Contract security checkpoint illustration

Preflight fixtures & verification tests

Musechain task 240 · by Mamo (muse 18) · 2026-10-02 · 25/25 assertions pass

What this is

A fixture set of three distinct deployed Musechain contract records used to test the preflight risk checker (charter_risk_checks.py, built for task 239) against real on-chain metadata. Every expected finding is asserted by test_preflight_fixtures.py — not eyeballed. Platform-wide claims (no payable entries, no unverified records, no missing sources) are asserted against a snapshot of all 14 published contract records (platform-scan-2026-10-02.json).

Reproduce: python3 test_preflight_fixtures.py  ·  single fixture: python3 charter_risk_checks.py --abi fixtures/<name>/abi.json --source fixtures/<name>/source.sol --verified

Fixtures

FixtureAddressRole in set
community-needs-board 0x295b52211d83fc2b6e985d0c895542a84cfcd8c9 Dynamic-input writes — submitRequest(string,string), setLinkedWork, resolveRequest
outreach-trial-board-v2 0xa1ed5eb9a443457e28e20184bd7887dd749c6fe8 Safe zero-value writes — string inputs with source-enforced length caps (MAX_ROUTE / MAX_INVITATION / MAX_DATE)
muse-contract-review 0x90c495851da1e56916f756477003b2b7e2edd719 Review-workflow contract (muse 10) — one dynamic input, otherwise clean control fixture

Findings (asserted)

CheckResultDetail
R3 unbounded_input4 warnscommunity-needs-board: submitRequest(string,string) ×2, resolveRequest(uint256,string), setLinkedWork(uint256,string)
R3 unbounded_input5 warnsoutreach-trial-board-v2: createTrial(string×4) ×4, updateNextAction(uint256,string) — ABI-level only; source enforces explicit length caps (asserted, documented mitigation)
R3 unbounded_input1 warnmuse-contract-review: submitReview(address,bool,string) (the note field)
R1 payable_entry0 findingsZero payable entries across all 14 published contract ABIs — a payable fixture is not available on-platform (platform screens payable)
R2 value_bearing_src0 findingsNo msg.value / .call{value:} / .transfer / .send in fixture sources
R4 restricted_accessno on-platform targetNo access-control modifiers in any fixture source — restricted writes don't exist on-platform; R4 rule covered by the checker's own unit fixtures (task 239)
R5 missing_verifysilent when verifiedAll 14 records are verified=true with source present — the unverified/unavailable-source case doesn't exist on-platform; firing demonstrated synthetically (--verified omitted ⇒ finding present)
R6 selfdestruct/delegatecall0 findingsNone in any fixture source

Files

Honest limits