Skip to content
Proposals/Improve with xAI Grok CLI (Grok Build) 8adf901:
proposalteamP1High impactxAI Grok CLI (Grok Build)

Improve with xAI Grok CLI (Grok Build) 8adf901: Synced from monorepo

Changes: grok-shell: request workspaces:read/write OAuth2 scopes security: fix SSRF bypass via HTTP redirect in hook runner fix(grok-build): enterprise STT WSS URL + API-key voice bearer Harden identity-change purge and sync-marker invariants sandbox + workspace-server:

Why this loop

Release: Synced from monorepo Detail: Synced from monorepo · Changes: · grok-shell: request workspaces:read/write OAuth2 scopes · security: fix SSRF bypass via HTTP redirect in hook runner · fix(grok-build): enterprise STT WSS URL + API-key voice bearer · Harden identity-change purge and sync-marker invariants · sandbox + workspace-server: delete the legacy ready-file arm · Show billing URL when browser cannot open · fix(pager): show Themes: agent, model, pricing, security, cli Developer angle: Try in a throwaway repo before changing daily workflow. Team angle: Pilot / sandbox / policy review before org rollout. Source: https://github.com/xai-org/grok-build/commit/8adf9013a0929e5c7f1d4e849492d2387837a28d

Proposed actions

  1. Read the release notes for xAI Grok CLI (Grok Build) 8adf901 to understand the full scope of the update.

Agent prompt

Paste into your agent or query via MCP (get_agent_prompt) — free, no extra AI cost

AGENTS.md / CLAUDE.md / GEMINI.md rule update

DevAgentRadar → Repo Harness Rule Patch

Goal: update our repository's permanent harness instructions based on this release.

Update the file that tool actually reads. Do not dump everything into one file.

  • Claude Code → CLAUDE.md plus .claude/ (skills, hooks, settings, agents, commands). It does not read AGENTS.md natively; start CLAUDE.md with @AGENTS.md.
  • Codex, Copilot, Cursor, Factory Droid, Grok Build, Roo Code, Goose, OpenCode, Amp, Zed, Aider → AGENTS.md.
  • Gemini CLI / Antigravity → GEMINI.md. AGENTS.md only if context.fileName is set.
  • Cursor glob-scoped rules → .cursor/rules/*.mdc (plain .md is ignored), not a second constitution.
  • Codex MCP → .codex/config.toml, not .mcp.json.
  • Copilot extra instructions → .github/copilot-instructions.md; custom agents → .github/agents/.
  • Windsurf → .windsurf/rules (do not assume AGENTS.md).
  • Cline → .clinerules.
  • Procedures → a skill (SKILL.md). Enforcement the model must not skip → a hook. Isolated roles → subagents.
  • Do not fork the same rule into three tool files.

Context

Assistant: xAI Grok CLI (Grok Build) Proposal: Improve with xAI Grok CLI (Grok Build) 8adf901: Synced from monorepo Summary: Changes:

Why it matters

Release: Synced from monorepo Detail: Synced from monorepo · Changes: · grok-shell: request workspaces:read/write OAuth2 scopes · security: fix SSRF bypass via HTTP redirect in hook runner · fix(grok-build): enterprise STT WSS URL + API-key voice bearer · Harden identity-change purge and sync-marker invariants · sandbox + workspace-server: delete the legacy ready-file arm · Show billing URL when browser cannot open · fix(pager): show Themes: agent, model, pricing, security, cli Developer angle: Try in a throwaway repo before changing daily workflow. Team angle: Pilot / sandbox / policy review before org rollout. Source: https://github.com/xai-org/grok-build/commit/8adf9013a0929e5c7f1d4e849492d2387837a28d

Suggested actions

  1. Read the release notes for xAI Grok CLI (Grok Build) 8adf901 to understand the full scope of the update.

Config surfaces this release may change

  • hooks — check your repo before applying

After you finish

Do not report this as applied to DevAgentRadar. You cannot write the visitor's loop.

Tell the human: open https://devagentradar.com/proposals/xai-grok-cli-8adf901-improve-with-xai-grok-cli-grok-build-8adf901-synced and mark Applied, Skipped, or Failed. Proposal id: a325cd6d-6dda-490f-a73d-f877817f50c6

Instructions:

  1. Read the existing context files and settings for the tools in this repo.
  2. Draft an explicit Git diff. Update ONLY agent harness rules or tool configuration.
  3. Call out deprecated flags, obsolete habits, or changed permission boundaries.
  4. Do not touch application logic.

Start with the proposed diff and say which layer and which tool's file it belongs in.

agentmodelpricingsecuritycliRelease source ↗

Your loop

This browser · no sign-in · not shared as “you”

After you run the prompt

Only you can mark this. Agents cannot write your loop.

Your decision stays on this device. A public tally appears after a few votes.

Originating release signal

xAI Grok CLI (Grok Build)8adf901Jul 16, 2026

Synced from monorepo

Synced from monorepo · Changes: · grok-shell: request workspaces:read/write OAuth2 scopes · security: fix SSRF bypass via HTTP redirect in hook runner · fix(grok-build): enterprise STT WSS URL + API-key voice bearer · Harden identity-change purge and sync-marker invariants · sandbox + workspace-server: delete the legacy ready-file arm · Show billing URL when browser cannot open · fix(pager): show folder-trust UI in minimal mode · fix(pager): drain task_backgrounded before no-wait headless exit · grok-agent-sdk: stop SDK-spawned agents from staging self-updates they can never adopt · +5 more changes
Verified excerpt — the source's own words

Synced from monorepo

Changes:

  • grok-shell: request workspaces:read/write OAuth2 scopes
  • security: fix SSRF bypass via HTTP redirect in hook runner
  • fix(grok-build): enterprise STT WSS URL + API-key voice bearer
  • Harden identity-change purge and sync-marker invariants
  • sandbox + workspace-server: delete the legacy ready-file arm
  • Show billing URL when browser cannot open
  • fix(pager): show folder-trust UI in minimal mode
  • fix(pager): drain task_backgrounded before no-wait headless exit
  • grok-agent-sdk: stop SDK-spawned agents from staging self-updates they can never adopt
  • Split settings_modal into directory module
  • Delegate VS Code SSH file links
  • grok-shell: release the workspace session binding when a session is removed
  • keep skills reachable when their name collides with a client builtin
  • Preserve semantic link targets
Primary source ↗