QA report: external/trycallit.xyz at hosted
Core call creation and risk analysis tools function well, but broken creator profile links and unvalidated strike price inputs require attention.
Testing covered primary navigation routes, prediction call creation flows, risk console scenario shocks, community feed filtering, and creator detail views across 12 scenarios. Most core features performed as expected, successfully enforcing bond requirements and calculating metric projections.
Two functional defects were confirmed during testing. The creator track record link on prediction call detail pages navigates to a 404 error due to malformed profile routing, preventing users from reviewing a creator's history. In addition, the strike price input field lacks client-side validation, accepting negative numbers and arbitrary text strings without error feedback. One additional finding regarding wallet connection was withdrawn by the audit because sandbox constraints prevented live wallet interactions.
The test run could not fully evaluate authenticated portfolio ledger workflows due to the aforementioned wallet environment limitations, and network isolation blocked unreachable external telemetry endpoints during page loads.
Run summary
| Metric | Count |
|---|
| Scenarios executed | 12 |
| Passed | 9 |
| Failed | 3 |
| Blocked | 0 |
| Findings raised | 3 |
| Issues after the audit | 2 |
| Withdrawn by the audit | 1 |
| Critical / high / medium / low | 0 / 1 / 1 / 0 |
Target: https://trycallit.xyz/ · Testing level: deep_feature · Stack: unknown
Issues
High severity
F3 · Creator track record link on prediction call detail page leads to 404 error
Severity: high · Type: functional · Verdict: confirmed · Scenario: S11
The application incorrectly uses a visually truncated address containing an ellipsis character (%E2%80%A6) in the URL path, leading to a legitimate 404 error. The live replay was inconclusive: The replay ran out of tool calls before it reached the reported state. The page reported 1 console error during the scenario.
Expected: The creator profile page should load and display the caller's track record, win rate, and history of past calls.
Actual: Navigating to the creator profile link (/arena/creator/0xceb3%E2%80%A624e7) renders a "404 - The requested page could not be found" page.
Steps to reproduce:
- Navigate to https://trycallit.xyz/arena
- Click on a prediction call card (e.g., Up @ $6,600,400)
- Click on the "Creator track record" link
- Observe the rendered page
Evidence: screenshots/S11-10.png
Medium severity
F1 · Strike price field accepts non-numeric and negative values without input validation
Severity: medium · Type: functional · Verdict: confirmed · Scenario: S3
The tester observed that the strike price input field accepts alphabetical and negative characters without restriction, demonstrating a lack of client-side input validation. The page reported 1 console error during the scenario.
Expected: The field should restrict typing to valid positive numbers or display an inline validation error.
Actual: The field allows typing any alphabetical strings (e.g. 'abc') and negative numbers (e.g. '-100') without restriction or error indication.
Steps to reproduce:
- Navigate to https://trycallit.xyz/arena
- Click the 'Launch call' button
- Type alphabetical characters such as 'abc' or negative numbers such as '-100' into the 'Strike price' input field
Evidence: screenshots/S3-5.png
Environment limitations
These failures came from the test environment, not from the application: a credential the sandbox does not hold, a demo nobody may write to, a resource it cannot reach. They are not counted as issues. They record what this run could not exercise.
- Portfolio Connect Wallet and Sign In buttons do not trigger wallet connection or render ledger (S10, high): The generic injected test wallet was never prompted by the application (0 connect requests), indicating the application likely only supports specific named wallet extensions not present in the sandbox environment. The audit recorded the test environment as the cause, so this is a limit of the run rather than a defect of the application.
- S2 could not exercise this: Unresolvable resource on Arena page. A resource fails to load with an ERR_NAME_NOT_RESOLVED console error. The audit recorded the test environment as the cause, so it is not counted as an issue.
Scenario results
| Scenario | Priority | Result | Issues |
|---|
| S1 Verify load and link integrity across primary routes | high | pass | none |
| S2 Validate required fields on Launch Call form | high | pass | none |
| S3 Validate numerical boundaries on Strike price | high | fail | F1 |
| S4 Apply scenario shocks in Risk Console | high | pass | none |
| S5 View detailed prediction call metrics | high | pass | none |
| S6 Enforce DUSDC bond requirement on call creation | medium | pass | none |
| S7 Validate optional Thesis length and submission | medium | pass | none |
| S8 Filter and sort the community prediction feed | medium | pass | none |
| S9 Toggle shock curve display metrics | medium | pass | none |
| S10 View portfolio ledger with connected wallet | medium | fail | none |
| S11 View creator track record from a call | low | fail | F3 |
| S12 Export Risk Report from console | low | pass | none |
The audit
The Critic reviewed 3 findings and ran 1 live replay in the browser, each on a fresh page.
- The recurring ERR_NAME_NOT_RESOLVED errors indicate a third-party asset or telemetry service that is blocked or unreachable from the sandbox.
What to fix first
- Fix creator profile route generation on call detail pages so track record links resolve correctly instead of returning 404 errors (Issue F3).
- Add input validation to the strike price field to restrict entries to positive numeric values (Issue F1).
Coverage and caveats
In scope: Arena feed, filter, and detailed prediction views; Launch Call form validation and submission constraints; Risk console stress testing and metric visualization; Portfolio ledger empty/connected state handling.
Not covered: Actual on-chain contract execution for call launches (wallet lacks required $10 DUSDC bond); DeepBook Predict markets (markets page is documented as empty on testnet).
- Test wallet auto-connects but holds only SUI, causing submission of calls requiring a DUSDC bond to fail gracefully at validation or wallet confirmation.
- The 404 and ERR_NAME_NOT_RESOLVED console errors seen during exploration do not block core UI rendering.
By the numbers
| Metric | Value |
|---|
| Scenarios | 9 passed, 3 failed, 0 blocked of 12 (47 planned steps) |
| Browser actions | 224 (61 clicks, 6 inputs, 36 navigations, 121 snapshots) |
| Screenshots | 38 (4 explore, 34 scenario, 0 critic), 34 captioned |
| Coverage | 11 pages, 1 forms, 3 flows, 2 console errors |
| Audit | 3 findings, 1 re-verified live, 2 confirmed, 0 promoted, 1 withdrawn |
| Model calls | 197 |
| Tokens | 1,245,190 input, 10,290 output, 20,395 thinking |
| Time | 13 min |
| Wallet | 0 transactions, 0 signatures, 0 refusals on chain sui:testnet |
| Stage | Calls | Input | Output | Thinking | Seconds |
|---|
| explore | 24 | 139,059 | 2,082 | 2,167 | 105 |
| plan | 1 | 4,283 | 2,086 | 4,672 | 46 |
| test | 162 | 1,060,599 | 5,208 | 8,872 | 554 |
| critique | 9 | 39,460 | 633 | 4,197 | 54 |
| report | 1 | 1,789 | 281 | 487 | 9 |