{
  "id": "VEYLOCK-2026-09-14-01",
  "title": "VEYLOCK internal audit report",
  "date": "2026-09-14",
  "reviewer": "Codex \u2014 internal AI-assisted review",
  "status": "Review complete; follow-up required",
  "independentAudit": false,
  "scope": "Local source snapshot, contract behavior, wallet transaction paths, public reads, dependency advisories and static hosting configuration",
  "tests": {
    "command": "npm test",
    "passed": 28,
    "failed": 0,
    "environment": "Node 24.14.1; local Ganache EVM; Solidity 0.8.30; optimizer 200 runs; Shanghai target"
  },
  "findings": [
    {
      "id": "VL-01",
      "severity": "Medium",
      "status": "Open",
      "title": "Large account histories can hide the dashboard",
      "location": "src/app.js \u00b7 refresh()",
      "evidence": "Source inspection: refresh() throws once the collected schedule IDs reach 2,000, including exactly 2,000. Its catch handler clears every displayed row. Anyone can create a funded schedule naming an arbitrary recipient.",
      "impact": "A sufficiently large history, including unsolicited schedules, can make the normal account dashboard unavailable. This does not change contract balances or recipient permissions. The public viewer can still read a known schedule ID.",
      "recommendation": "Paginate the dashboard and retain already loaded rows. Show the remaining-page state instead of clearing the workspace. Add a 2,000-schedule boundary regression.",
      "validation": "Confirmed from source; the full 2,000-transaction scenario was not executed."
    },
    {
      "id": "VL-02",
      "severity": "Low",
      "status": "Open",
      "title": "Extreme contract dates have an ambiguous display",
      "location": "contracts/Veylock.sol \u00b7 createSchedule(); src/app.js and src/public-vesting.js \u00b7 date formatting",
      "evidence": "A local transaction successfully created a schedule ending at uint64 max. The browser conversion rounded 18446744073709551615 to 18446744073709552000 and displayed \u201cInvalid Date\u201d.",
      "impact": "Schedules created outside the normal date form can show unreadable dates. Conversion to Number also loses precision outside the safe integer range. No fund loss was reproduced; the local vesting amount probe matched the contract in this specific case.",
      "recommendation": "Preserve uint64 timestamps as strings or BigInt and display exact Unix seconds when a date is outside the browser calendar range. Keep all financial time arithmetic exact.",
      "validation": "Reproduced on a local Ganache EVM; see the evidence JSON."
    },
    {
      "id": "VL-03",
      "severity": "Low",
      "status": "Open",
      "title": "Creation receipt parsing does not check the emitter",
      "location": "src/app.js \u00b7 confirmCreate()",
      "evidence": "The client chooses the first log that parses as ScheduleCreated. A synthetic log bearing a different emitter address was accepted by the same ABI parser.",
      "impact": "A nonstandard token emitting an identically shaped event before the workspace event could misdirect the saved label or opened schedule ID. The real contract allocation and beneficiary are unaffected.",
      "recommendation": "Filter receipt logs by the selected workspace address before parsing the event, and verify its creator, token and amount.",
      "validation": "Parser behavior reproduced locally; a complete malicious-token browser transaction was not executed."
    },
    {
      "id": "VL-04",
      "severity": "High \u00b7 tooling",
      "status": "Open",
      "title": "Local Ganache dependency tree contains known advisories",
      "location": "package-lock.json \u00b7 node_modules/ganache/node_modules/*",
      "evidence": "npm audit --omit=dev reported 27 affected package entries: 4 critical, 17 high, 5 moderate and 1 low. Every reported node is nested under Ganache, which is declared as a devDependency.",
      "impact": "These advisories concern the local test/build environment. Ganache is not imported by the browser entry points and is not copied into the Pages export. The command\u2019s omit flag alone is therefore not a reliable production-exposure label for this installed tree.",
      "recommendation": "Replace or isolate the outdated local EVM toolchain and re-run the advisory scan. Do not use this Ganache instance as a public RPC service.",
      "validation": "Registry scan captured on September 14, 2026; paths checked against the application imports and export allowlist. No independent exploitability analysis of all 27 entries was performed."
