Skip to Content
Card SDKInstalling community cards

Installing community cards

Community cards are cards other people built with the Card SDK and shared on GitHub. They live in Settings → Custom cards, and once installed you add them from the canvas like any other card.

Install a card

Open Settings → Custom cards

Under Install a card, paste the GitHub address you were given. Any of these work: owner/repo, owner/repo@v1.2.0 (a tag, branch or commit), owner/repo/cards/pomodoro (a card in a subfolder), or a full https://github.com/… link — including a /tree/<branch>/<folder> or /releases/tag/<tag> link.

Press Install and read the dialog

NeuroSquad downloads that exact commit, checks it, and shows you what the card is and what it asks to do. Nothing is installed yet.

Press Install in the dialog

Or Cancel — the download is thrown away.

Add it to a canvas

In the add menu (the + on the canvas or in the sidebar) choose Custom card… and pick it. You can add as many copies as you like; each has its own settings and data.

1/6In Settings → Custom cards, paste the card’s GitHub address — owner/repo is enough — and press Install.

Looking for cards someone has already checked? The verified cards list has community cards the NeuroSquad team reviewed, installable from the Verified tab of the Custom card… picker.

Reading the install dialog

Name, author, version

The author is self-declared — the card says who made it, nobody checked. Trust the repository address, not the name. Only official cards may call themselves “NeuroSquad”, “official” or “verified”; the app refuses any other card that tries.

Source and commit

The GitHub repository and the exact commit that will be installed, with View source to read that code. The install is pinned to that commit, and the commit must belong to the repository itself (be on its default branch): a commit that exists only in a fork is refused. A repository that was renamed or moved must be installed under its new name.

Community or Official

Every card is marked Community code, not made or checked by NeuroSquad — except cards published by the NeuroSquad team from the glmn-ai organization on GitHub (checked against GitHub’s own account id, not just the name), which carry an Official badge.

This card will be able to

The permissions it needs, high risk first and shown before the card’s own description, each with a plain explanation and, often, the author’s reason. They are all-or-nothing: to install the card you grant all of them.

It may ask later for

Optional permissions. They are not granted at install; the card asks on screen when it needs one, and you can say no.

Tools and ports

The tools it offers to agents you connect it to, and how many data ports it has for arrows.

Pay most attention to the High risk lines. A card that may give instructions to agents or run commands in terminals can do anything those agents and terminals can — edit your code, delete files, push to git. A card with read files plus any network address could send your project files there.

What a card can never do

Whatever it asks for, a card runs sealed inside its box. It cannot open windows, reach the app or other cards directly, read your files or go online outside what you granted, show system notifications, or draw outside its card. The app checks every request a card makes, on every call. See Cards never leave the canvas.

A real NeuroSquad prompt dims the whole window. Whenever a card needs your decision — a confirmation, a link, a permission, a prompt to an agent in dangerous mode, a secret key — the app asks in its own dialog headed NeuroSquad is asking, over a backdrop that darkens the sidebar and the title bar too. A card can only draw inside its own box, so it cannot imitate that. The card’s own words appear in such a dialog only as a quote, and Cancel is always the app’s.

Anything inside the card body belongs to the card. NeuroSquad never asks for passwords or API keys inside a card. When a card needs a key, you enter it through the card’s Settings… (the secret field opens the app’s dialog) — the key is stored encrypted, sent only to the internet addresses you granted, and the card never sees it.

Your agents’ settings and the repository are protected. Even a card allowed to change files cannot touch .git, agent settings and instructions (.claude/, .codex/, .cursor/, .mcp.json, CLAUDE.md, AGENTS.md, GEMINI.md, QWEN.md…), editor and CI configuration (.vscode/, .idea/, .github/workflows/, .husky/…) or package-manager settings (.npmrc, .yarnrc…). And no card gets any file access when the workspace folder is your home folder, the root of a drive, or contains NeuroSquad’s own data.

Using a card

  • Arrows. Most cards do more when you connect them. An arrow between a card and an agent lets it watch that agent’s screen or send it prompts (if it has those permissions) and lets the agent call the card’s tools. An arrow between two cards lets data flow over their ports, from the arrow’s tail to its head.
  • Settings… in the card’s ⋯ menu opens the card’s settings, if it has any. Some are shared by every copy of that card (marked so in the form).
  • Prompts to an agent in dangerous mode always need your OK: the app shows what the card wants to send, and you press Send prompt or Cancel. Prompts a card queued for an agent are dropped if you remove the arrow, revoke the permission or switch the agent to dangerous mode; the queue shows which card each one came from.
  • Links a card wants to open are shown in full first; only https:// links, and only after you press Open link.
  • Limits. A card can send at most 6 prompts and 30 terminal commands a minute, however it sends them.
  • Attention. A card can pulse and appear in the Inbox when it needs you — like an agent that is waiting. It cannot make sounds or OS notifications.
  • Paused cards. A card you have not looked at for a while (its workspace hidden for a minute, or too many cards open) is paused to save memory and resumes where it left off. Cards with the Keep running when you are not looking permission are not paused.

Updates

NeuroSquad checks for new versions a minute after it starts and then once a day (or when you press Check for updates). A card that follows a branch updates to its newest commit; one installed from a release follows the latest release; one pinned to a tag or a commit never updates.

Nothing updates on its own. An available update shows as Update in Settings → Custom cards and as a dot on the card. Pressing it shows what changes — new permissions, new addresses it will connect to, permissions it no longer needs, and changes to what it offers: new or reworded tools for agents, new or retyped ports, new secret settings, a changed name, author or homepage — with a link to see the code changes on GitHub. If the update asks for anything of that kind, it waits for your OK; until then the old version keeps running.

Turning off, revoking, removing

In Settings → Custom cards, each installed card has:

  • Turned on switch — off stops every copy of it (its cards show “This card is turned off”), its tools disappear from agents, and nothing is deleted.
  • Permissions — press Revoke next to any permission to take it back. Cards of that package reload without it.
  • Uninstall — removes the package. You choose whether to also delete its cards from every canvas (on by default; otherwise they stay as “package missing” placeholders) and whether to also delete its saved data and secrets (off by default).

Private repositories and GitHub limits

GitHub limits how often anyone can download without an account. If installing or checking for updates says GitHub is limiting requests — or you want to install from a private repository — add a GitHub token in Settings → Custom cards. It is stored encrypted and never shown to cards.

Custom cards on your phone

With remote access, a custom card shows on your phone as its header and its summary tile, with “Open on the computer to use this card”. Its code runs only on the computer — its tools, ports and prompts keep working there while you watch from the phone.