EVIDENCED
Repository and scope anchor
Repository identity, chain, commit, and in-scope source paths are explicit.
Source: Repository tree at 55effcaaa01a7569d7cd483ca18b5e6b50392b9b
Checked: 2026-07-10T12:00:00Z
This synthetic pack demonstrates the exact manual artifact shape. It is not a smart contract audit, vulnerability review, or security assurance.
Artifact identity
Scope and commands
In-scope and out-of-scope manifest
In scope: src/TreasuryVault.sol and src/RoleRegistry.sol. Out of scope: script/, test/fixtures/, and deployment operations.
Build and test commands
forge build
forge test
Architecture and actor map
TreasuryVault can receive assets and RoleRegistry assigns operator and emergency roles. Deployment addresses and any upgrade path remain missing evidence.
EVIDENCED
Repository identity, chain, commit, and in-scope source paths are explicit.
Source: Repository tree at 55effcaaa01a7569d7cd483ca18b5e6b50392b9b
Checked: 2026-07-10T12:00:00Z
PARTIAL
Roles are visible in source, but deployed addresses and upgrade-path evidence are absent.
Source: examples/vartovii-audit-scope-demo/src/RoleRegistry.sol
Checked: 2026-07-10T12:04:00Z
MISSING
No SECURITY.md or private disclosure path was found at the pinned commit.
Source: Pinned repository root and docs/
Checked: 2026-07-10T12:08:00Z
Prioritized gaps
Protocol team
Deployed proxy/admin addresses
The auditor cannot reconcile privileged actors with the proposed scope.
Protocol team
Upgrade and emergency-action owner map
Quote questions remain open around upgradeable components and response authority.
Protocol team
SECURITY.md and disclosure contact
The handoff lacks an incident and disclosure path.
Lead engineer
Dependency exception notes
The auditor must rediscover why selected packages are pinned.
Lead engineer
Deployment manifest by chain
The review target cannot be matched cleanly to deployed instances.
Auditor-ready RFQ summary
Review two Solidity source files at the pinned commit on Base. Confirm quote assumptions for proxy ownership, privileged roles, dependency review, deployment reconciliation, and remediation follow-up.
Delivery formats: branded PDF plus machine-readable YAML/JSON. The founding pilot includes one async revision within seven days.
Not claimed
No guarantee of audit acceptance, audit price, grant approval, absence of vulnerabilities, launch safety, or any security outcome. No finding in this sample is a vulnerability finding.