| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | detector | Untrusted CALL target/value reachable | no | no |
| high | detector | ETH value transfer possible | no | no |
| medium | codex | Swap pricing fully trusts external oracle output (no invariant check) | no | — |
| low | codex | Permit signatures are malleable (no EIP‑2 `s`/`v` checks) | no | — |
| low | codex | Pair initialization can be called multiple times by the factory | no | — |
| info | cast | Heavy CALL-family usage | no | — |
| info | cast | Heavy EXTCODE*/BALANCE usage | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 7f435b0b-07c9-42c2-8634-81c9a806bf16 | complete | crit 0 high 0 | 7 | 3 months ago |