Security & trust

The Agent Store is built so you can see exactly what an agent can do before you run it. Here is how we keep it safe.

  • Standardized, checksummed packages

    Every agent ships as a NAP package with a strict manifest. We compute a SHA-256 of the exact reviewed artifact and show it on the listing — downloads always serve that same bytes.

  • Automated security scans

    On every version upload we run secret detection, static-code and instruction audits, a dependency check, and a network-behavior review. A version is not installable until its scans pass, and versions are re-scanned so a later-discovered issue auto-suspends the listing.

  • Permissions shown before you install

    Each listing declares exactly what the agent can touch — filesystem, network domains, terminal, browser, and whether it shares data with third parties — computed into a Low / Medium / High level you can filter by.

  • Your secrets stay yours

    API keys and secrets are entered on your own machine when you deploy. Neura Market never stores your credentials.

  • Human review & takedowns

    Listings pass through a moderation queue, and anyone can report a listing. Confirmed problems are delisted. Publisher tiers (Community, Verified, Official) reflect identity checks.

Report a concern

Found a listing that looks unsafe or misleading? Use the “Report this listing” button on any agent page, or email team@neura.market. We review every report.