bundled-skills/grok-build/SKILL.md
Delegate well-specified implementation tasks to xAI's Grok Build CLI running headlessly while the orchestrating agent plans, writes task specs, reviews every diff, and owns the result.
npx skillsauth add FrancoStino/opencode-skills-antigravity grok-buildInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
The coding assistant is the orchestrator: it plans, writes self-contained task specs,
dispatches them to Grok Build headlessly, reviews every diff, and owns the final result.
Grok is the fast, cheap executor. Full CLI details and verified behaviors: references/cli.md.
Before every dispatch, show the user the exact task specification that will be sent to xAI,
the target worktree, and the permission mode. Obtain explicit approval to disclose that text
and to let Grok edit the scoped worktree. Never include secrets, proprietary source, customer
data, or credentials in a task specification. Do not run grok update, --always-approve,
or a destructive recovery command without separate, explicit approval.
| Delegate to Grok | Keep with the orchestrator | |---|---| | Plan tasks with clear acceptance criteria | Ambiguous requirements, architecture decisions | | Boilerplate, scaffolding, CRUD | Deep cross-file debugging | | Mechanical refactors | Security-sensitive code | | Test writing from clear specs | Anything touching production infrastructure | | UI components from mockups/specs | Tasks where writing the spec ≈ doing the work |
When in doubt, keep it with the orchestrator.
grok update --check --json — if updateAvailable is true, tell the user. Run
grok update only after explicit approval, then confirm with grok --version.grok models — if it errors or reports logged out, STOP and ask the user to run
grok login.Spec. Write a self-contained task file (template below) to a temp directory OUTSIDE the target repo — the harness scratchpad if one is available, else the OS temp dir. Never write it inside the target repo. Grok has zero conversation context: no one-liner prompts, ever.
mkdir -p "${TMPDIR:-/tmp}/grok-specs", then write task.md there.New-Item -ItemType Directory -Force "$env:TEMP\grok-specs",
then write task.md there.Clean state. No uncommitted source changes — commit or stash first, so the
post-run diff is exactly Grok's work. Ignore build artifacts (__pycache__, dist/,
etc.); if they show in git status, they're usually just un-gitignored, not your
concern. Never dispatch on a dirty source tree.
Dispatch.
POSIX:
grok --prompt-file <task-file> \
--output-format json \
--always-approve \
--max-turns 30 \
--cwd <repo>
Windows (PowerShell) — backtick line-continuation:
grok --prompt-file <task-file> `
--output-format json `
--always-approve `
--max-turns 30 `
--cwd <repo>
Parse the JSON output and save sessionId. (--always-approve is required for
headless runs — --permission-mode acceptEdits silently cancels edits with no
interactive approver. Use it only after the user explicitly approves Grok editing this
exact scoped worktree. See references/cli.md.) For a high-stakes task, add --check
so Grok self-verifies before you review; skip it otherwise (it ~doubles latency).
Review gate — non-negotiable.
git diff -- <files from the spec> to skip artifact noise):
does it do the task, only the task, and match repo conventions?git checkout -- . or
git clean -fd automatically; preserve the diff for review and use a non-destructive
recovery plan unless the user explicitly authorizes otherwise.# Task: <one-line title>
## Context
- Repo: <path> — <one line on what the project is>
- Conventions: <test runner, formatter, a good example file to imitate>
## Files
- Modify: <path>
- Create: <path>
## Task
<precise description of the change>
## Constraints
- Do not modify any files other than those listed above.
- <other constraints>
## Acceptance criteria
- `<exact command>` <expected result>
- [ ] → - [x]) as each task lands and passes
the review gate.Only when a plan explicitly marks tasks independent: dispatch each with
--worktree=<task-slug>, run concurrently, then review and merge one worktree at a
time through the same review gate. Merge conflicts usually eat the savings — prefer
sequential.
| Failure | Action |
|---|---|
| stopReason: "Cancelled", empty text, no diff | Missing --always-approve — retry with it |
| CLI error / timeout | Retry once; then do the task yourself and note the fallback |
| Auth expired | Stop; ask the user to run grok login |
| 2 fix-up rounds exhausted | Preserve the diff, ask the user for a recovery decision, then finish the task manually if authorized |
| Dirty tree at dispatch | Refuse; commit/stash first |
--always-approve allows edits without an interactive approval prompt. It must be limited to
a clean, explicitly approved worktree and never substitutes for the orchestrator's review.Default grok-4.5. Add -m grok-composer-2.5-fast only for trivial mechanical tasks.
tools
Authorized security assessment of LLM applications and AI agents: prompt injection, tool abuse, RAG exposure, memory poisoning, system-prompt extraction, and agent-compliance engineering per OWASP LLM/ASI Top 10.
development
Builds two parameterized UI modes—流光溢彩白 (iridescent white) and 五彩斑斓黑 (colorful black)—with OKLCH, WebGL/CSS fallback, vision gating, screenshot QA, and total/per-color intensity reports. Use when a UI request names either mode or needs measured color parameters.
tools
Delegate coding tasks to the Kimi Code CLI (`kimi`) only when the user explicitly requests it, while the orchestrator retains review and landing responsibility.
development
Front-end JavaScript reverse engineering: locate signature chains, analyze encrypted request parameters, sample runtime behavior, and reproduce logic locally in Node for evidence-based output.