Stylus Manager - Final Report & Grant Completion

Hi everyone,

We are closing out the Stylus Manager - Caching, Activating, and Tracking Stylus Contracts grant, funded through the Developer Tooling domain. All five milestones are delivered, and the platform is live on Arbitrum One, so this post consolidates the grant in one place: what we built, how we validated and audited it, where everything is deployed, and every link a reviewer or developer might need.

Thanks to the domain allocators and to everyone in the Stylus community who gave us feedback along the way.

1. Overview

Stylus programs stop being callable if you don’t reactivate them periodically. The failure is silent: the contract stays on chain, but every call reverts until someone calls activateProgram and pays for it again. Before this grant, there was no status indicator, no alert, and no way to automate it.

This grant extended the Stylus Cache Manager, which we built under the Stylus Sprint, into the Stylus Manager: one open-source platform to keep Stylus contracts cached, active, and monitored. Activation lives where caching already lived, inside each contract, so wherever you can cache a contract, you can now activate it.

The Stylus Manager is live on Arbitrum One at stylus.cobuilders.xyz, the same URL as the original Cache Manager. Cyfrin audited the automation contract, and the remediated CacheManagerAutomation v2.0.0 is the version running on mainnet.

2. Milestones delivered

Milestone Scope Amount Submitted Report
M1 Planning & Design 6,000 USD Jun 3, 2026 Report
M2 Backend Development 9,500 USD Jun 12, 2026 Report
M3 Frontend Development 9,500 USD Jul 30, 2026 Report
M4 Enhancements, QA, User Testing & Bug Fixing 6,000 USD Aug 21, 2026 Report
M5 Final Deployment 4,000 USD Sep 14, 2026 Report
Total 35,000 USD
  • M1, Planning & Design. Development plan, architecture across contracts, backend and frontend, user stories, and an interactive V0 prototype.
  • M2, Backend Development. Activation event capture, lifecycle alerts, placeActivations batch automation in CacheManagerAutomation, CI on devnode with integration tests, OpenAPI docs, and a v1.1.0 staging deployment on Arbitrum Sepolia.
  • M3, Frontend Development. Rebrand to Stylus Manager, activation status in the contract tables, a full Activation tab in the contract view, activation at Add Contract, alerts UI, and a public staging URL.
  • M4, QA, and hardening. Full-system testing, the Cyfrin audit with remediation delivered as v2.0.0, four frontend pull requests (design system, workflow rebalance, wallet network consistency, keyboard navigation and accessibility), and testing-driven fixes.
  • M5, Final Deployment. Mainnet deployment of contracts, backend and frontend, refreshed documentation, and the educational content committed in the proposal.

Across the five milestones, the reports list 33 merged pull requests (plus one NGINX commit) in the frontend, backend, contracts, and deploy repositories.

3. What shipped

  • Activation status everywhere. My Contracts and Explore Contracts show each contract’s activation status next to its cache status, with time remaining computed from the on-chain activation date and the network’s expiry parameter.
  • Four lifecycle alerts. Approaching expiration (configurable threshold, 1 to 365 days), expired, reactivation succeeded, and reactivation failed, delivered through Telegram, Slack, and Webhooks, the same channels used for caching alerts.
  • Manual activation. A direct wallet-signed call to arbWasm.activateProgram, with the activation fee discovered by simulation. No backend in the loop.
  • Opt-in auto-activation. Per contract, autoActivate plus a maxActivationCost cap. The automation contract draws only what is needed from the existing escrow, calls activateProgram and refunds the excess. Off by default, with a global cap of 5 activations per iteration.
  • Activation at Add Contract. Adding an expired or never-activated program offers to activate it right there instead of failing later.
  • Rebuilt UI. Responsive dark design system, consolidated alert management, wallet network consistency checks, and keyboard-first navigation with a global command palette.
  • Caching untouched. Regression testing covered the existing caching functionality throughout.

4. Security

Cyfrin performed an external audit of CacheManagerAutomation. The audit surfaced no critical findings and no issues putting user funds at risk. Cyfrin addressed each finding individually, and the remediation shipped as v2.0.0: hardened two-step ownership transfers, escrow and automation-withdrawal separation, funding-limit enforcement, per-batch authorization deduplication, owner-parameter bounds, gas optimizations, and build hardening.

Cyfrin completed the remediation review; the remediation was merged (PR #22), and the final report is public in the repository:

5. Deployments

Artifact Network Link
Stylus Manager (production) Arbitrum One stylus.cobuilders.xyz
CacheManagerAutomation v2.0.0 Arbitrum One 0x42affF7D0e6649fc006B5Dd9131373f869e622AF
CacheManagerAutomation v2.0.0 Arbitrum Sepolia 0x4f64b21496B319dCaef26EDd165cab3039f5aD86
API docs (Swagger) Production stylus-nginx-production.up.railway.app/api

The backend runs on the v2.0 ABI with the Activation module enabled and database migrations applied in production. The rebranded frontend is served at the same URL as the original Cache Manager.

6. Validation and testing

  • Backend unit tests and backend to contracts integration tests on fresh Nitro devnodes.
  • Contract tests: 73/73 deterministic, 28/28 CacheManager, and 29/29 CacheManagerAutomation on a fresh local Nitro environment.
  • Playwright UI validation at desktop and mobile widths: overflow checks, modal lifecycle, keyboard navigation, and focus restoration.
  • Structured user-testing sessions on the public staging deployment, triaged in Linear. The two highest-impact improvements were the Cache/Activation workflow rebalance (PR #87) and wallet network consistency enforcement (PR #88).

7. Documentation and educational content

The documentation site was refreshed for v2: rebrand, a What’s New in v2 page, UI tutorials for activation and auto-activation, and an Activation Lifecycle page in the Deep Dive section.

Educational content, each piece covering the concept, Cargo, a direct Hardhat call (with runnable example scripts), the platform, automation, and alerts:

8. Resources

The Stylus Manager is open source, and we keep maintaining it as infrastructure for Stylus developers. Thanks to the Arbitrum DAO Grants Program for supporting this work. Feedback and contributions are welcome on the repositories.

2 Likes

Nice for sharing the final report. The progress is visible, but some important accountability data is still missing. Please add approved versus actual budget, wallet and transaction level spending proof, deliverable wise completion status, timeline variance, measurable user impact, remaining funds, and any security or audit updates. This will help the community independently verify the outcomes and assess the full value created by the grant. @CoBuilders

The report explains for good activities, but it does not yet provide enough verifiable data for final accountability. Please disclose:

Approved budget versus actual expenditure by category

Treasury wallet, transaction proofs, and remaining balance

Promised versus delivered milestones with evidence

Target versus actual KPIs, including the measurement period and source

Delays, deviations, risks, and lessons learned

Any payments to contributors, multisig signers, or related parties

Audit, security, and custody information where applicable

Adding these details would make the final report more transparent, measurable, and useful for future grant decisions. @CoBuilders