Explore/Sui Campaign/Polymedia Explorer
Hosted appExplorerSui Testnet ↗succeeded

Open-source fork of the original Sui Explorer, covering transactions, checkpoints, objects and validators, with an in-app network switch. Tested in place on Sui Testnet.

Tested in place byDeepQA TeamonSui Testnetatexplorer.polymedia.app/?network=testnetonSep 27, 2026

Run #1model gemini-balanced (vertex)took 8m

6 of 12 scenarios passed, 6 failed, no issues after the audit.

Share on X
Polymedia Explorer in the browser during the run

By the numbers

6 of 12
scenarios passed, 6 failed
172
browser actions
30
screenshots
143
model calls
8.1
minutes
12
scenarios
6
passed
6
failed
0
blocked
0
issues

Walkthrough

Every scenario DeepQA drove in the browser, in plan order, with the 25 screenshots it captured along the way. A passing scenario is evidence too.

  1. S1
    Search for Address

    4 steps, 4 screenshotson-chain

    fail
    S1-1.png
    S1, Search for Address
    S1-3.png
    S1, Search for Address
    S1-11.png
    S1, Search for Address
    S1-15.png
    S1, Search for Address
    • Navigated to https://explorer.polymedia.app/?network=testnet.
    • Verified that the network selector shows Testnet.
    • Focused the search input combobox and entered the address 0x0000000000000000000000000000000000000000000000000000000000000002.
    • Pressed Enter to submit search.
    • The search combobox rendered 'No Results' and did not navigate to the address detail route (/address/0x0000000000000000000000000000000000000000000000000000000000000002).
  2. S2
    Search for Checkpoint

    4 steps, 2 screenshots

    fail
    S2-1.png
    S2, Search for Checkpoint
    S2-6.png
    S2, Search for Checkpoint
    • Navigated to Polymedia Explorer on Testnet.
    • Entered '1000' in search input and pressed Enter; search displayed 'No Results' and did not navigate to /checkpoint/1000.
    • Verified network selector shows Testnet.
    • Typed '1000' in search input and pressed Enter, which showed 'No Results' without routing to /checkpoint/1000.
  3. S3
    Search with Invalid Input

    4 steps, 2 screenshots

    pass
    S3-1.png
    S3, Search with Invalid Input
    S3-5.png
    S3, Search with Invalid Input
    • Loaded Polymedia Explorer on Testnet with search bar ready.
    • Entered 'invalid_random_string' in the search input and observed the inline message 'No Results' without navigating or crashing.
    • The network badge displayed 'Testnet'.
    • Typing 'invalid_random_string' into the Search input immediately displayed an inline 'No Results' indicator under the search field.
    • Pressing Enter did not trigger an unhandled error or navigate away to a broken route.
  4. S4
    Switch Network via Selector

    3 steps, 3 screenshots

    pass
    S4-1.png
    S4, Switch Network via Selector
    S4-3.png
    S4, Switch Network via Selector
    S4-5.png
    S4, Switch Network via Selector
    • Loaded initial page on Testnet with network button displaying 'Testnet'.
    • Clicked network selector button, revealing options for Mainnet, Testnet, Devnet, Local, and Custom RPC URL.
    • Selected Mainnet; URL successfully updated to include '?network=mainnet' and the selector button updated to 'Mainnet'.
    • The network dropdown menu opened upon clicking the network selector button.
    • Selecting 'Mainnet' updated the application URL to '?network=mainnet' and changed the selector label to 'Mainnet'.
  5. S5
    Navigate Homepage Tabs

    3 steps, 3 screenshots

    fail
    S5-2.png
    S5, Navigate Homepage Tabs
    S5-5.png
    S5, Navigate Homepage Tabs
    S5-11.png
    S5, Navigate Homepage Tabs
    • On clicking the Validators tab on the homepage, no validator list or panel content is rendered, and existing header links are removed from the page.
    • The application was confirmed on Testnet via the network selector displaying 'Testnet'.
    • On the homepage, the initial tab list displays Transaction Blocks and Validators tabs.
    • Clicking the Validators tab does not load or render validator data, leaving the tab panel area blank.
  6. S6
    Render Address Details

