Agent skill

Grok Executor

by elliothux in elliothux/open-compute

Delegate a concrete, locally authorized implementation or read-only web research task from Codex to the official Grok Build CLI.

Apache-2.0Auto-check: warningsDevOps & Cloud

Install Grok Executor

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add elliothux/open-compute --skill grok-executor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install elliothux/open-compute grok-executor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/elliothux/open-compute.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/grok-executor .claude/skills/grok-executor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
grok-executor
GitHub stars
1.6k
Token cost
~1.8k tokens
SKILL.md length
905 words
Files
8 (incl. scripts, references)
Skills in repo
7
Repo updated
First seen
Licence
Apache-2.0

At a glance

Delegate a concrete, locally authorized implementation or read-only web research task from Codex to the official Grok Build CLI.

  • Works in 4 steps: Read all applicable repository… → Form a concrete implementation plan. Do… → Read references/task-contract.md and… → …
  • The user explicitly asks Codex to have Grok
  • SKILL.md covers Preserve the role boundary, Prepare the task, Delegate and Verify independently, plus 1 more section
  • Runs Python and Shell scripts from its folder; calls git

What it does

Grok Executor is an agent skill from elliothux/open-compute. Delegate a concrete, locally authorized implementation or read-only web research task from Codex to the official Grok Build CLI. Use when the user explicitly asks Codex to have Grok, SuperGrok, or Grok CLI implement, inspect, test, or research something. Do not trigger for ordinary tasks that do not request Grok, or for external commits, pushes, deployments, publication, or production mutations.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including scripts and reference files (for example `agents/openai.yaml`, `references/grok-build.md` and `references/task-contract.md`).

It sits in DevOps & Cloud, covering Deployment. It works with Cloudflare Workers. The repository describes itself as: Self-hosted Cloudflare Workers-compatible platform with Workers、KV、D1、R2、DO、Queues、Workflows、Cron、Cache、Images、Vectorize、AI Search、Artifacts、Static Assets、Service… The licence is Apache-2.0.

When your agent uses it

  • The user explicitly asks Codex to have Grok
  • Grok CLI implement
  • Research something
  • Ordinary tasks that do not request Grok

Example prompts

  • “/grok-executor”

Requirements

  • Python 3
  • A Bash shell

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Read all applicable repository instructions and inspect git status --short plus the relevant diff. Preserve unrelated user changes.
  2. Form a concrete implementation plan. Do not wait for plan approval unless the request is ambiguous or high-impact enough to require a user…
  3. Read references/task-contract.md and write a complete task brief. Include exact scope, constraints, acceptance criteria, validation, and…
  4. Avoid putting sensitive values in the brief. The wrapper removes its temporary task session after Codex closes it, but task content and…

What it can do on your machine

Read from SKILL.md and the folder at commit efee6a9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python and Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Grok Executor loads about 1.8k tokens when it runs, and up to ~3.3k if it reads all its reference files. Until then it costs about 103 tokens; SKILL.md has 905 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~103
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningTells the agent its actions are pre-authorized / not to stop for confirmationSKILL.md:22
    2. Form a concrete implementation plan. Do not wait for plan approval unless the request is ambiguous or high-impact eno

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from elliothux/open-compute at commit efee6a9, republished under its Apache-2.0 licence (© elliothux). 905 words, ~1,835 tokens.

Download SKILL.mdSave it as .claude/skills/grok-executor/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
grok-executor
description
Delegate a concrete, locally authorized implementation or read-only web research task from Codex to the official Grok Build CLI. Use when the user explicitly asks Codex to have Grok, SuperGrok, or Grok CLI implement, inspect, test, or research something. Do not trigger for ordinary tasks that do not request Grok, or for external commits, pushes, deployments, publication, or production mutations.

Grok Executor

Keep Codex responsible for scope, planning, authorization, and final verification. Use the official grok CLI only as the implementation worker.

