Add Sprites plugin#120
Open
aezell wants to merge 1 commit into
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this PR does
Adds the official Fly.io Sprites plugin for Grok Build. The plugin connects Grok to the hosted Sprites MCP server and supplies skills for isolated remote compute, first-run authentication, safe command execution, services, checkpoints, network policy, and smoke testing.
a696ac338d86529c45f959b8b002e456330d349aOwnership
sourcerepo is published under our official org (or I've explained why not below).The plugin is published by Fly.io under the official
superflyGitHub organization.Checklist
.grok-plugin/marketplace.json(valid JSON, kebab-casename).sha, and that commit is public + reachable..grok-plugin/plugin-index.json(python3 scripts/generate-plugin-index.py).python3 scripts/validate-catalog.pypasses locally.python3 scripts/generate-plugin-index.py --checkpasses locally.homepage+ cleardescriptionset; local plugins includeREADME.md+.grok-plugin/plugin.json.Security
curl | bash, install-time remote-code download/exec, orpostinstallRCE..env, or env vars.https://sprites.dev/mcp, the Fly.io-operated hosted MCP control plane for Sprites. OAuth discovery and consent remain on thesprites.devhost.sprites:readandsprites:writescopes. The recommended/default connector token is restricted by a non-empty Sprite name prefix and a creation cap. Full organization access is optional and explicitly warned about in the README and skill.Notes for reviewers
execis an intentional product capability for user-requested commands inside hardware-isolated remote Sprites. It never executes commands on the Grok user's local machine.execschema. The plugin contains no encoded or obfuscated payload blobs.0.2.0, three skills (sprites,sprites-status,sprites-smoke), and one hosted MCP server (sprites).