Agent skill

Grok Build CLI Guide

by XiaomiMiMo in XiaomiMiMo/MiMo-Code

Reference for operating the Grok Build CLI (grok): interactive and headless runs, login, sandboxing and permissions, sessions, worktrees, MCP servers, plugins and output formats.

MITAuto-check passedAgent Workflows

Install Grok Build CLI Guide

skills CLI
$ npx skills add XiaomiMiMo/MiMo-Code --skill grok-build -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install XiaomiMiMo/MiMo-Code grok-build --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/XiaomiMiMo/MiMo-Code.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/cli/src/skill/builtin/.bundle/grok-build .claude/skills/grok-build && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
grok-build
GitHub stars
14k
Token cost
~1.3k tokens
SKILL.md length
537 words
Files
4 (incl. references)
Skills in repo
22
Repo updated
First seen
Licence
MIT

At a glance

Reference for operating the Grok Build CLI (grok): interactive and headless runs, login, sandboxing and permissions, sessions, worktrees, MCP servers, plugins and output formats.

  • Works in 4 steps: Confirm that the CLI is available → Inspect the installed command before… → Inspect the configuration discovered for… → …
  • Running Grok Build headlessly in a script or CI job
  • SKILL.md covers Start with Local Evidence, Choose an Execution Mode, Authenticate and Run Headlessly, plus 4 more sections
  • Needs XAI_API_KEY

What it does

This skill teaches an agent to run the grok command line deliberately. It begins with local evidence: confirm the CLI is installed, read its --help output before giving version-sensitive advice, and use grok inspect to see which rules, skills, plugins, hooks or MCP servers apply to a workspace. Installed help and current official docs win over the bundled reference when they differ. The execution modes are the interactive TUI, a TUI opened with a first task, a one-turn non-interactive run with -p, an ACP client over stdio, and a dashboard.

For authentication it covers interactive login, device-code login for headless or remote machines, and a cached login or XAI_API_KEY given only to the process that needs it, never printed or committed. Headless runs should set an explicit working directory and output format: plain for people, json for one final object, streaming-json for incremental events, and a JSON schema when the installed CLI supports it, with --no-auto-update in scripts and CI. Permissions and sandboxing are treated as separate controls. The skill is meant to be invoked only when Grok Build is explicitly requested, and reference files hold a CLI reference and workflows.

When your agent uses it

  • Running Grok Build headlessly in a script or CI job
  • Setting up login on a remote machine with device-code authentication
  • Choosing sandbox and permission settings for a Grok Build run
  • Inspecting which rules, plugins and MCP servers Grok Build sees in a repo

Example prompts

  • “Use the grok-build skill to run a one-shot grok -p task in CI with streaming JSON output.”
  • “Log in to Grok Build on this remote server where I have no browser.”
  • “Show me what grok inspect finds for the config in ~/work/api.”

Requirements

  • The grok CLI installed
  • Grok Build login or an XAI_API_KEY

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Confirm that the CLI is available
  2. Inspect the installed command before giving version-sensitive advice
  3. Inspect the configuration discovered for the target workspace when behavior depends on rules, skills, plugins, hooks, or MCP servers
  4. Treat current official documentation and installed help as authoritative when they differ from this bundled reference.

What it can do on your machine

Read from SKILL.md and the folder at commit 6babeb0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • XAI_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Grok Build CLI Guide loads about 1.3k tokens when it runs, and up to ~3.2k if it reads all its reference files. Until then it costs about 121 tokens; SKILL.md has 537 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~121
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from XiaomiMiMo/MiMo-Code at commit 6babeb0, republished under its MIT licence (© XiaomiMiMo). 537 words, ~1,291 tokens.

Download SKILL.mdSave it as .claude/skills/grok-build/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
grok-build
description
Reference and workflow guidance for the Grok Build CLI (`grok`), including interactive and headless runs, authentication, sessions, worktrees, permissions, sandboxing, MCP servers, plugins, inspection, updates, and automation output. Invoke only when the user explicitly requests the `grok-build` skill, explicitly asks to use Grok Build CLI, or an already-selected workflow requires Grok Build; do not invoke for general coding, generic shell tasks, or other agent CLIs.

Grok Build CLI

Operate Grok Build from a terminal while keeping execution mode, permissions, sandboxing, session state, and output handling explicit.

Start with Local Evidence

  1. Confirm that the CLI is available:

    bash
    command -v grok
    grok version
  2. Inspect the installed command before giving version-sensitive advice:

    bash
    grok --help
    grok <subcommand> --help
  3. Inspect the configuration discovered for the target workspace when behavior depends on rules, skills, plugins, hooks, or MCP servers:

    bash
    grok --cwd /path/to/repo inspect
    grok --cwd /path/to/repo inspect --json
  4. Treat current official documentation and installed help as authoritative when they differ from this bundled reference.

