Labels: documentation, security, priority:high
Body:
Problem
There's no document stating the system's core invariants (e.g., "total_supply(wPi) must never exceed verified Pi reserve," "only relayer-attested deposits can mint"). This is a prerequisite for any credible third-party audit.
Proposed fix
Write SECURITY.md covering: trust assumptions (admin key, relayer), invariants, known limitations, and out-of-scope items (e.g., current lack of proof-of-reserve).
Acceptance criteria
SECURITY.md merged
Linked from README
Labels: documentation, security, priority:high
Body:
Problem
There's no document stating the system's core invariants (e.g., "total_supply(wPi) must never exceed verified Pi reserve," "only relayer-attested deposits can mint"). This is a prerequisite for any credible third-party audit.
Proposed fix
Write SECURITY.md covering: trust assumptions (admin key, relayer), invariants, known limitations, and out-of-scope items (e.g., current lack of proof-of-reserve).
Acceptance criteria
SECURITY.md merged
Linked from README