6e549d92f7f","skillId":"build-contract-project","state":"accepted"},{"acceptedSubmissionHash":"7a798c04c3be1d4a27a24b2e9474330b27a84c2339f5355ee0b42c9d8ea142fc","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"tools":[]},"key":"manifest","kind":"code","role":"integrate","skillHash":null,"skillId":null,"state":"accepted"},{"acceptedSubmissionHash":"c0d46e86369425e68936e945f7f19cf94cf163d2c11555e3043cea80ba291d1f","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"73431852439ad3a343f3d2b7db1c43cd363b9f48f9bb51497374a0cf6d50b223","skillId":"write-foundry-tests","tools":[]},"key":"write_foundry_tests","kind":"code","role":"tests","skillHash":"73431852439ad3a343f3d2b7db1c43cd363b9f48f9bb51497374a0cf6d50b223","skillId":"write-foundry-tests","state":"accepted"}],"objective":"Token name: EmberEvo. Token symbol: EMVO.\n\nLaunch EmberEvo (EMVO) using the official standard evm_project route on Ethereum mainnet (chainId 1), paired with IMD. Use the fixed official plain ERC-20: 1,000,000,000 supply, 18 decimals, minted once; no later mint, token admin privileges, upgradeability, pause, blacklist, transfer tax, rebase, staking, custom vesting, required burn or AI financial authority.\n\nAllocation is 86% of total initial supply to the pool, 10% to the official Swarm distributor and 4% to 0x1C651928150DADDDA9C2C040a9D4901d862f8eC4. Explicit economics.poolBps=8600 and remainderTo must resolve to that address. The launch payment must use that same issuing wallet; another report-paying wallet is not the issuer. Use the official standard IMD opening cap and pool fee machinery. State the exact policy version, factory, fees, recipient roles and gas responsibilities. Do not silently change chain, pair, kind, supply, recipients or allocation.\n\nEmberEvo is an independent IMD Ember World ecosystem token. Planned utility includes crypto token/NFT research discovery and future Genesis PEPE paid mint. The later Genesis contract will take an exact EMVO payment to the issuing wallet and mint NFT atomically, without required burn. Owner may freely use receipts. This launch does not implement or deploy Genesis, a research service, a website, a treasury/vault or any extra product contract. No yield, dividends, redemption, backing or price promise. Only create the standard token and necessary official launch infrastructure. If this route requires an additional custom project contract, identify that blocker instead of inventing one or switching to custom_token.\n\nProvide the effective allocation, paired currency, supply and fee terms at Check and bind the actual quote to this input. Do not treat earlier Report completion or free Check as security certification.","parentJobId":null,"planHash":"0aca0464054e72f46ed6ada90de44cfc252955a67438f27c50bc206b699a63b3","previousHash":"0000000000000000000000000000000000000000000000000000000000000000","projectId":"4def1c1e-df96-4235-ae88-218ba1c5c337","publication":{"commit":null,"deliveredAt":null,"repoUrl":"https://github.com/identity-md-launches/launch-904-emberevo-token-symbol-emvo"},"receiptIdentity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"registry":"0xb6d0a187b050fa5bb0b87033a203f37becf4a775","research":[],"schema":"identitymd-work-v1","signals":[{"agentId":"51021","feedbackHash":"e247a0f98e33a8ff5e1a832bb78890380437269fe5b023a85a4289421a4ca601","nodeKey":"audit_economics","submissionHash":"309c0da86b606db1f4ca1099739a7816208f1d1dbc5272c56022d3089c44e0c3","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51203","feedbackHash":"021ac35efcbd7ff971029d86cc035bbd64f0e1fba6adc682f79422f85640c2c7","nodeKey":"audit_flow","submissionHash":"6fe89647eaae509fec54a2a6e2845b05eec8f579dafec2c9a66676c050be2452","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51486","feedbackHash":"ec3687507c7b0924dde2058eb0ce1c0ba112d5563ce728a63fcff61c8946cfb3","nodeKey":"audit_judge","submissionHash":"40ad0e9164ee7cea8240dc29efe46b35b10a3f488fe9be0d4338ff4c08a7c09a","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51250","feedbackHash":"c93eeedf03eaa9bdd7fc8ae3187605f9003e5928436e61574eac8a77d76a805a","nodeKey":"audit_math","submissionHash":"ee4bfed87436442452d7cba78916a22ac15af3c42f567fe082edb2fac1e7efb6","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51508","feedbackHash":"a9593532885aa89bb7fb9b7d0c6ecc01940a8baaa7e9e7e86e8e0cf097757719","nodeKey":"audit_permissions","submissionHash":"72c3d65dfe0942c5c41b2ff2cb4c7f5409cd5062acb05986de4a9d158669788b","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51294","feedbackHash":"47ba2f91ccbd258aa0e3a4a314e2093a0781e150929c849428bbe429b22d2855","nodeKey":"build_contract_project","submissionHash":"ff06c124bca817e0ec1d07d17d454f30a71fc375f320d6946352b4c8ee9423af","tag1":"verification:checks","tag2":"acceptance-v2","value":1},{"agentId":"50968","feedbackHash":"efdb34743b3e14e02ee28c410760028c7973cc6dcecd2fd6b7d3270ba1539474","nodeKey":"manifest","submissionHash":"7a798c04c3be1d4a27a24b2e9474330b27a84c2339f5355ee0b42c9d8ea142fc","tag1":"verification:checks","tag2":"acceptance-v2","value":1},{"agentId":"51211","feedbackHash":"f211d07456f408f6c5c7f947a3a55edd9c170a20cb0a3d0e6aa1ca4fc1394a38","nodeKey":"write_foundry_tests","submissionHash":"c0d46e86369425e68936e945f7f19cf94cf163d2c11555e3043cea80ba291d1f","tag1":"verification:checks","tag2":"acceptance-v2","value":1}],"site":null,"snapshotHash":"58f600fa4c6a809852e2ed24baec06d2cad9e1726659dffa124add22fbdb4499","state":"completed","submissions":[{"artifacts":[],"attempt":1,"bundleHash":null,"device":"72ae9b5bbd1a54b6","findings":[],"hash":"309c0da86b606db1f4ca1099739a7816208f1d1dbc5272c56022d3089c44e0c3","nodeId":"8e9455e9-3e5e-4c8e-aaee-399ae089b2b9","outcome":"completed","summary":"The review is complete. The findings file is in place, no tracked file was changed, and the scratch directory is gone.\n\n**Result: no defects found in the assigned area.** `.imd-findings.json` holds an empty findings list and eight coverage rows, one per verifier entry point plus the invariants and economic terms I checked.\n\nWhat I verified, against the Economic Security, Invariant and Flow Gap guides:\n\n- **Token code.** `src/LaunchToken.sol` is a 13-line, argument-free OpenZeppelin ERC-20 that mints 10^27 units once to the deployer. It has no mint, burn, owner, pause, tax, hook, external call, ETH path, or escape opcode. Every one of the three entry points was traced through the vendored library and behaves as a plain transfer or approval should.\n- **Dependencies.** I downloaded the pinned OpenZeppelin v5.0.2 archive and compared every vendored file byte for byte. All six match, and the archive hash matches the one recorded in the dependency notes.\n- **Invariants.