{
  "contract_version": "audit_scope_readiness.v1",
  "state": "QUOTE_READY",
  "repository": {
    "url": "https://github.com/Vetassikc/Vartovii",
    "pinned_commit": "55effcaaa01a7569d7cd483ca18b5e6b50392b9b",
    "chain": "Base",
    "nsloc": 38
  },
  "review": {
    "target": "Independent smart contract audit",
    "deadline": "2026-08-14"
  },
  "scope": {
    "in_scope": ["src/TreasuryVault.sol", "src/RoleRegistry.sol"],
    "out_of_scope": ["script/", "deployment operations"]
  },
  "commands": {
    "build": "forge build",
    "test": "forge test"
  },
  "evidence": [
    {
      "category": "repository_identity",
      "status": "EVIDENCED",
      "source": {
        "url": "https://github.com/Vetassikc/Vartovii/tree/55effcaaa01a7569d7cd483ca18b5e6b50392b9b/examples/vartovii-audit-scope-demo"
      },
      "checked_at": "2026-07-10T12:00:00Z",
      "note": "Repository identity, chain, commit, and in-scope source paths are explicit."
    },
    {
      "category": "privileged_roles_and_upgrades",
      "status": "PARTIAL",
      "source": {
        "artifact_reference": "src/RoleRegistry.sol"
      },
      "checked_at": "2026-07-10T12:04:00Z",
      "note": "Roles are visible, but deployed admin addresses and upgrade ownership evidence are absent."
    },
    {
      "category": "incident_and_disclosure_readiness",
      "status": "MISSING",
      "source": {},
      "checked_at": "2026-07-10T12:08:00Z",
      "note": "No SECURITY.md or private disclosure path was found in the synthetic fixture."
    }
  ],
  "gaps": [
    {
      "priority": "P1",
      "owner": "Protocol team",
      "required_artifact": "Deployed proxy and admin addresses",
      "audit_scoping_impact": "The auditor cannot reconcile privileged actors with the proposed scope."
    },
    {
      "priority": "P1",
      "owner": "Protocol team",
      "required_artifact": "Upgrade and emergency-action owner map",
      "audit_scoping_impact": "Quote questions remain open around upgradeable components and response authority."
    },
    {
      "priority": "P2",
      "owner": "Protocol team",
      "required_artifact": "SECURITY.md and disclosure contact",
      "audit_scoping_impact": "The handoff lacks an incident and disclosure path."
    },
    {
      "priority": "P2",
      "owner": "Lead engineer",
      "required_artifact": "Dependency exception notes",
      "audit_scoping_impact": "The auditor must rediscover why selected packages are pinned."
    },
    {
      "priority": "P2",
      "owner": "Lead engineer",
      "required_artifact": "Deployment manifest by chain",
      "audit_scoping_impact": "The review target cannot be matched cleanly to deployed instances."
    }
  ],
  "prepared_by": "Vartovii scope analyst",
  "disclaimer": "This synthetic artifact prepares audit scope and supporting evidence. It is not a smart contract audit, vulnerability assessment, or security assurance."
}
