Arbitrary call with user-controlled target
Concrete's assessment for RD-F-013 — scored gray on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Hook system uses role-gated external calls (Hook Manager Admin role). Strategy calls are factory-approved. No audit finding flagged arbitrary external call. Cannot confirm without Slither. Needs tool run.
Sources #
- GitHubConcrete Architecture DocumentationArchitecture.md — Hook Manager role gates hook addressesretrieved 2026-05-17
Methodology #
Determine whether any contract performs `.call(target, data)` where target and/or data is user-supplied without a target allowlist or selector filter.
See the full factor methodology and distribution across all protocols →
rubric_version v1.7.0 protocol concrete factor RD-F-013 score gray collected_at 2026-05-17 14:36:59