--- name: cross-chain-relayer-audit description: 'Cross-chain relayer bridge audit register: message hash verifications, replay protection nonces, validator quorum, and withdrawal proofs.' category: engineering risk: safe source: self source_type: self date_added: "2026-10-01" author: Ranjeet2063 tags: [cross-chain, bridge, relayer, security, cryptography, web3, stellar] tools: [] source_repo: Ranjeet2063/agentic-awesome-skills --- # Cross-Chain Relayer Security Audit **What it is:** Audits cross-chain message passing protocols, cryptographic commitment trees, and validator quorum consensus for cross-chain relayers. ## Overview Provides a standardized, auditable framework and data model for **Cross-Chain Relayer Security Audit** operations across distributed engineering and decentralized application systems. ## When to Use This Skill - When formalizing architectural contracts, security invariants, or operational limits for Cross-Chain Relayer Security Audit. - When cross-functional review is required between protocol developers, smart contract auditors, and AI engineering agents. - When generating reproducible CSV, SQL DDL, JSON Schema, and Notion property registers for tracking compliance. ## How It Works 1. Define the parameters, thresholds, and identity bindings required for the target operational register. 2. Select appropriate boundary enforcement values from validated enum select sets. 3. Export standardized artifacts (CSV table, SQL DDL, JSON Schema) to integrate into validation CI pipelines. ## Field Reference | # | Field Name | Type | SQL Type | JSON Schema Type | Notion Property Type | Example Value | |---|------------|------|----------|------------------|----------------------|---------------| | 1 | Relayer Audit ID | `id` | `SERIAL PRIMARY KEY` | `integer` | Text | `REL-001` | | 2 | Source Chain Domain | `text` | `VARCHAR(32)` | `string` | Text | `Ethereum Sepolia` | | 3 | Destination Chain Domain | `text` | `VARCHAR(32)` | `string` | Text | `Stellar Testnet` | | 4 | Message Hash Verification | `select` | `VARCHAR(32)` | `string` | Select | `Keccak256 Verified` | | 5 | Replay Protection Nonce Check | `select` | `VARCHAR(32)` | `string` | Select | `Enforced Strict Sequence` | | 6 | Validator Quorum Threshold | `text` | `VARCHAR(16)` | `string` | Text | `5-of-7 Quorum` | | 7 | Slashing Condition Active | `select` | `VARCHAR(16)` | `string` | Select | `Yes` | | 8 | Withdrawal Proof Standard | `select` | `VARCHAR(64)` | `string` | Select | `Merkle Patricia Trie Proof` | | 9 | Finality Confirmation Blocks | `number` | `INTEGER` | `number` | Number | `32` | | 10 | Bridge Security Posture | `select` | `VARCHAR(32)` | `string` | Select | `Verified Secure` | | 11 | Audit Stamp Date | `date` | `DATE` | `string, format: date` | Date | `2026-10-01` | ## Select Options **Message Hash Verification** ``` Keccak256 Verified | SHA256 Verified | Invalid Hash ``` **Replay Protection Nonce Check** ``` Enforced Strict Sequence | Bitmask Window | Unchecked ``` **Slashing Condition Active** ``` Yes | No ``` **Withdrawal Proof Standard** ``` Merkle Patricia Trie Proof | ZK-SNARK Validity Proof | Light Client Header ``` **Bridge Security Posture** ``` Verified Secure | Under Audit | Vulnerable Finding ``` ## Relations - `Audit Reference` -> links to the formal review documentation or test repository. - `Target Architecture` -> links to the deployed contract or autonomous agent runtime component. ## Examples **Prompt** ``` How do I configure and track Cross-Chain Relayer Security Audit for our production environment? ``` **Recommended Next Step** > Generate the unified field schema, SQL DDL migration, and JSON validation schema to register into your system catalog. > > Workflow: Define criteria -> Run automated verification -> Record baseline -> Monitor invariants. ## Best Practices - Enforce strict typing on numerical bounds and currency amounts; avoid unstructured free-text fields for critical states. - Re-run validation test suites on every state-altering commit or parameter change. - Keep example data synthetic and isolated from production cryptographic keys or private endpoints. ## Limitations - Provides architectural specifications, data models, and verification schemas; does not execute direct transaction signing without authorized external tooling. - Requires network connectivity and valid RPC credentials when querying on-chain states. ## Security & Safety Notes - All parameters declare `risk: safe`. No unauthorized state modification or privileged credential access is performed. - Use synthetic dummy keys and mock addresses in test suites and local verification scripts. ## Common Pitfalls - **Problem:** Mismatched decimal precision between contract runtime and database register. **Solution:** Always verify decimals using the explicit field mapping in this reference. - **Problem:** Missing authorization checks prior to state update. **Solution:** Cross-validate against the Security Audit register before deployment. ## Related Skills - @smart-contract-formal-verification - verifies state invariants mathematically. - @web3-rate-limiting-circuit-breaker - provides operational guardrails and threshold breakers. - @stellar-anchor-integration - covers SEP-10 and SEP-24 anchor compliance flows. ## Reusable Prompt ``` I want to establish a verified Cross-Chain Relayer Security Audit register for our production protocol. Guide me through the required field parameters and output the corresponding SQL DDL and JSON Schema. ```