@nprofile1q... @nprofile1q... @nprofile1q... @nprofile1q... My biggest concern is not a lack of a threat model, but without a spec, it is difficult to say what dat is. I appreciate hearing that "corestore" and "hypedht" are fundamental, but the website visualization doesn't even work for me, and besides that, there's only a flat list.
The fact it's written in javascript is also concerning, as that language is prone to dependency hell (as seen in the visualization).