> For the complete documentation index, see [llms.txt](https://funarchy.gitbook.io/funarchy/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://funarchy.gitbook.io/funarchy/pm-threat-modeling/test-result-dashboard/rain-test-result.md).

# Rain Test Result

| Configuration | Trading Mechanism | Oracle & Data | Governance | Operation |
| ------------- | ----------------- | ------------- | ---------- | --------- |
| ⚠️            | ✅                 | ⚠️            | -          | ✅         |

### Analysis stage

<details>

<summary>Configuration</summary>

❌  Ambiguous Resolution Criteria

✅  Manual Oracle Delay

✅  Extend market resolution time

</details>

<details>

<summary>Trading Mechanism</summary>

&#x20;**-**   Signature Replay Attacks

&#x20;**-**   Matching Engine Logic Errors

&#x20;**-**   State Inconsistency

✅  Slippage & Sandwich Attacks

✅  Permanent Loss

✅ Fee bypass

</details>

<details>

<summary>Oracle &#x26; Data</summary>

&#x20;**-**   Single Data Source Dependency

✅  Oracle Data Validation Logic Insufficiency

❌  Missing Oracle Authentication

&#x20;**-**   UI Latency Desynchronization

&#x20;**-**   UI–Oracle Price Mismatch

&#x20;**-**  Short-Horizon Settlement Price Manipulation

&#x20;**-**  Equality Boundary Settlement Precision Risk

</details>

<details>

<summary>Governance</summary>

&#x20;**-**   Whale Cartel Attack

&#x20;**-**   Dispute Mechanism Abuse

</details>

<details>

<summary>Operation</summary>

✅  Owner's Privilege too High

✅  DoS via Unrestricted Shared State Manipulation

✅  Calculation Logic Error

</details>

### Risk Summary&#x20;

#### **Configuration**

* Since there is no rulebook specified on the market UI, the conclusion about the market may be different from what general users want.

#### Oracle & Data

* A malicious operator can inject malicious results through the resolve account without going through AI, causing damage to users.

***

### Risk Analysis

#### Configuration

**Ambiguous Resolution Criteria**

<figure><img src="https://4210179539-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2DiVEbUgCTsp2iPassR9%2Fuploads%2FmTElWGzI9j1vyQgMsUdb%2Fimage.png?alt=media&amp;token=e196682e-b125-4309-9501-7ff45cd08be9" alt="" width="563"><figcaption></figcaption></figure>

* Currently, Rain lacks a clearly defined rulebook for market outcomes.<br>

  The vague settlement criteria of these prediction markets arise from the lack of standardized rules or objective indicators required for market creation, leading to structural problems.<br>

  Thus, attackers can distort judgments into a logical argument based on technical definitions rather than objective facts.

#### Oracle & Data

**Missing Oracle Authentication**

<figure><img src="https://4210179539-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2DiVEbUgCTsp2iPassR9%2Fuploads%2FmTElWGzI9j1vyQgMsUdb%2Fimage.png?alt=media&amp;token=e196682e-b125-4309-9501-7ff45cd08be9" alt="" width="563"><figcaption></figcaption></figure>

* Currently, Rain only explicitly states that Olympus AI is used as a resolver.<br>

  Actually, in the on-chain logic, there are two addresses: resolveAI and disputeresolveAI, both of which are EOA addresses. Resolvers can only call choosewinner to deliver results or check the status after a dispute. Furthermore, because they are EOA accounts, they cannot determine whether they are AI or human. Ultimately, general users cannot verify the accuracy of the data used to resolve the market, nor can they verify the identity of the entity (AI or human) using the EOA account.\
  \
  Thus, a malicious operator could inject malicious results through the resolve account, bypassing the AI, and harm users.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://funarchy.gitbook.io/funarchy/pm-threat-modeling/test-result-dashboard/rain-test-result.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
