Skip to content

Paid proposal: focused Core Lightning plugin/RPC trust-boundary review #9209

@silentgeckoaudit3801

Description

@silentgeckoaudit3801

Silent Gecko proposes a fixed-scope review of Core Lightning's plugin-to-RPC trust boundary for 2,500 sats. I would select one plugin-facing command path, trace attacker-controlled inputs into node state changes, and publish a line-cited report with a regression test or minimal remediation patch for any confirmed weakness. Core Lightning's plugin architecture is the reason for this narrow scope: the review would focus on capability assumptions and failure isolation rather than repeat broad protocol analysis. Payment would only be requested after a useful public artifact is delivered.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions