🐝 VeehiveCurated, not crowdsourcedVelnode-signedShips off by default

A plugin store you can
actually trust.

Every plugin in Veehive is first-party, Velnode-signed, and ships disabled. You choose what to enable — and each one can only do what you explicitly allow.

Velnode-signed

Why Veehive exists

We didn’t plug into the extension market. We built a smaller, safer one.

Open extension stores let almost anyone publish, and most listings clear an automated check rather than a line-by-line human review. That openness is their strength — and their weakness. An extension you trusted can quietly change hands, then push new code to everyone who already installed it, with no fresh permission prompt. It’s how popular extensions have turned into adware overnight, and how a single 2024 phishing wave slipped malicious updates into more than a dozen well-known extensions at once.

We could have bolted Velnode onto that same marketplace. We chose not to. Veehive is first-party and curated: every plugin is written, reviewed, and cryptographically signed by us before it can load, declares exactly what it’s allowed to touch, and ships switched off until you turn it on.

To be fair: open stores have real advantages — scale, breadth, and thousands of niche tools Veehive doesn’t have yet. We’re betting that, for the software you live inside all day, a clear chain of trust matters more than a giant catalogue.

The store

What you can switch on

Everything here ships OFF by default — you enable exactly what you want.

Veehive plugins 🔏 Velnode-signed
OFF

Citation Collector

Capture quotes into a structured bibliography — export to Markdown or BibTeX.

OFF

Counter-Research

Surfaces the strongest opposing view and a source-diversity score, via Vee.

OFF

Multi-Tab Synthesis

Reads your open tabs into one brief and an agree/disagree map. On-device.

OFF

Personal Wikipedia

Turns your browsing into a queryable, private knowledge base with sources.

OFF

Vee for Code

Explains selected code, summarises PR diffs, and flags stale answers.

🐝

More signed plugins coming soon

Built-in tools part of the browser
OFF

Ad Blocker

Blocks trackers and ads at the network level. No subscription, no filter-list upsell.

OFF

Reader Mode

Strips the page to readable text. No distractions, no re-format ads.

OFF

Screenshot + Annotate

Capture any page, draw on it, save locally. Never uploaded.

OFF

Password Vault

Integrates the vault into the browser chrome for auto-fill. Data stays on-device.

OFF

Enhanced Incognito

Deeper session isolation — no history, no vault writes, no local-LLM memory.

Open marketplace vs Veehive

Two very different trust models

The trust model of an open extension marketplace is genuinely hard. Here’s how Veehive is built differently.

Open extension stores

  • ! Almost anyone can publish; review is automated-first
  • ! Installed add-ons auto-update silently — new code, no new prompt
  • ! Ownership can change hands invisibly
  • ! “Read & change all your data on all sites” is common
  • ! Trust often rides on install counts

Veehive

  • First-party only (for now) — every plugin known to us
  • Ed25519-signed; loads only if Velnode-signed
  • Re-signed on every change — no silent code swap
  • Per-capability consent — it touches only what you allow
  • Ships off; signed revocation list if one ever needs pulling

The open model’s track record. Researchers at Stanford and CISPA found roughly 280 million installs of extensions later classified as malware, policy-violating, or critically vulnerable (2020–2023). In December 2024, a single phishing wave pushed malicious updates into 16+ popular extensions at once. — Stanford/CISPA, 2024; TechCrunch & Sekoia, Dec 2024.

How safety works

The trust model, in plain terms

These aren’t features you toggle. They’re how the plugin loader works.

Signed before it loads (Ed25519)

Every bundle is signed with Velnode’s key. Unsigned or modified code is refused at the gate — never loaded.

Per-capability consent

Each plugin declares exactly what it needs — read this page, use Vee, save a note. You approve the list; anything else is wired shut.

Off by default, revocable

Nothing runs until you switch it on — and a signed revocation list can pull any plugin if it ever needs to be.

AI stays on the rails

Plugins reach Vee only through the gateway — so Kids Mode, Local-Only, and token caps still apply to plugin AI.

Light by default

Plugins earn their keep — or get unloaded

A plugin you’re not using shouldn’t cost you anything. The runtime enforces that.

Zero cost when off. A disabled plugin uses no memory and loads no code at startup.
Capped memory. Each plugin gets a RAM budget; the runtime kills and cold-restarts anything that overruns it.
Idles out. Unused plugins unload after 10 minutes — disk kept, RAM freed.
You can see it. Settings shows live RAM and disk per plugin, so nothing hides.

A developer portal and third-party / paid plugins are planned for after launch — once the full sandbox is proven. Today’s Veehive is first-party and curated on purpose: we want the trust model solid before we open the doors.