rule catalogue
12 checks for confidential contracts
Each rule targets a bug class that plaintext tools cannot see: ciphertext ACLs, input attestations, decryption proofs and data-oblivious control flow. Run homomorph rules HM00x for the same text in your terminal.
HM001
missing-input-proof
CRITICAL
External encrypted input is used without FHE.fromExternal and its input proof
HM002
missing-allow-this
HIGH
Encrypted value stored in state without FHE.allowThis
HM003
missing-allow-user
MEDIUM
Per-user encrypted value stored without FHE.allow for that user
HM004
transient-allow-on-storage
MEDIUM
Handle persisted to storage but only granted FHE.allowTransient
HM005
unguarded-public-decrypt
HIGH
Anyone can mark an encrypted value publicly decryptable
HM006
unverified-cleartext
CRITICAL
Decrypted cleartext accepted on-chain without FHE.checkSignatures
HM007
missing-sender-allowed
HIGH
Caller-supplied ciphertext handle used without FHE.isSenderAllowed
HM008
plaintext-branch-on-encrypted
HIGH
Control flow branches on encrypted data instead of using FHE.select
HM009
uninitialized-handle
LOW
ACL call on a mapping entry that may still be an uninitialised (zero) handle
HM010
checksignatures-handle-order
MEDIUM
Handle list and abi.encode(...) cleartexts appear misaligned in FHE.checkSignatures
HM011
deprecated-fhe-api
LOW
Legacy TFHE / Gateway API in use
HM012
public-handle-exposure
HIGH
Per-user confidential value made publicly decryptable