All skills
sanjay3290 avatar

/grok-build

@0e202f7

Orchestrate coding work by delegating well-specified implementation tasks to xAI's Grok Build CLI (grok) running headlessly, while the coding assistant plans, writes the task specs, reviews every diff, and owns the result. Use when user says: 'use grok', 'grok build', 'delegate to grok', 'have grok implement', 'have grok execute', 'have grok build', 'send to grok', 'execute this plan with grok'. Executes a Markdown implementation plan task-by-task, or ad-hoc tasks with an inline spec.

Use this Skill: https://skilld.dev/gh/sanjay3290/ai-skills/grok-build

This session only. Nothing lands on disk.

referencescli.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Grok Build CLI — headless reference

Verified against grok 0.2.93 (stable channel), 2026-07-09. Re-verify with grok --help after major version bumps — flags mirror Claude Code's.

One-shot headless run

grok -p "prompt" --output-format json
grok --prompt-file task.md --output-format json   # preferred: no shell-quoting issues

⚠️ grok agent is NOT a one-shot command — it runs the agent as a stdio/WebSocket server for SDK/ACP integrations. Always use top-level grok -p / --prompt-file.

JSON output shape (verified)

{
  "text": "final response text",
  "stopReason": "EndTurn",
  "sessionId": "019f470d-3e02-7601-b726-1133cc72ef76",
  "requestId": "…",
  "thought": "…"
}

sessionId is the handle for fix-ups.

  • POSIX: grok --prompt-file task.md --output-format json | python3 -c "import json,sys;print(json.load(sys.stdin)['sessionId'])"
  • Windows (PowerShell): grok --prompt-file task.md --output-format json | ConvertFrom-Json | Select-Object -ExpandProperty sessionId

stopReason: "Cancelled" with empty text means a tool call hit a permission gate and was auto-cancelled headlessly — you forgot --always-approve (see below).

Permissions — the headless gotcha

Use --always-approve for headless dispatch. Do NOT rely on --permission-mode acceptEdits.

Verified 2026-07-09: --permission-mode acceptEdits FAILS headlessly — the edit tool hits a permission gate with no interactive approver, and the run returns stopReason: "Cancelled" with no file change. --always-approve auto-approves BOTH edits AND shell commands in one flag (Grok ran the acceptance test itself in the same run). This is safe in the grok-build workflow because dispatch happens on a clean tree, the task spec constrains scope, and the orchestrator reviews the full diff before committing.

Optional hardening: --sandbox <profile> (env GROK_SANDBOX) restricts filesystem and network access — layer it on for untrusted repos.

Resume / fix-up

grok --resume <sessionId> -p "specific feedback" --always-approve --output-format json

Verified: the resumed session retains full context — it knows the repo and files touched without re-explanation. Pass only the specific feedback, not the whole task again.

Self-verification (--check) — opt-in only

--check appends a self-verification loop: Grok spawns a verifier subagent that emits a checklist, action trace, scope/edge-case evaluation, and its own VERDICT: PASS.

Verified: correct but ~doubles wall-clock (a trivial task went from a few seconds to ~48s) and adds token cost, undercutting Grok's speed/cost advantage. Skip it by default — the orchestrator's review gate is the authority. Add --check only for high-stakes tasks where you want Grok to self-correct before review.

Update check (session preflight)

grok update --check --json
# → {"currentVersion":"0.2.93","latestVersion":"0.2.93","updateAvailable":false,"channel":"stable",…}
grok update        # installs latest stable

Key flags

Flag Purpose
--always-approve Auto-approve all tool executions (edits + shell). Required for headless.
--permission-mode <m> default, acceptEdits, auto, dontAsk, bypassPermissions, plan — but see gotcha above
--allow / --deny Fine-grained permission rules (Claude Code --allowedTools syntax)
--max-turns <N> Turn cap — always set for headless runs
--check Appends a self-verification loop (opt-in; see above)
--worktree[=name] Run in a fresh git worktree (parallel tasks)
--json-schema '<schema>' Constrain final output to a JSON Schema
-m <model> grok-4.5 (default) or grok-composer-2.5-fast
--cwd <dir> Working directory for the run
--best-of-n <N> Run N ways in parallel, pick best (headless)

Install & auth

  • Install / update: follow xAI's Grok CLI install docs for your OS; verify with grok --version. Works on macOS, Linux, and Windows (PowerShell).
  • Auth: grok.com subscription OAuth (grok login / grok logout). Check with grok models.
  • Models available: grok-4.5 (default), grok-composer-2.5-fast.

Source: SKILL.md on GitHub

1 warning2mo3 checks · Risk MEDIUM
  • Gen Agent Trust Hub2mo

    The skill orchestrates coding tasks by delegating them to the xAI Grok Build CLI (grok). It employs the --always-approve flag, which grants the delegated agent permission to execute shell commands and modify files without manual confirmation for each step. This configuration presents a security risk, as a delegated agent could potentially execute harmful commands if it encounters adversarial instructions within a repository (indirect prompt injection) or performs unintended actions before the user reviews the resulting diffs.

  • Socket2mo

    No alerts

  • Snyk2mo

    Risk: LOW · No issues

Signed by skilld at 0e202f7. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 weeks ago.

Activeupdated 3 months ago
metadata
{
  "author": "sanjay3290",
  "version": "1.0"
}

README badge

README badge for sanjay3290/ai-skills/grok-build