Choose an Execution Mode

  • Run grok with no arguments for the interactive TUI.
  • Run grok "<initial prompt>" to open the TUI with an initial task.
  • Run grok -p "<prompt>" for one non-interactive turn that prints a result and exits.
  • Run grok agent stdio for an ACP client that communicates over stdin/stdout.
  • Run grok dashboard to open the Agent Dashboard.

Prefer headless mode for scripts, CI, bots, and agent orchestration. Prefer ACP only when the caller implements the ACP JSON-RPC lifecycle and consumes session/update chunks.

Authenticate

Use an interactive login on a developer machine:

bash
grok login

Use device-code authentication in headless or remote environments:

bash
grok login --device-auth

Use a locally cached login or provide XAI_API_KEY only to the process that needs it. Never print, persist, or commit credentials. Use grok logout to clear cached credentials.

Run Headlessly

Use an explicit working directory and output format:

bash
grok --no-auto-update \
  --cwd /path/to/repo \
  --sandbox workspace \
  -p "Inspect the repository and explain the failing test." \
  --output-format json

Choose output according to the consumer:

  • Use plain for humans.
  • Use json for one final machine-readable object.
  • Use streaming-json for newline-delimited incremental events.
  • Add --json-schema '<schema>' when the installed CLI supports constrained structured output.

Pass --no-auto-update in scripts and CI to suppress background update checks. Do not parse interactive TUI rendering in automation.

Show full SKILL.md (267 more words)Show less

Control Permissions and Isolation

Treat permissions and sandboxing as separate controls:

  • Use permission rules to decide whether a tool call may run.
  • Use a sandbox profile to limit what an approved call may access.
  • Prefer --sandbox workspace for normal repository changes.
  • Prefer --sandbox read-only for review and auditing.
  • Prefer --sandbox strict for an untrusted repository, then add narrow permission rules.
  • Use --allow <RULE> and --deny <RULE> for per-run policy; remember that deny rules win.
  • Use --always-approve only when the environment and command scope justify unattended execution. Pair it with a suitable sandbox and explicit deny rules.

Do not describe --always-approve as equivalent to sandboxing. The sandbox is off by default unless configured or selected.

Manage Sessions and Worktrees

Continue or resume intentionally:

bash
grok -c
grok --resume <session-id>
grok --resume

Use --session-id <UUID> for a new named session, not to resume an existing one. Add --fork-session when branching from a resumed session.

Use a worktree when concurrent work could collide:

bash
grok --worktree --ref main "Fix the flaky test"
grok --worktree=feature-name "Implement the feature"

Preview removal with grok worktree rm --dry-run <id> before deleting a worktree. Do not assume deleting a session removes its worktree.

Diagnose Before Editing Configuration

Use built-in inspection and diagnostics first:

bash
grok inspect --json
grok mcp list --json
grok mcp doctor
grok plugin list
grok models

Prefer grok mcp add, grok mcp remove, and plugin subcommands over manually editing configuration when the CLI supports the requested operation. Keep secrets in environment variables rather than command history or committed configuration.

Read the Bundled References

Verify destructive commands such as session deletion, plugin removal, MCP removal, memory clearing, and worktree removal with the user or the governing workflow before running them.

© XiaomiMiMo, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in packages/cli/src/skill/builtin/.bundle/grok-build of XiaomiMiMo/MiMo-Code.

  • SKILL.md
  • agents/openai.yaml
  • references/cli-reference.md
  • references/workflows.md

Open the folder on GitHubat commit 6babeb0

Compare with similar skills

Grok Build CLI Guide next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Grok Build CLI Guide compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Grok Build CLI Guide this skillXiaomiMiMo/MiMo-Code14k—~1.3kAutomated safety check: PassMIT
Crush Configurationcharmbracelet/crush29k—~3.7kAutomated safety check: PassCustom licence
Agent Setup Health Audittw93/Waza7.2k—~5.2kAutomated safety check: NotesMIT
Paseo Plugin Buildergetpaseo/paseo20k—~9.4kAutomated safety check: PassCustom licence
Devcontainer Devstacklok/toolhive-studio170—~3.8kAutomated safety check: NotesApache-2.0
Knowledge Integration And Workflow Tool AdaptersechoVic/blade-code180—~2.1kAutomated safety check: PassMIT

Similar skills

  • Crush Configuration

    charmbracelet/crush

    Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.

    29k GitHub stars~3.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Audits a project's agent configuration, instruction drift, hooks, MCP and AI maintainability, then reports prioritized findings with evidence and next actions.

    7.2k GitHub stars~5.2k tokensUpdated today
    Agent WorkflowsAuto-check: notes
  • Paseo Plugin Builder

    getpaseo/paseo

    Builds, installs and troubleshoots trusted local Paseo plugins, from lifecycle hooks and slash commands to screens, themes and timeline renderers.

    20k GitHub stars~9.4k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Devcontainer Dev

    stacklok/toolhive-studio

    Spin up and interact with ToolHive Studio's containerized dev environment (Xvfb + noVNC + DinD).