Preserve the role boundary

  • Derive the plan from the user's request, repository instructions, current code, and current diff before invoking Grok.
  • Resolve material design choices yourself. Ask the user only when a missing choice would materially change the result.
  • Delegate one bounded task with explicit acceptance criteria. Do not ask Grok to choose the product direction or broaden scope.
  • Do not make implementation edits in parallel with Grok. If its result is incomplete, give it a focused correction turn in the same task session or report the blocker.
  • Never delegate secrets, credentials, production data, or actions outside the local workspace.
  • Never let Grok commit, push, deploy, publish, change remote systems, or edit user-level configuration. Perform any separately authorized external step yourself after reviewing the result.

Prepare the task

  1. Read all applicable repository instructions and inspect git status --short plus the relevant diff. Preserve unrelated user changes.
  2. Form a concrete implementation plan. Do not wait for plan approval unless the request is ambiguous or high-impact enough to require a user choice.
  3. Read references/task-contract.md and write a complete task brief. Include exact scope, constraints, acceptance criteria, validation, and known dirty-worktree context.
  4. Avoid putting sensitive values in the brief. The wrapper removes its temporary task session after Codex closes it, but task content and follow-ups are still sent to Grok for inference.

Delegate

Pass the task brief through a file or stdin; never interpolate a multiline task into shell syntax. Use a fresh session for every bounded task—do not add --continue or --resume across tasks. Within that bounded task, keep the wrapper's ACP process alive and use the same Grok session for progress updates, steering, corrections, and validation follow-ups.

For implementation:

bash
.codex/skills/grok-executor/scripts/run-grok-executor.sh \
  --execute \
  --cwd /absolute/path/to/repo \
  --prompt-file /absolute/path/to/task-brief.md

For a Grok read-only investigation explicitly requested by the user:

bash
.codex/skills/grok-executor/scripts/run-grok-executor.sh \
  --inspect \
  --cwd /absolute/path/to/repo \
  --prompt-file /absolute/path/to/task-brief.md

For live web research explicitly requested by the user, add --web-search to the read-only command. This opt-in is accepted only with --inspect; the wrapper rejects it in execute mode. Keep the brief read-only, require source URLs, and do not authenticate to sites or perform external interactions.

Allocate a PTY when Codex may need to steer the task. The wrapper prints GROK_ACP_SESSION once the fresh session exists, GROK_ACP_TURN_STARTED for each turn, and GROK_ACP_IDLE after a turn completes. It remains alive at idle and accepts one JSON control object per input line:

json
{"type":"interject","text":"Stop the single-crate approach; keep the requested workspace boundaries."}
{"type":"prompt","text":"The clippy run failed with this exact error. Fix it and rerun the scoped checks."}
{"type":"prompt_file","path":"/absolute/path/to/follow-up.md"}
{"type":"status"}
{"type":"cancel"}
{"type":"close"}
  • Use interject to steer an active turn. The controller uses Grok's native interjection when available and otherwise cancels safely, then sends the text as the next turn in the same session.
  • Use prompt or prompt_file for an ordinary same-session follow-up. If a turn is active, the controller queues it.
  • Use cancel to stop the active turn without abandoning the task session.
  • After Codex accepts the implementation, send close; only then is the isolated session removed. On non-interactive stdin EOF, the wrapper waits for the initial turn and closes automatically for one-shot compatibility.

The default summary output is the context-efficient interface. It suppresses streamed reasoning, individual tool-call events, and Grok stderr. Each turn emits one GROK_ACP_RESULT containing the final assistant handoff capped at 4 KiB, elapsed time, tool-call count, and last tool, followed by GROK_ACP_IDLE. status is likewise compact. Keep Codex tool-output budgets small and do not replay unchanged polls into the conversation.

Show full SKILL.md (349 more words)Show less

GROK_ACP_SESSION includes a diagnosticFile path. Full ACP traffic, prompts, tool events, and stderr are recorded there with mode 0600 and a 16 MiB cap. The file is inside the task's temporary Grok home and disappears on close; it may contain sensitive task text. Read only a targeted tail or matching lines when a result fails or is ambiguous, and do so before closing. Use --output-format plain or --output-format streaming-json only for an explicitly diagnosed transport problem; these debug modes can consume substantial context. json keeps controller events structured without streaming raw ACP traffic.