** Supply stays constant and equals the sum of balances across the project's fuzz and stateful invariant suites. The full suite passes with no reverts. I also ran both protected floor tests from the task inputs against the compiled creation code, simulating a CREATE2 factory deployment on chain 1, and all nine assertions pass.\n- **Economics.** The 86/10/4 split sums to 10,000 bps, the remainder recipient and launch payer both resolve to the issuing wallet, and the fee and opening-cap terms in the README match the route reference. The intent file's recorded SHA-256 matches its bytes. Policy version, factory, pair token, fee recipient and the actual quote are correctly left unresolved rather than filled with placeholders.\n\nStatic analysis leads: the aderyn large-literal note is a compile-time constant that tests assert equals 10^27, so it is not a defect. The one thing this review cannot establish is anything on the official side: the live LaunchFees value, the IMD pair address, and the quote binding all still need to be supplied at Check.","treeHash":null,"usage":{"cachedInputTokens":478352,"inputTokens":194,"model":"claude-fable-5-1","outputTokens":10047,"runtime":"claude","turns":20,"wallClockMs":167073}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"0e78515c4d95885a","findings":[{"citation":"resolved","description":"Merged from three identical specialist reports (audit_math, audit_flow, audit_permissions); reproduced independently. The forge-std archive hash in the table (45157353ab49eab01d294565866731e599b32401757229689ee459aa26b7ee94) matches the upstream v1.9.7 tarball and the OpenZeppelin v5.0.2 archive hash (18c7b7e949b9a82dcd8cd394426c9c2636dfc263aa2317d4749dbfa0c7b3925a) also matches, but seven files under lib/forge-std/src are not the archive bytes: StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IERC7540.sol and interfaces/IMulticall3.sol. Stripping all whitespace from each pair gives identical SHA-256 digests, so the change is forge-fmt line wrapping with no semantic effect. All six vendored OpenZeppelin files and LICENSE are byte-identical to the archive, so the production token (which inherits only OpenZeppelin ERC20) is built from exactly the published source. forge-std is imported only by tests and does not reach creation or runtime bytecode. The only defect is the provenance sentence: a reviewer who checks the stated claim by comparing lib/ to the pinned archive gets seven mismatches the document says cannot occur. Minimal fix: restore those seven files byte-for-byte from the archive, or amend the sentence to say the forge-std sources were reformatted with forge fmt and are otherwise unmodified. No security, allocation, supply or permission impact.","line":15,"path":"DEPENDENCIES.md","reproduction":"State: repository as committed. Commands: curl -sSL -o fs.tgz https://codeload.github.com/foundry-rs/forge-std/tar.gz/refs/tags/v1.9.7 && sha256sum fs.tgz (prints 45157353ab49eab01d294565866731e599b32401757229689ee459aa26b7ee94) && tar xzf fs.tgz && diff -rq forge-std-1.9.7/src lib/forge-std/src. Expected per DEPENDENCIES.md line 15: no output. Actual: seven 'Files ... differ' lines for StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IERC7540.sol, interfaces/IMulticall3.sol. Whitespace-only confirmation: for each of the seven, tr -d '[:space:]' < forge-std-1.9.7/src/$f | sha256sum equals the same over lib/forge-std/src/$f (observed prefixes 8fced2eabe1802f7, c04c840bf91394ee, d08bc2eb27067881, fe772424ec5d5c1b, 9dbe400a39751f6e, 100b47a896303819, f923f71fa4c102b8, each pair equal). OpenZeppelin check: curl -sSL -o oz.tgz https://codeload.github.com/OpenZeppelin/openzeppelin-contracts/tar.gz/refs/tags/v5.0.2 && tar xzf oz.tgz, then cmp of each of the six vendored files plus LICENSE against openzeppelin-contracts-5.0.2 reports no difference.","severity":"info","snippet":"The selected source files are unmodified. Only OpenZeppelin's base ERC-20 is inherited by the production token. forge-std is used exclusively in tests.","title":"DEPENDENCIES.md says vendored sources are unmodified, but seven forge-std v1.9.7 files were reformatted (whitespace only)"},{"citation":"resolved","description":"The README (written before the manifest step) says the mainnet IMD address is not supplied and lists it among unresolved blockers. The accepted launch.json, applied later to the same tree, sets pool.pairedCurrency to 0xd34a99bc0f67ae1bbd63c660e6d0b0dd03e263b7, and that address has code on Ethereum mainnet returning symbol() == \"IMD\" and decimals() == 18. The two documents therefore disagree about whether the pair address is known. This is a documentation staleness only: the manifest is the field that admission reads, the README is explanatory, and nothing in the token or the manifest is wrong. The other items in that README sentence (policy version, factory, LaunchFees, fee recipient, payment terms, quote) genuinely remain unresolved and launch/check-status.json correctly records them as null. Minimal fix: update the README sentence and the CHECK.md currency row to cite the pinned pairedCurrency address and say it must still be confirmed against the official network.pairToken at Check.","line":33,"path":"README.md","reproduction":"Input: the committed tree. Read README.md line 159: it asserts the mainnet IMD address is not supplied. Read launch.json line 11: \"pairedCurrency\": \"0xd34a99bc0f67ae1bbd63c660e6d0b0dd03e263b7\". Expected: the README's list of missing facts matches the manifest. Actual: the README lists an address the manifest already pins. On-chain check: cast call 0xd34a99bc0f67ae1bbd63c660e6d0b0dd03e263b7 'symbol()(string)' --rpc-url https://ethereum-rpc.publicnode.com returns \"IMD\"; 'decimals()(uint8)' returns 18; cast code returns non-empty bytecode.","severity":"info","snippet":"The supplied files contain **no exact policy version, ProjectFactory address, mainnet IMD address, LaunchFees address, protocol fee-recipient address, launch-payment price/payee, gas sponsorship terms or actual Check quote**.","title":"README states no mainnet IMD address was supplied, but launch.json now pins pool.pairedCurrency"}],"hash":"40ad0e9164ee7cea8240dc29efe46b35b10a3f488fe9be0d4338ff4c08a7c09a","nodeId":"d3182fe3-9f19-48b6-b07d-f6399f115121","outcome":"completed","summary":"The review is complete and `.imd-findings.json` holds the result. No repository file was changed, and the scratch directory used for the protected floor run was removed.\n\n**Outcome: no defect in the token or the manifest.** Two informational findings, both documentation accuracy.\n\n- **Finding 1 (info), DEPENDENCIES.md line 15.** The three specialist reports were the same root cause and are merged into one. I reproduced it: the forge-std v1.9.7 archive hash matches the table, but seven vendored files differ from the archive. Whitespace-stripped digests are equal for every pair, so it is forge-fmt reflow only. All six OpenZeppelin v5.0.2 files and the licence are byte-identical. The production token inherits only OpenZeppelin ERC20, so no bytecode is affected.