Skip to Content
Card SDKVerified cards

Verified cards

Anyone can publish a community card on GitHub, and nobody checks it before you install it. Verified cards are the exception: community cards the NeuroSquad team has read and tested, one exact version at a time. They are listed in a public catalog, and the app can install them straight from it.

The catalog is the file verified.json in the public repository glmn-ai/neurosquad-cards . Each entry records what was reviewed:

  • the card’s name and description (in English, Russian and Chinese), its author and licence;
  • where it lives — the GitHub repository owner/repo and, optionally, a folder inside it;
  • the reviewed version, the exact reviewed commit, and the tree hash of the card’s folder at that commit;
  • the permissions and network addresses the card uses;
  • tags and a category — agents, productivity, dev tools, data, integrations, fun or other;
  • who reviewed it, when, and any notes from the review.

The app downloads the list when it starts, every 6 hours, and when you press Refresh. Offline, it shows the last copy it downloaded — or, on a fresh install, the copy that ships with the app.

Find and install a verified card

The list is in two places: the Verified tab of the Custom card… picker in the add menu (the + on the canvas or in the sidebar), and the Verified cards section of Settings → Custom cards.

Search looks at names in all three languages, descriptions and tags, right on your computer. You can also filter by category. Each row shows the card’s icon, name, description, author, category and a summary of its permissions, with a button: Install, Installed, or Verified update.

Find the card

Open the Verified tab or the Verified cards section, search or pick a category.

Press Install

NeuroSquad downloads exactly the reviewed commit — not the newest code in the repository — and compares the files’ tree hash with the reviewed one. If they differ, the install is refused: “the files differ from what was reviewed”.

Read the permission dialog and confirm

You see the same install dialog as for any other card. Verified does not skip your consent: you still decide whether the card gets what it asks for.

You can still install any card by its GitHub address, as before. The catalog only adds a list of cards somebody has looked at.

The Verified badge

A verified card carries a Verified badge — a shield with a check mark — on its catalog row, in the install dialog, on the installed card in Settings → Custom cards, and in the card’s About panel.

It is a different badge from Official. Official means the card is published by the NeuroSquad team from its glmn-ai organization on GitHub; Verified means the team reviewed this version. A card can carry both.

The badge is shown only when all three match a current entry of the list:

  • the card’s source — the same repository and folder;
  • the commit it was installed from;
  • the tree hash of its files, equal to the reviewed one.

So a card linked from a local folder, installed from another commit (for example, the newest commit of a branch), or whose files differ carries no badge — even if another version of it is verified.

Verified means: reviewed by the NeuroSquad team at version X on date Y. It is not a guarantee that the card has no bugs or will stay safe forever, and it says nothing about any other version. Read the permission dialog as carefully as for any other card.

Verified updates

When the list points a card at a newer reviewed version, Settings → Custom cards shows Verified update available for it. Pressing it installs exactly that reviewed commit through the usual update dialog, which shows what changes in the card’s permissions. Nothing is updated automatically.

If a card is removed from the list, its badge disappears and a neutral note says it is no longer in the verified list. The card stays installed and keeps working; whether to keep it is your call.

On the phone

With remote access, you can browse the verified list on your phone, but not install from it: installing is only possible on the computer.

For card authors: get your card verified

Verification is a pull request to glmn-ai/neurosquad-cards  that adds your card’s entry to verified.json. The exact rules and the entry format are in its CONTRIBUTING.md  — read it before you open the pull request.

Publish the card

It must be in a public GitHub repository, on the default branch. See Publishing & updates.

Get the commit and the tree hash

Take the exact commit you want reviewed. For the tree hash, run neurosquad-card pack on the card’s folder at that commit — it prints the tree hash the app records at install.

Open a pull request

Add your entry to verified.json — names and descriptions, repository and folder, version, commit, tree hash, permissions, network addresses, tags, category, licence — as CONTRIBUTING.md describes.

Updating a verified card is another pull request that bumps the version, commit and tree hash. Each version is reviewed again; until the new one is accepted, users keep the badge on the version that was reviewed, and code you push in the meantime is not offered as a verified update.

What reviewers check

  • The full source at that commit. No obfuscated code, and no minified-only code without its source.
  • Permissions and network addresses are the minimum the card needs, and match the entry.
  • The descriptions of its tools and ports are honest.
  • The manifest matches the entry — name and version.
  • The tree hash reproduces.
  • The card has a licence.
  • It installs and works on the current version of the app.
  • It does not impersonate NeuroSquad or any other brand.
  • It does no tracking beyond what it declares.

The security checklist covers most of this — go through it before you submit.