Explore/Arc Campaign/UnitFlow Finance
Hosted appDEXArc Testnetsucceeded

UnitFlow Finance

www.unitflow.finance

The Next Generation Innovative Dex on Arc L1 Blockchain.

Tested in place byDeepQA TeamonArc Testnetatwww.unitflow.finance/onSep 17, 2026

Run #1model gemini-balanced (vertex)took 6m

6 of 9 scenarios passed, 3 failed, 4 issues after the audit, 2 high.

Share on X
UnitFlow Finance in the browser during the run

By the numbers

6 of 9
scenarios passed, 3 failed
99
browser actions
22
screenshots
93
model calls
5.7
minutes
9
scenarios
6
passed
3
failed
0
blocked
4
issues
high2medium2

Walkthrough

Every scenario DeepQA drove in the browser, in plan order, with the 19 screenshots it captured along the way. A passing scenario is evidence too.

  1. S1
    Landing page load and resource integrity

    3 steps, 2 screenshots

    pass
    S1-1.png
    S1 · Landing page load and resource integrity
    S1-3.png
    S1 · Landing page load and resource integrity
    • Loaded landing page at https://www.unitflow.finance/ and verified header, banner, main headings, and structural elements are intact.
    • Verified page title 'Dex | UnitFlow Finance' and that interactive theme switching functions without errors.
    • Page loaded successfully at https://www.unitflow.finance/ with document title 'Dex | UnitFlow Finance'.
    • All main structural elements (header logo, navigation, hero banner, feature highlights, Genesis Pass NFT cards, and footer) are rendered properly without errors.
    • UI interactions like theme toggling and carousel slides respond properly with no critical console or rendering failures.
  2. S2
    Primary dApp navigation via Header Link

    3 steps, 1 screenshot

    pass
    S2-1.png
    S2 · Primary dApp navigation via Header Link
    • Verified that the 'Launch App' link in the header navigation targets 'https://app.unitflow.finance'.
    • Navigated to https://www.unitflow.finance/ and inspected the header banner.
    • Located the 'Launch App' link in the top header navigation.
    • Observed that the link destination URL correctly points to 'https://app.unitflow.finance'.
  3. S3
    Primary dApp navigation via CTA button

    3 steps, 2 screenshots

    fail
    S3-1.png
    S3 · Primary dApp navigation via CTA button
    S3-6.png
    S3 · Primary dApp navigation via CTA button
    • Navigated to https://www.unitflow.finance/ and observed the home page with Launch App CTA links and buttons.
    • Clicked the 'Launch App' CTA button in the 'Don’t just join the room. Use the stack.' section; no action, navigation, or feedback occurred because it is an inert button element.
    • Header links point to https://app.unitflow.finance with target=_blank, but the primary CTA buttons in the 'Don’t just join the room. Use the stack.' section are non-functional button elements with no handlers.
  4. S4
    Theme toggle functionality

    4 steps, 3 screenshots

    pass
    S4-1.png
    S4 · Theme toggle functionality
    S4-3.png
    S4 · Theme toggle functionality
    S4-5.png
    S4 · Theme toggle functionality
    • Observed the initial landing page theme and captured a screenshot.
    • Clicked the 'Toggle theme' button and captured a screenshot of the updated theme state.
    • Clicked the 'Toggle theme' button again to verify switching back.
    • Navigated to https://www.unitflow.finance/ and observed the initial visual theme.
    • Clicked the 'Toggle theme' button in the navigation header to switch themes.
    • Clicked the 'Toggle theme' button again to switch the theme back.
    • Theme toggle button operates cleanly and transitions between themes as expected.
  5. S5
    Promotional carousel slide navigation

    4 steps, 3 screenshots

    pass
    S5-1.png
    S5 · Promotional carousel slide navigation
    S5-3.png
    S5 · Promotional carousel slide navigation
    S5-5.png
    S5 · Promotional carousel slide navigation
    • Initial slide 1 displays heading 'Genesis Pass NFT' and description 'Become a founding member of UnitFlow from day 1.'
    • Clicking 'Go to slide 2' updated the carousel content to show 'Exchange' and 'Instant pairs. Best path. No app-hopping.'
    • Clicking 'Go to slide 3' updated the carousel content to show 'Liquidity' and 'Put size in. Pull size out. Watch the pool live.'
    • Navigated to https://www.unitflow.finance/ and verified that slide 1 shows Genesis Pass NFT information.
    • Clicked 'Go to slide 2' and confirmed the carousel transitioned smoothly to display 'Exchange' with description 'Instant pairs. Best path. No app-hopping.'.
    • Clicked 'Go to slide 3' and confirmed the carousel transitioned smoothly to display 'Liquidity' with description 'Put size in. Pull size out. Watch the pool live.'.
  6. S6
    Genesis Pass Minting access via Header