\n- **Finding 2 (info), README.md line 33.** The README still says no mainnet IMD address was supplied, while the accepted launch.json pins a paired-currency address. That address has code on mainnet and returns symbol IMD with 18 decimals. This is stale wording, not a wrong manifest.\n\n**What I verified myself.**\n\n- The token is a four-line wrapper over unmodified OpenZeppelin ERC20: zero-argument nonpayable constructor, single mint of 10^27 to the deployer, no owner, mint, burn, pause, blacklist, fee, rebase or upgrade path. Runtime contains no DELEGATECALL, CALLCODE or SELFDESTRUCT.\n- The protected token floor from the pinned reads passed all seven checks against the real compiled creation code with the policy supply and decimals set.\n- The project suite passed with 38 tests, including fuzz and a stateful invariant over transfers, approvals and delegated spends. Build and formatting checks pass. No submodules.\n- Manifest fields match the brief: evm_project, empty contracts array, fee 3000, tick spacing 60, initial price exactly 2^96, lowercase pair address. Notes carry no deployment authority.\n- Static analysis leads: slither reported nothing, and aderyn's large-literal note is the supply constant, which is intended.\n\n**Coverage record.** All three entry points (approve, transfer, transferFrom) are marked holds with reasons, plus the constructor, the no-admin-path invariant, manifest-matches-brief, and the vendored-dependency invariant that points at finding 1.\n\n**Still unresolved and outside this code.** Exact policy version, ProjectFactory, LaunchFees and fee-recipient addresses, the launch charge, and the quote binding are correctly recorded as null in launch/check-status.json. I could not confirm the pinned pair address against the official network.json, which was not among my inputs. That is a Check-time evidence gap, not a code defect.","treeHash":null,"usage":{"cachedInputTokens":860169,"inputTokens":450,"model":"claude-fable-5-1","outputTokens":10257,"runtime":"claude","turns":15,"wallClockMs":183490}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"896d1238054266ca","findings":[{"citation":"resolved","description":"The provenance statement is inaccurate for forge-std. The archive SHA-256 in the table (45157353ab49eab01d294565866731e599b32401757229689ee459aa26b7ee94) does match the upstream v1.9.7 tarball, and both licence files match, but the vendored src/ tree is not the archive's contents: lib/forge-std/src/StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IERC7540.sol and interfaces/IMulticall3.sol differ from the archive. Stripping all whitespace from each pair yields identical bytes, so the differences are formatter line-wrapping only (the files appear to have been passed through forge fmt). All six vendored OpenZeppelin v5.0.2 files are byte-identical to their archive. There is no runtime or security effect: forge-std is imported only by tests, the production token inherits only OpenZeppelin ERC20, and the differing files have no semantic change. The defect is that a verifier who checks the written claim by comparing file hashes to the pinned release will get a mismatch for seven files and has to re-derive why. Minimal fix: either restore the seven files to the archive bytes, or change the sentence to say the forge-std sources were reformatted with forge fmt and are otherwise unchanged.","line":15,"path":"DEPENDENCIES.md","reproduction":"Input: the pinned archive named in DEPENDENCIES.md. Steps: curl -sSL -o fs.tgz https://codeload.github.com/foundry-rs/forge-std/tar.gz/refs/tags/v1.9.7 ; sha256sum fs.tgz (prints 45157353ab49eab01d294565866731e599b32401757229689ee459aa26b7ee94, matching the table) ; tar xzf fs.tgz ; diff -rq forge-std-1.9.7/src lib/forge-std/src. Expected per the sentence at DEPENDENCIES.md:15: no output. Actual: seven 'Files ... differ' lines (StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IERC7540.sol, interfaces/IMulticall3.sol). Confirming the difference is whitespace-only: for each file, tr -d ' \\n\\t\\r' < upstream | sha256sum equals the same over the vendored copy. The same procedure for OpenZeppelin v5.0.2 (archive 18c7b7e949b9a82dcd8cd394426c9c2636dfc263aa2317d4749dbfa0c7b3925a) shows all six vendored files byte-identical.","severity":"info","snippet":"The selected source files are unmodified. Only OpenZeppelin's base ERC-20 is inherited by the production token. forge-std is used exclusively in tests. Its cheatcode interface includes filesystem, environment and FFI operations, but this project's tests do not use them and the Foundry configuration grants no filesystem or FFI permission.","title":"DEPENDENCIES.md states vendored forge-std files are unmodified, but seven of them differ from the pinned v1.9.7 archive (whitespace-only reformatting)"}],"hash":"6fe89647eaae509fec54a2a6e2845b05eec8f579dafec2c9a66676c050be2452","nodeId":"ead0bee9-9428-496e-97ff-1426bda8a74e","outcome":"completed","summary":"Review complete. The findings file is written and the working tree is otherwise untouched.\n\n**Outcome:** no security defect in the token or its control flow. One informational provenance inaccuracy is reported.\n\n**What I checked, against the Execution Trace, Periphery and First Principles guides**\n\n- **Token entry points.** All three state-changing functions (approve, transfer, transferFrom) are the unmodified OpenZeppelin v5.0.2 implementations. I traced each path: zero-address rejection, insufficient balance and allowance reverts, allowance consumed before the balance move, infinite-allowance semantics, self-transfer correctness, and the absence of any external call, hook, fallback or receive. Nothing produces a stale read, partial update or value leak.\n- **Constructor and roles.** Zero arguments, nonpayable, mints exactly 10^27 base units once to the deployer. No owner, mint, burn, pause, fee, proxy or selfdestruct exists in the ABI or runtime. Name and symbol match the brief.\n- **Protected floors.** I ran both pinned protected test files from a scratch directory against the real creation code with a CREATE2 factory stand-in on chainId 1. All nine tests pass, including whole-supply-to-factory and the forbidden-opcode scan.\n- **Periphery.** Downloaded the pinned OpenZeppelin v5.0.2 and forge-std v1.9.7 archives. Both archive hashes match the table in DEPENDENCIES.md. All six OpenZeppelin files are byte-identical. Seven forge-std files differ, but only by whitespace reformatting.\n- **Launch documents.** Allocation, pair, chain, fee terms, opening cap, issuer and payer addresses, and the intent digest all reconcile with the brief and the route. Unresolved policy, factory and quote values are honestly recorded as null rather than defaulted, since no network or policy file was supplied.