    170 GitHub stars~3.8k tokensUpdated today
    Agent WorkflowsAuto-check: notes
  • Covers 领域能力如何包装成内置工具、getBuiltinTools 的 Session 依赖注入、ToolSearch 延迟激活,以及 Goal/Task/Team/Plan/Skill/LSP/MCP/Web/Config/Worktree 适配边界。

    180 GitHub stars~2.1k tokensUpdated 10 days ago
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    37k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed

More from XiaomiMiMo/MiMo-Code

All 22 skills in this repo
  • Paper Research on arXiv

    XiaomiMiMo/MiMo-Code

    Searches arXiv, fetches metadata, generates BibTeX, downloads PDFs and finds citations and related papers using a bundled Python script.

    14k GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Agent Skill Creator

    XiaomiMiMo/MiMo-Code

    Interactive guide for creating, reviewing and fixing agent skills (SKILL.md folders), covering structure, frontmatter rules, trigger phrases and validation before sharing.

    14k GitHub stars~1.9k tokensUpdated 4 days ago
    Auto-check passed
  • DOCX Toolkit

    XiaomiMiMo/MiMo-Code

    Produces, edits and reads Microsoft Word files through python-docx and lxml, with a decision table for picking the lightest workflow for a given task.

    14k GitHub stars~2.4k tokensUpdated 4 days ago
    Auto-check passed
  • Drive MiMo Code

    XiaomiMiMo/MiMo-Code

    Lets one MiMoCode process drive another, headless with JSON events or interactively through tmux, to test behavior and visual regressions with parseable evidence.

    14k GitHub stars~3.9k tokensUpdated 4 days ago
    Auto-check passed
  • PDF Toolkit

    XiaomiMiMo/MiMo-Code

    Reads, transforms, composes and fills PDFs with Python scripts for extraction, merging, watermarking, encryption, OCR and form filling.

    14k GitHub stars~1.7k tokensUpdated 4 days ago
    Auto-check passed
  • XLSX Spreadsheet Toolkit

    XiaomiMiMo/MiMo-Code

    Builds, edits, cleans, recalculates and reads Excel workbooks and CSV files with openpyxl and pandas, plus LibreOffice for recalculation and PDF export.

    14k GitHub stars~2.9k tokensUpdated 4 days ago
    Auto-check passed

Questions about Grok Build CLI Guide

What does Grok Build CLI Guide do?

Reference for operating the Grok Build CLI (grok): interactive and headless runs, login, sandboxing and permissions, sessions, worktrees, MCP servers, plugins and output formats. This skill teaches an agent to run the grok command line deliberately. It begins with local evidence: confirm the CLI is installed, read its --help output before giving version-sensitive advice, and use grok inspect to see which rules, skills, plugins, hooks or MCP servers apply to a workspace.

When should I use Grok Build CLI Guide?

Grok Build CLI Guide fits situations like: running Grok Build headlessly in a script or CI job; setting up login on a remote machine with device-code authentication; choosing sandbox and permission settings for a Grok Build run; inspecting which rules, plugins and MCP servers Grok Build sees in a repo.

How do I install Grok Build CLI Guide in Claude Code?

Run `npx skills add XiaomiMiMo/MiMo-Code --skill grok-build -a claude-code`. Or copy the skill folder (packages/cli/src/skill/builtin/.bundle/grok-build in XiaomiMiMo/MiMo-Code) into .claude/skills/grok-build in your project. Claude Code loads it when a task matches its description.

How do I install Grok Build CLI Guide in Codex?

Run `npx skills add XiaomiMiMo/MiMo-Code --skill grok-build -a codex`. Or copy the skill folder (packages/cli/src/skill/builtin/.bundle/grok-build in XiaomiMiMo/MiMo-Code) into .agents/skills/grok-build in your project. Codex loads it when a task matches its description.

Can I use Grok Build CLI Guide in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add XiaomiMiMo/MiMo-Code --skill grok-build -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/grok-build, .gemini/skills/grok-build, .github/skills/grok-build and .opencode/skills/grok-build in your project.

What does Grok Build CLI Guide need to run?

Going by SKILL.md and its folder, Grok Build CLI Guide needs credentials named XAI_API_KEY. Our summary lists: The grok CLI installed; Grok Build login or an XAI_API_KEY.

Does Grok Build CLI Guide access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Grok Build CLI Guide safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Grok Build CLI Guide use?

Grok Build CLI Guide is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Grok Build CLI Guide use?

About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.

What are the alternatives to Grok Build CLI Guide?

Skills that share tags, products or a category with Grok Build CLI Guide: Crush Configuration (charmbracelet/crush, 29k stars), Agent Setup Health Audit (tw93/Waza, 7.2k stars), Paseo Plugin Builder (getpaseo/paseo, 20k stars) and Devcontainer Dev (stacklok/toolhive-studio, 170 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Grok Build CLI Guide?

XiaomiMiMo (a GitHub organization) maintains it in XiaomiMiMo/MiMo-Code, which has 13,601 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on October 3, 2026.

Source: XiaomiMiMo/MiMo-Code on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.