Skip to content
Proposals/Improve with xAI Grok CLI (Grok Build) 8adf901:
proposalteamP5High impactxAI Grok CLI (Grok Build)

Improve with xAI Grok CLI (Grok Build) 8adf901: Synced from monorepo

Changes: - grok-shell: request workspaces:read/write OAuth2 scopes - security: fix SSRF bypass via HTTP redirect in hook runner - fix(grok-build): enterprise STT WSS URL + API-key voice bearer - Harden identity-change purge and sync-marker invariants - sandbox + workspace-server:

Why this loop

Signal: Synced from monorepo Detail: Changes: - grok-shell: request workspaces:read/write OAuth2 scopes - security: fix SSRF bypass via HTTP redirect in hook runner - fix(grok-build): enterprise STT WSS URL + API-key voice bearer - Harden identity-change purge and sync-marker invariants - sandbox + workspace-server: delete the legacy ready-file arm - Show billing URL when browser cannot open - fix(pager): show folder-trust UI in mini Themes: agent, model, pricing, security, cli, breaking Developer implication: Try in a throwaway repo before changing daily workflow. Team implication: Pilot / sandbox / policy review before org rollout.

Proposed actions

  1. Run a 30-minute bake-off of xAI Grok CLI (Grok Build)'s new/default model on one real task you care about.
  2. Re-check agent/tool permissions for xAI Grok CLI (Grok Build) on a throwaway repo before daily use.
  3. Read the primary release notes and note any permission, sandbox, or API breaks for xAI Grok CLI (Grok Build).
  4. Verify plan/credit impact for xAI Grok CLI (Grok Build) before expanding usage.
  5. Try in a throwaway repo before changing daily workflow.
  6. Pilot / sandbox / policy review before org rollout.

Action pack

Paste into your agent — free, no extra AI cost

Paste into Claude Code / CLAUDE.md task

# DevAgentRadar → Claude Code

You are helping me adopt a real coding-assistant change. Work only from the facts below. Do not invent features.

## Context
Assistant: xAI Grok CLI (Grok Build)
Proposal: Improve with xAI Grok CLI (Grok Build) 8adf901: Synced from monorepo
Summary: Changes:
- grok-shell: request workspaces:read/write OAuth2 scopes
- security: fix SSRF bypass via HTTP redirect in hook runner
- fix(grok-build): enterprise STT WSS URL + API-key voice bearer
- Harden identity-change purge and sync-marker invariants
- sandbox + workspace-server:
Primary source: https://github.com/xai-org/grok-build/commit/8adf9013a0929e5c7f1d4e849492d2387837a28d

## Why it matters
Signal: Synced from monorepo
Detail: Changes:
- grok-shell: request workspaces:read/write OAuth2 scopes
- security: fix SSRF bypass via HTTP redirect in hook runner
- fix(grok-build): enterprise STT WSS URL + API-key voice bearer
- Harden identity-change purge and sync-marker invariants
- sandbox + workspace-server: delete the legacy ready-file arm
- Show billing URL when browser cannot open
- fix(pager): show folder-trust UI in mini
Themes: agent, model, pricing, security, cli, breaking
Developer implication: Try in a throwaway repo before changing daily workflow.
Team implication: Pilot / sandbox / policy review before org rollout.

## Suggested actions
1. Run a 30-minute bake-off of xAI Grok CLI (Grok Build)'s new/default model on one real task you care about.
2. Re-check agent/tool permissions for xAI Grok CLI (Grok Build) on a throwaway repo before daily use.
3. Read the primary release notes and note any permission, sandbox, or API breaks for xAI Grok CLI (Grok Build).
4. Verify plan/credit impact for xAI Grok CLI (Grok Build) before expanding usage.
5. Try in a throwaway repo before changing daily workflow.
6. Pilot / sandbox / policy review before org rollout.


## Your job
1. Restate the change in one sentence.
2. Propose a minimal plan for my repo (or a throwaway pilot).
3. Implement only what I approve; prefer small diffs and tests.
4. Call out risks (permissions, breaking APIs, cost).

Start by confirming you understood the proposal.
agentmodelpricingsecuritycliRelease source ↗

Your loop

This browser · no sign-in · not shared as “you”

Community signal · 0 approved · 0 deferred · 0 ignored

Anonymous public tally (one vote per visitor; changing choice updates your vote). Not moderated product truth.

Originating release signal

xAI Grok CLI (Grok Build)8adf9017/16/2026, 7:27:30 PM

Synced from monorepo

Changes: - grok-shell: request workspaces:read/write OAuth2 scopes - security: fix SSRF bypass via HTTP redirect in hook runner - fix(grok-build): enterprise STT WSS URL + API-key voice bearer - Harden identity-change purge and sync-marker invariants - sandbox + workspace-server: delete the legacy ready-file arm - Show billing URL when browser cannot open - fix(pager): show folder-trust UI in minimal mode - fix(pager): drain task_backgrounded before no-wait headless exit - grok-agent-sdk: stop S

Verified excerpt — the source's own words
Synced from monorepo

Changes:
- grok-shell: request workspaces:read/write OAuth2 scopes
- security: fix SSRF bypass via HTTP redirect in hook runner
- fix(grok-build): enterprise STT WSS URL + API-key voice bearer
- Harden identity-change purge and sync-marker invariants
- sandbox + workspace-server: delete the legacy ready-file arm
- Show billing URL when browser cannot open
- fix(pager): show folder-trust UI in minimal mode
- fix(pager): drain task_backgrounded before no-wait headless exit
- grok-agent-sdk: stop SDK-spawned agents from staging self-updates they can never adopt
- Split settings_modal into directory module
- Delegate VS Code SSH file links
- grok-shell: release the workspace session binding when a session is removed
- keep skills reachable when their name collides with a client builtin
- Preserve semantic link targets
Primary source ↗