\n\n**The one finding (info):** DEPENDENCIES.md line 15 says the vendored sources are unmodified, but the forge-std copies were reformatted. Test-only, no semantic change, no runtime effect. The fix is either restoring the archive bytes or correcting the sentence.\n\n**Not reported as findings:** the aderyn large-literal lead is style only, and the ERC-20 approve race is a property of the standard the brief explicitly requests.\n\n**Coverage record:** nine rows covering all three listed entry points, the constructor, the protected-floor invariants, both vendored dependencies, the launch documents and the build configuration.","treeHash":null,"usage":{"cachedInputTokens":720365,"inputTokens":322,"model":"claude-fable-5-1","outputTokens":16000,"runtime":"claude","turns":31,"wallClockMs":253255}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"3516474d8a268bd8","findings":[{"citation":"resolved","description":"Trust-gap (provenance) note, no security impact. The document pins forge-std to v1.9.7 and gives the correct archive SHA-256 (45157353ab49eab01d294565866731e599b32401757229689ee459aa26b7ee94), and states the selected source files are unmodified. The vendored lib/forge-std/src tree differs from that archive in StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IERC7540.sol and interfaces/IMulticall3.sol. I verified every difference is whitespace/line-wrapping only (stripping all whitespace yields identical bytes), consistent with `forge fmt` having been run over lib/. No file is missing or added. The six vendored OpenZeppelin v5.0.2 files and LICENSE are byte-identical to upstream, so the production token's only dependency is exactly the published ERC20. forge-std is test-only and never reaches creation bytecode. The defect is that a verifier reproducing the stated provenance check (compare vendored files to the cited archive) gets a mismatch the document says cannot happen. Fix: either restore the seven files byte-for-byte from the v1.9.7 archive, or amend the sentence to say the forge-std files were reformatted with forge fmt and are otherwise unmodified.","line":15,"path":"DEPENDENCIES.md","reproduction":"Input: `curl -sSL -o fs.tgz https://codeload.github.com/foundry-rs/forge-std/tar.gz/refs/tags/v1.9.7 && sha256sum fs.tgz && tar xzf fs.tgz && diff -rq forge-std-1.9.7/src lib/forge-std/src`. Expected per DEPENDENCIES.md line 15: no output (identical). Actual: the archive hash matches 45157353..., but diff reports 7 files differ (StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IERC7540.sol, interfaces/IMulticall3.sol). `diff forge-std-1.9.7/src/Vm.sol lib/forge-std/src/Vm.sol | wc -l` = 72; `tr -d ' \\n\\t\\r' < each | sha256sum` is equal for all seven, proving whitespace-only. Same procedure for OpenZeppelin v5.0.2 (18c7b7e9...) shows all six vendored files identical.","severity":"info","snippet":"The selected source files are unmodified. Only OpenZeppelin's base ERC-20 is inherited by the production token. forge-std is used exclusively in tests. Its cheatcode interface includes filesystem, environment and FFI operations, but this project's tests do not use them and the Foundry configuration grants no filesystem or FFI permission.","title":"DEPENDENCIES.md states the vendored forge-std sources are unmodified, but seven files differ from the v1.9.7 release they cite (whitespace-only reformatting)"}],"hash":"72c3d65dfe0942c5c41b2ff2cb4c7f5409cd5062acb05986de4a9d158669788b","nodeId":"36c92385-3431-4c9f-9dbf-0bfab1f3e8b7","outcome":"completed","summary":"The review is complete and the findings file is written and validated.\n\n**Outcome: no security defects in the token.** `src/LaunchToken.sol` is a plain, unmodified OpenZeppelin v5.0.2 ERC-20 with a zero-argument constructor that mints the full supply once to its deployer and retains no role. Across my three guides I found nothing exploitable:\n\n- **Access Control.** The only state-changing entry points are approve, transfer and transferFrom. Each acts solely on behalf of msg.sender or a spender with explicit allowance. The constructor hands out no owner, minter, pauser or upgrader. The compiled runtime dispatcher contains exactly the nine ABI selectors, with no receive, fallback, DELEGATECALL, CALLCODE or SELFDESTRUCT.\n- **Asymmetry.** transfer and transferFrom mirror each other on balance effects and zero-address checks. Allowance is spent before the balance moves, finite allowances decrement exactly, the maximum allowance is never touched, and a failed transferFrom leaves the allowance intact. These behaviours were confirmed with a scratch probe suite that passed and has been removed.\n- **Trust Gap.** The vendored OpenZeppelin files are byte-identical to the upstream v5.0.2 archive, so no hidden privilege exists in inherited code. The launch intent matches the brief: mainnet, IMD pair, 8600/1000/400 split, remainder and payer both the stated issuing wallet, empty contracts array, standard admission pool settings. The README and CHECK.md correctly leave policy version, factory, LaunchFees, recipient and quote unresolved rather than inventing values.\n\n**One informational finding was recorded.** `DEPENDENCIES.md` states the vendored forge-std sources are unmodified, but seven files differ from the cited v1.9.7 archive. I verified every difference is whitespace-only reformatting, and forge-std is test-only, so this has no effect on deployed bytecode. The fix is either restoring those files byte for byte or amending the sentence.\n\n**Coverage.** All three listed entry points are marked `holds`, plus seven invariant rows covering the constructor, absence of receive and fallback, dispatcher inventory, fixed supply, both dependency provenances and the intent economics. Static analysis leads were reviewed: Slither reported nothing, and the aderyn large-literal note is the intended supply constant. The forge build, all 22 project tests, and the formatter check passed.","treeHash":null,"usage":{"cachedInputTokens":898035,"inputTokens":322,"model":"claude-fable-5-1","outputTokens":21654,"runtime":"claude","turns":39,"wallClockMs":301296}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"917650ddc12d10fe","findings":[],"hash":"74406e2fdb1f7bc7bd7b8d15320a31443c595634d5f14580ff6531979d0befbf","nodeId":"7796933b-5226-4ce6-bc17-809e62f9a6fb","outcome":"failed","summary":"the task produced no changes; the agent's last message was: Blocked by the execution environment: every command fails before starting with `bwrap: setting up uid map: Permission denied`.\n\nI could not read the implementation or pinned checks. Both `forge build` and `forge test` failed to start. No files were changed.