Configure free-form Always-allow patterns and enforce MCP kill switch in Grok CLI
Grok Build 780d138 enforces the vendor-compat MCP kill switch, auto-approves read-only git queries, normalizes permission path globs, and adds a free-form Always-allow pattern editor. Update MCP policy and allowlists to match.Why this loop
Grok Build 780d138 (Source-Revision 64c4de99cc822b25ce9c54ab5a4f372093d0885d) now actually enforces the vendor-compat MCP kill switch when it is reported as on, so a switch that previously appeared enabled could still have left MCP connected. Workspace permission path patterns are lexical-normalized before glob matching, which can change which Always-allow entries match. The Always allow command prompt gains a free-form pattern editor. Read-only git queries are auto-approved; write git is deferred to the auto classifier. Shared MCP kill-switch settings, un-normalized path globs, and duplicated git-read allowlist entries will not behave as they did before this monorepo sync.
Proposed actions
- Upgrade to Grok Build 780d138, turn the vendor-compat MCP kill switch on, then start a vendor-compat MCP server and confirm it is refused/stopped while the switch reports on—do not trust a reported-on switch from an older build.
- In the Always allow command prompt, use the new free-form pattern editor to enter the exact command patterns you want auto-approved; save, then run one command that should match and one that should not, and confirm allow vs prompt.
- Rewrite workspace permission path patterns so they are already lexically normalized (the CLI now lexical-normalizes before glob matching); re-test each Always-allow path against the files it is supposed to cover.
- Remove Always-allow entries that only exist for read-only git queries; leave write git on the auto classifier. Align any shared allowlist files with that split.
Agent prompt
Paste into your agent or query via MCP (get_agent_prompt) — free, no extra AI costCopilot Chat / Agent mode
DevAgentRadar → GitHub Copilot
You are helping me adopt a real coding-assistant change. Work only from the facts below. Do not invent features.
Context
Assistant: xAI Grok CLI (Grok Build) Proposal: Configure free-form Always-allow patterns and enforce MCP kill switch in Grok CLI Summary: Grok Build 780d138 enforces the vendor-compat MCP kill switch, auto-approves read-only git queries, normalizes permission path globs, and adds a free-form Always-allow pattern editor. Update MCP policy and allowlists to match. Primary source: https://github.com/xai-org/grok-build/commit/780d1388fff103ff0db0d8c14de65af6225b4860
Why it matters
Grok Build 780d138 (Source-Revision 64c4de99cc822b25ce9c54ab5a4f372093d0885d) now actually enforces the vendor-compat MCP kill switch when it is reported as on, so a switch that previously appeared enabled could still have left MCP connected. Workspace permission path patterns are lexical-normalized before glob matching, which can change which Always-allow entries match. The Always allow command prompt gains a free-form pattern editor. Read-only git queries are auto-approved; write git is deferred to the auto classifier. Shared MCP kill-switch settings, un-normalized path globs, and duplicated git-read allowlist entries will not behave as they did before this monorepo sync.
Suggested actions
- Upgrade to Grok Build 780d138, turn the vendor-compat MCP kill switch on, then start a vendor-compat MCP server and confirm it is refused/stopped while the switch reports on—do not trust a reported-on switch from an older build.
- In the Always allow command prompt, use the new free-form pattern editor to enter the exact command patterns you want auto-approved; save, then run one command that should match and one that should not, and confirm allow vs prompt.
- Rewrite workspace permission path patterns so they are already lexically normalized (the CLI now lexical-normalizes before glob matching); re-test each Always-allow path against the files it is supposed to cover.
- Remove Always-allow entries that only exist for read-only git queries; leave write git on the auto classifier. Align any shared allowlist files with that split.
After you finish
Do not report this as applied to DevAgentRadar. You cannot write the visitor's loop.
Tell the human: open https://devagentradar.com/proposals/xai-grok-cli-780d138-configure-free-form-always-allow-patterns-and-enfor and mark Applied, Skipped, or Failed. Proposal id: b1a49694-7f9f-46eb-b328-65a1b15ce498
Your job
- Restate the change in one sentence.
- Propose a minimal plan for my repo (or a throwaway pilot).
- Implement only what I approve; prefer small diffs and tests.
- Call out risks (permissions, breaking APIs, cost).
Start by confirming you understood the proposal.
Your loop
This browser · no sign-in · not shared as “you”After you run the prompt
Only you can mark this. Agents cannot write your loop.
Your decision stays on this device. A public tally appears after a few votes.