
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
@fairseal/core
Advanced tools
Part of FairSeal — formerly OpenRNG.
VEO-2 types, schema, and shared primitives for the FairSeal ecosystem.
VEO = Verifiable Execution Object — a standard format for recording, proving, and explaining AI decisions.
npm install @fairseal/core
import { createVEO, validateVEO, createVEOHash } from '@fairseal/core';
// Create a VEO for an AI execution
const veo = createVEO({
provider_id: 'my-service',
execution: {
prompt_hash: 'sha256-of-prompt',
output_hash: 'sha256-of-output',
model_id: 'gpt-4o',
latency_ms: 412,
cost: { total_tokens: 1500, cost_usd: 0.003 },
},
confidence: { score: 850, grade: 'AA' },
});
// Validate
const { valid, errors } = validateVEO(veo);
// Hash (for anchoring)
const hash = createVEOHash(veo);
| Class | Name | Use Case |
|---|---|---|
| VEO-2A | Raw Execution | Single AI call (chat, completion, inference) |
| VEO-2B | Composite Execution | Multi-step chains, agent pipelines |
| VEO-2C | Anchored Execution | With blockchain proof / Merkle anchor |
| VEO-2D | Governed Execution | With policy assertions, human approvals |
created → signed → anchored → indexed → verified
| Package | Purpose |
|---|---|
@fairseal/core | Types, schema, validation (this package) |
@fairseal/verify | Verify any VEO object |
@fairseal/auto | Auto-instrument AI SDK calls |
MIT — FairSeal
FAQs
Cryptographic primitives, signing, and Merkle trees for FairSeal
We found that @fairseal/core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.