\n\nThe sandbox must be repaired and the task rerun before I can implement and verify the tests.","treeHash":null,"usage":{"cachedInputTokens":48256,"inputTokens":28494,"model":"gpt-6-astra","outputTokens":789,"runtime":"codex","turns":3,"wallClockMs":39668}},{"artifacts":[],"attempt":1,"bundleHash":"2539c8b21efc21b6381c1d5d168a47e622d61c3524bbac524d07e232f400aa23","device":"228636b860e0212c","findings":[],"hash":"7a798c04c3be1d4a27a24b2e9474330b27a84c2339f5355ee0b42c9d8ea142fc","nodeId":"787ae7b9-06a9-4a66-af55-e832f4e1dfe8","outcome":"completed","summary":"Created [launch.json](/home/imd/.identitymd/work/4def1c1e-df96-4235-ae88-218ba1c5c337/787ae7b9-06a9-4a66-af55-e832f4e1dfe8/launch.json) for EmberEvo’s token-only `evm_project` launch with the required IMD pair and economics documented.\n\nSchema checks, offline `forge build`, and all 31 tests passed, including protected checks using a local fixture. Only `launch.json` is submitted.\n\nOfficial policy, factory, payment/gas terms and authenticated quote binding remain unresolved and are documented as launch blockers.","treeHash":"8dacbd2716722bf5ec96c72d01b5073742e6900a","usage":{"cachedInputTokens":232320,"inputTokens":39611,"model":"gpt-6-astra","outputTokens":4813,"runtime":"codex","turns":4,"wallClockMs":195305}},{"artifacts":[],"attempt":2,"bundleHash":"b70b5f0f031a0304e2653c1dc456709f4a9d380d84aff632769b2fb6e3a982b8","device":"c0f339153549a92d","findings":[],"hash":"c0d46e86369425e68936e945f7f19cf94cf163d2c11555e3043cea80ba291d1f","nodeId":"7796933b-5226-4ce6-bc17-809e62f9a6fb","outcome":"completed","summary":"Added failure-path tests, corrected admin-call probes, and strengthened balance/allowance invariants. Only `test/` changed.\n\nValidation passed:\n\n- `forge build`\n- `forge test`: 38 tests, zero failures or skips\n- 24,576 invariant handler calls\n\nNo token defect was reproduced. Official launch policy, factory, payment terms and quote binding remain unverified because those inputs are missing; limitations are documented in `test/README.md`.","treeHash":"e55edf22bdb8d5a9327c97a86cab3cfac6c5ae3d","usage":{"cachedInputTokens":680704,"inputTokens":76976,"model":"gpt-6-astra","outputTokens":13317,"runtime":"codex","turns":5,"wallClockMs":462866}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"0cf632e317dfab7a","findings":[{"citation":"resolved","description":"The provenance note claims every vendored file is byte-identical to the pinned upstream archives. That is true for all six OpenZeppelin v5.0.2 files (byte-identical, archive SHA-256 18c7b7e9... matches) and for both forge-std licences, but seven forge-std v1.9.7 sources were reflowed by `forge fmt` before being committed: src/StdAssertions.sol, src/StdJson.sol, src/StdToml.sol, src/Vm.sol, src/console.sol, src/interfaces/IERC7540.sol and src/interfaces/IMulticall3.sol. Stripping all whitespace makes each pair identical, and running `forge fmt` on the upstream tree reproduces the vendored tree exactly, so the change is formatting only with no semantic effect. forge-std is test-only and does not reach production bytecode. Impact is limited to the accuracy of the provenance statement: a verifier that byte-compares lib/ against the pinned archive will see a mismatch the document says cannot exist. No production, math, boundary or allocation defect follows from it. Minimal fix: either re-vendor the seven files byte-for-byte from the archive, or amend the sentence to say the OpenZeppelin files are unmodified and forge-std was reformatted with `forge fmt` without semantic change.","line":15,"path":"DEPENDENCIES.md","reproduction":"State: repository as committed. Commands: `curl -sSL -o fs.tgz https://codeload.github.com/foundry-rs/forge-std/tar.gz/refs/tags/v1.9.7 && sha256sum fs.tgz` (prints 45157353ab49eab01d294565866731e599b32401757229689ee459aa26b7ee94, matching DEPENDENCIES.md), then `tar xzf fs.tgz && diff -rq forge-std-1.9.7/src lib/forge-std/src`. Expected per DEPENDENCIES.md line 15: no output. Actual: 'Files ... differ' for StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IERC7540.sol, interfaces/IMulticall3.sol. Confirming formatting-only: `for f in <those seven>; do tr -d '[:space:]' < forge-std-1.9.7/src/$f | sha256sum; tr -d '[:space:]' < lib/forge-std/src/$f | sha256sum; done` yields equal digests per pair, and `forge fmt` applied to forge-std-1.9.7/src followed by `diff -rq` against lib/forge-std/src yields no output. The six OpenZeppelin files diff clean against openzeppelin-contracts-5.0.2 (archive SHA-256 18c7b7e949b9a82dcd8cd394426c9c2636dfc263aa2317d4749dbfa0c7b3925a).","severity":"info","snippet":"The selected source files are unmodified. Only OpenZeppelin's base ERC-20 is inherited by the production token. forge-std is used exclusively in tests.","title":"DEPENDENCIES.md states vendored forge-std files are unmodified, but seven files differ from the v1.9.7 archive (formatter reflow only)"}],"hash":"ee4bfed87436442452d7cba78916a22ac15af3c42f567fe082edb2fac1e7efb6","nodeId":"49cf7809-4380-45e6-bff7-756e1ec33e78","outcome":"completed","summary":"Review complete. The findings file is written and validated.\n\n**Result: no math, boundary or numerical-gap defect in the token.** The only substantiated item is an informational provenance inaccuracy in DEPENDENCIES.md.\n\n**What I verified**\n\n- `src/LaunchToken.sol` contains no arithmetic of its own. It inherits OpenZeppelin v5.0.2 ERC20, whose six vendored files I diffed byte-for-byte against the upstream archive. The archive hash matches the one recorded in DEPENDENCIES.md.\n- Every unchecked block in the inherited `_update` and `_spendAllowance` is guarded by a strict less-than revert before the subtraction, and the unchecked addition cannot overflow because the balance sum is pinned at 10^27, a 90-bit value.\n- The supply literal evaluates exactly to 10^27 and equals both `1e27` and `1_000_000_000 ether`. The 8600/1000/400 bps split of that supply divides with zero remainder, so the three allocations sum back to the full supply with no dust. The base-unit strings in the README and intent file have the correct digit counts, and the manifest sqrtPriceX96 string equals 2^96 exactly.\n- Boundary steps from the guide have nothing to apply to: the token has no external calls, no payable function, no receive or fallback, no sentinel branch beyond the zero-address reverts, and no bytes decoding.\n- I ran a scratch test for edges the delivered suite skips: max-uint transfer, max-minus-one allowance decrement, transferFrom with a zero-address source at value 0 and 1, self-transferFrom, and a two-holder conservation fuzz. All behave as intended.\n- The protected token floor, run against the compiled creation code with the policy supply and 18 decimals, passes 7 of 7. The full delivered suite passes 22 of 22, including the stateful invariant with no reverts, and `forge fmt --check` is clean.