    2 steps, 1 screenshoton-chain

    pass
    S6-2.png
    S6, Render Address Details
    • Navigated to address 0x0000000000000000000000000000000000000000000000000000000000000002 on Sui Testnet, which rendered the address header, copy button, and Owned Objects tabpanel.
    • The address details page loaded successfully for address 0x0000000000000000000000000000000000000000000000000000000000000002 on Sui Testnet.
    • The page rendered the address header, copy button, and Owned Objects tabpanel structure without errors or blank screens.
  7. S7
    Render Object Details

    2 steps, 2 screenshotson-chain

    fail
    S7-2.png
    S7, Render Object Details
    S7-12.png
    S7, Render Object Details
    • Navigated to https://explorer.polymedia.app/object/0x2?network=testnet and observed that the page displays 'Data could not be extracted on the following specified object ID: 0x2' instead of rendering the object details, ownership, or type.
    • Confirmed network shown is Testnet in the header selector.
    • Navigating to https://explorer.polymedia.app/object/0x2?network=testnet resulted in 'Data could not be extracted on the following specified object ID: 0x2'.
    • Tested full 32-byte hex ID 0x0000000000000000000000000000000000000000000000000000000000000002 and system object 0x6 with identical extraction failures.
  8. S8
    Render Checkpoint Details

    2 steps, 2 screenshots

    fail
    S8-2.png
    S8, Render Checkpoint Details
    S8-6.png
    S8, Render Checkpoint Details
    • Navigated to checkpoint 1000 on testnet; the page displays 'There was an issue retrieving data for checkpoint: 1000'.
    • Verified the application network selector displays 'Testnet'.
    • Navigated to https://explorer.polymedia.app/checkpoint/1000?network=testnet.
    • The page does not render the checkpoint summary, sequence number, or timestamp, and instead displays 'There was an issue retrieving data for checkpoint: 1000'.
  9. S9
    Render Epoch Details

    2 steps, 2 screenshots

    fail
    S9-2.png
    S9, Render Epoch Details
    S9-9.png
    S9, Render Epoch Details
    • Navigated to https://explorer.polymedia.app/epoch/0?network=testnet and observed that instead of displaying epoch details, duration, and start/end boundaries, the page displayed an error message 'There was an issue retrieving data for epoch 0.'
    • Verified that the network selector shows Testnet.
    • Navigating to /epoch/0?network=testnet results in the error message 'There was an issue retrieving data for epoch 0.' without loading epoch metrics, duration, or boundary data.
  10. S10
    Handle Missing Transaction Block

    2 steps, 1 screenshot

    pass
    S10-2.png
    S10, Handle Missing Transaction Block
    • Navigated to missing transaction block URL and verified that the application displays a clear 'Invalid Transaction digest' error message gracefully without crashing.
    • The network is set to Testnet.
    • Navigating to a non-existent or invalid transaction block digest displays 'Invalid Transaction digest: Data could not be extracted for the following specified transaction ID: 11111111111111111111111111111111111111111111' cleanly.
  11. S11
    Render Validators List

    2 steps, 1 screenshot

    pass
    S11-3.png
    S11, Render Validators List
    • Navigated to /validators?network=testnet and observed the inline message 'Validator data could not be loaded' when fetching validator data from the RPC.
    • Network indicator confirmed as Testnet.
    • Navigated to /validators?network=testnet and observed that the page rendered an inline error message 'Validator data could not be loaded' as feedback when RPC validator data was unavailable.
  12. S12
    Header Home Link Integrity

    2 steps, 2 screenshots

    pass
    S12-2.png
    S12, Header Home Link Integrity
    S12-4.png
    S12, Header Home Link Integrity
    • Navigated to validators page with network set to Testnet.
    • Clicked the header home logo link and successfully returned to the root dashboard at /?network=testnet.
    • The header home link on /validators?network=testnet links to /?network=testnet and successfully navigates back to the root dashboard when clicked.

