index-cardsSend real, physical greeting cards through the mail. Design custom cards with the user, print on premium cardstock, and mail with a first-class stamp. Use when the user wants to send a card, mentions a birthday or occasion, or asks about greeting cards. Requires a free API registration (POST /v1/auth/register returns a Bearer token). Works via API — no browser needed. Homepage https://indexcards.com — privacy policy at https://indexcards.com/privacy.
Install via ClawdBot CLI:
clawdbot install jonwheatley/index-cardsGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
POST → https://generativelanguage.googleapis.com/v1beta/models/imagen-4.0-generate-001:Calls external URL not in known-safe list
https://indexcards.comUses known external API (expected, informational)
googleapis.comAI Analysis
The skill's primary external API (indexcards.com) is documented and consistent with its stated purpose of sending physical cards. The undocumented call to googleapis.com for image generation is a functional dependency for card artwork, not a hidden data exfiltration channel, as it processes user-provided descriptions into images. The skill requires explicit user consent for data access and uses secure payment flows.
Generated Mar 21, 2026
Users send custom-designed physical cards for personal occasions like birthdays, holidays, and thank-yous. The AI assists in designing artwork and handling mailing logistics, ideal for individuals wanting to send thoughtful, personalized cards without manual effort.
Businesses use the skill to send branded or custom cards to clients, employees, or partners for events like anniversaries or holidays. It streamlines design and delivery, enhancing relationship management through personalized physical mail.
Event planners or individuals organizing weddings, parties, or gatherings create and mail custom invitation cards. The AI helps design visually appealing cards and ensures timely delivery, reducing planning overhead.
Non-profits send thank-you cards or updates to donors, leveraging custom designs to foster connections. The skill automates card creation and mailing, supporting outreach efforts with personalized physical communications.
Schools or teachers send cards to students, parents, or staff for achievements, holidays, or events. It simplifies creating educational-themed designs and managing bulk mailing, enhancing community engagement.
Users purchase credits in bundles (e.g., $50 for 5 cards, $100 for 12 cards) to send cards, with image generation free and printing costs covered by credits. This model encourages bulk purchases and recurring revenue through card usage.
The skill's API is licensed to third-party platforms (e.g., CRM systems, event apps) for embedding card-sending capabilities. Revenue comes from licensing fees or revenue-sharing agreements based on card usage through integrations.
Additional revenue is generated by offering premium features like expedited shipping, custom paper stocks, or advanced design tools (e.g., QR code overlays). Users pay extra for enhanced services beyond basic card sending.
💬 Integration Tip
Ensure user consent for data access and handle API rate limits by generating images sequentially to avoid errors.
Scored Apr 19, 2026
Audited Apr 18, 2026 · audit v1.0
Self-hosted auth for TypeScript/Cloudflare Workers with social auth, 2FA, passkeys, organizations, RBAC, and 15+ plugins. Requires Drizzle ORM or Kysely for D1 (no direct adapter). Self-hosted alternative to Clerk/Auth.js. Use when: self-hosting auth on D1, building OAuth provider, multi-tenant SaaS, or troubleshooting D1 adapter errors, session caching, rate limits, Expo crashes, additionalFields bugs.
Clerk integration. Manage Users, Organizations. Use when the user wants to interact with Clerk data.
Clerk auth with API Keys beta (Dec 2025), Next.js 16 proxy.ts (March 2025 CVE context), API version 2025-11-10 breaking changes, clerkMiddleware() options, webhooks, production considerations (GCP outages), and component reference. Prevents 15 documented errors. Use when: API keys for users/orgs, Next.js 16 middleware filename, troubleshooting JWKS/CSRF/JWT/token-type-mismatch errors, webhook verification, user type inconsistencies, or testing with 424242 OTP.
Use when auditing Go code involving authentication flows, RBAC policies, Kubernetes admission webhooks, JWT/OAuth token validation, or privilege escalation i...
Agent verification via ClawX OAuth system. Use when checking agent verification status, embedding verification widgets, or working with agent identity/trust tiers.
Complete Reva wallet management - passwordless authentication, PayID name claiming, multi-chain crypto transfers to PayIDs or wallet addresses, balance track...