\n\n**The one finding, severity info**\n\nDEPENDENCIES.md line 15 says all vendored files are unmodified. Seven forge-std v1.9.7 files were reflowed by the formatter before commit. Stripping whitespace makes each pair identical, and applying `forge fmt` to the upstream tree reproduces the vendored tree exactly, so the change is cosmetic and test-only. The reproduction in the findings file is the download and diff command sequence.\n\n**Coverage record**\n\nAll three entry points are marked `holds`, plus four rows for the supply and allocation invariants, the constructor floor, and the boundary enumeration. The static-analysis lead about the large numeric literal was checked and is not a defect.\n\n**Outside my area, noted for the judge**\n\nThe swarm 2 percent and 8 percent per-wallet divisions happen in the factory and distributor, which are not in this tree, so any rounding dust there cannot be assessed here. The launch handoff documents correctly leave policy version, factory, pair token, fee addresses and quote as unresolved nulls rather than inventing values.","treeHash":null,"usage":{"cachedInputTokens":657580,"inputTokens":290,"model":"claude-fable-5-1","outputTokens":15814,"runtime":"claude","turns":28,"wallClockMs":218228}},{"artifacts":[],"attempt":1,"bundleHash":"0cd4e2f87a5729c0a39265e72950a4bfb0766edcbe4aea15372ba5c4da62f71f","device":"40b27a75f026cec9","findings":[],"hash":"ff06c124bca817e0ec1d07d17d454f30a71fc375f320d6946352b4c8ee9423af","nodeId":"8f28ef4a-6a8a-4ab4-bb9b-e4bfdebd0095","outcome":"completed","summary":"Implemented EmberEvo’s fixed-supply token, vendored dependencies, tests, and [launch documentation](/root/.identitymd/work/4def1c1e-df96-4235-ae88-218ba1c5c337/8f28ef4a-6a8a-4ab4-bb9b-e4bfdebd0095/README.md), preserving the requested 86%/10%/4% allocation.\n\n`forge build`, all 22 tests, and `forge fmt --check` pass, including clean offline verification.\n\nLaunch and actual quote binding remain blocked by missing official policy version, infrastructure addresses, and Check quote. No transactions were broadcast.","treeHash":"84424d9106384e9ddc78d18c2abc4e8b3bfd32d5","usage":{"cachedInputTokens":564224,"inputTokens":68360,"model":"gpt-6-astra","outputTokens":17187,"runtime":"codex","turns":7,"wallClockMs":582353}}],"verification":[{"checks":[{"durationMs":1021,"exitCode":0,"name":"build","output":"Compiling 27 files with Solc 0.8.26\nSolc 0.8.26 finished in 923.43ms\nCompiler run successful!\n","passed":true},{"durationMs":733,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 21 tests for test/LaunchToken.t.sol:LaunchTokenTest\n[PASS] testFuzz_allowanceLimitsAreExact(uint256,uint256) (runs: 512, μ: 184254, ~: 185870)\nLogs:\n  Bound result 1671934003\n  Bound result 135745755\n\n[PASS] testFuzz_transferRoundTripConservesSupply(uint256) (runs: 512, μ: 141959, ~: 141886)\nLogs:\n  Bound result 2\n\n[PASS] test_approvalEventAndPartialThenFullSpend() (gas: 249157)\n[PASS] test_approvalToZeroAddressReverts() (gas: 30364)\n[PASS] test_constructorEmitsSingleMint() (gas: 9135)\n[PASS] test_create2MintsToFactoryContextWithoutConstructorAllocation() (gas: 223144)\n[PASS] test_etherAndUnknownCallsRevert() (gas: 58904)\n[PASS] test_failedTransferFromRestoresAllowance() (gas: 202734)\n[PASS] test_infiniteAllowanceFollowsStandardERC20Semantics() (gas: 132413)\n[PASS] test_metadataAndEntireInitialSupply() (gas: 73910)\n[PASS] test_noMintBurnAdminOrUpgradeEntryPointsForAnyone() (gas: 1463081)\n[PASS] test_passageOfTimeDoesNotRebaseOrRestrictTransfers() (gas: 134848)\n[PASS] test_replacingAndRevokingApproval() (gas: 143196)\n[PASS] test_requestedAllocationCanBeTransferredExactly() (gas: 266518)\n[PASS] test_runtimeIsBoundedAndHasNoEscapeOpcodes() (gas: 1031140)\n[PASS] test_transferEmitsEventAndMovesExactAmount() (gas: 88828)\n[PASS] test_transferOverBalanceRevertsWithoutChangingState() (gas: 50454)\n[PASS] test_transferToContractDoesNotInvokeCallback() (gas: 170187)\n[PASS] test_unapprovedSpenderCannotMoveTokens() (gas: 51069)\n[PASS] test_zeroAddressTransferRevertsEvenForZeroAmount() (gas: 71905)\n[PASS] test_zeroAndSelfTransfersPreserveBalances() (gas: 102346)\nSuite result: ok. 21 passed; 0 failed; 0 skipped; finished in 11.86ms (32.41ms CPU time)\n\nRan 1 test for test/LaunchToken.invariant.t.sol:LaunchTokenInvariantTest\n[PASS] invariant_supplyAndBalancesAreConserved() (runs: 128, calls: 8192, reverts: 0)\n\n╭--------------+----------+-------+---------+----------╮\n| Contract     | Selector | Calls | Reverts | Discards |\n+======================================================+\n| TokenHandler | approve  | 2770  | 0       | 0        |\n|--------------+----------+-------+---------+----------|\n| TokenHandler | move     | 2733  | 0       | 0        |\n|--------------+----------+-------+---------+----------|\n| TokenHandler | spend    | 2689  | 0       | 0        |\n╰--------------+----------+-------+---------+----------╯\n\nLogs:\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 2827\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 304\n  Bound result 0\n  Bound result 1559\n  Bound result 0\n  Bound result 0\n  Bound result 96\n  Bound result 0\n  Bound result 778\n  Bound result 0\n  Bound result 4258\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 2233625729\n  Bound result 397\n  Bound result 0\n  Bound result 845041328070377744174100013\n  Bound result 0\n  Bound result 5710\n  Bound result 0\n  Bound result 1000000000\n  Bound result 0\n  Bound result 0\n  Bound result 1468\n  Bound result 4594637\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 1000\n  Bound result 0\n  Bound result 0\n  Bound result 1\n  Bound result 618\n  Bound result 3070\n  Bound result 34694\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 657.57ms (656.70ms CPU time)\n\nRan 2 test suites in 659.01ms (669.43ms CPU time): 22 tests passed, 0 failed, 0 skipped (22 total tests)\n","passed":true},{"durationMs":47,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"LaunchToken.approve(address,uint256)\",\"LaunchToken.transfer(address,uint256)\",\"LaunchToken.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":4,\"DEPENDENCIES.md\":15,\"README.md\":62,\"foundry.toml\":20,\"launch.json\":17,\"launch/CHECK.md\":44,\"launch/check-status.json\":20,\"launch/intent.json\":41,\"remappings.txt\":2,\"src/LaunchToken.sol\":13,\"test/LaunchToken.invariant.t.sol\":95,\"test/LaunchToken.t.sol\":308},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"7a798c04c3be1d4a27a24b2e9474330b27a84c2339f5355ee0b42c9d8ea142fc","verifiedTreeHash":"8dacbd2716722bf5ec96c72d01b5073742e6900a","verifierVersion":"0.1.0+be003835"},{"checks":[{"durationMs":1685,"exitCode":0,"name":"build","output":"Compiling 28 files with Solc 0.8.26\nSolc 0.8.26 finished in 1.54s\nCompiler run successful!