The script defaults to --inspect; require the explicit --execute flag for writes and --web-search for live research. Let the script own Grok's ACP lifecycle, permission, sandbox, update, plan, subagent, memory, web-search, and destructive-command controls. Do not bypass or weaken them. The wrapper isolates each task home but atomically preserves an OAuth auth file refreshed by the official CLI, because refresh-token rotation would otherwise invalidate the next fresh session.

Read references/grok-build.md only when CLI flags drift or sandbox behavior needs troubleshooting.

Verify independently

When Grok reports GROK_ACP_RESULT and GROK_ACP_IDLE:

  1. Inspect git status --short and the complete diff yourself.
  2. Check every changed file against the plan, repository rules, and acceptance criteria.
  3. Confirm unrelated changes were preserved and no external action occurred.
  4. Run the relevant validation yourself when safe and practical; do not treat Grok's claim that tests passed as proof.
  5. If the result is wrong but the task is still well-scoped, send one focused prompt follow-up in the same Grok task session. Include the observed diff or error, not a vague request to retry.
  6. If Grok needs secrets, external authority, a material user choice, or broader scope, stop and report the blocker.
  7. Send close only after the task is accepted, blocked, or deliberately abandoned; then confirm the controller exits and perform the final status/diff check.

Report the outcome

State separately:

  • the plan Codex delegated;
  • what Grok actually changed;
  • what Codex independently verified;
  • any remaining manual QA or blocker.

Do not imply the task succeeded merely because the Grok process exited successfully.

© elliothux, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references) in .agents/skills/grok-executor of elliothux/open-compute.

  • SKILL.md
  • agents/openai.yaml
  • references/grok-build.md
  • references/task-contract.md
  • scripts/grok-acp-executor.py
  • scripts/run-grok-executor.sh
  • tests/fake-grok-acp.py
  • tests/test_grok_acp_executor.py

Open the folder on GitHubat commit efee6a9

Compare with similar skills

Grok Executor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Grok Executor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Grok Executor this skillelliothux/open-compute1.6k—~1.8kAutomated safety check: WarnApache-2.0
Nextjs On Cloudflarecloudflare/skills3k2 repos~678Automated safety check: PassApache-2.0
Prepare Cloudflare Production DeploymentLubomirGeorgiev/cloudflare-workers-nextjs-saas-template786—~5.9kAutomated safety check: NotesMIT
Lunora Deployanolilab/lunora283—~2.1kAutomated safety check: PassCustom licence
Deploy Microfeedmicrofeed/microfeed4.1k—~6.6kAutomated safety check: PassAGPL-3.0
Cloudflare Temporary DeployLuciole-Studio/Misaka-Agent1252 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Nextjs On Cloudflare

    cloudflare/skills

    Official

    Build, migrate, and deploy Next.js apps on Cloudflare Workers with vinext.

    3k GitHub starsUsed in 2 repos~678 tokens
    DevOps & CloudAuto-check passed
  • Prepare Cloudflare Production Deployment

    LubomirGeorgiev/cloudflare-workers-nextjs-saas-template

    Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.

    786 GitHub stars~5.9k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Lunora Deploy

    anolilab/lunora

    Deploys a Lunora app to Cloudflare. An agent skill from anolilab/lunora.

    283 GitHub stars~2.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Deploy Microfeed

    microfeed/microfeed

    Deploy and administer microfeed through the source-code-free @microfeed/cli launcher or the project-owned yarn manage CLI.

    4.1k GitHub stars~6.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Cloudflare Temporary Deploy

    Luciole-Studio/Misaka-Agent

    Deploy a Worker live, no account, via wrangler --temporary. An agent skill from Luciole-Studio/Misaka-Agent.

