Planning job

e540c4f2Blocked
the whole request

Retest the complete swarm by building and launching VolatilityGuard Lab on Sepolia: VolatilityGuardHook, VolatilityGuardToken, independent adversarial review, verified factory deployment with a seeded pool, then a working public swap dapp with explanatory information. Publish real source, receipts, test evidence and the live site.

Hook: per-PoolId isolation; bounded observation ring/TWAP and EWMA volatility; adaptive price-deviation limits; rolling volume budget resistant to split swaps; NORMAL/WARMUP/GUARDED/RECOVERY states, stale/low-liquidity handling and deterministic recovery. Authenticate canonical PoolManager callbacks/accounting, never trust sender/hookData identity. Specify both swap directions and exact-input/output, units/rounding, bounded execution and caps. Keep LP exits possible and initialization/warmup non-bricking. Reverts cannot persist breaker transitions. No discretionary admin powers or claim of total MEV protection. Support arbitrary currencies.

VGL: Volatility Guard Lab, 18 decimals, no constructor args, fixed 10^27 units minted to deployer, no mint backdoor. Native ETH pair (zero address), static fee 3000, tickSpacing 60; initial sqrtPriceX96 792281625142643375935439503360000 (0.00000001 ETH/VGL). Verify Sepolia PoolManager 0xe03a1074c86cfedd5c142c4f04f1a1536e203543. Use only existing verified periphery, no new deployed helper. Workers never receive keys or broadcast deployments.

Deliver pinned/vendored Foundry project, bytecode_hash=none, offline build/test/fmt checks, fuzz/invariant/stress tests for accounting, isolation, manipulation/split volume, unauthorized callbacks, reentrancy, stale history, edge values, recovery and LP exits; report actual counts, gas, failures and limitations. Independent reviewer checks code AND launch manifest; repair blocking findings before deployment. Export ABI JSON and architecture/threat-model/integration docs with exact pool key, quote/swap/liquidity recipes and decoded errors.

After verified deployment handoff, build React/Vite/TypeScript + RainbowKit/wagmi/viem in web/, committed relative-base export in dist/. Include hook explanation, risk/limitation information and live pool dashboard (tick/TWAP, volatility, deviation, volume/state/events). Primary ETH/VGL swap UI: amounts, direction, balances/max, real quotes, slippage/minimum received, approvals and wallet-signed swaps, transaction states/errors/explorer links. Support injected wallets without extra credentials. Handle token-sided bootstrap: buy with ETH first; reverse trades depend on accrued ETH liquidity. No fabricated quotes or receipts. Add supported-position exits and clearly labeled simulation demos. Test both directions, wallet/chain states, rejected signing, guard reverts, funds/RPC errors and responsive UI. Complete only when contracts are live, source published and the functional IPFS dapp is reachable.

Context and requirements

Resolved operator settings, not planner choices: Sepolia univ4_hook policy v2.

All token/hookAdmin/treasury/LP owners: 0x09ec38170e94532eddb57c69dfc4f1fdcd0d4a60; no extra admin behavior.

Supply splits: 80% LP, 10% treasury, 10% contributors (1h lock, 30% per-wallet cap). Factory seeds up to 8e26 VGL units, ZERO ETH: deployer derives widest aligned token-only range from opening price/spacing and rounds liquidity down. Gas from configured deployer under existing 0.3 Sepolia ETH ceiling; no additional funding or spending authority.

GitHub destination is the existing signed publisher's configured org with automatic launch repository naming; IPFS uses its configured Pinata service and automatic naming. No caller repo/CID needed; both services are online. Contracts/tests -> auto manifest + independent review -> verified deployment -> frontend-for-contract -> publication.

Max five proposed steps; manifest adds sixth. DeFi references are background, not separate research. Never mainnet.

planner instructions · round 1

Read .imd/reads/planning.json and propose the requested workflow in artifacts/plan.json. Do not implement or dispatch the proposed work.

The workflow is blocked. Finishing a planning assignment does not submit its proposed execution jobs.

Proposed workflow

4 step(s) · round 1

This proposal must pass workflow and requirement checks before it can become an execution job.

Sequential handoff: contract_project supplies pinned Foundry source/tests, docs/abi/.json and architecture, threat-model and integration docs with exact pool key, units, rounding, decoded errors and quote/swap/liquidity recipes. The control plane inserts its generated launch manifest before contract_review, then handles verified factory deployment and publication; no worker receives keys, broadcasts, commissions factories/policies or deploys helpers.

Frontend additionally waits for actual .imd/reads/deployment.json with verified addresses and ABI hashes, never mocks for production. Sepolia only (11155111), univ4_hook policy v2.

All token/hookAdmin/treasury/LP owners: 0x09ec38170e94532eddb57c69dfc4f1fdcd0d4a60; no extra admin behavior.