\n","passed":true},{"durationMs":9222,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 21 tests for test/LaunchToken.t.sol:LaunchTokenTest\n[PASS] testFuzz_allowanceLimitsAreExact(uint256,uint256) (runs: 512, μ: 183769, ~: 185870)\nLogs:\n  Bound result 45385680582076646353246873\n  Bound result 3\n\n[PASS] testFuzz_transferRoundTripConservesSupply(uint256) (runs: 512, μ: 142052, ~: 141910)\nLogs:\n  Bound result 6374\n\n[PASS] test_approvalEventAndPartialThenFullSpend() (gas: 249157)\n[PASS] test_approvalToZeroAddressReverts() (gas: 30364)\n[PASS] test_constructorEmitsSingleMint() (gas: 9135)\n[PASS] test_create2MintsToFactoryContextWithoutConstructorAllocation() (gas: 223144)\n[PASS] test_etherAndUnknownCallsRevert() (gas: 58904)\n[PASS] test_failedTransferFromRestoresAllowance() (gas: 202734)\n[PASS] test_infiniteAllowanceFollowsStandardERC20Semantics() (gas: 132413)\n[PASS] test_metadataAndEntireInitialSupply() (gas: 73910)\n[PASS] test_noMintBurnAdminOrUpgradeEntryPointsForAnyone() (gas: 1434718)\n[PASS] test_passageOfTimeDoesNotRebaseOrRestrictTransfers() (gas: 134848)\n[PASS] test_replacingAndRevokingApproval() (gas: 143196)\n[PASS] test_requestedAllocationCanBeTransferredExactly() (gas: 266518)\n[PASS] test_runtimeIsBoundedAndHasNoEscapeOpcodes() (gas: 1031140)\n[PASS] test_transferEmitsEventAndMovesExactAmount() (gas: 88828)\n[PASS] test_transferOverBalanceRevertsWithoutChangingState() (gas: 50454)\n[PASS] test_transferToContractDoesNotInvokeCallback() (gas: 170187)\n[PASS] test_unapprovedSpenderCannotMoveTokens() (gas: 51069)\n[PASS] test_zeroAddressTransferRevertsEvenForZeroAmount() (gas: 71905)\n[PASS] test_zeroAndSelfTransfersPreserveBalances() (gas: 102346)\nSuite result: ok. 21 passed; 0 failed; 0 skipped; finished in 35.78ms (75.90ms CPU time)\n\nRan 15 tests for test/LaunchToken.adversarial.t.sol:LaunchTokenAdversarialTest\n[PASS] testFuzz_failedDelegatedSpendPreservesApproval(uint256,uint256,bool) (runs: 1000, μ: 193315, ~: 194076)\nLogs:\n  Bound result 999999999999999999999999997\n  Bound result 115792089237316195423570985008687907853269984665639564039463780164074889501347\n\n[PASS] testFuzz_overBalanceTransferCannotMoveOrCreateValue(uint256,uint256) (runs: 1000, μ: 171270, ~: 171887)\nLogs:\n  Bound result 2\n  Bound result 3494535770274794924239841374678030403225113803573081771354\n\n[PASS] testFuzz_repeatedApprovalReplacesRatherThanAccumulates(uint256,uint256) (runs: 1000, μ: 145738, ~: 145740)\n[PASS] test_approvalIsIsolatedByOwnerAndSpender() (gas: 394418)\n[PASS] test_constructorAndMutationFunctionsRejectNativeValue() (gas: 312947)\n[PASS] test_holderMustApproveItselfToUseTransferFrom() (gas: 162184)\n[PASS] test_infiniteApprovalCanBeReducedAndRevokedAfterSpending() (gas: 257186)\n[PASS] test_issuerAndTransactionOriginHaveNoSpendingPrivilege() (gas: 227629)\n[PASS] test_maxMinusOneAllowanceIsFinite() (gas: 140553)\n[PASS] test_maximumTransferAndDelegatedTransferRevertAtomically() (gas: 185616)\n[PASS] test_oneWeiAndFullSupplyRoundTrips() (gas: 568242)\n[PASS] test_selfTransferFromConsumesAllowanceWithoutMovingBalance() (gas: 243439)\n[PASS] test_zeroReceiverCannotBurnThroughTransferFrom() (gas: 322468)\n[PASS] test_zeroSpenderRejectedEvenForZeroApproval() (gas: 188003)\n[PASS] test_zeroTransferFromWithoutApprovalEmitsTransfer() (gas: 80394)\nSuite result: ok. 15 passed; 0 failed; 0 skipped; finished in 35.78ms (106.66ms CPU time)\n\nRan 2 tests for test/LaunchToken.invariant.t.sol:LaunchTokenInvariantTest\n[PASS]\nLaunchTokenInvariantTest invariants:\n[PASS] invariant_allowancesMatchOnlyAuthorizedChanges\n[PASS] invariant_metadataRemainsFixed\n[PASS] invariant_supplyAndBalancesAreConserved\n LaunchTokenInvariantTest invariants (runs: 256, calls: 24576, reverts: 0)\n\n╭--------------+---------------------------+-------+---------+----------╮\n| Contract     | Selector                  | Calls | Reverts | Discards |\n+=======================================================================+\n| TokenHandler | advanceTime               | 2370  | 0       | 0        |\n|--------------+---------------------------+-------+---------+----------|\n| TokenHandler | approve                   | 2425  | 0       | 0        |\n|--------------+---------------------------+-------+---------+----------|\n| TokenHandler | boundaryApproval          | 2478  | 0       | 0        |\n|--------------+---------------------------+-------+---------+----------|\n| TokenHandler | move                      | 2459  | 0       | 0        |\n|--------------+---------------------------+-------+---------+----------|\n| TokenHandler | moveFullBalance           | 2484  | 0       | 0        |\n|--------------+---------------------------+-------+---------+----------|\n| TokenHandler | rejectOverAllowanceSpend  | 2525  | 0       | 0        |\n|--------------+---------------------------+-------+---------+----------|\n| TokenHandler | rejectOverBalanceSpend    | 2491  | 0       | 0        |\n|--------------+---------------------------+-------+---------+----------|\n| TokenHandler | rejectOverBalanceTransfer | 2480  | 0       | 0        |\n|--------------+---------------------------+-------+---------+----------|\n| TokenHandler | rejectZeroReceiver        | 2389  | 0       | 0        |\n|--------------+---------------------------+-------+---------+----------|\n| TokenHandler | spend                     | 2475  | 0       | 0        |\n╰--------------+---------------------------+-------+---------+----------╯\n\nLogs:\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 4\n  Bound result 100\n  Bound result 0\n  Bound result 1\n  Bound result 1744\n  Bound result 9870\n  Bound result 8087\n  Bound result 0\n  Bound result 4097\n  Bound result 999001\n  Bound result 0\n  Bound result 2827\n  Bound result 655\n  Bound result 1000000\n  Bound result 19278653\n  Bound result 4\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 7827\n  Bound result 40\n  Bound result 0\n  Bound result 31535991\n  Bound result 999994\n  Bound result 1643\n  Bound result 1524\n  Bound result 439768\n  Bound result 100000000000000000000000000\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 1282\n  Bound result 659918\n  Bound result 9628\n  Bound result 6873\n  Bound result 0\n  Bound result 0\n  Bound result 24471153\n  Bound result 2941\n  Bound result 26837161\n  Bound result 7718\n  Bound result 51966\n  Bound result 282402\n  Bound result 96\n  Bound result 255\n  Bound result 0\n  Bound result 9321\n  Bound result 647\n  Bound result 0\n  Bound result 5000000000000000000\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 100000000000000000000\n  Bound result 0\n  Bound result 31150184990860438924886101\n  Bound result 0\n  Bound result 5034\n  Bound result 31535991\n  Bound result 623496\n  Bound result 18\n  Bound result 5702\n  Bound result 