    3 steps, 1 screenshot

    pass
    S6-1.png
    S6 · Genesis Pass Minting access via Header
    • Located the 'Mint Genesis Pass' link in the top banner/hero carousel targeting https://app.unitflow.finance.
    • Navigated to https://www.unitflow.finance/ and located the 'Mint Genesis Pass' link.
    • Verified that the link targets a valid URL for the minting application (https://app.unitflow.finance).
  7. S7
    Genesis Pass Minting access via CTA button

    3 steps, 2 screenshots

    fail
    S7-1.png
    S7 · Genesis Pass Minting access via CTA button
    S7-7.png
    S7 · Genesis Pass Minting access via CTA button
    • Navigated to homepage and identified the Mint Genesis Pass CTA button.
    • Navigated to https://www.unitflow.finance/ and located the 'Mint Genesis Pass' CTA button in the 'Don't just join the room. Use the stack.' section.
    • Clicked the 'Mint Genesis Pass' CTA button multiple times.
    • Observed that clicking the button produced no navigation, network request, or user feedback, leaving the user on the homepage.
  8. S8
    UnitPay access via CTA button

    3 steps, 2 screenshots

    fail
    S8-1.png
    S8 · UnitPay access via CTA button
    S8-3.png
    S8 · UnitPay access via CTA button
    • Loaded https://www.unitflow.finance/ homepage showing hero, features, and CTA buttons including 'Open UnitPay'.
    • Clicked the 'Open UnitPay' CTA button; the button does not trigger any navigation, event, or page change.
    • Loaded https://www.unitflow.finance/ and located the 'Open UnitPay' CTA button under 'Don’t just join the room. Use the stack.'.
    • Clicked the 'Open UnitPay' CTA button multiple times and verified that no URL change, modal popup, or navigation occurs.
  9. S9
    Footer placeholder links behavior

    5 steps, 3 screenshots

    pass
    S9-1.png
    S9 · Footer placeholder links behavior
    S9-3.png
    S9 · Footer placeholder links behavior
    S9-5.png
    S9 · Footer placeholder links behavior
    • Clicked Privacy Policy link; URL changed to https://www.unitflow.finance/# without reloading or error.
    • Clicked Terms of Service link; URL remained https://www.unitflow.finance/# without reloading or errors.
    • Navigated to the home page and clicked both 'Privacy Policy' and 'Terms of Service' footer placeholder links.
    • Both links gracefully appended '#' to the URL without triggering full page reloads, 404 errors, or broken navigation.

Issues

Findings that survived the Critic's audit. Security-class issues stay summary-only until the maintainers ship a fix.

highconfirmed ✓functionalF1 · S3

'Launch App' CTA button in stack section does not navigate to the dApp

Clicked the 'Launch App' button under the 'Don't just join the room. Use the stack.' heading. The URL remained https://www.unitflow.finance/ and no navigation occurred, as the element is rendered as an inert button rather than a link to the dApp.

Expected

Clicking the 'Launch App' CTA button should navigate the user to the application (https://app.unitflow.finance).

Actual

The 'Launch App', 'Mint Genesis Pass', and 'Open UnitPay' controls under 'Don’t just join the room. Use the stack.' are rendered as inert `<button>` elements without click handlers or href links, resulting in no action or navigation when clicked.

Repro · 4 steps
  1. Navigate to https://www.unitflow.finance/
  2. Locate the 'Don’t just join the room. Use the stack.' section
  3. Click the 'Launch App' button
  4. Observe that nothing happens and the browser does not navigate
highconfirmed ✓functionalF3 · S8

Open UnitPay CTA button does not trigger navigation

I clicked the 'Open UnitPay' button in the 'Don't just join the room. Use the stack.' section on the homepage. As reported, clicking the button did not result in any navigation, modal opening, or visible state change on the page.

Expected

Clicking the 'Open UnitPay' CTA button should trigger navigation to the UnitPay application or feature section.

Actual

Clicking the 'Open UnitPay' button does not trigger any navigation, modal, or state change; the user remains on the homepage.

