Find a file
A ea39c8bf28
fix: prevent command injection in update-check reExecWithArgs (#951)
Replace execSync with execFileSync in reExecWithArgs() to prevent shell
metacharacter injection via binary path. execFileSync bypasses the shell
entirely, executing the binary directly with an argv array.

The performAutoUpdate() call retains execSync since it legitimately needs
a shell for piping (curl | bash).

Fixes #950

Agent: security-auditor

Co-authored-by: A <6723574+louisgv@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-02-13 08:34:04 -08:00
.claude feat: Add PR comment triage to security reviewer and refactor pr-maintainer (#940) 2026-02-13 06:25:45 -08:00
.githooks Add guardrails: CLAUDE.md rules, hooks, pre-commit validation (#33) 2026-02-07 20:02:19 -08:00
.github refactor: Simplify security workflow to match discovery/refactor pattern (#929) 2026-02-13 05:26:21 -08:00
atlanticnet fix: use safe inject_env_vars helpers in 4 missed scripts (#941) 2026-02-13 07:00:26 -08:00
aws-lightsail refactor: replace Python with jq in Hetzner lib, fix /lab → /labs URLs (#827) 2026-02-12 23:14:11 -08:00
binarylane fix: replace jargon "Remediation" with plain "How to fix" in error messages (#925) 2026-02-13 05:52:31 -08:00
cherry refactor: replace hand-rolled polling with generic_wait_for_instance in 3 clouds (#850) 2026-02-13 06:52:22 -08:00
civo fix: use safe inject_env_vars helpers in 3 missed scripts (#937) 2026-02-13 06:42:13 -08:00
cli fix: prevent command injection in update-check reExecWithArgs (#951) 2026-02-13 08:34:04 -08:00
cloudsigma fix: improve CloudSigma error messages and update RamNode README (#947) 2026-02-13 07:54:31 -08:00
codesandbox fix: use safe inject_env_vars helpers in 4 missed scripts (#941) 2026-02-13 07:00:26 -08:00
contabo refactor: use sys.argv instead of bash interpolation in Python body builders (#842) 2026-02-13 01:45:11 -08:00
daytona refactor: decompose Daytona create_server and test_daytona_token into focused helpers (#939) 2026-02-13 06:46:13 -08:00
digitalocean refactor: deduplicate _ensure_jq and decompose DO create_server (#943) 2026-02-13 07:25:08 -08:00
e2b fix: replace jargon "Remediation" with plain "How to fix" in error messages (#925) 2026-02-13 05:52:31 -08:00
exoscale fix: replace jargon "Remediation" with plain "How to fix" in error messages (#925) 2026-02-13 05:52:31 -08:00
fly fix: replace jargon "Remediation" with plain "How to fix" in error messages (#925) 2026-02-13 05:52:31 -08:00
gcp refactor: replace Python with jq in Hetzner lib, fix /lab → /labs URLs (#827) 2026-02-12 23:14:11 -08:00
genesiscloud fix: replace jargon "Remediation" with plain "How to fix" in error messages (#925) 2026-02-13 05:52:31 -08:00
github-codespaces refactor: replace Python with jq in Hetzner lib, fix /lab → /labs URLs (#827) 2026-02-12 23:14:11 -08:00
hetzner refactor: deduplicate _ensure_jq and decompose DO create_server (#943) 2026-02-13 07:25:08 -08:00
hostinger refactor: use sys.argv instead of bash interpolation in Python body builders (#842) 2026-02-13 01:45:11 -08:00