Issues

Findings that survived the Critic's audit. Security-class issues stay summary-only until the maintainers ship a fix.

highwithdrawnfunctionalF3 in S5

Validators tab fails to render content and causes homepage elements to unmount

I clicked on the Validators tab and observed that no content was rendered in the Validators tab panel. Furthermore, the Epoch link, @juzybits link, SOURCE CODE link, and MORE PROJECTS link all disappeared from the header as reported. The page reported 2 console errors during the scenario. Hand re-check, 2026-09-27: reproduced on the live app in a real browser after the runner's tab-panel snapshot fix (44cdfe8). Clicking the Validators tab shows its own tabpanel with a plain 'Validator data could not be loaded' message (a real, separate CORS-driven limitation, not a rendering failure), and the header's Epoch, @juzybits, SOURCE CODE and MORE PROJECTS links were confirmed present and unchanged both before and after the click, in two independent page loads. The harness could not see content inside a tab panel (fixed 44cdfe8), which is what produced this finding originally.

Expected

The Validators tab panel should render validator data and replace the Transaction Blocks view.

Actual

The Validators tab panel renders no content, and header links (@juzybits, SOURCE CODE, MORE PROJECTS, Epoch link) disappear from the page.

3 repro steps
  1. Navigate to https://explorer.polymedia.app/?network=testnet
  2. Click on the 'Validators' tab
  3. Observe the content area below the tabs

Environment limitations

These failures came from the test environment, not from the application: a credential the sandbox does not hold, a demo nobody may write to, a resource it cannot reach. They are not counted as issues.

  • Search does not navigate to address detail page when pressing Enter on a valid addressS1, high

    The search fails to resolve the address because the test environment's CORS policy blocks requests to the Sui fullnode RPC. The audit recorded the test environment as the cause, so this is a limit of the run rather than a defect of the application. The page reported 2 console errors during the scenario.

  • Search for numeric checkpoint sequence returns 'No Results' instead of navigating to checkpoint detail pageS2, high

    The search failure is caused by the test environment's CORS policy blocking the application from reaching the Sui RPC. The audit recorded the test environment as the cause, so this is a limit of the run rather than a defect of the application. The page reported 2 console errors during the scenario.

  • Object detail view fails to extract data and display object details for 0x2S7, high

    The application gracefully handles the data extraction failure caused by the test environment's CORS restriction blocking the RPC request. The audit recorded the test environment as the cause, so this is a limit of the run rather than a defect of the application. The page reported 3 console errors during the scenario.

  • Checkpoint details page fails to render checkpoint summary and timestamp on TestnetS8, high

    The data retrieval issue is due to the test environment's CORS policy blocking access to the RPC, which the application handles by showing an error message. The audit recorded the test environment as the cause, so this is a limit of the run rather than a defect of the application. The page reported 2 console errors during the scenario.

  • Epoch details page fails to retrieve and render epoch dataS9, high

    The environment's CORS restriction prevents the application from fetching epoch data, causing the expected failure message. The audit recorded the test environment as the cause, so this is a limit of the run rather than a defect of the application. The page reported 3 console errors during the scenario.

  • S4 could not exercise this: Mainnet RPC requests blocked by CORS policy. The Mainnet RPC requests fail due to a CORS policy restriction in the test environment. The audit recorded the test environment as the cause, so it is not counted as an issue.

Wallet activity

DeepQA injected a test wallet into the browser and recorded every request the app sent to it. Testnet funds only.

App network: Testnet

address
0xfe186a…f00bbd ↗
chain
Sui Testnet
browsers opened
3
connects
0
signing requests
0

The app connected the test wallet 0 times and asked for no signature.

Critic audit

An adversarial second pass over every finding before it reaches the report.

6
findings reviewed
1
live replays
6
withdrawn
  • F1withdrawn

    The search fails to resolve the address because the test environment's CORS policy blocks requests to the Sui fullnode RPC. The audit recorded the test environment as the cause, so this is a limit of the run rather than a defect of the application.

  • F2withdrawn

    The search failure is caused by the test environment's CORS policy blocking the application from reaching the Sui RPC. The audit recorded the test environment as the cause, so this is a limit of the run rather than a defect of the application.