Repro · 4 steps
  1. Navigate to https://www.unitflow.finance/
  2. Scroll down to the 'Don’t just join the room. Use the stack.' section
  3. Click the 'Open UnitPay' button
  4. Observe the resulting page state and URL
mediumconfirmed ✓functionalF2 · S7

'Mint Genesis Pass' button in 'Don't just join the room. Use the stack.' section is unclickable and does not trigger navigation

The observation that clicking the 'Mint Genesis Pass' button produces no navigation or event supports the claim.

Expected

The browser attempts navigation to the Genesis Pass minting page or dapp interface.

Actual

Clicking the button has no effect; no event handler or navigation URL is triggered.

Repro · 3 steps
  1. Navigate to https://www.unitflow.finance/
  2. Scroll to the 'Don’t just join the room. Use the stack.' section
  3. Click the 'Mint Genesis Pass' button
mediumpromoted ↑functionalF4 · S9

Privacy Policy and Terms of Service links are non-functional placeholders

Surfaced by the audit of S9, which the Tester passed, and reproduced live: Clicking the Privacy Policy and Terms of Service links in the footer simply appends '#' to the URL without loading any actual policy content. I confirmed this on the homepage footer.

Expected

Clicking the links should navigate the user to the actual Privacy Policy and Terms of Service pages.

Actual

The links are placeholders that simply append '#' to the URL without loading any actual policy content.

Repro · 3 steps
  1. Navigate to the homepage.
  2. Scroll down to the footer.
  3. Click the 'Privacy Policy' or 'Terms of Service' link.

Wallet activity

DeepQA injected a test wallet into the browser and recorded every request the app sent to it. Testnet funds only.

address
0x28C278…7c39AF
chain
Arc Testnet
browsers opened
3
read requests forwarded
0
signing requests
0

Critic audit

An adversarial second pass over every finding before it reaches the report.

3
findings reviewed
3
re-verified live
0
withdrawn
  • F1confirmed ✓

    Clicked the 'Launch App' button under the 'Don't just join the room. Use the stack.' heading. The URL remained https://www.unitflow.finance/ and no navigation occurred, as the element is rendered as an inert button rather than a link to the dApp.

  • F2confirmed ✓

    The observation that clicking the 'Mint Genesis Pass' button produces no navigation or event supports the claim.

  • F3confirmed ✓

    I clicked the 'Open UnitPay' button in the 'Don't just join the room. Use the stack.' section on the homepage. As reported, clicking the button did not result in any navigation, modal opening, or visible state change on the page.

  • F4promoted ↑

    Surfaced by the audit of S9, which the Tester passed, and reproduced live: Clicking the Privacy Policy and Terms of Service links in the footer simply appends '#' to the URL without loading any actual policy content. I confirmed this on the homepage footer.

  • The tester applied inconsistent severity levels to identical defects, marking F1 and F3 as 'high' and F2 as 'medium' despite all three being inert CTA buttons in the exact same section.
  • In scenario S9, the tester rationalized broken placeholder legal links as acceptable behavior because they 'gracefully' did nothing.

Report

QA report: external/www.unitflow.finance at hosted

Core call-to-action buttons across the landing page are completely non-functional, preventing users from accessing key application features.

Testing exercised the landing page across nine scenarios, evaluating initial page loading, theme toggling, promotional carousel navigation, header links, mid-page call-to-action buttons, and footer links.

While page rendering, header navigation, theme toggling, and carousel controls passed, primary interactive controls in the page body failed. Specifically, the 'Launch App', 'Open UnitPay', and 'Mint Genesis Pass' buttons in the stack section are inert elements with no click handlers or navigation links. Furthermore, the Privacy Policy and Terms of Service footer links are non-functional placeholders that append a hash to the URL.

With key conversion funnels in the main body failing to direct users to the dApp, minting flow, or payment tools, new visitors cannot reach the platform's core products through the primary promotional section.

Run summary
MetricCount
Scenarios executed9
Passed6
Failed3
Blocked0
Findings raised3
Issues after the audit4
Withdrawn by the audit0
Critical / high / medium / low0 / 2 / 2 / 0

Target: https://www.unitflow.finance/ · Testing level: deep_feature · Stack: unknown

Issues
High severity
F1 · 'Launch App' CTA button in stack section does not navigate to the dApp

Severity: high · Type: functional · Verdict: confirmed · Scenario: S3

Clicked the 'Launch App' button under the 'Don't just join the room. Use the stack.' heading. The URL remained https://www.unitflow.finance/ and no navigation occurred, as the element is rendered as an inert button rather than a link to the dApp.

