Verified cards
Anyone can publish a community card on GitHub, and nobody checks it before you install it. Verified cards are the exception: community cards the NeuroSquad team has read and tested, one exact version at a time. They are listed in a public catalog, and the app can install them straight from it.
The catalog is the file verified.json in the public repository
glmn-ai/neurosquad-cards . Each entry records what
was reviewed:
- the card’s name and description (in English, Russian and Chinese), its author and licence;
- where it lives — the GitHub repository
owner/repoand, optionally, a folder inside it; - the reviewed version, the exact reviewed commit, and the tree hash of the card’s folder at that commit;
- the permissions and network addresses the card uses;
- tags and a category — agents, productivity, dev tools, data, integrations, fun or other;
- who reviewed it, when, and any notes from the review.
The app downloads the list when it starts, every 6 hours, and when you press Refresh. Offline, it shows the last copy it downloaded — or, on a fresh install, the copy that ships with the app.
Find and install a verified card
The list is in two places: the Verified tab of the Custom card… picker in the add menu (the + on the canvas or in the sidebar), and the Verified cards section of Settings → Custom cards.
Search looks at names in all three languages, descriptions and tags, right on your computer. You can also filter by category. Each row shows the card’s icon, name, description, author, category and a summary of its permissions, with a button: Install, Installed, or Verified update.
Open the Verified tab or the Verified cards section, search or pick a category.
NeuroSquad downloads exactly the reviewed commit — not the newest code in the repository — and compares the files’ tree hash with the reviewed one. If they differ, the install is refused: “the files differ from what was reviewed”.
You see the same install dialog as for any other card. Verified does not skip your consent: you still decide whether the card gets what it asks for.
You can still install any card by its GitHub address, as before. The catalog only adds a list of cards somebody has looked at.
The Verified badge
A verified card carries a Verified badge — a shield with a check mark — on its catalog row, in the install dialog, on the installed card in Settings → Custom cards, and in the card’s About panel.
It is a different badge from Official. Official means the card is published by the NeuroSquad
team from its glmn-ai organization on GitHub; Verified means the team reviewed this version. A card
can carry both.
The badge is shown only when all three match a current entry of the list:
- the card’s source — the same repository and folder;
- the commit it was installed from;
- the tree hash of its files, equal to the reviewed one.
So a card linked from a local folder, installed from another commit (for example, the newest commit of a branch), or whose files differ carries no badge — even if another version of it is verified.
Verified means: reviewed by the NeuroSquad team at version X on date Y. It is not a guarantee that the card has no bugs or will stay safe forever, and it says nothing about any other version. Read the permission dialog as carefully as for any other card.
Verified updates
When the list points a card at a newer reviewed version, Settings → Custom cards shows Verified update available for it. Pressing it installs exactly that reviewed commit through the usual update dialog, which shows what changes in the card’s permissions. Nothing is updated automatically.
If a card is removed from the list, its badge disappears and a neutral note says it is no longer in the verified list. The card stays installed and keeps working; whether to keep it is your call.
On the phone
With remote access, you can browse the verified list on your phone, but not install from it: installing is only possible on the computer.
For card authors: get your card verified
Verification is a pull request to
glmn-ai/neurosquad-cards that adds your card’s entry
to verified.json. The exact rules and the entry format are in its
CONTRIBUTING.md — read it
before you open the pull request.
It must be in a public GitHub repository, on the default branch. See Publishing & updates.
Take the exact commit you want reviewed. For the tree hash, run
neurosquad-card pack on the card’s folder at that commit — it prints the
tree hash the app records at install.
Add your entry to verified.json — names and descriptions, repository and folder, version,
commit, tree hash, permissions, network addresses, tags, category, licence — as CONTRIBUTING.md
describes.
Updating a verified card is another pull request that bumps the version, commit and tree hash. Each version is reviewed again; until the new one is accepted, users keep the badge on the version that was reviewed, and code you push in the meantime is not offered as a verified update.
What reviewers check
- The full source at that commit. No obfuscated code, and no minified-only code without its source.
- Permissions and network addresses are the minimum the card needs, and match the entry.
- The descriptions of its tools and ports are honest.
- The manifest matches the entry — name and version.
- The tree hash reproduces.
- The card has a licence.
- It installs and works on the current version of the app.
- It does not impersonate NeuroSquad or any other brand.
- It does no tracking beyond what it declares.
The security checklist covers most of this — go through it before you submit.