Supply Chain
Compiler version CVEs, library dependencies, build reproducibility, and proxy pattern risk.
How This Score Is Built
Compiler version CVEs, library dependencies, build reproducibility, and proxy pattern risk.
Scoring Tree
Score Composition
Custom in-house L1Write / L1Read precompile lib (0x3333 / 0x2222 / 0x1111 endpoints) is bespoke Hyperliquid integration code — non-standard, less-audited surface (slight deduction)
Standard OpenZeppelin upgradeable libraries (AccessControlEnumerableUpgradeable, Initializable, Math, EnumerableSet/Map); pinned via git submodules (forge-std, openzeppelin-contracts, openzeppelin-contracts-upgradeable)
Modern Solidity ^0.8.20 (built-in overflow checks; the one notable unchecked subtraction is the L200-207 economic bug, not a library issue); built with via_ir=true, optimizer 200 runs
DATA GAP: exact compiler-version reproducibility / lockfile-pin commit not independently verified against deployed bytecode
Evidence Chain (1 files)
Score History
No dimension-level score changes recorded yet.