Find a file
A 35b4bd5ada
fix: Add port validation and CSRF protection to OAuth server (#72)
SECURITY FIXES:
- Add validate_oauth_port() to prevent command injection via port parameter
  - Ensures port is numeric and in range 1024-65535
  - Prevents JavaScript injection in OAuth server code
- Add CSRF state parameter to OAuth flow
  - Generate random 128-bit state token per session
  - Validate state parameter in callback to prevent OAuth code interception
  - Display error page if state validation fails

IMPACT:
- Prevents CRITICAL command injection vulnerability (CVE-worthy)
- Prevents HIGH OAuth code stealing attacks via CSRF

TESTING:
- All 101 tests pass (bun test)
- Syntax validated (bash -n)
- No regressions introduced

Agent: security-auditor

Co-authored-by: A <6723574+louisgv@users.noreply.github.com>
Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-02-09 03:37:43 -08:00
.claude fix: Use git fetch --prune to clean stale remote-tracking refs (#68) 2026-02-09 03:19:04 -08:00
.githooks Add guardrails: CLAUDE.md rules, hooks, pre-commit validation (#33) 2026-02-07 20:02:19 -08:00
.github feat: Add agent and cloud request issue templates 2026-02-09 10:10:10 +00:00
aws-lightsail fix: Use robust OpenCode install method across all clouds (#48) 2026-02-07 23:02:18 -08:00
binarylane fix: Use robust OpenCode install method across all clouds (#48) 2026-02-07 23:02:18 -08:00
civo fix: Use robust OpenCode install method across all clouds (#48) 2026-02-07 23:02:18 -08:00
cli feat: Improve error messages and troubleshooting guidance (#71) 2026-02-09 03:37:17 -08:00
daytona Security: fix critical command injection vulnerabilities in container providers (#54) 2026-02-08 12:00:43 -08:00
digitalocean fix: Use robust OpenCode install method across all clouds (#48) 2026-02-07 23:02:18 -08:00
e2b Security: fix critical command injection vulnerabilities in container providers (#54) 2026-02-08 12:00:43 -08:00
fly refactor: Security fixes, complexity reduction, and UX improvements (#58) 2026-02-08 17:09:27 -08:00
gcp fix: Use robust OpenCode install method across all clouds (#48) 2026-02-07 23:02:18 -08:00
genesiscloud Add Genesis Cloud scripts for amazonq, cline, gptme, opencode, plandex (#47) 2026-02-07 23:02:04 -08:00
hetzner feat: Add community-coordinator agent to refactor team (#64) 2026-02-09 02:58:26 -08:00
lambda fix: Use robust OpenCode install method across all clouds (#48) 2026-02-07 23:02:18 -08:00
linode fix: Use robust OpenCode install method across all clouds (#48) 2026-02-07 23:02:18 -08:00
modal feat: Improve error messages and troubleshooting guidance (#71) 2026-02-09 03:37:17 -08:00
railway Security: fix critical command injection vulnerabilities in container providers (#54) 2026-02-08 12:00:43 -08:00
runpod fix: Use robust OpenCode install method across all clouds (#48) 2026-02-07 23:02:18 -08:00
scaleway refactor: Extract common API retry interval update logic to reduce duplication (#70) 2026-02-09 03:36:08 -08:00
shared fix: Add port validation and CSRF protection to OAuth server (#72) 2026-02-09 03:37:43 -08:00
sprite feat: Improve error messages and troubleshooting guidance (#71) 2026-02-09 03:37:17 -08:00
test refactor: Security fixes, complexity reduction, and UX improvements (#58) 2026-02-08 17:09:27 -08:00
upcloud refactor: Extract common API retry interval update logic to reduce duplication (#70) 2026-02-09 03:36:08 -08:00
vultr fix: Use robust OpenCode install method across all clouds (#48) 2026-02-07 23:02:18 -08:00
.gitignore refactor: Move trigger service scripts into skill directory 2026-02-08 18:50:27 +00:00
.shellcheckrc ci: add shellcheck linting infrastructure 2026-02-08 01:08:34 +00:00
CLAUDE.md Enforce PR merge-or-close-with-comment policy (#50) 2026-02-07 23:12:51 -08:00
LICENSE Improve README with better intro, how-it-works, and dev guide (#51) 2026-02-08 18:16:46 +00:00
manifest.json Add Genesis Cloud scripts for amazonq, cline, gptme, opencode, plandex (#47) 2026-02-07 23:02:04 -08:00
README.md UX: Improve error messages, help text, and progress indicators (#55) 2026-02-08 12:00:59 -08:00

Spawn

Launch any AI coding agent on any cloud with a single command. All models powered by OpenRouter. (ALPHA software, use at your own risk!)

