skeletonv0.1 · skeleton docs
Security
What is real today, what the design will enforce, and the threats it has to survive.
What's real today
| Area | State |
|---|---|
| Contracts / programs | Not written for production. Interfaces in docs are conceptual. |
| Audit | Not started. Planned before any mainnet deployment. |
| Admin keys | Not created. Governance model in CORE_TECH_PLAN.md. |
| Data | Simulated. |
Trust assumptions (design)
- Wormhole guardians. A VAA is accepted if 13 of 19 guardians signed it. WORMHOOK inherits that assumption; it adds no additional verifier in v1.
- Executors are untrusted for correctness. They can delay or decline, not forge or replay. See Executor model.
- Adapters and hooks are trusted only by the apps that call them. WORMHOOK does not review third-party hook logic. The registry shows audit status honestly.
- Admins can pause the router and gateway and manage the registry. During a pilot they may also upgrade contracts. This is a real trust assumption and is labelled as one.
Planned protections
| Threat | Mitigation |
|---|---|
| Forged caller | Router only posts for registered apps; gateway checks the router emitter. |
| Forged hook / unknown hook | Gateway only dispatches registry entries (WH-303). |
| Replay / duplicate delivery | Call ID consumed before execution (WH-302). |
| Stale message | Expiry in the call; gateway refuses late calls (WH-201). |
| Overspend | maxSpend checked against hook and app caps at the gateway and in adapters (WH-306). |
| Malicious adapter | Gas limit per hook, try/catch isolation, no gateway re-entrancy, per-hook pause. |
| EVM re-entrancy | nonReentrant gateway, checks-effects-interactions. |
| Compromised admin | Timelock + multisig planned; pause separated from upgrade authority. |
| Relay delay / censorship | Expiry bounds the damage; permissionless redelivery planned. |
| Duplicate receipt | Router records exactly one receipt per pending call ID. |
| Partial execution | First-class partial status; adapters report what succeeded. |
| Failed return path | Receipts can be redelivered; the hook never re-runs. |
| Finality mismatch | Finalized consistency on the outbound leg; return-leg setting chosen per destination. |
The full threat model, with test plans for each item, is in CORE_TECH_PLAN.md §Security.
Reporting
There's no production deployment to report against yet. Design feedback is welcome now, while it's cheap to change.