# Installing community cards

> What a community card is, how to install one from GitHub, how to read the permission dialog, and how to update, turn off, revoke or remove it.

Source: https://docs.neurosquad.ai/en/card-sdk/community-cards

Community cards are cards other people built with the [Card SDK](https://docs.neurosquad.ai/en/card-sdk) and shared on GitHub.
They live in **Settings → Custom cards**, and once installed you add them from the canvas like any
other card.

## Install a card

**1. Open Settings → Custom cards**

Under **Install a card**, paste the GitHub address you were given. Any of these work:
`owner/repo`, `owner/repo@v1.2.0` (a tag, branch or commit), `owner/repo/cards/pomodoro` (a card in
a subfolder), or a full `https://github.com/…` link — including a `/tree/<branch>/<folder>` or
`/releases/tag/<tag>` link.

**2. Press Install and read the dialog**

NeuroSquad downloads that exact commit, checks it, and shows you what the card is and what it
asks to do. Nothing is installed yet.

**3. Press Install in the dialog**

Or **Cancel** — the download is thrown away.

**4. Add it to a canvas**

In the add menu (the **+** on the canvas or in the sidebar) choose **Custom card…** and pick it.
You can add as many copies as you like; each has its own settings and data.

> Looking for cards someone has already checked? The [verified cards](https://docs.neurosquad.ai/en/card-sdk/verified-cards) list
> has community cards the NeuroSquad team reviewed, installable from the **Verified** tab of the
> **Custom card…** picker.

## Reading the install dialog

  - **Name, author, version**: The author is **self-declared** — the card says who made it, nobody checked. Trust the repository address, not the name. Only official cards may call themselves "NeuroSquad", "official" or "verified"; the app refuses any other card that tries.
  - **Source and commit**: The GitHub repository and the exact commit that will be installed, with **View source** to read that code. The install is pinned to that commit, and the commit must belong to the repository itself (be on its default branch): a commit that exists only in a fork is refused. A repository that was renamed or moved must be installed under its new name.
  - **Community or Official**: Every card is marked **Community code, not made or checked by NeuroSquad** — except cards published by the NeuroSquad team from the `glmn-ai` organization on GitHub (checked against GitHub's own account id, not just the name), which carry an **Official** badge.
  - **This card will be able to**: The [permissions](https://docs.neurosquad.ai/en/card-sdk/permissions) it needs, **high risk first** and shown before the card's own description, each with a plain explanation and, often, the author's reason. They are all-or-nothing: to install the card you grant all of them.
  - **It may ask later for**: Optional permissions. They are **not** granted at install; the card asks on screen when it needs one, and you can say no.
  - **Tools and ports**: The tools it offers to agents you connect it to, and how many data ports it has for arrows.

> Pay most attention to the **High risk** lines. A card that may **give instructions to agents** or
> **run commands in terminals** can do anything those agents and terminals can — edit your code,
> delete files, push to git. A card with **read files** plus **any network address** could send your
> project files there.

## What a card can never do

Whatever it asks for, a card runs sealed inside its box. It cannot open windows, reach the app or
other cards directly, read your files or go online outside what you granted, show system
notifications, or draw outside its card. The app checks every request a card makes, on every call.
See [Cards never leave the canvas](https://docs.neurosquad.ai/en/card-sdk#cards-never-leave-the-canvas).

**A real NeuroSquad prompt dims the whole window.** Whenever a card needs your decision — a
confirmation, a link, a permission, a prompt to an agent in dangerous mode, a secret key — the app
asks in its own dialog headed **NeuroSquad is asking**, over a backdrop that darkens the sidebar and
the title bar too. A card can only draw inside its own box, so it cannot imitate that. The card's
own words appear in such a dialog only as a quote, and **Cancel** is always the app's.

**Anything inside the card body belongs to the card.** NeuroSquad never asks for passwords or API
keys inside a card. When a card needs a key, you enter it through the card's **Settings…** (the
secret field opens the app's dialog) — the key is stored encrypted, sent only to the internet
addresses you granted, and the card never sees it.

**Your agents' settings and the repository are protected.** Even a card allowed to change files
cannot touch `.git`, agent settings and instructions (`.claude/`, `.codex/`, `.cursor/`,
`.mcp.json`, `CLAUDE.md`, `AGENTS.md`, `GEMINI.md`, `QWEN.md`…), editor and CI configuration
(`.vscode/`, `.idea/`, `.github/workflows/`, `.husky/`…) or package-manager settings (`.npmrc`,
`.yarnrc`…). And no card gets any file access when the workspace folder is your home folder, the root
of a drive, or contains NeuroSquad's own data.

## Using a card

- **Arrows.** Most cards do more when you connect them. An arrow between a card and an agent lets
it watch that agent's screen or send it prompts (if it has those permissions) and lets the agent
call the card's tools. An arrow between two cards lets data flow over their ports, from the arrow's
tail to its head.
- **Settings…** in the card's **⋯** menu opens the card's settings, if it has any. Some are shared
by every copy of that card (marked so in the form).
- **Prompts to an agent in dangerous mode** always need your OK: the app shows what the card wants
to send, and you press **Send prompt** or **Cancel**. Prompts a card queued for an agent are
dropped if you remove the arrow, revoke the permission or switch the agent to dangerous mode; the
queue shows which card each one came from.
- **Links** a card wants to open are shown in full first; only `https://` links, and only after you
press **Open link**.
- **Limits.** A card can send at most 6 prompts and 30 terminal commands a minute, however it sends
them.
- **Attention.** A card can pulse and appear in the Inbox when it needs you — like an agent that is
waiting. It cannot make sounds or OS notifications.
- **Paused cards.** A card you have not looked at for a while (its workspace hidden for a minute,
or too many cards open) is paused to save memory and resumes where it left off. Cards with the
**Keep running when you are not looking** permission are not paused.

## Updates

NeuroSquad checks for new versions a minute after it starts and then once a day (or when you press
**Check for updates**). A card that follows a branch updates to its newest commit; one installed
from a release follows the latest release; one pinned to a tag or a commit never updates.

**Nothing updates on its own.** An available update shows as **Update** in **Settings → Custom
cards** and as a dot on the card. Pressing it shows what changes — **new permissions**, **new
addresses it will connect to**, permissions it **no longer needs**, and changes to what it offers:
new or reworded **tools** for agents, new or retyped **ports**, new **secret settings**, a changed
**name, author or homepage** — with a link to see the code changes on GitHub. If the update asks for
anything of that kind, it waits for your OK; until then the old version keeps running.

## Turning off, revoking, removing

In **Settings → Custom cards**, each installed card has:

- **Turned on** switch — off stops every copy of it (its cards show "This card is turned off"), its
tools disappear from agents, and nothing is deleted.
- **Permissions** — press **Revoke** next to any permission to take it back. Cards of that package
reload without it.
- **Uninstall** — removes the package. You choose whether to **also delete its cards from every
canvas** (on by default; otherwise they stay as "package missing" placeholders) and whether to
**also delete its saved data and secrets** (off by default).

## Private repositories and GitHub limits

GitHub limits how often anyone can download without an account. If installing or checking for
updates says GitHub is limiting requests — or you want to install from a private repository — add
a **GitHub token** in **Settings → Custom cards**. It is stored encrypted and never shown to cards.

## Custom cards on your phone

With [remote access](https://docs.neurosquad.ai/en/remote), a custom card shows on your phone as its header and its summary
tile, with "Open on the computer to use this card". Its code runs only on the computer — its tools,
ports and prompts keep working there while you watch from the phone.
