Security & trust
The Agent Store is built so you can see exactly what an agent can do before you run it. Here is how we keep it safe.
Standardized, checksummed packages
Every agent ships as a NAP package with a strict manifest. We compute a SHA-256 of the exact reviewed artifact and show it on the listing — downloads always serve that same bytes.
Automated security scans
On every version upload we run secret detection, static-code and instruction audits, a dependency check, and a network-behavior review. A version is not installable until its scans pass, and versions are re-scanned so a later-discovered issue auto-suspends the listing.
Permissions shown before you install
Each listing declares exactly what the agent can touch — filesystem, network domains, terminal, browser, and whether it shares data with third parties — computed into a Low / Medium / High level you can filter by.
Your secrets stay yours
API keys and secrets are entered on your own machine when you deploy. Neura Market never stores your credentials.
Human review & takedowns
Listings pass through a moderation queue, and anyone can report a listing. Confirmed problems are delisted. Publisher tiers (Community, Verified, Official) reflect identity checks.
Report a concern
Found a listing that looks unsafe or misleading? Use the “Report this listing” button on any agent page, or email team@neura.market. We review every report.