| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | detector | Authorization based on tx.origin | no | — |
| medium | codex | CALLCODE to computed target allows execution in caller storage | no | — |
| medium | codex | tx.origin used in guard logic (phishing-prone if used for auth) | no | — |
| medium | detector | Untrusted CALL target/value reachable | no | no |
| medium | detector | CREATE/CREATE2 reachable | no | no |
| medium | detector | ETH value transfer possible | no | no |
| low | codex | Value-carrying CALLs to computed targets (untrusted-call risk, target uncertainty) | no | — |
| low | codex | CREATE2 opcode reachable (factory capability) | no | — |
| low | cast | Contract creation opcode present | no | — |
| info | cast | Heavy CALL-family usage | no | — |
| info | cast | Heavy EXTCODE*/BALANCE usage | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 019bb377-699e-73c4-bcd1-6c9ed4a4ebb9 | complete | crit 0 high 0 | 11 | 3 months ago |