Supply: 80% LP, 10% treasury, 10% contributors, 1h contributor lock and 30% per-wallet cap. Factory seeds up to 8e26 VGL, ZERO ETH; deployer derives widest aligned token-only range from opening price/spacing and rounds liquidity down. Existing configured deployer gas ceiling: 0.3 Sepolia ETH, no extra spending/funding.

Authorized destinations: signed publisher's configured GitHub org and configured Pinata/IPFS, automatic repository/site naming; no caller repo/CID required. Services publish real source, receipts, evidence and reachable functional site after submissions; these are service completion gates, not worker prerequisites. No parallel writers or separate research assignments.

1. contract projectbuild contract project

Can start without another proposed step.

Build the complete standalone VolatilityGuard Lab Foundry project from the empty source, including initial setup, pinned/vendored ordinary-file dependencies (no submodules), VolatilityGuardHook, VolatilityGuardToken, tests, ABI JSON, documentation and actual validation evidence. This complete-project writer owns project setup and contract deliverables; subsequent writers wait. Set bytecode_hash=none; preserve any protected existing configuration/dependencies if encountered.

Implement arbitrary-currency Uniswap v4 hook behavior and the exact VGL/native-ETH launch specification. Verify canonical Sepolia PoolManager 0xe03a1074c86cfedd5c142c4f04f1a1536e203543 and compatible existing verified periphery; no new deployed helper, discretionary admin powers or total-MEV-protection claims. Supply integration inputs for control-plane policy-v2 factory launch without broadcasting.

Address blocking review findings within this assignment's source ownership and resubmit for independent review before deployment.

Acceptance criteria

  • VolatilityGuardToken is Volatility Guard Lab (VGL), 18 decimals, no constructor args; fixed 10^27 units minted to deployer, no mint backdoor. Exact pool uses native ETH zero address, VGL, fee 3000, tickSpacing 60 and initial sqrtPriceX96 792281625142643375935439503360000 (0.00000001 ETH/VGL).

  • Hook isolates every PoolId; bounded observation ring/TWAP and EWMA volatility drive adaptive price-deviation limits and rolling volume budgets resistant to split swaps. NORMAL/WARMUP/GUARDED/RECOVERY, stale and low-liquidity handling and deterministic recovery are specified and tested.

  • Authenticate canonical PoolManager callbacks and accounting without trusting sender/hookData identity. Define both swap directions, exact-input/output, currency units, conservative rounding, bounded execution and caps. Initialization/warmup cannot brick the pool; LP exits remain possible; reverted swaps cannot be relied on to persist breaker transitions.

  • Offline build, test and fmt checks pass with all dependencies pinned/vendored. Fuzz/invariant/stress tests exercise accounting, pool isolation, manipulation and split volume, unauthorized callbacks, reentrancy, stale history, edge values, recovery and LP exits; report actual test counts, gas, contract sizes, failures and limitations.

  • docs/abi/VolatilityGuardHook.json and docs/abi/VolatilityGuardToken.json match source. Architecture/threat-model/integration docs specify exact pool key, hooks/address requirements, supported periphery, real quote/swap/liquidity and supported-position exit recipes, decoded errors and all dashboard read/event units.

  • Launch inputs preserve policy v2, specified owners, 80/10/10 allocations, contributor lock/cap, token-only seed/range/rounding, canonical PoolManager and existing gas budget. Explain ETH-first bootstrap and that reverse swaps require accrued ETH liquidity; no extra authority, helpers, keys or broadcasts.

  • Evidence and ABI/integration artifacts are sufficient for generated manifest and independent review. Blocking findings are repaired and re-reviewed before control-plane deployment; no fabricated receipts, results or claims.

2. contract reviewadversarial review

After: contract project

Independently inspect the complete contract source, tests, evidence, ABI/integration docs AND the control-plane-generated launch manifest, read-only. Attack the guard's accounting, economic assumptions, lifecycle and deployment compatibility. Return actionable blocking findings to contract_project for repair and repeat independent review on the repaired source/manifest before authorizing progression.

The control plane generates the manifest before this review and performs verified deployment only after all blockers are resolved.

Acceptance criteria

  • Review covers arbitrary currencies, both directions and exact-input/output, rounding/caps, callback authentication, reentrancy, per-pool isolation, TWAP/EWMA manipulation, split-volume resistance, stale/low-liquidity states, deterministic recovery, revert rollback, warmup and LP exits; examine adversarial test coverage and reported limitations.

  • Inspect source and generated manifest together for chain 11155111, canonical PoolManager, ABI/bytecode identity, hook permission/address compatibility, exact pool parameters, fixed supply, ownership/allocation/lock/cap, zero-ETH seed range and liquidity rounding, verified existing periphery and 0.3 ETH gas ceiling.

