Can start without another proposed step.
Build and test the complete VolatilityGuard Lab Foundry project from the supplied empty source, including initial setup and pinned ordinary-file vendored dependencies, VolatilityGuardHook and VolatilityGuardToken, ABI exports and architecture/threat-model/integration documentation. This complete-project writer owns initial project setup; preserve any protected existing configuration/dependencies. Set bytecode_hash=none and prove offline build/test/fmt.
Implement the coupled hook/token and launch-ready integration without deploying anything, new deployed helpers, factory/policy commissioning or extra admin behavior. Use the supplied DeFi references as implementation background, not a research assignment. Supply actual test/gas/size/failure/limitation evidence and all source inputs needed by the control-plane manifest.
Repair blocking independent-review findings before deployment.
Acceptance criteria
Hook isolates every PoolId, supports arbitrary currencies, uses bounded observation ring/TWAP and EWMA volatility, adaptive price-deviation limits and rolling volume budgets resistant to split swaps. Define NORMAL/WARMUP/GUARDED/RECOVERY, stale/low-liquidity behavior and deterministic recovery; initialization/warmup cannot brick the pool and LP exits remain possible. Breaker transitions must not rely on reverted writes.
Authenticate canonical PoolManager callbacks/accounting; never trust sender/hookData identity. Specify both directions, exact-input and exact-output, units, rounding, caps and bounded execution. No discretionary admin powers or claims of total MEV protection. Verify Sepolia PoolManager 0xe03a1074c86cfedd5c142c4f04f1a1536e203543 and existing verified periphery; no newly deployed helper.
VolatilityGuardToken is Volatility Guard Lab (VGL), 18 decimals, no constructor arguments, fixed 10^27 units minted to deployer, no mint backdoor. Pair native ETH (zero address) with VGL using static fee 3000, tickSpacing 60, initial sqrtPriceX96 792281625142643375935439503360000 (0.00000001 ETH/VGL); document the exact sorted pool key and hook permissions.
Preserve all token/hookAdmin/treasury/LP owners as 0x09ec38170e94532eddb57c69dfc4f1fdcd0d4a60, with no extra admin behavior. Supply allocations: 80% LP, 10% treasury, 10% contributors, 1h contributor lock and 30% per-wallet cap. Launch specification uses resolved Sepolia univ4_hook policy v2, not worker-chosen ownership or policy.
Factory seeds up to 8e26 VGL units and ZERO ETH. Document/test the deployer derivation of widest aligned token-only range from opening price/spacing, rounding liquidity down. Gas comes from configured deployer under existing 0.3 Sepolia ETH ceiling; no additional funding/spending authority. No worker keys or broadcasts.
Pinned/vendored ordinary files support network-free build, test and fmt with bytecode_hash=none, no submodules. Run meaningful fuzz/invariant/stress coverage for accounting, isolation, manipulation/split volume, unauthorized callbacks, reentrancy, stale history, edge values, recovery and LP exits, including swap modes/directions; record actual counts, gas, sizes, failures and limitations in docs/contract-evidence.md.
Export valid ABI JSON at docs/abi/VolatilityGuardHook.json and docs/abi/VolatilityGuardToken.json. Deliver architecture/threat-model docs and docs/integration.md defining dashboard reads/events, units, exact pool key, quote/swap/liquidity recipes, supported-position exits and decoded errors. Explain token-only bootstrap and accrued-ETH limits for reverse swaps; evidence contains no fabricated receipts.