Expected: Clicking the 'Launch App' CTA button should navigate the user to the application (https://app.unitflow.finance).

Actual: The 'Launch App', 'Mint Genesis Pass', and 'Open UnitPay' controls under 'Don’t just join the room. Use the stack.' are rendered as inert <button> elements without click handlers or href links, resulting in no action or navigation when clicked.

Steps to reproduce:

  1. Navigate to https://www.unitflow.finance/
  2. Locate the 'Don’t just join the room. Use the stack.' section
  3. Click the 'Launch App' button
  4. Observe that nothing happens and the browser does not navigate

Evidence: screenshots/S3-6.png

F3 · Open UnitPay CTA button does not trigger navigation

Severity: high · Type: functional · Verdict: confirmed · Scenario: S8

I clicked the 'Open UnitPay' button in the 'Don't just join the room. Use the stack.' section on the homepage. As reported, clicking the button did not result in any navigation, modal opening, or visible state change on the page.

Expected: Clicking the 'Open UnitPay' CTA button should trigger navigation to the UnitPay application or feature section.

Actual: Clicking the 'Open UnitPay' button does not trigger any navigation, modal, or state change; the user remains on the homepage.

Steps to reproduce:

  1. Navigate to https://www.unitflow.finance/
  2. Scroll down to the 'Don’t just join the room. Use the stack.' section
  3. Click the 'Open UnitPay' button
  4. Observe the resulting page state and URL

Evidence: screenshots/S8-1.png, screenshots/S8-3.png

Medium severity
F2 · 'Mint Genesis Pass' button in 'Don't just join the room. Use the stack.' section is unclickable and does not trigger navigation

Severity: medium · Type: functional · Verdict: confirmed · Scenario: S7

The observation that clicking the 'Mint Genesis Pass' button produces no navigation or event supports the claim.

Expected: The browser attempts navigation to the Genesis Pass minting page or dapp interface.

Actual: Clicking the button has no effect; no event handler or navigation URL is triggered.

Steps to reproduce:

  1. Navigate to https://www.unitflow.finance/
  2. Scroll to the 'Don’t just join the room. Use the stack.' section
  3. Click the 'Mint Genesis Pass' button

Evidence: screenshots/S7-1.png, screenshots/S7-7.png

F4 · Privacy Policy and Terms of Service links are non-functional placeholders

Severity: medium · Type: functional · Verdict: promoted · Scenario: S9

Surfaced by the audit of S9, which the Tester passed, and reproduced live: Clicking the Privacy Policy and Terms of Service links in the footer simply appends '#' to the URL without loading any actual policy content. I confirmed this on the homepage footer.

Expected: Clicking the links should navigate the user to the actual Privacy Policy and Terms of Service pages.

Actual: The links are placeholders that simply append '#' to the URL without loading any actual policy content.

Steps to reproduce:

  1. Navigate to the homepage.
  2. Scroll down to the footer.
  3. Click the 'Privacy Policy' or 'Terms of Service' link.

Evidence: screenshots/critic-M1-1.png

Scenario results
ScenarioPriorityResultIssues
S1 Landing page load and resource integrityhighpassnone
S2 Primary dApp navigation via Header Linkhighpassnone
S3 Primary dApp navigation via CTA buttonhighfailF1
S4 Theme toggle functionalitymediumpassnone
S5 Promotional carousel slide navigationmediumpassnone
S6 Genesis Pass Minting access via Headermediumpassnone
S7 Genesis Pass Minting access via CTA buttonmediumfailF2
S8 UnitPay access via CTA buttonmediumfailF3
S9 Footer placeholder links behaviorlowpassF4
The audit

The Critic reviewed 3 findings and re-verified 3 of them live in the browser, replaying the reported steps on a fresh page.

