Claude security directory
Sprites
Published by Fly.io
High risk
A Sprite is a hardware-isolated execution environment for arbitrary code: a persistent Linux computer. When working with Claude on your next great idea, Sprites are the simplest answer for "where should I run a blob of code". This MCP server gives you full access to create and manage all of your sprites in a safe way.
Security assessment
Plutonium assessed this web connector for permissions, capabilities, and security-relevant behavior.
- Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
- Can run commands or queries on your behalf: This connector can execute scripts, shell commands, or arbitrary database queries. In a worst case, an attacker could install software, read files, or pull or change any data its login can reach.
- Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
- Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
- Sends your data to outside companies: Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.
Available capabilities
This add-on exposes 18 tools or capabilities.
- checkpoint_create
- checkpoint_get
- checkpoint_list
- checkpoint_restore
- create_sprite
- destroy_sprite
- exec
- exec_kill
- exec_list
- list_sprites
- policy_network_get
- policy_network_update
- service_create
- service_get
- service_list
- service_logs
- service_start
- service_stop
The interactive security report will load automatically.