  • F3withdrawn

    Hand re-check, 2026-09-27: reproduced on the live app in a real browser after the runner's tab-panel snapshot fix (44cdfe8). The Validators tabpanel shows a plain 'Validator data could not be loaded' message, a real CORS limitation, not a rendering failure. The header's Epoch, @juzybits, SOURCE CODE and MORE PROJECTS links were confirmed present and unchanged before and after the click. The harness could not see content inside a tab panel (fixed 44cdfe8), which is what produced this finding originally.

  • F4withdrawn

    The application gracefully handles the data extraction failure caused by the test environment's CORS restriction blocking the RPC request. The audit recorded the test environment as the cause, so this is a limit of the run rather than a defect of the application.

  • F5withdrawn

    The data retrieval issue is due to the test environment's CORS policy blocking access to the RPC, which the application handles by showing an error message. The audit recorded the test environment as the cause, so this is a limit of the run rather than a defect of the application.

  • F6withdrawn

    The environment's CORS restriction prevents the application from fetching epoch data, causing the expected failure message. The audit recorded the test environment as the cause, so this is a limit of the run rather than a defect of the application.

  • The test environment's origin was blocked by the Sui fullnode RPCs' CORS policies, limiting the run's ability to fetch and assert against live blockchain data.
  • The application generally handled RPC network failures gracefully with empty states or error messages, except for the Validators tab on the homepage which crashed the layout.
  • Hand correction, 2026-09-27: F3 was re-checked by hand after the tab-panel snapshot fix (44cdfe8) and withdrawn. The tabpanel's own content and the header links both render and persist correctly, the original claim does not reproduce.

Report

QA report: external/explorer.polymedia.app at hosted

No confirmed application defects. All findings were withdrawn, most due to test environment CORS limits.

Testing evaluated core explorer features on Testnet across 12 scenarios, exercising network switching, header navigation, homepage data tabs, search input resolution, and detail views for addresses, objects, checkpoints, and epochs.

A finding that selecting the Validators tab on the homepage renders no content and unmounts key header links was withdrawn after a hand check. The tabpanel does render its own content, a plain "Validator data could not be loaded" message, the same CORS-driven limitation seen elsewhere in this run, not a rendering failure. The header's Epoch, @juzybits, SOURCE CODE and MORE PROJECTS links were confirmed present and unchanged both before and after clicking the tab, checked twice independently. The harness could not see content inside a tab panel at the time this run was tested (fixed in commit 44cdfe8), which is what produced this finding. Five other findings involving search navigation and detail page rendering were withdrawn by the audit because CORS policy restrictions on fullnode RPCs prevented the test environment from fetching live blockchain data.

The application displayed appropriate empty states and error notices throughout, and no confirmed defect remains from this run.

Run summary
MetricCount
Scenarios executed12
Passed6
Failed6
Blocked0
Findings raised6
Issues after the audit0
Withdrawn by the audit6
Critical / high / medium / low0 / 0 / 0 / 0

Target: https://explorer.polymedia.app/?network=testnet · Testing level: deep_feature · Stack: unknown

Issues

No issues survived the audit.

Environment limitations

These failures came from the test environment, not from the application: a credential the sandbox does not hold, a demo nobody may write to, a resource it cannot reach. They are not counted as issues. They record what this run could not exercise.

  • Search does not navigate to address detail page when pressing Enter on a valid address (S1, high): The search fails to resolve the address because the test environment's CORS policy blocks requests to the Sui fullnode RPC. The audit recorded the test environment as the cause, so this is a limit of the run rather than a defect of the application. The page reported 2 console errors during the scenario.
  • Search for numeric checkpoint sequence returns 'No Results' instead of navigating to checkpoint detail page (S2, high): The search failure is caused by the test environment's CORS policy blocking the application from reaching the Sui RPC. The audit recorded the test environment as the cause, so this is a limit of the run rather than a defect of the application. The page reported 2 console errors during the scenario.
  • Object detail view fails to extract data and display object details for 0x2 (S7, high): The application gracefully handles the data extraction failure caused by the test environment's CORS restriction blocking the RPC request. The audit recorded the test environment as the cause, so this is a limit of the run rather than a defect of the application. The page reported 3 console errors during the scenario.
  • Checkpoint details page fails to render checkpoint summary and timestamp on Testnet (S8, high): The data retrieval issue is due to the test environment's CORS policy blocking access to the RPC, which the application handles by showing an error message. The audit recorded the test environment as the cause, so this is a limit of the run rather than a defect of the application. The page reported 2 console errors during the scenario.
  • Epoch details page fails to retrieve and render epoch data (S9, high): The environment's CORS restriction prevents the application from fetching epoch data, causing the expected failure message. The audit recorded the test environment as the cause, so this is a limit of the run rather than a defect of the application. The page reported 3 console errors during the scenario.
  • S4 could not exercise this: Mainnet RPC requests blocked by CORS policy. The Mainnet RPC requests fail due to a CORS policy restriction in the test environment. The audit recorded the test environment as the cause, so it is not counted as an issue.
Withdrawn findings