hostkey refactor: deduplicate _ensure_jq and decompose DO create_server (#943) 2026-02-13 07:25:08 -08:00
hyperstack fix: use log_step (cyan) for progress messages instead of log_warn (yellow) (#534) 2026-02-11 14:37:43 -08:00
ionos refactor: replace hand-rolled loops/helpers with shared utilities in cherry and ionos (#916) 2026-02-13 05:07:17 -08:00
kamatera fix: replace jargon "Remediation" with plain "How to fix" in error messages (#925) 2026-02-13 05:52:31 -08:00
koyeb refactor: replace Python with jq in Hetzner lib, fix /lab → /labs URLs (#827) 2026-02-12 23:14:11 -08:00
latitude refactor: reduce complexity in latitude and ovh cloud libs (#835) 2026-02-13 01:17:20 -08:00
linode fix: replace jargon "Remediation" with plain "How to fix" in error messages (#925) 2026-02-13 05:52:31 -08:00
local feat: Add local/amazonq (#871) 2026-02-13 06:11:13 -08:00
modal refactor: replace Python with jq in Hetzner lib, fix /lab → /labs URLs (#827) 2026-02-12 23:14:11 -08:00
netcup refactor: extract helpers to reduce complexity in fly and netcup providers (#912) 2026-02-13 05:07:53 -08:00
northflank refactor: replace Python with jq in Hetzner lib, fix /lab → /labs URLs (#827) 2026-02-12 23:14:11 -08:00
oracle refactor: replace Python with jq in Hetzner lib, fix /lab → /labs URLs (#827) 2026-02-12 23:14:11 -08:00
ovh refactor: use sys.argv instead of bash interpolation in Python body builders (#842) 2026-02-13 01:45:11 -08:00
railway refactor: replace Python with jq in Hetzner lib, fix /lab → /labs URLs (#827) 2026-02-12 23:14:11 -08:00
ramnode fix: improve CloudSigma error messages and update RamNode README (#947) 2026-02-13 07:54:31 -08:00
render refactor: replace raw curl calls in render/lib/common.sh with render_api wrapper (#933) 2026-02-13 05:56:20 -08:00
scaleway refactor: replace hand-rolled polling with generic_wait_for_instance in 3 clouds (#850) 2026-02-13 06:52:22 -08:00
shared refactor: extract ensure_jq to shared lib and decompose CloudSigma helpers (#946) 2026-02-13 07:34:36 -08:00
sprite refactor: replace Python with jq in Hetzner lib, fix /lab → /labs URLs (#827) 2026-02-12 23:14:11 -08:00
test feat: add CloudSigma cloud provider (#860) 2026-02-13 06:50:25 -08:00
upcloud fix: replace jargon "Remediation" with plain "How to fix" in error messages (#925) 2026-02-13 05:52:31 -08:00
vultr fix: replace jargon "Remediation" with plain "How to fix" in error messages (#925) 2026-02-13 05:52:31 -08:00
.gitignore fix: address medium security findings from #753 (#755) 2026-02-12 15:48:52 -08:00
.shellcheckrc ci: add shellcheck linting infrastructure 2026-02-08 01:08:34 +00:00
CLAUDE.md feat: Add PR comment triage to security reviewer and refactor pr-maintainer (#940) 2026-02-13 06:25:45 -08:00
LICENSE Improve README with better intro, how-it-works, and dev guide (#51) 2026-02-08 18:16:46 +00:00
manifest.json feat: add CloudSigma cloud provider (#860) 2026-02-13 06:50:25 -08:00
README.md docs: Sync README matrix with manifest.json (#884) 2026-02-13 06:23:55 -08:00