115792089237316195423570985008687907853269984665640464039557584007913129650175\n  Bound result 115792089237316195423570985008687907853269984665640464039557584007913129640212\n  Bound result 4097\n  Bound result 132526448823540303695336173\n  Bound result 9066\n  Bound result 37\n  Bound result 0\n  Bound result 736876\n  Bound result 3972256019223\n  Bound result 89622809563556123081897041840816014639138942293158154584485133346364573191189\n  Bound result 115792089237316195423570985008687907853269984665640564039357584003940873626919\n  Bound result 0\n  Bound result 115792089237316195423570985008687907853269984665640464039557584007913130639935\n  Bound result 125483394036324\n  Bound result 99999999999999999999\n  Bound result 29293789601624550708\n  Bound result 518\n\n[PASS] test_handlerSequenceSpendsRevokesRejectsAndRecovers() (gas: 1612841)\nLogs:\n  Bound result 100\n  Bound result 40\n  Bound result 0\n  Bound result 115792089237316195423570985008687907853269984665640564039457584007913129639935\n  Bound result 1\n  Bound result 31536000\n  Bound result 1000000\n  Bound result 60\n\nSuite result: ok. 2 passed; 0 failed; 0 skipped; finished in 9.12s (9.12s CPU time)\n\nRan 3 test suites in 9.12s (9.19s CPU time): 38 tests passed, 0 failed, 0 skipped (38 total tests)\n","passed":true},{"durationMs":41,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"LaunchToken.approve(address,uint256)\",\"LaunchToken.transfer(address,uint256)\",\"LaunchToken.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":4,\"DEPENDENCIES.md\":15,\"README.md\":62,\"foundry.toml\":20,\"launch/CHECK.md\":44,\"launch/check-status.json\":20,\"launch/intent.json\":41,\"remappings.txt\":2,\"src/LaunchToken.sol\":13,\"test/LaunchToken.adversarial.t.sol\":275,\"test/LaunchToken.invariant.t.sol\":238,\"test/LaunchToken.t.sol\":310,\"test/README.md\":52},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"c0d46e86369425e68936e945f7f19cf94cf163d2c11555e3043cea80ba291d1f","verifiedTreeHash":"e55edf22bdb8d5a9327c97a86cab3cfac6c5ae3d","verifierVersion":"0.1.0+be003835"},{"checks":[{"durationMs":970,"exitCode":0,"name":"build","output":"Compiling 27 files with Solc 0.8.26\nSolc 0.8.26 finished in 877.67ms\nCompiler run successful!\n","passed":true},{"durationMs":725,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 21 tests for test/LaunchToken.t.sol:LaunchTokenTest\n[PASS] testFuzz_allowanceLimitsAreExact(uint256,uint256) (runs: 512, μ: 183605, ~: 185890)\nLogs:\n  Bound result 1000\n  Bound result 726\n\n[PASS] testFuzz_transferRoundTripConservesSupply(uint256) (runs: 512, μ: 142162, ~: 141922)\nLogs:\n  Bound result 962632984197054541411448393\n\n[PASS] test_approvalEventAndPartialThenFullSpend() (gas: 249157)\n[PASS] test_approvalToZeroAddressReverts() (gas: 30364)\n[PASS] test_constructorEmitsSingleMint() (gas: 9135)\n[PASS] test_create2MintsToFactoryContextWithoutConstructorAllocation() (gas: 223144)\n[PASS] test_etherAndUnknownCallsRevert() (gas: 58904)\n[PASS] test_failedTransferFromRestoresAllowance() (gas: 202734)\n[PASS] test_infiniteAllowanceFollowsStandardERC20Semantics() (gas: 132413)\n[PASS] test_metadataAndEntireInitialSupply() (gas: 73910)\n[PASS] test_noMintBurnAdminOrUpgradeEntryPointsForAnyone() (gas: 1463081)\n[PASS] test_passageOfTimeDoesNotRebaseOrRestrictTransfers() (gas: 134848)\n[PASS] test_replacingAndRevokingApproval() (gas: 143196)\n[PASS] test_requestedAllocationCanBeTransferredExactly() (gas: 266518)\n[PASS] test_runtimeIsBoundedAndHasNoEscapeOpcodes() (gas: 1031140)\n[PASS] test_transferEmitsEventAndMovesExactAmount() (gas: 88828)\n[PASS] test_transferOverBalanceRevertsWithoutChangingState() (gas: 50454)\n[PASS] test_transferToContractDoesNotInvokeCallback() (gas: 170187)\n[PASS] test_unapprovedSpenderCannotMoveTokens() (gas: 51069)\n[PASS] test_zeroAddressTransferRevertsEvenForZeroAmount() (gas: 71905)\n[PASS] test_zeroAndSelfTransfersPreserveBalances() (gas: 102346)\nSuite result: ok. 21 passed; 0 failed; 0 skipped; finished in 12.01ms (32.50ms CPU time)\n\nRan 1 test for test/LaunchToken.invariant.t.sol:LaunchTokenInvariantTest\n[PASS] invariant_supplyAndBalancesAreConserved() (runs: 128, calls: 8192, reverts: 0)\n\n╭--------------+----------+-------+---------+----------╮\n| Contract     | Selector | Calls | Reverts | Discards |\n+======================================================+\n| TokenHandler | approve  | 2767  | 0       | 0        |\n|--------------+----------+-------+---------+----------|\n| TokenHandler | move     | 2686  | 0       | 0        |\n|--------------+----------+-------+---------+----------|\n| TokenHandler | spend    | 2739  | 0       | 0        |\n╰--------------+----------+-------+---------+----------╯\n\nLogs:\n  Bound result 7000000000000000000\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 4097\n  Bound result 0\n  Bound result 0\n  Bound result 3\n  Bound result 386846\n  Bound result 18\n  Bound result 0\n  Bound result 0\n  Bound result 1791\n  Bound result 5502195658302365505\n  Bound result 2173\n  Bound result 0\n  Bound result 1643\n  Bound result 0\n  Bound result 0\n  Bound result 61232\n  Bound result 0\n  Bound result 20\n  Bound result 500\n  Bound result 1898949789309431694\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 20\n  Bound result 0\n  Bound result 1000\n  Bound result 0\n  Bound result 0\n  Bound result 371\n  Bound result 242338\n  Bound result 0\n  Bound result 0\n  Bound result 2827\n  Bound result 281\n  Bound result 0\n  Bound result 205\n  Bound result 95\n  Bound result 0\n  Bound result 10000\n  Bound result 0\n  Bound result 325\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 654.88ms (653.58ms CPU time)\n\nRan 2 test suites in 655.84ms (666.89ms CPU time): 22 tests passed, 0 failed, 0 skipped (22 total tests)\n","passed":true},{"durationMs":28,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"LaunchToken.approve(address,uint256)\",\"LaunchToken.transfer(address,uint256)\",\"LaunchToken.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":4,\"DEPENDENCIES.md\":15,\"README.md\":62,\"foundry.toml\":20,\"launch/CHECK.md\":44,\"launch/check-status.json\":20,\"launch/intent.json\":41,\"remappings.txt\":2,\"src/LaunchToken.sol\":13,\"test/LaunchToken.invariant.t.sol\":95,\"test/LaunchToken.t.sol\":308},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true},{"durationMs":362,"exitCode":0,"name":"slither","output":"slither: no results at low impact or above","passed":true},{"durationMs":184,"exitCode":0,"name":"aderyn","output":"[low] large-numeric-literal at src/LaunchToken.sol:11: Large Numeric Literal","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"ff06c124bca817e0ec1d07d17d454f30a71fc375f320d6946352b4c8ee9423af","verifiedTreeHash":"84424d9106384e9ddc78d18c2abc4e8b3bfd32d5","verifierVersion":"0.1.0+be003835"}]}