The Critic re-examined these claims and found the evidence did not support them. They are kept here rather than deleted.

  • Validators tab fails to render content and causes homepage elements to unmount (S5, high): I clicked on the Validators tab and observed that no content was rendered in the Validators tab panel. Furthermore, the Epoch link, @juzybits link, SOURCE CODE link, and MORE PROJECTS link all disappeared from the header as reported. The page reported 2 console errors during the scenario. Hand re-check, 2026-09-27: reproduced on the live app in a real browser after the runner's tab-panel snapshot fix (44cdfe8). Clicking the Validators tab shows its own tabpanel with a plain 'Validator data could not be loaded' message (a real, separate CORS-driven limitation, not a rendering failure), and the header's Epoch, @juzybits, SOURCE CODE and MORE PROJECTS links were confirmed present and unchanged both before and after the click, in two independent page loads. The harness could not see content inside a tab panel (fixed 44cdfe8), which is what produced this finding originally.
Scenario results
ScenarioPriorityResultIssues
S1 Search for Addresshighfailnone
S2 Search for Checkpointhighfailnone
S3 Search with Invalid Inputhighpassnone
S4 Switch Network via Selectorhighpassnone
S5 Navigate Homepage Tabshighfailnone
S6 Render Address Detailsmediumpassnone
S7 Render Object Detailsmediumfailnone
S8 Render Checkpoint Detailsmediumfailnone
S9 Render Epoch Detailsmediumfailnone
S10 Handle Missing Transaction Blockmediumpassnone
S11 Render Validators Listlowpassnone
S12 Header Home Link Integritylowpassnone
The audit

The Critic reviewed 6 findings and ran 1 live replay in the browser, each on a fresh page.

  • The test environment's origin was blocked by the Sui fullnode RPCs' CORS policies, limiting the run's ability to fetch and assert against live blockchain data.
  • The application generally handled RPC network failures gracefully with empty states or error messages, except for the Validators tab on the homepage which crashed the layout.
  • Hand correction, 2026-09-27: F3 was re-checked by hand after the tab-panel snapshot fix (44cdfe8) and withdrawn. The tabpanel's own content and the header links both render and persist correctly, the original claim does not reproduce.
What to fix first

No confirmed issue to fix. Every finding from this run was withdrawn, either as a test environment CORS limit or, for the Validators tab claim, as a harness snapshot bug already fixed upstream (44cdfe8).

Coverage and caveats

In scope: Global search functionality for various blockchain entity types; Network switching mechanism via UI; Homepage dashboard tabs (Transaction Blocks, Validators); Detail views for Address, Object, Checkpoint, Epoch, and Transaction Block; Validators list view.

Not covered: Wallet connection and transaction signing (out of scope for read-only hosted explorer run, no UI captured in AppMap).