Spawn

Launch any AI agent on any cloud with a single command. Coding agents, research agents, self-hosted AI tools — Spawn deploys them all. All models powered by OpenRouter. (ALPHA software, use at your own risk!)

15 agents. 34 clouds. 485 combinations. Zero config.

Install

curl -fsSL https://openrouter.ai/labs/spawn/cli/install.sh | bash

Or install directly from GitHub:

curl -fsSL https://raw.githubusercontent.com/OpenRouterTeam/spawn/main/cli/install.sh | bash

Usage

spawn                         # Interactive picker
spawn <agent> <cloud>         # Launch directly
spawn matrix                  # Show the full agent x cloud matrix

Examples

spawn                                    # Interactive picker
spawn claude sprite                      # Claude Code on Sprite
spawn aider hetzner                      # Aider on Hetzner
spawn claude sprite --prompt "Fix bugs"  # Non-interactive with prompt
spawn aider sprite -p "Add tests"        # Short form
spawn claude                             # Show clouds available for Claude

Commands

Command Description
spawn Interactive agent + cloud picker
spawn <agent> <cloud> Launch agent on cloud directly
spawn <agent> <cloud> --dry-run Preview without provisioning
spawn <agent> <cloud> -p "text" Non-interactive with prompt
spawn <agent> <cloud> --prompt-file f.txt Prompt from file
spawn <agent> Show available clouds for an agent
spawn matrix Full agent x cloud matrix
spawn list Show previously launched spawns
spawn agents List all agents
spawn clouds List all cloud providers
spawn update Check for CLI updates

Without the CLI

Every combination works as a one-liner — no install required:

bash <(curl -fsSL https://openrouter.ai/labs/spawn/{cloud}/{agent}.sh)

Non-Interactive Mode

Skip prompts by providing environment variables:

# OpenRouter API key (required for all agents)
export OPENROUTER_API_KEY=sk-or-v1-xxxxx

# Cloud-specific credentials (varies by provider)
export SPRITE_API_KEY=...        # For Sprite
export HCLOUD_TOKEN=...           # For Hetzner
export DO_API_TOKEN=...           # For DigitalOcean

# Run non-interactively
spawn claude sprite

You can also use inline environment variables:

OPENROUTER_API_KEY=sk-or-v1-xxxxx spawn claude sprite

Get your OpenRouter API key at: https://openrouter.ai/settings/keys

For cloud-specific auth, see each cloud's README in this repository.

Matrix

Sprite Hetzner Cloud DigitalOcean Vultr Linode (Akamai) AWS Lightsail GCP Compute Engine GitHub Codespaces CodeSandbox E2B Modal Fly.io Civo Scaleway Daytona UpCloud BinaryLane Latitude.sh OVHcloud Kamatera Cherry Servers Oracle Cloud Infrastructure Koyeb Northflank Railway Render IONOS Cloud Exoscale Contabo Hostinger Netcup Local Machine RamNode Atlantic.Net
Claude Code
OpenClaw
NanoClaw
Aider
Goose
Codex CLI
Open Interpreter
Gemini CLI
Amazon Q CLI
Cline
gptme
OpenCode
Plandex
Kilo Code
Continue

How it works

Each cell in the matrix is a self-contained bash script that:

  1. Provisions a server on the cloud provider
  2. Installs the agent
  3. Injects your OpenRouter API key so every agent uses the same billing
  4. Drops you into an interactive session

Scripts work standalone (bash <(curl ...)) or through the CLI.

Development

git clone https://github.com/OpenRouterTeam/spawn.git
cd spawn
git config core.hooksPath .githooks

Structure

{cloud}/lib/common.sh    # Cloud provider primitives (provision, SSH, cleanup)
{cloud}/{agent}.sh        # Agent deployment script
shared/common.sh          # Shared utilities (OAuth, logging, SSH helpers)
cli/                      # TypeScript CLI (bun)
manifest.json             # Source of truth for the matrix

Adding a new cloud

  1. Create {cloud}/lib/common.sh with provisioning primitives
  2. Add to manifest.json
  3. Implement agent scripts using the cloud's primitives
  4. See CLAUDE.md for full contributor guide

Adding a new agent

  1. Add to manifest.json
  2. Implement on 1+ cloud by adapting an existing agent script
  3. Must support OpenRouter via env var injection

Contributing

The easiest way to contribute is by testing and reporting issues. You don't need to write code.

Test a cloud provider

Pick any agent + cloud combination from the matrix and try it out:

spawn claude hetzner      # or any combination

If something breaks, hangs, or behaves unexpectedly, open an issue using the bug report template. Include:

  • The exact command you ran
  • The cloud provider and agent
  • What happened vs. what you expected
  • Any error output

Request a cloud or agent

Want to see a specific cloud provider or agent supported? Use the dedicated templates:

Requests with real-world use cases get prioritized.

Report auth or credential issues

Cloud provider APIs change frequently. If you hit authentication failures, expired tokens, or permission errors on a provider that previously worked, please report it — these are high-priority fixes.

Code contributions

See CLAUDE.md for the full contributor guide covering shell script rules, testing, and the shared library pattern.

License

Apache 2.0