{"analyzer_versions":{"semgrep":"1.163.0"},"body":{"audit_stages":[{"blockers":[],"completed_at":"2026-09-24T16:43:45.260Z","description":"Normalize the submitted contract target and confirm it can enter the Solidity audit lane.","elapsed_ms":320,"id":"intake","label":"Audit intake","limitations":[],"next_step":"Acquire verified source or scan the pasted Solidity source.","order":1,"status":"passed"},{"blockers":[],"completed_at":"2026-09-24T16:43:45.260Z","description":"Resolve pasted source or verified explorer source without treating malformed input as demo data.","elapsed_ms":1450,"id":"source_acquisition","label":"Source acquisition","limitations":[],"next_step":"Validate the analyzer toolchain against the acquired source.","order":2,"status":"passed"},{"blockers":[],"completed_at":"2026-09-24T16:43:45.260Z","description":"Confirm the configured static analyzers can run and produce parseable output.","elapsed_ms":2300,"id":"toolchain_validation","label":"Toolchain validation","limitations":[],"next_step":"Run static analysis and capture raw detector evidence.","order":3,"status":"passed"},{"blockers":[],"completed_at":"2026-09-24T16:43:45.260Z","description":"Run static analyzers against the sandboxed source and collect raw detector evidence.","elapsed_ms":8800,"findings_count":0,"id":"static_analysis","label":"Static analysis","limitations":[],"next_step":"Normalize detector output into one deduped finding set.","order":4,"status":"passed"},{"blockers":[],"completed_at":"2026-09-24T16:43:45.260Z","description":"Dedupe detectors, classify vulnerability classes and compute severity-weighted risk.","elapsed_ms":1150,"findings_count":0,"id":"finding_normalization","label":"Finding normalization","limitations":[],"next_step":"Review exploitability conservatively against confidence and limitations.","order":5,"status":"passed"},{"blockers":[],"completed_at":"2026-09-24T16:43:45.260Z","description":"Frame automated findings with conservative exploitability and limitation notes.","elapsed_ms":1900,"findings_count":0,"id":"exploitability_review","label":"Exploitability review","limitations":["Automated exploitability review is conservative and does not replace a manual exploitability assessment."],"next_step":"Draft remediation notes from the normalized evidence.","order":6,"status":"partial"},{"blockers":[],"completed_at":"2026-09-24T16:43:45.260Z","description":"Prepare remediation-oriented evidence for the shareable report artifact.","elapsed_ms":1500,"findings_count":0,"id":"remediation_draft","label":"Remediation draft","limitations":["Remediation notes are generated from detector evidence and require project-specific engineering review."],"next_step":"Attach an operator review artifact before claiming human review.","order":7,"status":"partial"},{"blockers":["No operator review artifact is attached to this automated scan."],"completed_at":"2026-09-24T16:43:45.260Z","description":"Record whether a human operator artifact exists before buyer escalation.","elapsed_ms":0,"id":"operator_review","label":"Operator review","limitations":["Human operator review has not been attached to this automated scan yet."],"next_step":"Attach a real operator review artifact before claiming human review.","order":8,"status":"blocked"},{"artifact":{"created_at":"2026-09-24T16:43:45.260Z","id":"solidity-2f746d702f766567","label":"Automated Solidity report","type":"report"},"blockers":[],"completed_at":"2026-09-24T16:43:45.260Z","description":"Publish the automated report artifact or explain why the scan failed closed.","elapsed_ms":620,"findings_count":0,"id":"finalization","label":"Finalization","limitations":["Final report is an automated static-analysis artifact; no operator review artifact is attached."],"next_step":"Share the report with explicit limitations and review state.","order":9,"status":"partial"}],"counts":{"access-control":0,"centralization":0,"flash-loan":0,"front-running":0,"gas-dos":0,"logic":0,"math-overflow":0,"oracle-manipulation":0,"other":0,"reentrancy":0,"timestamp-dependence":0,"unchecked-call":0,"uninitialized":0},"executive_summary":["No detector raised a finding against the submitted source. This is not a guarantee of safety; manual review remains required.","Automated static analysis only. A human operator review has not been attached to this report."],"findings":[],"limitations":["VegaSec runs static analysis only. Findings can include false positives, miss patterns the configured detectors do not cover, and never replace manual auditor judgement.","Scan ran slither and semgrep against a single sandboxed copy of the source. Multi-file dependency analysis beyond what slither resolves automatically is out of scope.","This report is not a certification, audit attestation, or financial advice."],"warnings":[]},"canonical_version":"vss-canonical-1","coverage_status":"complete","final_score":100,"findings_count":0,"generated_at":"2026-09-24T16:43:45.260Z","id":"VSS-20260924-WA6CSGKV","severity_counts":{"critical":0,"high":0,"informational":0,"low":0,"medium":0},"source_filename":"Contract.sol","source_hash":"19bbc9e901ebb05e6c1309ee3778a29dbf82415b577cf7160496c29231a8ce7f","surface":"solidity","warnings_count":0}