
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
@fairseal/auto
Advanced tools
Auto-instrument AI SDK calls to emit VEO-2 objects. One line, zero code changes.
Auto-instrument AI SDK calls to emit VEO-2 objects. One line, zero code changes.
npm install @openrng/auto @openrng/core
import OpenAI from 'openai';
import { auto } from '@openrng/auto';
// Wrap your existing client — one line
const client = auto(new OpenAI());
// Use exactly as before — VEOs are emitted automatically
const response = await client.chat.completions.create({
model: 'gpt-4o',
messages: [{ role: 'user', content: 'What is the capital of France?' }],
});
// response is unchanged — same OpenAI response object
// but a VEO-2 record was created in the background
import Anthropic from '@anthropic-ai/sdk';
import { auto } from '@openrng/auto';
const client = auto(new Anthropic());
const message = await client.messages.create({
model: 'claude-4-sonnet',
messages: [{ role: 'user', content: 'Hello' }],
});
import { auto } from '@openrng/auto';
import { generateSigningKeys } from '@openrng/core';
const keys = generateSigningKeys();
const client = auto(new OpenAI(), {
privateKey: keys.privateKey,
provider: 'my-service',
});
// Every VEO is now Ed25519-signed and independently verifiable
import { auto, MemoryStore } from '@openrng/auto';
const store = new MemoryStore();
const client = auto(new OpenAI(), { store });
await client.chat.completions.create({ ... });
// Get all recorded VEOs
const veos = store.list();
console.log(veos[0].execution?.model_id); // 'gpt-4o'
console.log(veos[0].execution?.cost); // { total_tokens: 150 }
const client = auto(new OpenAI(), {
onVEO: (veo) => {
console.log('AI call recorded:', veo.object_id);
// Send to your observability pipeline, database, etc.
},
});
Every instrumented call produces a VEO with:
| Field | Source |
|---|---|
execution.prompt_hash | SHA-256 of the prompt/messages |
execution.output_hash | SHA-256 of the response |
execution.model_id | Model from the request |
execution.latency_ms | Measured response time |
execution.cost | Token usage from response |
execution.tool_calls | Tool/function calls if any |
confidence.score | 700 (success) or 100 (error) |
lifecycle.state | 'created' or 'signed' |
| SDK | Methods |
|---|---|
| OpenAI | chat.completions.create, completions.create, embeddings.create, images.generate |
| Anthropic | messages.create |
| Generic | create, generate, complete |
| Package | Purpose |
|---|---|
@openrng/core | Types, schema, signing, validation |
@openrng/auto | Auto-instrumentation (this package) |
MIT — OpenRNG
FAQs
Auto-instrument AI SDK calls to emit VEO-2 objects. One line, zero code changes.
The npm package @fairseal/auto receives a total of 2 weekly downloads. As such, @fairseal/auto popularity was classified as not popular.
We found that @fairseal/auto demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.