defirisk.co
rubric v1.7.0

Contributor tenure at admin-permissioned PR

Sushi (SushiSwap) — v2 + v3 + Trident + BentoBox/Kashi + SushiXSwap's assessment for RD-F-116 — scored gray on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Insufficient data at OSINT tier to determine tenure of the author of the most recent admin-permissioned code change. GitHub API access needed for commit-level attribution with timestamps. MISO case (2021) confirms a short-tenure freelancer (AristoK3) had production write access — a historical red signal for contributor vetting. Current team tenure: Matthew Lilley appears to have been contributing since at least 2022–2023 (CTO nomination coverage); LufyCZ active contributor but tenure start date not confirmed. Formal contributor-tenure analysis not completable via OSINT.

Sources #

  • GitHub
    SushiSwap GitHub Organization MembersGitHub sushiswap org public member page — 2 public membersretrieved 2026-05-17
  • Internal
    JayPegs Automart Hack — Contractor Access Findinghacksdatabase/hacks/jaypegs-automart.md — short-tenure freelancer with production accessretrieved 2026-05-17

Methodology #

Measure the number of days contributing to the repo of the author of the most recent admin-permissioned code change.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol sushi factor RD-F-116 score gray collected_at 2026-05-16 19:50:37