{"analyzer_versions":{"semgrep":"1.163.0"},"body":{"audit_stages":[{"completed_at":"2026-05-29T03:34:47.037Z","description":"Normalize the submitted contract target and confirm it can enter the Solidity audit lane.","id":"intake","label":"Audit intake","limitations":[],"status":"passed"},{"completed_at":"2026-05-29T03:34:47.037Z","description":"Resolve pasted source or verified explorer source without treating malformed input as demo data.","id":"source_acquisition","label":"Source acquisition","limitations":[],"status":"passed"},{"completed_at":"2026-05-29T03:34:47.037Z","description":"Confirm the configured static analyzers can run and produce parseable output.","id":"toolchain_validation","label":"Toolchain validation","limitations":["One or more analyzers emitted warnings; report findings remain usable but should be read with limitations."],"status":"partial"},{"completed_at":"2026-05-29T03:34:47.037Z","description":"Run static analyzers against the sandboxed source and collect raw detector evidence.","id":"analyzer_execution","label":"Analyzer execution","limitations":["One or more analyzers emitted warnings; report findings remain usable but should be read with limitations."],"status":"partial"},{"completed_at":"2026-05-29T03:34:47.037Z","description":"Dedupe detectors, classify vulnerability classes and compute severity-weighted risk.","id":"finding_aggregation","label":"Finding aggregation","limitations":[],"status":"passed"},{"completed_at":"2026-05-29T03:34:47.037Z","description":"Frame automated findings with conservative exploitability and limitation notes.","id":"exploitability_context_review","label":"Exploitability context review","limitations":["Automated context review is conservative and does not replace a manual exploitability assessment."],"status":"partial"},{"completed_at":"2026-05-29T03:34:47.037Z","description":"Prepare remediation-oriented evidence for the shareable report artifact.","id":"remediation_draft","label":"Remediation draft","limitations":["Remediation notes are generated from detector evidence and require project-specific engineering review."],"status":"partial"},{"completed_at":"2026-05-29T03:34:47.037Z","description":"Flag whether a human operator has reviewed the automated result before buyer escalation.","id":"operator_review","label":"Operator review","limitations":["Human operator review has not been attached to this automated scan yet."],"status":"blocked"},{"completed_at":"2026-05-29T03:34:47.037Z","description":"Publish the report artifact or explain why the scan failed closed.","id":"final_report","label":"Final report","limitations":[],"status":"passed"}],"counts":{"access-control":0,"centralization":0,"flash-loan":0,"front-running":0,"gas-dos":0,"logic":0,"math-overflow":0,"oracle-manipulation":0,"other":0,"reentrancy":0,"timestamp-dependence":0,"unchecked-call":1,"uninitialized":0},"executive_summary":["1 finding surfaced (0 critical, 0 high, 1 medium, 0 low, 0 informational).","No critical or high severity findings; medium and low signals still require operator review before public promotion.","Automated static analysis only. A human operator review has not been attached to this report."],"findings":[{"class":"unchecked-call","confidence":"unknown","description":"Low-level .call to an externally-controlled target. Combined with reentrancy or unchecked return values, this is a common fund-draining pattern.","exploitability":"unknown","exploitability_note":"Analyzer did not report a confidence level; treat as unverified until reviewed.","file":"Contract.sol","id":"77a805d0bc3b9d557233741248c529f8ea37d76ff3526d553a60a241a48ad384","line":4,"references":["https://github.com/JE4NVRG/vegasec/blob/main/apps/web/src/lib/risk/solidity/semgrep-rules/vegasec-solidity.yml#vegasec-low-level-call-untrusted"],"remediation":"Check the boolean return of low-level call/delegatecall/send and revert on failure with a descriptive reason string.","rule_id":"semgrep:vegasec-low-level-call-untrusted","severity":"medium","source":"semgrep","title":"Low-level"}],"limitations":["VegaSec runs static analysis only. Findings can include false positives, miss patterns the configured detectors do not cover, and never replace manual auditor judgement.","Scan ran slither and semgrep against a single sandboxed copy of the source. Multi-file dependency analysis beyond what slither resolves automatically is out of scope.","Some detectors emitted warnings (see `warnings`); their output was still ingested but should be read with extra care.","This report is not a certification, audit attestation, or financial advice."],"warnings":["slither exit 1: "]},"canonical_version":"vss-canonical-1","coverage_status":"unknown","final_score":95,"findings_count":1,"generated_at":"2026-05-29T03:34:47.037Z","id":"VSS-20260529-ZY120KX9","severity_counts":{"critical":0,"high":0,"informational":0,"low":0,"medium":1},"source_filename":"Contract.sol","source_hash":"4151a8c205de3dc840f975f3a711c42ca5aaa8368904cf52c5ec3fdfcbd296fb","surface":"solidity","warnings_count":1}