rules / HM001
HM001 missing-input-proof CRITICAL
External encrypted input is used without FHE.fromExternal and its input proof
Why it matters
Every `externalEuintX` / `externalEbool` parameter carries an attestation that the ciphertext was produced correctly for this contract and user. Skipping `FHE.fromExternal(value, inputProof)` lets an attacker submit arbitrary or replayed handles, including other users' ciphertexts, and have the contract compute on them as if they were legitimately encrypted inputs.
Fix
Convert every external input exactly once with `euint64 v = FHE.fromExternal(param, inputProof);` and only use `v` afterwards. Accept a `bytes calldata inputProof` parameter and pass it through unchanged.
Check locally
homomorph scan . --rules HM001