code-423n4 / 2023-11-shellprotocol-findings

7 stars 7 forks source link

QA Report #336

Open c4-bot-3 opened 8 months ago

c4-bot-3 commented 8 months ago

See the markdown file with the details of this report here.

raymondfam commented 8 months ago

Possible upgrade:

L-01 --> #252

c4-pre-sort commented 8 months ago

raymondfam marked the issue as sufficient quality report

c4-sponsor commented 8 months ago

viraj124 (sponsor) acknowledged

0xA5DF commented 8 months ago

[L-01] Potential Overcharge on Unwrapping Fee

L

[L-02] Incorrect Event Parameter in Swap Action

R

[L-03] Incorrect Documentation Regarding int256 Maximum Value

I

[L-04] Unnecessary Fallback Function

R

[L-05] Missing Sender Address Check

L

[N-01] slippageProtection type and naming

R

[N-02] Inconsistent Accounting of ETH Wrapping as Interactions

R

[N-03] Potential Revert in _getNegativeBalanceDelta Function

NC

[N-04] Misleading Function Name in Curve2PoolAdapter Contracts

I

[N-05] Misleading Variable Name

NC

[N-01] Inconsistent Variable Naming for IDs

NC

0xA5DF commented 8 months ago

Side note: regarding layout I'd recommend adding a direct link to the relevant code (including line number), this way it's easier to see the context of the finding

0xA5DF commented 8 months ago

+1 low from #299

c4-judge commented 8 months ago

0xA5DF marked the issue as grade-a