Files
orcs-code/src/utils/modifiers.ts
salmanrajz cb24750cb7 security: remove runtime require of unverified modifiers-napi package
Fixes #7. The modifiers-napi package is an Anthropic-internal native
addon, but a package with the same name exists on npm and could be a
supply chain attack vector. The build script already stubs it, but
the source code had live require() calls that would execute when
running without the bundler (e.g. bun dev, ts-node).

Replaced both functions with safe no-ops since modifier key detection
is not needed in the open-source build. Build verified passing.
2026-04-01 12:10:31 +04:00

23 lines
757 B
TypeScript

export type ModifierKey = 'shift' | 'command' | 'control' | 'option'
/**
* Pre-warm the native module by loading it in advance.
*
* NOTE: The `modifiers-napi` package is an Anthropic-internal native addon
* that is not shipped with the open-source build. All calls are no-ops here
* to avoid supply-chain risk from unverified npm packages with the same name.
*/
export function prewarmModifiers(): void {
// No-op in open-source build — native modifier detection is not available.
}
/**
* Check if a specific modifier key is currently pressed (synchronous).
*
* Always returns false in the open-source build since the native addon
* is not available.
*/
export function isModifierPressed(_modifier: ModifierKey): boolean {
return false
}