Skip to content
Proposals/Configure free-form Always-allow patterns and en
proposaldeveloperP3Worth a lookxAI Grok CLI (Grok Build)

Configure free-form Always-allow patterns and enforce MCP kill switch in Grok CLI

Grok Build 780d138 enforces the vendor-compat MCP kill switch, auto-approves read-only git queries, normalizes permission path globs, and adds a free-form Always-allow pattern editor. Update MCP policy and allowlists to match.

Why this loop

Grok Build 780d138 (Source-Revision 64c4de99cc822b25ce9c54ab5a4f372093d0885d) now actually enforces the vendor-compat MCP kill switch when it is reported as on, so a switch that previously appeared enabled could still have left MCP connected. Workspace permission path patterns are lexical-normalized before glob matching, which can change which Always-allow entries match. The Always allow command prompt gains a free-form pattern editor. Read-only git queries are auto-approved; write git is deferred to the auto classifier. Shared MCP kill-switch settings, un-normalized path globs, and duplicated git-read allowlist entries will not behave as they did before this monorepo sync.

Proposed actions

  1. Upgrade to Grok Build 780d138, turn the vendor-compat MCP kill switch on, then start a vendor-compat MCP server and confirm it is refused/stopped while the switch reports on—do not trust a reported-on switch from an older build.
  2. In the Always allow command prompt, use the new free-form pattern editor to enter the exact command patterns you want auto-approved; save, then run one command that should match and one that should not, and confirm allow vs prompt.
  3. Rewrite workspace permission path patterns so they are already lexically normalized (the CLI now lexical-normalizes before glob matching); re-test each Always-allow path against the files it is supposed to cover.
  4. Remove Always-allow entries that only exist for read-only git queries; leave write git on the auto classifier. Align any shared allowlist files with that split.

Agent prompt

Paste into your agent or query via MCP (get_agent_prompt) — free, no extra AI cost

Copilot Chat / Agent mode

DevAgentRadar → GitHub Copilot

You are helping me adopt a real coding-assistant change. Work only from the facts below. Do not invent features.

Context

Assistant: xAI Grok CLI (Grok Build) Proposal: Configure free-form Always-allow patterns and enforce MCP kill switch in Grok CLI Summary: Grok Build 780d138 enforces the vendor-compat MCP kill switch, auto-approves read-only git queries, normalizes permission path globs, and adds a free-form Always-allow pattern editor. Update MCP policy and allowlists to match. Primary source: https://github.com/xai-org/grok-build/commit/780d1388fff103ff0db0d8c14de65af6225b4860

Why it matters

Grok Build 780d138 (Source-Revision 64c4de99cc822b25ce9c54ab5a4f372093d0885d) now actually enforces the vendor-compat MCP kill switch when it is reported as on, so a switch that previously appeared enabled could still have left MCP connected. Workspace permission path patterns are lexical-normalized before glob matching, which can change which Always-allow entries match. The Always allow command prompt gains a free-form pattern editor. Read-only git queries are auto-approved; write git is deferred to the auto classifier. Shared MCP kill-switch settings, un-normalized path globs, and duplicated git-read allowlist entries will not behave as they did before this monorepo sync.

Suggested actions

  1. Upgrade to Grok Build 780d138, turn the vendor-compat MCP kill switch on, then start a vendor-compat MCP server and confirm it is refused/stopped while the switch reports on—do not trust a reported-on switch from an older build.
  2. In the Always allow command prompt, use the new free-form pattern editor to enter the exact command patterns you want auto-approved; save, then run one command that should match and one that should not, and confirm allow vs prompt.
  3. Rewrite workspace permission path patterns so they are already lexically normalized (the CLI now lexical-normalizes before glob matching); re-test each Always-allow path against the files it is supposed to cover.
  4. Remove Always-allow entries that only exist for read-only git queries; leave write git on the auto classifier. Align any shared allowlist files with that split.

After you finish

Do not report this as applied to DevAgentRadar. You cannot write the visitor's loop.

Tell the human: open https://devagentradar.com/proposals/xai-grok-cli-780d138-configure-free-form-always-allow-patterns-and-enfor and mark Applied, Skipped, or Failed. Proposal id: b1a49694-7f9f-46eb-b328-65a1b15ce498

Your job

  1. Restate the change in one sentence.
  2. Propose a minimal plan for my repo (or a throwaway pilot).
  3. Implement only what I approve; prefer small diffs and tests.
  4. Call out risks (permissions, breaking APIs, cost).

Start by confirming you understood the proposal.

mcpmodelsecuritycliRelease source ↗

Your loop

This browser · no sign-in · not shared as “you”

After you run the prompt

Only you can mark this. Agents cannot write your loop.

Your decision stays on this device. A public tally appears after a few votes.

Originating release signal

xAI Grok CLI (Grok Build)780d138Aug 3, 2026

Synced from monorepo

Synced from monorepo · Synced from monorepo · Changes: · grok-shell: send an expired external-provider credential to the sign-in flow, not a 401 loop · pager: clickable ▲ jumps to the top of the response being read · grok-shell: keep a large task log from making the completion message too long · Plan viewer scrollbar: widen grab zone to the border column; fix striped thumb in Terminal.app · pager: poll the tmux probe teardown grace instead of sleeping it · security: vendor-compat MCP kill switch is now actually enforced when reported as on · +19 more changes
Verified excerpt — the source's own words

Synced from monorepo

Synced from monorepo

Changes:

  • grok-shell: send an expired external-provider credential to the sign-in flow, not a 401 loop
  • pager: clickable ▲ jumps to the top of the response being read
  • grok-shell: keep a large task log from making the completion message too long
  • Plan viewer scrollbar: widen grab zone to the border column; fix striped thumb in Terminal.app
  • pager: poll the tmux probe teardown grace instead of sleeping it
  • security: vendor-compat MCP kill switch is now actually enforced when reported as on
  • grok-shell: restore session eviction when a leader client disconnects
  • Bump rust-toolchain to 1.93.0
  • workspace: lexical-normalize permission path patterns before glob matching
  • pager: reject garbage Enter in the /resume picker
  • pager: show Mermaid affordances in plan mode preview
  • pager: drop manage-account link from /session-info
  • workspace: auto-approve read-only git queries; defer write floor to auto classifier
  • Add free-form pattern editor to the "Always allow" command prompt
  • grok-shell: fix /btw caching
  • pager: Tab walks answers in the ask_user_question card
  • External-provider auth refresh: single 7s attempt instead of 3×5s

Excerpt ends here — this release continues at the source ↗.

Primary source ↗