13 agents. 18 clouds. 234 combinations. Zero config.

Install

curl -fsSL https://openrouter.ai/lab/spawn/cli/install.sh | bash

Or install directly from GitHub:

curl -fsSL https://raw.githubusercontent.com/OpenRouterTeam/spawn/main/cli/install.sh | bash

Usage

spawn                         # Interactive picker
spawn <agent> <cloud>         # Launch directly
spawn list                    # Show the full matrix

Examples

spawn                                    # Interactive picker
spawn claude sprite                      # Claude Code on Sprite
spawn aider hetzner                      # Aider on Hetzner
spawn claude sprite --prompt "Fix bugs"  # Non-interactive with prompt
spawn aider sprite -p "Add tests"        # Short form
spawn claude                             # Show clouds available for Claude

Commands

Command Description
spawn Interactive agent + cloud picker
spawn <agent> <cloud> Launch agent on cloud directly
spawn <agent> <cloud> -p "text" Non-interactive with prompt
spawn <agent> <cloud> --prompt-file f.txt Prompt from file
spawn <agent> Show available clouds for an agent
spawn list Full agent x cloud matrix
spawn agents List all agents
spawn clouds List all cloud providers
spawn update Check for CLI updates

Without the CLI

Every combination works as a one-liner — no install required:

bash <(curl -fsSL https://openrouter.ai/lab/spawn/{cloud}/{agent}.sh)

Non-Interactive Mode

Skip prompts by providing environment variables:

# OpenRouter API key (required for all agents)
export OPENROUTER_API_KEY=sk-or-v1-xxxxx

# Cloud-specific credentials (varies by provider)
export SPRITE_API_KEY=...        # For Sprite
export HCLOUD_TOKEN=...           # For Hetzner
export DIGITALOCEAN_TOKEN=...     # For DigitalOcean

# Run non-interactively
spawn claude sprite

You can also use inline environment variables:

OPENROUTER_API_KEY=sk-or-v1-xxxxx spawn claude sprite

Get your OpenRouter API key at: https://openrouter.ai/settings/keys

For cloud-specific auth, see each cloud's README in this repository.

Matrix

Sprite Hetzner DigitalOcean Vultr Linode Lambda Lightsail GCP E2B Modal Fly.io Civo Scaleway Daytona RunPod UpCloud BinaryLane Genesis Cloud
Claude Code
OpenClaw
NanoClaw
Aider
Goose
Codex CLI
Open Interpreter
Gemini CLI
Amazon Q CLI
Cline
gptme
OpenCode
Plandex

How it works

Each cell in the matrix is a self-contained bash script that:

  1. Provisions a server on the cloud provider
  2. Installs the coding agent
  3. Injects your OpenRouter API key so every agent uses the same billing
  4. Drops you into an interactive session

Scripts work standalone (bash <(curl ...)) or through the CLI.

Development

git clone https://github.com/OpenRouterTeam/spawn.git
cd spawn
git config core.hooksPath .githooks

Structure

{cloud}/lib/common.sh    # Cloud provider primitives (provision, SSH, cleanup)
{cloud}/{agent}.sh        # Agent deployment script
shared/common.sh          # Shared utilities (OAuth, logging, SSH helpers)
cli/                      # TypeScript CLI (bun)
manifest.json             # Source of truth for the matrix

Adding a new cloud

  1. Create {cloud}/lib/common.sh with provisioning primitives
  2. Add to manifest.json
  3. Implement agent scripts using the cloud's primitives
  4. See CLAUDE.md for full contributor guide

Adding a new agent

  1. Add to manifest.json
  2. Implement on 1+ cloud by adapting an existing agent script
  3. Must support OpenRouter via env var injection

License

Apache 2.0