sparkeyProvides time-limited, self-revoking SSH access for AI agents using certificate TTL, user expiry, forced command restrictions, and scheduled automated cleanup.
Install via ClawdBot CLI:
clawdbot install sanjeevneo/sparkeyRequires:
Grade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdAccesses system directories or attempts privilege escalation
/var/log/Calls external URL not in known-safe list
https://github.com/sanjeevneo/sparkeyAI Analysis
The skill's core functionality (creating temporary SSH access) inherently requires system-level operations like user management and accessing /etc/passwd, which explains the flagged signals. The external URL is the project's documented homepage, not a data exfiltration endpoint. No evidence of hidden instructions, credential harvesting beyond stated purpose, or obfuscation was found.
Generated Mar 22, 2026
A cloud operations team uses Sparkey to grant temporary SSH access to an AI agent for diagnosing a production server outage. The agent performs fast recon, identifies a misconfigured service, and applies a fix, with all credentials self-destructing after the session to prevent lingering access.
During CI/CD pipeline execution, an AI agent leverages Sparkey to access a staging server for security vulnerability scanning. The agent runs automated checks, reports findings, and ensures no persistent credentials remain, maintaining audit compliance and reducing attack surface.
An MSP employs Sparkey to provide time-limited SSH access for AI agents assisting clients with server maintenance. The agent troubleshoots issues, updates configurations, and automatically revokes access post-session, ensuring client security and operational efficiency.
In a regulated industry like finance, an AI agent uses Sparkey to access servers for compliance audits and hardening tasks. The agent executes restricted commands, documents changes, and leaves zero artifacts, meeting strict security and regulatory requirements.
Offer Sparkey as part of a SaaS platform for automated incident response and security management. Charge monthly fees per server or user, providing features like audit logs, integration with existing tools, and premium support for enterprise clients.
Provide professional services to integrate Sparkey into client environments, including customization, training, and ongoing maintenance. Revenue comes from project-based fees and retainer agreements for continuous support and updates.
Distribute Sparkey under the MIT license for free use, while monetizing through premium add-ons such as advanced analytics, multi-tenancy support, and enterprise-grade security features. Offer tiered pricing based on usage scale and support levels.
💬 Integration Tip
Ensure target servers have sshd running and required tools installed; use the one-liner with expiry-time for crash-safe key management, and schedule dead-man cleanup to automate credential removal.
Scored Apr 19, 2026
Audited Apr 18, 2026 · audit v1.0
Creates a comfort-focused room airflow map, timing routine, and weekly review checklist for stuffy rooms without HVAC diagnosis, repair advice, allergy guida...
Dynamic goal-aware browsing assistant that generates checklists, evaluates page relevance, produces session wrap-ups, and persists all session data to the wo...
Create a 20-minute phone notification audit card for attention hygiene, without account, credential, surveillance, or monitoring setup.
Create a clinician-friendly migraine or recurring headache pattern log with episode timelines, possible context factors, symptom notes, medication response t...
Automate Karpak Life registration and SBT minting on the Karpak Living Map. Activate when user asks to register/mint an SBT.
Install, configure, authorize and run wakehook so the user's agent (OpenClaw or Hermes) runs their morning routine when they wake up. wakehook turns Google H...