Hook record
0x7c92f61817e1e3f81a2cf9248e36f093a2e4b323
Repository publication, publisher claims, and observed public-task usage are shown as separate evidence layers.
Repository listed means only that this canonical manifest was merged into Taskmarket's registry. It is not an endorsement, audit, RPC check, source or codehash verification, liveness guarantee, or default selection.
Publisher-declared gas estimates
Foundry gas report at source commit 2d25e107c3ff0cc811a42a1005d7525665a93e26: median and maximum gas for the mock Taskmarket checkFund wrapper across 277 calls, including 256 fuzz runs, with fixed-size local metadata and a mock ERC-20.
Foundry gas report at source commit 2d25e107c3ff0cc811a42a1005d7525665a93e26: one successful onCancel call through the mock Taskmarket wrapper.
Foundry gas report at source commit 2d25e107c3ff0cc811a42a1005d7525665a93e26: one successful onComplete call through the mock Taskmarket wrapper.
Foundry gas report at source commit 2d25e107c3ff0cc811a42a1005d7525665a93e26: one successful onExpire call through the mock Taskmarket wrapper.
The manifest's listing field is a publisher declaration. The separate Repository listed badge only means this manifest was merged here.
No source-verifier link was declared.
Publisher-declared security reviews
unaudited: AffiliateSidecarEscrowHook V1 source, deployment, and Taskmarket integration.
X and Y are independent explicit token amounts; the hook imposes no percentage or Y <= X relationship. Taskmarket holds X and the hook holds Y.
The funding authorization binds task ID, requester, payment token, X, canonical task terms, payer, beneficiary, refund recipient, affiliate ID, Y, nonce, and deadline; payer signature, balance, and allowance are required.
Lifecycle callbacks only make Y claimable; they do not transfer it. Y is fixed and paid once per task, including split, partial, or discounted-auction outcomes.
Funding checks the hook's exact inbound token balance increase and therefore rejects fee-on-transfer funding. Outbound claims assume canonical USDC transfer behavior.
Recipients and Y are immutable after funding. There is no emergency withdrawal or recipient rotation, so a lost, mistyped, incompatible, or token-blocked recipient can strand Y. Tokens sent outside a recorded allocation have no recovery path.
checkFund directly decodes Taskmarket's shared V1 hookData bytes and may be incompatible with another attached hook that consumes a different payload format.
The Taskmarket Diamond is owner-upgradeable. The funding authorization does not pin Diamond facet bytecode or implementation bytecode behind other hook proxies.
Gas values are local Foundry observations, not production upper bounds. Large metadata or hook data and expensive ERC-1271 validation can exhaust the 1,000,000-gas stipend and revert creation.
This Base Sepolia deployment is unaudited and intended for testing; no real-funds safety claim is made.