[
  {
    "contract": "06_tx_origin_wallet.sol",
    "status": 200,
    "expected": "tx.origin auth misuse",
    "findings": 1,
    "severities": "High",
    "summary": "The contract has one real security issue: it uses `tx.origin` for authorization in `transferAll`. This enables phishing-style attacks where "
  },
  {
    "contract": "07_predictable_lottery.sol",
    "status": 200,
    "expected": "weak randomness/manipulable winner",
    "findings": 1,
    "severities": "High",
    "summary": "The contract has a high-severity randomness flaw in winner selection. `pickWinner()` uses on-chain values (`block.timestamp`, `block.prevran"
  },
  {
    "contract": "08_unbounded_loop_dos.sol",
    "status": 200,
    "expected": "DoS risk from unbounded loop/refund pattern",
    "findings": 2,
    "severities": "High",
    "summary": "The contract is vulnerable to denial-of-service in its refund flow. `refundAll()` can become uncallable as the user list grows, and a single"
  },
  {
    "contract": "09_signature_replay.sol",
    "status": 200,
    "expected": "signature replay due to missing nonce/deadline",
    "findings": 2,
    "severities": "High, Medium",
    "summary": "The contract has a high-impact signature design flaw: signed claims can be replayed indefinitely because there is no nonce/deadline/consumed"
  },
  {
    "contract": "10_price_oracle_stale.sol",
    "status": 200,
    "expected": "oracle staleness/mispricing risk",
    "findings": 2,
    "severities": "Critical, High",
    "summary": "The contract has two serious lending-logic issues: (1) borrowers can repeatedly borrow against the same collateral because no debt is record"
  }
]