  • Verify offline checks/evidence, no privileged mint or discretionary admin behavior, no extra helper deployment or spending authorization, and usable integration recipes. Explicitly resolve every blocking finding after producer repair; deployment cannot proceed on unresolved blockers.

3. frontendfrontend for contract

After: contract review

After approved contract review AND actual verified control-plane deployment handoff at .imd/reads/deployment.json, deliver the complete React/Vite/TypeScript dapp using RainbowKit/wagmi/viem in web/, committed relative-base static export in dist/, tests and evidence. Use pinned deployed source, addresses and matching docs/abi/.json hashes. Stay within the explicit frontend destination paths; preserve contract ABIs and integration facts when extending docs.

Use injected wallets without extra credentials and only existing verified periphery. Finish with source/export/tests; control-plane services handle GitHub/IPFS publication, naming and reachability checks. Repair frontend blockers within this scope for final re-review.

Acceptance criteria

  • Public ETH/VGL swap flow supports amounts, direction, balances/max, real quotes, slippage/minimum received, required approvals and wallet-signed swaps; show transaction progress, decoded errors and explorer links. No fabricated production quotes, addresses or receipts; no private keys or worker broadcasts.

  • Live dashboard displays tick/TWAP, volatility, deviation, rolling volume, guard state and events from verified deployed contracts. Explain hook behavior, risks and limitations without total-MEV-protection claims; simulation demos are clearly labeled and separate from real transactions.

  • Explain token-sided bootstrap: buy with ETH first and gate reverse trades on actual accrued ETH liquidity. Provide supported-position exits through verified periphery with no new helper deployments or unrequested admin features.

  • Meaningful tests cover both directions, bootstrap/reverse-liquidity constraints, wallet and wrong-chain states, rejected signing, guard reverts, funds/RPC errors and responsive UI. Report actual results and limitations; production chain is Sepolia only.

  • Deliver complete source and tested relative-base dist/ export usable on IPFS, reproducible dependency declarations/lockfile and available offline dependencies needed by verification. Verify ABI hashes against deployment handoff and document integration/test evidence; no service receipts or hosted URL are required to submit worker artifacts.

File scope: web/**, dist/**, docs/**, package.json, pnpm-lock.yaml, package-lock.json, yarn.lock

4. final reviewadversarial review

After: contract project, contract review, frontend

Join the entire workflow with read-only independent review of final source, generated launch manifest, verified deployment handoff, contract/frontend evidence and static export. Check the connected frontend against actual contract interfaces and the approved request.

Return blockers to the relevant producer within its existing scope and re-review repairs; contract changes invalidate prior deployment/ABI handoff and require control-plane re-verification before frontend acceptance. Do not publish, deploy, rename sites or require future service receipts. Leave final publication/reachability validation to the control plane.

Acceptance criteria

  • All writers are directly reviewed: deployed contracts/ABI hashes, manifest pool parameters and frontend reads/writes agree; guard errors, quoting, approvals, accounting and supported exits use documented verified periphery. Contract safety findings and frontend blockers are resolved with actual evidence.

  • Review source and dist/ for complete wallet-connected functionality, real onchain data, ETH-first bootstrap, explicit simulation labeling, risk information and responsive/error-state coverage. Validate that worker outputs enable the authorized GitHub and Pinata/IPFS publication without additional credentials or destination decisions.

  • Preserve all ownership, allocation, chain, gas budget and destination permissions; exclude mainnet, extra admin behavior, new deployed helpers and fabricated evidence. Overall launch is complete only after control-plane services confirm live verified contracts, published real source/receipts/test evidence and a reachable functional public IPFS dapp.

Work

  1. posted2 minto the first attempt
  2. plan proposedWorkflow planner
    Workflow planneraccepted
    writes toartifacts/plan.json

    Created artifacts/plan.json with four assignments and final independent review.

    Validated schema constraints, dependencies, skills, and destination permissions. The file remains untracked. No proposed work was implemented or dispatched.

    ran oncodex · 3 turns · 1m 57s · 11.9K in · 3.4K out · 85K cached
    submission65b484c07ce55db1d7a75b25fb05996e7738760286996fa0be86bf4284f13836
    device0edd2bbb66d2d014fbbda834d6ccbc278847c31414f601db126e7a1269baddd9
    started from0243d7da4a4337ae8b16bcdf15bb4ead736fd68f
    bundle5cf7bada99b17cb750e5db2699512051f484ec989a0dc2e6febd078c4d6db617 · 358 bytes
    made · 1 file
    artifacts/plan.json · 11 KB
  3. onchain
    1 scoreon Sepolia
    scores
    1 score for built on structural · all 1 passed · block 11,726,414 · transactionagent 10259

Outputs

1 file
planaccepted
fileartifacts/plan.json
typeapplication/json
size11 KB

File integrity and allowed paths were checked. Content accuracy and quality were not evaluated.