    125 GitHub starsUsed in 2 repos~1.9k tokens
    DevOps & CloudAuto-check passed
  • Wrangler

    cloudflare/skills

    Official

    Run or troubleshoot Wrangler CLI commands and configure Worker projects for local development, Previews, deployment, and Cloudflare resource management.

    3k GitHub starsUsed in 2 repos~2.8k tokens
    DevOps & CloudAuto-check passed

More from elliothux/open-compute

  • Kumo Design

    elliothux/open-compute

    Cloudflare product design guidance. An agent skill from elliothux/open-compute.

    1.6k GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Cf Compatibility Check

    elliothux/open-compute

    Review branch and working-tree implementation changes for conformance with open-compute's Cloudflare Workers runtime target under explicit single-machine self-host exclusions.

    1.6k GitHub stars~3.5k tokensUpdated yesterday
    Auto-check passed
  • Anti Cheating

    elliothux/open-compute

    Audit the current Lynx branch and working tree for test-, fixture-, demo-, page-, domain-, or scenario-tuned production logic.

    1.6k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Simplify

    elliothux/open-compute

    Simplify recently modified Lynx business code while preserving behavior.

    1.6k GitHub stars~984 tokensUpdated yesterday
    Auto-check passed
  • Update Workerd Upstream

    elliothux/open-compute

    Update open-compute's workerd fork onto current Cloudflare upstream, minimize fork-owned code, regroup fork commits by capability, and coordinate the submodule, pin, tests, and docs.

    1.6k GitHub stars~922 tokensUpdated yesterday
    Auto-check passed
  • Product Surface Check

    elliothux/open-compute

    Manually review changed open-compute behavior for drift across maintained user, operator, API, SDK, configuration, deployment, capability, CLI, Dashboard, and release surfaces.

    1.6k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Grok Executor

What does Grok Executor do?

Delegate a concrete, locally authorized implementation or read-only web research task from Codex to the official Grok Build CLI. Grok Executor is an agent skill from elliothux/open-compute. Delegate a concrete, locally authorized implementation or read-only web research task from Codex to the official Grok Build CLI.

When should I use Grok Executor?

Grok Executor fits situations like: the user explicitly asks Codex to have Grok; grok CLI implement; research something; ordinary tasks that do not request Grok.

How do I install Grok Executor in Claude Code?

Run `npx skills add elliothux/open-compute --skill grok-executor -a claude-code`. Or copy the skill folder (.agents/skills/grok-executor in elliothux/open-compute) into .claude/skills/grok-executor in your project. Claude Code loads it when a task matches its description.

How do I install Grok Executor in Codex?

Run `npx skills add elliothux/open-compute --skill grok-executor -a codex`. Or copy the skill folder (.agents/skills/grok-executor in elliothux/open-compute) into .agents/skills/grok-executor in your project. Codex loads it when a task matches its description.

Can I use Grok Executor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elliothux/open-compute --skill grok-executor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/grok-executor, .gemini/skills/grok-executor, .github/skills/grok-executor and .opencode/skills/grok-executor in your project.

What does Grok Executor need to run?

Going by SKILL.md and its folder, Grok Executor needs Python and a shell for the scripts in its folder and the command-line tools its instructions call (git). Our summary lists: Python 3; A Bash shell.

Does Grok Executor access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Grok Executor safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): tells the agent its actions are pre-authorized / not to stop for confirmation. Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Grok Executor use?

Grok Executor is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Grok Executor use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Grok Executor?

Skills that share tags, products or a category with Grok Executor: Nextjs On Cloudflare (cloudflare/skills, 3k stars), Prepare Cloudflare Production Deployment (LubomirGeorgiev/cloudflare-workers-nextjs-saas-template, 786 stars), Lunora Deploy (anolilab/lunora, 283 stars) and Deploy Microfeed (microfeed/microfeed, 4.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Grok Executor?

elliothux (a GitHub user) maintains it in elliothux/open-compute, which has 1,591 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 6, 2026.

Source: elliothux/open-compute on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.