# Verified cards

> The list of community cards the NeuroSquad team has reviewed — where to find it, what the Verified badge means and doesn't, how verified updates work, and how authors submit a card for review.

Source: https://docs.neurosquad.ai/en/card-sdk/verified-cards

Anyone can publish a [community card](https://docs.neurosquad.ai/en/card-sdk/community-cards) on GitHub, and nobody checks it
before you install it. **Verified cards** are the exception: community cards the NeuroSquad team has
read and tested, one exact version at a time. They are listed in a public catalog, and the app can
install them straight from it.

The catalog is the file `verified.json` in the public repository
[glmn-ai/neurosquad-cards](https://github.com/glmn-ai/neurosquad-cards). Each entry records what
was reviewed:

- the card's name and description (in English, Russian and Chinese), its author and licence;
- where it lives — the GitHub repository `owner/repo` and, optionally, a folder inside it;
- the reviewed **version**, the exact reviewed **commit**, and the **tree hash** of the card's folder
at that commit;
- the permissions and network addresses the card uses;
- tags and a category — agents, productivity, dev tools, data, integrations, fun or other;
- who reviewed it, when, and any notes from the review.

The app downloads the list when it starts, every 6 hours, and when you press **Refresh**. Offline, it
shows the last copy it downloaded — or, on a fresh install, the copy that ships with the app.

## Find and install a verified card

The list is in two places: the **Verified** tab of the **Custom card…** picker in the add menu (the
**+** on the canvas or in the sidebar), and the **Verified cards** section of **Settings → Custom
cards**.

Search looks at names in all three languages, descriptions and tags, right on your computer. You can
also filter by category. Each row shows the card's icon, name, description, author, category and a
summary of its permissions, with a button: **Install**, **Installed**, or **Verified update**.

**1. Find the card**

Open the **Verified** tab or the **Verified cards** section, search or pick a category.

**2. Press Install**

NeuroSquad downloads **exactly the reviewed commit** — not the newest code in the repository — and
compares the files' tree hash with the reviewed one. If they differ, the install is refused:
"the files differ from what was reviewed".

**3. Read the permission dialog and confirm**

You see the same [install dialog](https://docs.neurosquad.ai/en/card-sdk/community-cards#reading-the-install-dialog) as for
any other card. Verified does not skip your consent: you still decide whether the card gets
what it asks for.

You can still install any card by its GitHub address, as before. The catalog only adds a list of
cards somebody has looked at.

## The Verified badge

A verified card carries a **Verified** badge — a shield with a check mark — on its catalog row, in the
install dialog, on the installed card in **Settings → Custom cards**, and in the card's **About**
panel.

It is a different badge from **Official**. Official means the card is published by the NeuroSquad
team from its `glmn-ai` organization on GitHub; Verified means the team reviewed this version. A card
can carry both.

The badge is shown only when all three match a current entry of the list:

- the card's source — the same repository and folder;
- the commit it was installed from;
- the tree hash of its files, equal to the reviewed one.

So a card linked from a local folder, installed from another commit (for example, the newest commit
of a branch), or whose files differ carries no badge — even if another version of it is verified.

> **Verified** means: reviewed by the NeuroSquad team at version X on date Y. It is not a guarantee
> that the card has no bugs or will stay safe forever, and it says nothing about any other version.
> Read the permission dialog as carefully as for any other card.

## Verified updates

When the list points a card at a newer reviewed version, **Settings → Custom cards** shows **Verified
update available** for it. Pressing it installs exactly that reviewed commit through the usual
[update dialog](https://docs.neurosquad.ai/en/card-sdk/community-cards#updates), which shows what changes in the card's
permissions. Nothing is updated automatically.

If a card is removed from the list, its badge disappears and a neutral note says it is no longer in
the verified list. The card stays installed and keeps working; whether to keep it is your call.

## On the phone

With [remote access](https://docs.neurosquad.ai/en/remote), you can browse the verified list on your phone, but not install from
it: installing is only possible on the computer.

## For card authors: get your card verified

Verification is a pull request to
[glmn-ai/neurosquad-cards](https://github.com/glmn-ai/neurosquad-cards) that adds your card's entry
to `verified.json`. The exact rules and the entry format are in its
[CONTRIBUTING.md](https://github.com/glmn-ai/neurosquad-cards/blob/HEAD/CONTRIBUTING.md) — read it
before you open the pull request.

**4. Publish the card**

It must be in a **public** GitHub repository, on the **default branch**. See
[Publishing & updates](https://docs.neurosquad.ai/en/card-sdk/publishing).

**5. Get the commit and the tree hash**

Take the exact commit you want reviewed. For the tree hash, run
[`neurosquad-card pack`](https://docs.neurosquad.ai/en/card-sdk/cli#pack) on the card's folder at that commit — it prints the
tree hash the app records at install.

**6. Open a pull request**

Add your entry to `verified.json` — names and descriptions, repository and folder, version,
commit, tree hash, permissions, network addresses, tags, category, licence — as CONTRIBUTING.md
describes.

**Updating a verified card** is another pull request that bumps the version, commit and tree hash.
Each version is reviewed again; until the new one is accepted, users keep the badge on the version
that was reviewed, and code you push in the meantime is not offered as a verified update.

### What reviewers check

- The full source at that commit. No obfuscated code, and no minified-only code without its source.
- Permissions and network addresses are the minimum the card needs, and match the entry.
- The descriptions of its tools and ports are honest.
- The manifest matches the entry — name and version.
- The tree hash reproduces.
- The card has a licence.
- It installs and works on the current version of the app.
- It does not impersonate NeuroSquad or any other brand.
- It does no tracking beyond what it declares.

The [security checklist](https://docs.neurosquad.ai/en/card-sdk/security) covers most of this — go through it before you submit.
