# Card Master puts your userscripts in a card deck, and the deck is empty until one toggle is on

> A TypeScript browser extension that presents userscripts, an AI script workshop, content filtering, media speed control and WebDAV sync as playable cards, built from one codebase for Chromium, Firefox and Safari. The zips are not installers, Safari has no notarized build yet, and the card layout depends on a per-site permission that reads as cosmetic until it is missing.

**LYiHub/Card-master-browser-extension-public** — 一个卡牌游戏浏览器扩展，可以把各种浏览器脚本、扩展做成可游玩的卡牌，还可以用AI自动生成全新卡牌插件

- Repository: https://github.com/LYiHub/Card-master-browser-extension-public
- Stars: 421 · Forks: 45
- Language: TypeScript
- License: GPL-3.0
- Published: 2026-09-18 · Updated: 2026-09-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/lyihub-card-master-browser-extension-public

## Without the allow user scripts toggle, every script under the deck stays inert

The most common broken install here is a warning rather than a numbered step. On Chromium, the fifth install step is opening the extension details and switching on the toggle the interface labels as allow user scripts. Leave it off and no userscript runs at all, including the ones bundled with the extension. The deck still renders, which is what makes this confusing: the failure looks like a feature with nothing behind it.

That matters more here than in a plain userscript manager, because the card layout is the interface to the scripts rather than a view over them.

A second Chromium gate sits behind the first, and it is per-origin. When a site reports that access is not allowed, the fix is in the extension icon or in the sites-with-access list on the details page, where you can grant the current site or all sites. A working install therefore needs two permissions granted in two different places, and the second one has to be granted again for every new origin you care about.

Firefox has no equivalent switch, because about:debugging#/runtime/this-firefox offers no such toggle. You extract the folder, choose load temporary add-on, select the manifest.json inside it, and allow the userscript permission when Firefox prompts. One gate instead of two, and it is the first one that disappears.

## Four zips per engine pair, and the new-tab variant changes one manifest declaration

Each engine ships two packages, and the difference between them is a single declaration.

The set is card-master-v*-chromium.zip, card-master-v*-chromium-browser-new-tab.zip, and the same pair for firefox. Take the browser-new-tab build and the extension stops claiming the browser's new tab page, so your own start page comes back. Cards, scripts and the AI features behave the same on ordinary web pages either way.

Two caveats travel with that choice. Browser native pages are limited by what the extension can be granted, so the card layout does not appear on them. And when some other new tab extension also claims the page, that conflict is settled in the browser rather than in this project.

The settings screen contains one trap. The option that selects the Card Master page only clears the custom URL stored by the standard build. Restoring the browser's native new tab means switching install packages, not flipping that setting. The browser-new-tab build still reaches its own page from the extension settings entry that opens the Card Master page.

One core codebase produces all three platform packages, so the differences above are build flags rather than forks.

## Upgrades overwrite the original folder, because the extension identity holds your data

The upgrade procedure is specific enough to be worth stating plainly. When Card Master is already installed, extract the matching package completely and overwrite the original install directory, the one that directly contains manifest.json. Then reload it from the extensions page and open a new tab.

Three things are forbidden in that sequence: do not uninstall the extension, do not clear storage, and do not install into a fresh directory. Stored data is tied to the extension identity the browser assigned the first time you pointed it at a folder, and each of those three moves discards that identity along with the data.

Switching between the standard build and the browser-new-tab build follows the same procedure, and the card library, API configuration and custom URL settings survive it. That is the practical reason to decide which new tab you want before the first install rather than after.

This is the cost of loading unpacked code, and it follows directly from the fact that the zips are not installers. There is no signed package for a browser to update on its own, so the directory you first loaded is the thing that has to keep existing.

## The zips are not installers, and SHA256SUMS.txt is the only integrity check named

Download from the Releases page, verify SHA256SUMS.txt, then extract.

That order matters. A zip you are about to unpack and then hand to a browser as executable code is exactly where a substituted file does damage, and SHA256SUMS.txt ships alongside the artifacts for that check. Nothing in the install path signs the package beyond that checksum file.

For Chromium browsers, Chrome, Edge, Brave, Arc and the rest, the extracted folder goes in through load unpacked on chrome://extensions or the equivalent page, with developer mode enabled in the top right. Firefox takes the same folder as a temporary add-on.

Two lines elsewhere in the install notes read as warnings rather than steps. One says not to turn off system security checks. The other, under Safari, says not to fall back on an old un-notarized preview package, because the current release deliberately offers no Safari download while Apple notarization is still pending and progress is tracked as Issue #2. The project is asking you to have no Safari build rather than to have an unverifiable one.

## Safari ships no download, and its documented path applies to source builds only

Safari is the one platform the project refuses to hand you a build for.

The release table lists macOS Safari as no download provided yet and points at Issue #2 for notarization progress. The Safari instructions that remain are labelled as applying to source builds and to the state after official distribution resumes, which is a clear statement that the documented Safari path is not the path an installed user should follow today.

Permission handling differs in shape as well. Opening Card Master.app is not enough on its own; the site permissions still have to be granted inside Safari, and without them no card layout appears on web pages at all. The sequence is Safari settings, then Extensions, then tick the extension, then choose always allow on every website and confirm it for all sites. After an update or a reinstall you must quit Safari completely before opening it again, which is the kind of step that gets skipped and then blamed on the extension.

The card layout shortcut is Command-Shift-E. There is also no Chromium-style userscript switch on Safari, because scripts there run through injection the extension performs itself. The toggle that silently breaks everything on Chromium does not exist to be left off.

## Two cards never appear on Safari, and the reason is the web extension API

Safari loses two cards permanently, and the cause is the platform's web extension API rather than a packaging mistake.

