Skip to content

Security: JS-PACKAGE/Neko.js

SECURITY.md

Security

Reporting a vulnerability

Please do not publish exploit details or sensitive data in a public issue. Report suspected vulnerabilities through GitHub's private vulnerability reporting for this repository when available. If it is unavailable, use the maintainer contact route listed on the repository profile and request a private disclosure channel. Include affected version, reproduction steps, impact, and any relevant mitigations. Do not include real user images, prompts, access tokens, or private model/cache contents.

Threat model

Neko.js runs registered, pinned multimodal models locally in Node.js or a browser and exposes inference, document questions, page reporting, and HTML/image helpers. The SDK is not a security boundary. Model-generated text can be false, manipulated, or unsafe; never use it to make authorization, security, or other consequential decisions.

  • Untrusted page content: HTML is parsed as data; scripts and page subresources are not executed or fetched by extractPage. This does not prevent prompt injection in extracted text or model output. Treat extracted content and all generated output as untrusted. renderMarkdown escapes report text, but applications must use a safe Markdown renderer and appropriate content security policy.
  • URL fetching / SSRF: Neko.describe, remote image inputs to Neko.infer, extractPage, and image helpers can fetch HTTP(S) URLs, including discovered page images. In Node.js, attacker-controlled URLs can reach private or internal hosts from the application's network context. The optional validateDestination hook checks the initial HTTP(S) destination and every followed redirect; it does not itself resolve or block private IP addresses or prevent DNS rebinding. Enforce destination allowlists, DNS/IP policy, and outbound network controls at the application boundary; do not expose arbitrary URL processing as a proxy. Response limits and timeouts do not replace SSRF defenses. Browser fetching remains subject to CORS, and redirects that cannot be inspected are rejected when the destination hook is active.
  • Model downloads and cache: Registry assets are pinned to immutable Hub revisions and checked against expected file sizes and SHA-256 before use or caching. Integrity failures are errors, not fallback opportunities. These checks detect altered files relative to the checked-in manifest; they do not authenticate a compromised application build or replace model provenance/license review. cache.model.clear() removes only registered files for the selected model/revision, preserving unrelated entries. Node rejects symlink paths and requests 0700/0600 for new directories/files. On POSIX, cache ancestors must be owned by the current UID or root and cannot be group/world-writable unless sticky; a private leaf beneath an untrusted writable parent is not sufficient. ACLs, Windows permissions and browser storage remain host responsibilities; same-UID application code is not isolated by these checks.
  • Offline bundles: Imports validate bounded manifests, model/profile identity, filenames, lengths and pinned SHA-256 before staged promotion. Cancellation or invalid input removes staging without replacing valid/unrelated entries. Corrupt installed entries fail closed rather than being silently replaced. Bundles contain model assets, not an authenticated application or user-data backup; browser storage quotas/availability are host-dependent and filesystem quota diagnostics may be unknown.
  • Local image processing: Node image inputs can read filesystem paths and file: URLs with the application's permissions; restrict allowed paths before accepting untrusted inputs. Raster signature, byte-size, decoded-pixel, normalized-dimension and ROI/tiling limits reduce exposure but are not a general-purpose sanitizer. Cached preprocessing still reauthorizes and validates current inputs; it does not permit revoked paths/URLs. Node uses sharp; browser inputs use browser decoders. SVG is rejected, and decoder/runtime vulnerabilities remain possible.
  • Cancellation and resource limits: Abort signals cancel fetch/stream work and cooperatively stop generation; slow-consumer overflow and iterator early return cancel bounded streams. Native decoding, ONNX execution, and synchronous preprocessing cannot necessarily be interrupted mid-step. Worker hard deadlines terminate the entire worker and reject all its pending/queued calls; recovery requires explicit restart and never automatically replays requests. Inline execution does not support this hard-deadline/restart contract. These controls are not instantaneous OS-level CPU/memory isolation; applications must enforce admission and resource boundaries appropriate to their threat model.
  • Runtime ownership: Transformers.js environment/cache/fetch hooks are shared within a realm. Only one inline Neko owner may be active there; await dispose() before creating another. Independent workers have separate owners, while browser CacheStorage can still be origin-shared. Disposal releases the engine and restores hooks. Do not mutate hooks concurrently or treat worker/session ownership as isolation from same-privilege application code. Session snapshots may contain conversation text and owned image pixels; protect them as user data.
  • Generated and persisted reports: Version-3 report/checkpoint checks validate source references, retained quotes and resume identity; language checks are heuristics. Budgets count failed attempts and are authorization, not an authentication mechanism. Tokenizer constraints ensure supported JSON structure, not meaning. Claim–evidence audits (supported, contradicted, unknown) are conservative lexical heuristics; document-question citations identify exact paragraph slices, not truth or answer relevance. Neither these checks, quote coverage nor a finite-fixture quality gate proves factual entailment, faithful translation or prompt-injection resistance. Extractive mode avoids model inference but still contains untrusted source text. Unsupported persisted versions are rejected without automatic migration. Source hashes/unkeyed integrity checks do not authenticate an author; reports, tables, questions and omitted-image errors remain untrusted data.
  • Third-party runtime: Transformers.js, ONNX Runtime, WebAssembly and WebGPU drivers are part of the trusted computing base. Build and install with the committed lockfile, review dependency updates, and do not load the browser demo or package bundle into an untrusted page. A configured ONNX execution provider is not proof that every model operation runs on the corresponding device.

Data handling

The SDK contains no application telemetry or model-output upload feature. Initial model setup or explicit prefetch downloads pinned assets from Hugging Face. Local image/text inference does not upload those inputs; passing remote page or image URLs initiates network access from the caller's runtime. Node filesystem inputs access local data with host permissions. Applications remain responsible for their own logging, analytics, hosting, network policies, and privacy notices. Avoid logging prompts, image data, fetched content, or generated content unless required and appropriately protected.

Dependency and model integrity policy

Direct dependencies are version-pinned in package.json, and transitive versions are recorded in package-lock.json. Changes to the Transformers.js version, ONNX Runtime, model revision, pinned file sizes/digests, provider configuration, or cache implementation require review and targeted tests. Never weaken integrity failures into silent cache misses or use an unpinned model fallback. The pinned sharp dependency is kept current with security advisories for its bundled native image codecs; version changes must retain a compatible, exact-version install-script approval and be verified against supported Node platforms. The npm allowScripts list is intentionally limited to the pinned esbuild, onnxruntime-node, and sharp packages: their install hooks select or provide platform-specific build/runtime artifacts. Do not replace this with a blanket script approval; review any proposed change to the allowlist and the exact package version first.

There aren't any published security advisories