No confirmed defects were identified, though test environment connectivity limits prevented full functional verification of backend-dependent flows.
Testing covered 12 scenarios focused on wallet connection, interface mode toggles, volatility structure builder configurations, input validation, band weight adjustments, and oracle index feed views. Ten scenarios passed their client-side interaction and validation checks.
Two scenarios encountered failures during test fund minting and expiry tenor loading, resulting in two initial findings that were both withdrawn during audit. These failures stemmed from CORS misconfigurations in the test sandbox that blocked backend API communication rather than application defects.
Because outbound API calls could not complete in the testing environment, live on-chain operations and dynamic market data fetching could not be fully exercised. Comprehensive validation of transaction settlement and live data feeds will require verification in an environment with unrestricted API access.
| Metric | Count |
|---|---|
| Scenarios executed | 12 |
| Passed | 10 |
| Failed | 2 |
| Blocked | 0 |
| Findings raised | 2 |
| Issues after the audit | 0 |
| Withdrawn by the audit | 2 |
| Critical / high / medium / low | 0 / 0 / 0 / 0 |
Target: https://pelagos-sui.vercel.app/ · Testing level: deep_feature · Stack: unknown
No issues survived the audit.
These failures came from the test environment, not from the application: a credential the sandbox does not hold, a demo nobody may write to, a resource it cannot reach. They are not counted as issues. They record what this run could not exercise.
- Test funds faucet fails to mint collateral and gas displaying 'Failed to fetch' alert (S2, high): The failure to mint test funds is caused by a CORS policy error blocking the '/api/dev/faucet' endpoint, indicating an environment or deployment misconfiguration rather than an application defect. The audit recorded the test environment as the cause, so this is a limit of the run rather than a defect of the application. The page reported 16 console errors during the scenario.
- Expiry tenor selector on Volatility page remains disabled in loading state (S10, high): The expiry tenor dropdown remains stuck in a loading state because the required market data API requests fail with CORS errors, which is an environment limitation. The audit recorded the test environment as the cause, so this is a limit of the run rather than a defect of the application. The page reported 9 console errors during the scenario.
- S1 could not exercise this: CORS policy blocks API requests on initial load. Multiple API requests are blocked by the browser's CORS policy, throwing console errors. The audit recorded the test environment as the cause, so it is not counted as an issue.
| Scenario | Priority | Result | Issues |
|---|---|---|---|
| S1 Connect Sui Wallet | high | pass | none |
| S2 Mint Test Funds | high | fail | none |
| S3 Volatility Page Resilience to API Errors | high | pass | none |
| S4 Volatility Structure Presets | high | pass | none |
| S5 Volatility Amount - Empty Validation | high | pass | none |
| S6 Volatility Structure Builder - Execution Path | high | pass | none |
| S7 Interface Mode Toggle on Volatility | medium | pass | none |
| S8 Volatility Analytics View Tabs | medium | pass | none |
| S9 Adjusting Custom Band Weights | medium | pass | none |
| S10 Adjusting Volatility Strip Width and Tenor | medium | fail | none |
| S11 Volatility Amount - Invalid Input Validation | medium | pass | none |
| S12 Oracle Index Feed Inspection | low | pass | none |
The Critic reviewed 2 findings and ran 0 live replays in the browser, each on a fresh page.
- The test environment exhibits pervasive CORS misconfigurations that block all requests to the backend API, severely limiting functional test coverage across most scenarios.
In scope: Sui wallet connection via injected DeepQA test wallet; Test funds minting flow; Volatility page layout and Analytics view tabs; Volatility Structure Builder form inputs and presets; Form validation for Volatility amount; Interface mode switching (Basic/Advanced).
Not covered: Distribution market explorer (out of scope for Volatility deep feature); BTC Range Desk interface (out of scope for Volatility deep feature); Basket prediction markets (out of scope for Volatility deep feature); Protocol documentation (static external content).
- The AppMap shows extensive CORS errors for the backend API; scenarios interacting with live market data expect graceful loading or error states rather than successful data renders.
- The DeepQA test wallet automatically approves transactions or prompts are intercepted by the test harness.
- Wallet connection state persists across subsequent scenarios.
- The Volatility form submit button is identifiable even if its exact text label wasn't captured in the interactive elements.
| Metric | Value |
|---|---|
| Scenarios | 10 passed, 2 failed, 0 blocked of 12 (39 planned steps) |
| Browser actions | 181 (40 clicks, 9 inputs, 34 navigations, 98 snapshots) |
| Screenshots | 40 (4 explore, 36 scenario, 0 critic), 36 captioned |
| Coverage | 7 pages, 2 forms, 5 flows, 30 console errors |
| Audit | 2 findings, 0 re-verified live, 0 confirmed, 0 promoted, 2 withdrawn |
| Model calls | 175 |
| Tokens | 1,263,721 input, 9,981 output, 18,284 thinking |
| Time | 9 min |
| Wallet | 0 transactions, 0 signatures, 0 refusals on chain sui:testnet |
| Stage | Calls | Input | Output | Thinking | Seconds |
|---|---|---|---|---|---|
| explore | 29 | 189,601 | 2,360 | 1,582 | 94 |
| plan | 1 | 7,775 | 2,181 | 4,664 | 48 |
| test | 143 | 1,042,561 | 4,761 | 8,859 | 355 |
| critique | 1 | 22,115 | 483 | 2,624 | 22 |
| report | 1 | 1,669 | 196 | 555 | 6 |