  • The transaction block hash '11111111111111111111111111111111111111111111' from the AppMap is likely a dummy or invalid hash; expected behavior is a graceful 'not found' state.
  • Network state is driven by the '?network=' URL parameter, so explicit navigation steps will reset the network context for each scenario.
  • Reported CORS errors from public RPC nodes might prevent actual on-chain data from loading; displaying a clean error message rather than crashing is considered a pass.
By the numbers
MetricValue
Scenarios6 passed, 6 failed, 0 blocked of 12 (32 planned steps)
Browser actions172 (17 clicks, 15 inputs, 47 navigations, 93 snapshots)
Screenshots30 (4 explore, 25 scenario, 1 critic), 25 captioned
Coverage7 pages, 1 forms, 2 flows, 2 console errors
Audit6 findings, 1 re-verified live, 0 confirmed, 0 promoted, 6 withdrawn
Model calls143
Tokens771,527 input, 10,411 output, 23,751 thinking
Time8 min
Wallet0 transactions, 0 signatures, 0 refusals on chain sui:testnet
StageCallsInputOutputThinkingSeconds
explore25135,0651,8112,46770
plan13,6972,1222,90034
test112616,0655,32111,283317
critique414,5639236,39858
report12,1372347038

Run log

stagecallstokenstime
Explore25139.3k1m 10s
Plan18.7k34s
Test112632.7k5m 17s
Critique421.9k58s
Report13.1k8s
Total143805.7k8m 7s
○Intake
✓Explore
✓Plan
✓Test
✓Critique
✓Report
  • 04:19:40Zexploreexplore started
  • 04:27:47ZexploreExplored / (17 controls, 0 forms)
  • 04:27:47ZexploreExplored /address/0x0000000000000000000000000000000000000000000000000000000000000002 (11 controls, 0 forms)
  • 04:27:47ZexploreExplored /object/0x2 (8 controls, 0 forms)
  • 04:27:47ZexploreExplored /object/0x0000000000000000000000000000000000000000000000000000000000000002 (8 controls, 0 forms)
  • 04:27:47ZexploreExplored /epoch/100 (8 controls, 0 forms)
  • 04:27:47ZexploreExplored /txblock/11111111111111111111111111111111111111111111 (8 controls, 0 forms)
  • 04:27:47ZexploreExplored /checkpoint/1000 (8 controls, 0 forms)
  • 04:27:47ZexploreExplored /validators (8 controls, 0 forms)
  • 04:27:47ZexploreExplored /epoch/0 (8 controls, 0 forms)
  • 04:27:47ZexploreMapped 7 pages, 1 forms, 2 flows in 25 turns.
  • 04:27:47Zexploreexplore completed in 70s.
  • 04:27:47Zplanplan started
  • 04:27:47ZplanPlanned 12 scenarios (5 high, 5 medium, 2 low).
  • 04:27:47Zplanplan completed in 34s.
  • 04:27:47Ztesttest started
  • 04:27:47ZtestS1 executed (fail), 1 finding
  • 04:27:47ZtestS2 executed (fail), 1 finding
  • 04:27:47ZtestS3 executed (pass)
  • 04:27:47ZtestS4 executed (pass)
  • 04:27:47ZtestS5 executed (fail), 1 finding
  • 04:27:47ZtestS6 executed (pass)
  • 04:27:47ZtestS7 executed (fail), 1 finding
  • 04:27:47ZtestS8 executed (fail), 1 finding
  • 04:27:47ZtestS9 executed (fail), 1 finding
  • 04:27:47ZtestS10 executed (pass)
  • 04:27:47ZtestS11 executed (pass)
  • 04:27:47ZtestS12 executed (pass)
  • 04:27:47ZtestExecuted 12 scenarios: 6 passed, 6 failed, 0 blocked, 6 findings.
  • 04:27:47Ztesttest completed in 317s.
  • 04:27:47Zcritiquecritique started
  • 04:27:47ZcritiqueReviewed 6 findings; 1 possible defect spotted in passed scenarios.
  • 04:27:47ZcritiqueRe-verified F3: reproduced.
  • 04:27:47ZcritiqueAudit complete: 1 confirmed, 5 withdrawn, 0 promoted, 1 re-verified live.
  • 04:27:47Zcritique6 failures came from the test environment rather than the application. They are reported as environment limitations, not issues.
  • 04:27:47Zcritiquecritique completed in 58s.
  • 04:27:47Zreportreport started
  • 04:27:47ZreportReported 1 issue (0 critical, 1 high, 0 medium, 0 low) from 6 findings.
  • 04:27:47Zreportreport completed in 8s.

Put an agent team on your next pull request.

Connect a repo, dispatch a Run, and read an audited, evidence-backed report the same day.