Aegis is a Seed-stage concept and local synthetic/mock validation artifact. It is not deployed, does not hold funds and does not include live Alpend or OneSwap credentials/interfaces.
Please report vulnerabilities privately to the repository owner through GitHub's private vulnerability reporting feature when enabled. Do not include private keys, wallet seeds, credentials or sensitive borrower data in an issue.
Include:
- affected commit/file;
- minimal reproduction;
- security impact within the documented mock boundary;
- suggested mitigation if known.
- fail-open simulator paths;
- arithmetic/state mutation errors;
- Daml authorization or direct-create invariant bypass;
- lifecycle races and replay within implemented contracts;
- release packaging that leaks secrets or contradicts claim boundaries;
- misleading evidence generation.
- no official/live Alpend integration;
- no authenticated OneSwap receipt adapter;
- no real-capital deployment;
- no full Python–Daml economic parity;
- the synthetic constant-product venue model.
A vulnerability may still exist if the code falsely claims or behaves as though one of these limitations were solved.
- fail closed on missing, malformed, stale, future or unknown evidence;
- preserve canonical protocol authority;
- separate projected from realized state;
- require multi-party authorization for lifecycle evidence;
- bind policy/state provenance;
- never treat ambiguous execution as terminal success;
- publish bounded evidence rather than broad assurances.