L1 · PR Check
Secrets, deps, SRI, unlimited approve patterns. Hosted App or Action.
ShippedFrontend security for web3 · L1 shipped
Norekt watches the path users trust: packages, secrets, dangerous approvals on every PR — then optional pre-sign intent and deploy integrity for design partners. No code execution. Min GitHub permissions.
On the PR
Same frontend change — without a security Check vs with Norekt on Checks and Files.
build · passed
lint · passed
No security Check. Key and token land in main if review is rushed.
Norekt · 2 enforced findings
Product
Same story everywhere: ship L1 on PRs, dogfood L2 before the wallet, pilot L3 after deploy. Full product page.
Secrets, deps, SRI, unlimited approve patterns. Hosted App or Action.
ShippedPartner SDK: danger shapes + UI≠payload sheet before the wallet opens.
DogfoodCDN hash + DNS vs trusted baseline. Operator-owned, fail-closed.
PilotMultisig / Safe risk and simulation gates — enterprise later.
RoadmapLayer 1 · day one
The install path today. Pre-sign and CDN layers on Product.
W3-SEC-*
Private keys, ghp_* tokens, high-confidence secret shapes — path and line only, never the value.
Often enforceW3-DEP-*
Unpinned ranges on packages you care about — wagmi, viem, ethers, Safe SDKs — when they change in the PR.
Review signalW3-W3-*
Unlimited approve (incl. object form), eth_sign, localStorage → transaction heuristics.
Shadow-friendlyLayer 2 · dogfood
Partner installs @norekt/sdk in their dApp. Danger shapes and UI≠payload get a pre-sign sheet — not a map of all DeFi, not GitHub write.
Opt-in package the partner ships — same boundary as analytics. CDN takeover still needs L3.
Review carefully. Unlimited ERC-20 approve — even if the button said “enable trading.”
W3-RT-001 · ATK-SIGN-001Get it on a PR
Pick org and frontend repo. Contents R · PRs R · Checks write.
Start with mode: shadow. Policy from base only.
Look for Checks → Norekt. Files for annotations.