Safari web extensions have no history, no bookmarks, no topSites, no downloads and no complete webRequest. The new tab card builds an AI daily review wallpaper from browsing history, so on Safari it has nothing to read and the card and its related pages are not shown. The card named for picking things up, which discovers and obtains media from a page, has no runnable upstream implementation on Safari and is omitted for the same reason. Both absences are stated as expected rather than as a failed install.

That also tells you what the other cards are standing on. On Chromium and Firefox, the new tab card, the media card and the content filtering card all sit on top of extension APIs that Safari restricts or withholds, so a capability you use daily on Chrome may simply have no Safari counterpart.

The rest do work there: user scripts, the AI script workshop, the click-to-hide card for ads and other content, the dark theme recompute, unified audio and video speed control, video enhancement including SponsorBlock for Bilibili and YouTube, and the mouse, keyboard and gamepad layer with its on-screen keyboard, pinyin and voice input. What you give up is the two cards that need browsing history and a full webRequest surface.

## WebDAV sync keeps scripts, cards and plugin config behind a server you run

One card leaves the browser, and it is the one that moves your data between machines.

Under Settings, then Data Management, then cross-device sync, you connect a WebDAV service of your own and the extension synchronises scripts, cards and plugin configuration as a single set. Three details make it usable rather than dangerous: a merge preview before anything is written, a choice when the same item differs on both sides, and history restore to return to an earlier state.

Running your own endpoint is the point. A userscript library is the list of code that executes on every page you open, so the boundary around it should be one you chose rather than an account on somebody else's server.

What the documentation does not cover is as relevant as what it does. No WebDAV implementation is named as supported, no conflict is described in practice, and no limit is given for how large a library the merge preview handles. On a source build the same three menu levels apply. A first sync over a small script set is the sensible way to find out, before pointing it at a library you would not want to reconcile by hand.

## pnpm check runs Biome, then tsc, then Vitest, and packaging is a separate script

Building from source takes three commands and a pinned toolchain.

```bash
pnpm install --frozen-lockfile
pnpm check
pnpm extension:package --platform=all
```

Node 22 or newer is required, and pnpm 11.18.0 is pinned as the package manager. Artifacts land in extension-dist/, where the Chromium and Firefox builds also emit the matching browser-new-tab directories alongside and share every runtime file with the standard build for the same platform.

pnpm check is the contributor gate and it runs three things in order: Biome with --error-on-warnings, then tsc --noEmit against tsconfig.json, then vitest run. lint and typecheck exist as separate scripts if you want one of them on its own.

Packaging sits outside that gate. extension:package calls scripts/package-extensions.mjs, extension:zip calls scripts/package-chromium-zip.mjs, and release:package has a preview twin, release:package:preview, which passes --allow-unnotarized-safari. That flag is the only route to a Safari artifact, which is why the Safari permission notes exist at all. A secrets:check script runs node scripts/check-secrets.mjs, and ship runs scripts/check-commit-push.mjs. The runtime dependencies include react 18, gsap 3.15, acorn 8.17, tldts 7.4.9, the AdGuard tsurlfilter packages, lucide-react, and spatial-nav-css vendored from vendor/. This manifest copy ends inside devDependencies, so the pinned versions of the remaining tooling are not visible.

## Conclusion

Card Master is worth a look if you already run userscripts and want them and your page tools in one surface, and if you are willing to manage an unpacked extension by hand, because that is the only install path offered and it is why upgrades need care. Do not pick it for Safari today: there is no notarized download and Issue #2 is where that is tracked. Before installing, verify the zip against SHA256SUMS.txt, then confirm you can enable allow user scripts and grant site access, because a card deck over inert scripts looks like a working install and is not one. Decide which new tab you want first, since switching later means overwriting the folder in place rather than reinstalling.

## FAQ

### How do I install Card Master on Chrome or Edge?

Extract card-master-v*-chromium.zip, open chrome://extensions, turn on developer mode, choose load unpacked and select the extracted folder. Then open the extension details, switch on the toggle that allows user scripts, and reload. Without that toggle no userscript runs, including the preinstalled ones.

### What is the difference between the two Card Master zip builds?

The browser-new-tab package differs only in the new tab takeover declaration in manifest.json, so the browser keeps its own new tab page while cards, scripts and AI features still work on ordinary pages. Restoring the native new tab means switching packages, not changing a setting.

### Can I install Card Master on Safari?

Not from a release yet. The macOS Safari row lists no download while Apple notarization is pending, with progress tracked in Issue #2, and the project asks users not to fall back on old un-notarized preview packages or to disable system security checks.

### How do I upgrade Card Master without losing my cards?

Extract the new package completely and overwrite the original install directory, the one that directly contains manifest.json, then reload from the extensions page. Do not uninstall the extension, clear storage, or move to a new directory, because stored data is tied to the original extension identity.

### What does WebDAV sync cover in Card Master?

Connecting your own WebDAV service under Settings, Data Management, then cross-device sync synchronises scripts, cards and plugin configuration together, with a merge preview, conflict selection and history restore.

## Sources

- [Issues](https://github.com/LYiHub/Card-master-browser-extension-public/issues)
- [License: GPL-3.0](https://github.com/LYiHub/Card-master-browser-extension-public/blob/main/LICENSE)
- [LYiHub/Card-master-browser-extension-public on GitHub](https://github.com/LYiHub/Card-master-browser-extension-public)
- [README](https://github.com/LYiHub/Card-master-browser-extension-public/blob/main/README.md)
- [Releases](https://github.com/LYiHub/Card-master-browser-extension-public/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/lyihub-card-master-browser-extension-public
