security: remove runtime require of unverified modifiers-napi package - #12
Conversation
Fixes Twigpine#7. The modifiers-napi package is an Anthropic-internal native addon, but a package with the same name exists on npm and could be a supply chain attack vector. The build script already stubs it, but the source code had live require() calls that would execute when running without the bundler (e.g. bun dev, ts-node). Replaced both functions with safe no-ops since modifier key detection is not needed in the open-source build. Build verified passing.
|
Good questions! macOS impact: The modifier detection was used for checking if Shift/Command/etc keys were held during certain interactions. Since the open-source build already had all feature flags disabled (VOICE_MODE, PROACTIVE, etc.) and the build script was stubbing Windows/WSL: This change doesn't affect the Windows situation. The original code already had a |
…y-and-build-docs security: remove runtime require of unverified modifiers-napi package
…y-and-build-docs security: remove runtime require of unverified modifiers-napi package
…y-and-build-docs security: remove runtime require of unverified modifiers-napi package
Fixes #7
Problem
src/utils/modifiers.tshas liverequire('modifiers-napi')calls that execute at runtime. Themodifiers-napipackage is an Anthropic-internal native addon, but a package with the same name exists on npm — this is a supply chain attack vector.While the build script (
scripts/build.ts) stubs these native modules during bundling, the source code still has directrequire()calls that would execute when running without the bundler (e.g.bun run dev,ts-node, or any unbundled execution path).I verified all 5 native addon package names exist on npm:
modifiers-napi✅ existsaudio-capture-napi✅ existsimage-processor-napi✅ existsurl-handler-napi✅ existscolor-diff-napi✅ existsFix
Replaced both functions in
modifiers.ts(prewarmModifiersandisModifierPressed) with safe no-ops. Modifier key detection is macOS-only and not needed in the open-source build.The other native addon imports (
image-processor-napi,audio-capture-napi,url-handler-napi) use dynamicawait import()behind feature flags that are all disabled, so they are lower risk but could be addressed similarly in a follow-up.Verification
Build passes:
bun run buildproducesdist/cli.mjssuccessfully.