{
  "reports": {
    "R-001": {
      "title": "Unbounded approval drift in Celo ecosystem token distributor",
      "severity": "HIGH",
      "priceCusd": "0.01",
      "summary": "Distributor contract allows infinite approvals to drift after role rotation.",
      "project": "CeloSentry Demo Vault"
    },
    "R-002": {
      "title": "cUSD fee-currency rounding leak in x402 facilitator flow",
      "severity": "MEDIUM",
      "priceCusd": "0.01",
      "summary": "Rounding direction leaks dust to the caller on partial settlements.",
      "project": "CeloSentry Demo Vault"
    },
    "R-003": {
      "title": "Critical authorization bypass in Celo rewards distributor",
      "severity": "CRITICAL",
      "priceCusd": "0.01",
      "summary": "A callable reward-claim path does not bind the signed authorization to the intended beneficiary.",
      "project": "CeloSentry Demo Vault"
    },
    "R-004": {
      "title": "Critical emergency pause bypass through alternate withdrawal path",
      "severity": "CRITICAL",
      "priceCusd": "0.01",
      "summary": "The emergency pause stops deposits but leaves an alternate withdrawal route callable.",
      "project": "CeloSentry Demo Vault"
    },
    "R-005": {
      "title": "Stale oracle price accepted during Celo collateral update",
      "severity": "MEDIUM",
      "priceCusd": "0.01",
      "summary": "A collateral operation accepts an oracle round outside the intended freshness window.",
      "project": "CeloSentry Demo Vault"
    },
    "R-006": {
      "title": "Missing slippage bound in stablecoin rebalance helper",
      "severity": "MEDIUM",
      "priceCusd": "0.01",
      "summary": "The rebalance helper executes a swap without a minimum output bound supplied by the caller.",
      "project": "CeloSentry Demo Vault"
    },
    "R-007": {
      "title": "Insufficient nonce separation in signed payout requests",
      "severity": "MEDIUM",
      "priceCusd": "0.01",
      "summary": "Payout signatures use a shared nonce namespace across assets and recipients.",
      "project": "CeloSentry Demo Vault"
    },
    "R-008": {
      "title": "Dust accumulation in fee refund calculation",
      "severity": "LOW",
      "priceCusd": "0.01",
      "summary": "Integer truncation leaves small unaccounted fee dust on repeated refunds.",
      "project": "CeloSentry Demo Vault"
    },
    "R-009": {
      "title": "Missing zero-address validation in reward configuration",
      "severity": "LOW",
      "priceCusd": "0.01",
      "summary": "An administrator can configure a zero token or recipient address.",
      "project": "CeloSentry Demo Vault"
    },
    "R-010": {
      "title": "Event omits effective recipient in fee settlement",
      "severity": "LOW",
      "priceCusd": "0.01",
      "summary": "Settlement events do not expose the final recipient used by downstream indexers.",
      "project": "CeloSentry Demo Vault"
    },
    "R-011": {
      "title": "Critical upgrade authorization gap in proxy admin handoff",
      "severity": "CRITICAL",
      "priceCusd": "0.01",
      "summary": "The upgrade handoff can leave a transient state where both old and new administrators can authorize upgrades.",
      "project": "CeloSentry Demo Vault"
    },
    "R-012": {
      "title": "Callback reentrancy in token recovery function",
      "severity": "MEDIUM",
      "priceCusd": "0.01",
      "summary": "A recovery function performs an external token callback before updating its internal accounting.",
      "project": "CeloSentry Demo Vault"
    }
  },
  "ledger": {
    "settlements": 19,
    "findings": 0
  }
}