Engagement Deskscope, plan and govern a security engagement
Independent work sample built for a job application. Not affiliated with or endorsed by OpenZeppelin. Reads public GitHub data only. Calendar estimates are benchmarked on OpenZeppelin's published audit reports (see Method). Homework write-up ↗

A client sends a repo. What goes in the SOW?

Paste any public GitHub repo (optionally @ref or a /tree/ URL). The desk pins the commit, reads every source file at that hash, separates in-scope code from tests, scripts, mocks and vendored libraries, counts nSLOC, flags the patterns that cost review time, checks audit readiness, then drafts the effort estimate, milestone plan and RAID log. Toggle files to reshape scope.

Mid-audit, the client pushes new code. In scope or change order?

Give the frozen commit from the SOW and the commit the client now wants reviewed. The desk diffs every in-scope source file at normalised-line level, sizes the change against the original scope, applies a written change-order rule, and drafts the note to send.

Account intelligence: how is each ecosystem library moving?

Each strategic ecosystem account has an OpenZeppelin library or tool behind it. This board reads their public repos: latest release and its age, commits and merged PRs in the last 90 days, open work, and a prompt for the next account review.

How the desk measures code, and how well the estimate holds up

The estimate is checked against OpenZeppelin's own published audit reports. For each report the desk reads the scope commit and the in-scope file list, measures those exact files with the same engine the Scope tab uses, and compares the result with the audit's published timeline.