    }
  ],
  "sources": [
    {
      "path": "contracts/Veylock.sol",
      "sha256": "e6d0917f76d6e3daba33920dde7a1b3f7edcc61d4d9b507b187839d6528701a1",
      "snapshot": "/audit/reference/contracts--Veylock.sol.txt"
    },
    {
      "path": "src/app.js",
      "sha256": "70041c1ad2cd330ac4f1850abfd35fa2ffbf97e4d5694cbd5779b14d3642409e",
      "snapshot": "/audit/reference/src--app.js.txt"
    },
    {
      "path": "src/vesting.js",
      "sha256": "dfaac6f1230e135f1611caa39217c24d7659e03972518443a271448e4aebce24",
      "snapshot": "/audit/reference/src--vesting.js.txt"
    },
    {
      "path": "src/public-reader.js",
      "sha256": "4f312e3eae0dcfb5c1f9e70e468e592afb83c179daf1f902e61c77e0cdc492cf",
      "snapshot": "/audit/reference/src--public-reader.js.txt"
    },
    {
      "path": "src/public-vesting.js",
      "sha256": "c014748106f2f0d4ca1776388b08fe1fec1bf3498a0832e240258e67cb1276ca",
      "snapshot": "/audit/reference/src--public-vesting.js.txt"
    },
    {
      "path": "src/wallet-tokens.js",
      "sha256": "78155a3ab614158c82cffb46d850f2bba962741132bf7909e096e2ad6ba8f641",
      "snapshot": "/audit/reference/src--wallet-tokens.js.txt"
    },
    {
      "path": "src/token-metadata.js",
      "sha256": "968e57492ff378a81dd5610d23d0810810fc7894a93517345c6c989f5f72ba4c",
      "snapshot": "/audit/reference/src--token-metadata.js.txt"
    },
    {
      "path": "tests/contracts.test.mjs",
      "sha256": "ecacddbb6ffe1fbbc0dca8ab1f199026f72055c15b0e9af46376e4f49767d2c2",
      "snapshot": "/audit/reference/tests--contracts.test.mjs.txt"
    },
    {
      "path": "tests/public-reader.test.mjs",
      "sha256": "973b17dc0df9c1bcdcbebb4c161bd57c443d8d341b06a6643a8e1ecf900f387d",
      "snapshot": "/audit/reference/tests--public-reader.test.mjs.txt"
    },
    {
      "path": "tests/vesting.test.mjs",
      "sha256": "12ddcfad1427719a5772ab21831fc4def3a345ef38d68ac22dc89a6eed36db23",
      "snapshot": "/audit/reference/tests--vesting.test.mjs.txt"
    },
    {
      "path": "tests/wallet-tokens.test.mjs",
      "sha256": "a1e5abcbff7261706ffcfa2a0f01178c4dee038328df4da18f3c266f73d6d925",
      "snapshot": "/audit/reference/tests--wallet-tokens.test.mjs.txt"
    },
    {
      "path": "tests/token-metadata.test.mjs",
      "sha256": "605dcc6345cf8958cf86e48a34b742205416583cb4a099878fce4b77807b1730",
      "snapshot": "/audit/reference/tests--token-metadata.test.mjs.txt"
    },
    {
      "path": "scripts/build.mjs",
      "sha256": "54c29b13fcea02d875c546fc8d1402dd9de71c0b916d6cde44c42f6cbbeb207b",
      "snapshot": "/audit/reference/scripts--build.mjs.txt"
    },
    {
      "path": "scripts/build-cloudflare.mjs",
      "sha256": "68e537c4cd1931275935a8df7f615111666ab4193c1a3fd37845e9ae2db2d3bc",
      "snapshot": "/audit/reference/scripts--build-cloudflare.mjs.txt"
    },
    {
      "path": "package.json",
      "sha256": "dcd8eec8b4a161574a9938872c77224dc04362fb2ff7bd7da09a08155414ec89",
      "snapshot": "/audit/reference/package.json.txt"
    },
    {
      "path": "package-lock.json",
      "sha256": "3c7790ae3b7c569de6c1a3d7b69762850933c2f7322dd4dee85367d7f3fc0465",
      "snapshot": "/audit/reference/package-lock.json.txt"
    },
    {
      "path": "scripts/audit-evidence.mjs",
      "sha256": "62df2b0b732b3977677ac67ec334de23f6f1f536c862937a8aeea9a6124de041",
      "snapshot": "/audit/reference/scripts--audit-evidence.mjs.txt"
    },
    {
      "path": "public/build/contracts.json",
      "sha256": "49f0c5ed0a5aea227b51af8e3800d7b6406ec1ce344a476cd00d025b363a4ca7",
      "snapshot": "/audit/reference/public--build--contracts.json.txt"
    }
  ],
  "limitations": [
    "No independent external auditor or certification.",
    "No mainnet wallet transaction, deployed workspace address or live contract bytecode was validated by this review.",
    "No formal verification, coverage percentage, dedicated static-analysis engine, fuzzing campaign or comprehensive reentrancy test suite.",
    "The wallet-extension signing flow was inspected in source, not exercised end-to-end in a wallet-enabled browser.",
    "Third-party tokens, RPC/indexer operations, hosting-account security and all transitive dependency implementations are outside comprehensive coverage.",
    "This is a dated source snapshot, not continuous assurance of later releases."
  ]
}