  • The tester applied inconsistent severity levels to identical defects, marking F1 and F3 as 'high' and F2 as 'medium' despite all three being inert CTA buttons in the exact same section.
  • In scenario S9, the tester rationalized broken placeholder legal links as acceptable behavior because they 'gracefully' did nothing.
What to fix first
  1. F1: Implement functional navigation or click handlers on the 'Launch App' call-to-action button in the stack section.
  2. F3: Attach proper navigation or interaction handlers to the 'Open UnitPay' call-to-action button.
  3. F2: Wire the 'Mint Genesis Pass' button to the pass minting destination.
  4. F4: Replace placeholder links with functional URLs for the Privacy Policy and Terms of Service in the footer.
Coverage and caveats

In scope: Landing page rendering and asset integrity; Carousel slide navigation; Theme toggle functionality; Navigation links and CTA buttons pointing to the main dApp.

Not covered: Main dApp functionality (swap, farm, etc.) because it is hosted on a separate external subdomain (app.unitflow.finance) and was not explored.; Wallet connection flows because the marketing landing page does not request wallet connection..

  • The 404 console error observed in the AppMap may indicate a missing marketing asset, which could cause the resource integrity scenario to fail.
  • Footer policy links are intentionally set to '#' placeholders for now.
  • External navigations to 'app.unitflow.finance' are treated as successful if the correct URL is targeted, even if the destination origin is out of scope for deep functional testing here.
By the numbers
MetricValue
Scenarios6 passed, 3 failed, 0 blocked of 9 (31 planned steps)
Browser actions99 (32 clicks, 0 inputs, 16 navigations, 51 snapshots)
Screenshots22 (1 explore, 19 scenario, 2 critic), 19 captioned
Coverage1 pages, 0 forms, 1 flows, 1 console errors
Audit3 findings, 3 re-verified live, 3 confirmed, 1 promoted, 0 withdrawn
Model calls93
Tokens387,470 input, 6,232 output, 11,320 thinking
Time6 min
Wallet0 transactions, 0 signatures, 0 refusals on chain 5042002
StageCallsInputOutputThinkingSeconds
explore1041,46478273530
plan12,5461,5941,88828
test71313,8572,7506,157217
critique1027,9487801,97248
report11,65532656816

Run log

stagecallstokenstime
Explore1043k30s
Plan16k28s
Test71322.8k3m 37s
Critique1030.7k48s
Report12.5k16s
Total93405k5m 39s
Intake
Explore
Plan
Test
Critique
Report
  • 15:15:49Zexploreexplore started
  • 15:21:29ZexploreExplored / (19 controls, 0 forms)
  • 15:21:29ZexploreExplored /privacy (5 controls, 0 forms)
  • 15:21:29ZexploreExplored /robots.txt (5 controls, 0 forms)
  • 15:21:29ZexploreMapped 1 pages, 0 forms, 1 flows in 10 turns.
  • 15:21:29Zexploreexplore completed in 30s.
  • 15:21:29Zplanplan started
  • 15:21:29ZplanPlanned 9 scenarios (3 high, 5 medium, 1 low).
  • 15:21:29Zplanplan completed in 28s.
  • 15:21:29Ztesttest started
  • 15:21:29ZtestS1 executed (pass)
  • 15:21:29ZtestS2 executed (pass)
  • 15:21:29ZtestS3 executed (fail), 1 finding
  • 15:21:29ZtestS4 executed (pass)
  • 15:21:29ZtestS5 executed (pass)
  • 15:21:29ZtestS6 executed (pass)
  • 15:21:29ZtestS7 executed (fail), 1 finding
  • 15:21:29ZtestS8 executed (fail), 1 finding
  • 15:21:29ZtestS9 executed (pass)
  • 15:21:29ZtestExecuted 9 scenarios: 6 passed, 3 failed, 0 blocked, 3 findings.
  • 15:21:29Ztesttest completed in 217s.
  • 15:21:29Zcritiquecritique started
  • 15:21:29ZcritiqueReviewed 3 findings; 1 possible defect spotted in passed scenarios.
  • 15:21:29ZcritiqueRe-verified F1: reproduced.
  • 15:21:29ZcritiqueRe-verified F3: reproduced.
  • 15:21:29ZcritiqueRe-verified a possible defect in S9: reproduced.
  • 15:21:29ZcritiqueAudit complete: 3 confirmed, 0 withdrawn, 1 promoted, 3 re-verified live.
  • 15:21:29Zcritiquecritique completed in 48s.
  • 15:21:29Zreportreport started
  • 15:21:29ZreportReported 4 issues (0 critical, 2 high, 2 medium, 0 low) from 3 findings.
  • 15:21:29Zreportreport completed in 16s.

Put an agent team on your next pull request.

Connect a repo, dispatch a Run, and read an audited, evidence-backed report the same day.