# Defense-in-Depth Score: Grok Build

**Repo:** https://github.com/xai-org/grok-build · **Commit:** `2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8` · **Reviewed:** 2026-10-03
**What it is:** xAI/SpaceXAI coding agent harness and TUI
**Category:** Coding
**Scored configuration:** Released `grok` binary (release build), interactive TUI in a fresh ~/.grok with no flags: Ask permission mode, sandbox off, memory off, folder trust on.
**Agent surface (default):** code execution yes · filesystem write yes · network egress yes · external credentials yes · persistent memory opt-in · untrusted input yes · third party extensions opt-in · sub agents yes · external communication yes

## Score: 3.8 / 10.0 (Minimal)

| # | Criterion | S | C | D | B | Raw | Cap | Score | Confidence |
|---|---|---|---|---|---|---|---|---|---|
| C1 | Identity & least privilege | L0 | L1 | L0 | L1 | 0.12 | — | **0.12** | High |
| C2 | Approval gates | L3 | L2 | L1 | L1 | 0.47 | — | **0.47** | High |
| C3 | Tool & action scoping | L2 | L1 | L1 | L0 | 0.28 | — | **0.28** | High |
| C4 | Code-execution isolation | L3 | L3 | L0 | L2 | 0.55 | G1 | **0.50** (alt) | High |
| C5 | Untrusted input blast radius | L2 | L2 | L2 | L2 | 0.50 | — | **0.50** | High |
| C6 | Memory, context & configuration integrity | L2 | L2 | L2 | L2 | 0.50 | — | **0.50** | High |
| C7 | Third-party extensions | L1 | L0 | L2 | L1 | 0.23 | — | **0.23** | High |
| C8 | Secrets & sensitive-data protection | L2 | L1 | L1 | L1 | 0.33 | — | **0.33** | High |
| C9 | Audit & traceability | L2 | L2 | L2 | L1 | 0.45 | — | **0.45** | High |
| C10 | Limits & kill switch | L2 | L2 | L1 | L1 | 0.40 | — | **0.40** | High |


Grok Build has a carefully engineered approval gate: in its default mode every shell command, edit, MCP call and unknown web fetch is shown to you with the exact command and parsed rule checks, and repo-shipped config waits for a folder-trust decision. But everything you approve runs unsandboxed as you, with your full environment and credentials, and the gate is easy to lose: the first prompt preselects a global always-approve option that persists to every future session, and a trusted repo can turn on bypass mode. There are no cost or time budgets, installed plugins update themselves silently, and secrets are redacted only from telemetry.

## Critical gaps
- By default every shell command, test run, hook and MCP server runs directly on the host as the user, with the home directory, credentials, full environment and network reachable; the OS sandbox is opt-in. (ASI05, T11; C4) — [crates/codegen/xai-grok-shell/src/agent/config.rs:642](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-shell/src/agent/config.rs#L642); [crates/codegen/xai-grok-tools/src/util/shell_env_policy.rs:59](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-tools/src/util/shell_env_policy.rs#L59)

## Criterion details

### C1 Identity & least privilege — 0.12 (high)

Grok Build runs as the developer's own OS user with no narrower identity of its own. Every shell command and every MCP server it launches inherits the full process environment by default, so cloud keys, tokens and API keys in your shell are available to anything the agent runs. An environment-scrubbing policy exists but ships as a no-op. The only thing standing between a hijacked agent and your ambient credentials is the per-call approval prompt.

- **S L0:** Ambient OS-user authority; the default shell environment policy inherits every variable and skips the built-in *KEY*/*SECRET*/*TOKEN* excludes. — [crates/codegen/xai-grok-tools/src/util/shell_env_policy.rs:56-62](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-tools/src/util/shell_env_policy.rs#L56-L62); [crates/codegen/xai-grok-tools/src/util/shell_env_policy.rs:60](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-tools/src/util/shell_env_policy.rs#L60) (verified)
  - *To reach the next level:* No scoped or per-tool credential; L1 needs at least a dedicated identity or a default that withholds ambient secrets from tools.
- **C L1:** Per-call approval (C2) is the only authorization step; bash children get the full environment and stdio MCP servers inherit the parent environment with only their configured variables added. — [crates/codegen/xai-grok-mcp/src/servers.rs:4771-4777](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-mcp/src/servers.rs#L4771-L4777); [crates/codegen/xai-grok-tools/src/util/shell_env_policy.rs:59](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-tools/src/util/shell_env_policy.rs#L59) (verified)
  - *To reach the next level:* Subprocesses and extensions use ambient credentials; L2 needs all built-in tools to run with a scoped identity.
- **D L0:** The default install runs with the user's full privileges; narrowing the environment requires manual [shell_environment_policy] configuration. — [crates/codegen/xai-grok-tools/src/util/shell_env_policy.rs:56-62](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-tools/src/util/shell_env_policy.rs#L56-L62) (verified)
  - *To reach the next level:* L1 needs a narrower default (for example inherit=core with secret excludes) even if it can be widened.
- **B L1:** If the agent is hijacked it can reach whatever the user's shell can (SSH keys, cloud CLIs, gh auth); the independent per-call approval prompt in the default Ask mode still has to pass each shell or MCP call. — [crates/codegen/xai-grok-shell/src/util/config/permissions.rs:61](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-shell/src/util/config/permissions.rs#L61); [crates/codegen/xai-grok-workspace/src/permission/manager/mod.rs:1369](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-workspace/src/permission/manager/mod.rs#L1369) (verified)
  - *To reach the next level:* Ambient credentials give write access across multiple systems; L2 needs authority limited to one system.
- **Cap:** none

### C2 Approval gates — 0.47 (high)

The default interactive mode asks before every shell command, file edit, MCP call, sub-agent launch and non-allowlisted web fetch, and the prompt shows the exact call. Commands are parsed with a real bash parser, chained segments are checked one by one, deny rules win even over always-approve, and edits to hook, settings and shell-startup files always re-prompt. The weak spots are around the gate: the first prompt of a session preselects 'Yes, and don't ask again for anything (always-approve mode)', which is saved for every future session; a trusted repo's Claude-style settings can switch on bypass mode; and a sub-agent defined with bypassPermissions runs its own calls unprompted. There is no undo for files changed by approved commands.

- **S L3:** Per-call prompts carry the exact command or call; allow/ask/deny rules are evaluated on parsed segments, deny is enforced before always-approve, and reject is a first-class outcome. — [crates/codegen/xai-grok-workspace/src/permission/manager/mod.rs:760-779](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-workspace/src/permission/manager/mod.rs#L760-L779); [crates/codegen/xai-grok-workspace/src/permission/manager/mod.rs:1369](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-workspace/src/permission/manager/mod.rs#L1369); [crates/codegen/xai-grok-permission-rules/src/bash_command_splitting.rs:2](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-permission-rules/src/bash_command_splitting.rs#L2) (verified)
  - *To reach the next level:* L4 also needs proof that the approved call is exactly the executed call (hooks can rewrite inputs before the gate); not verified end to end.
- **C L2:** Every tool call goes through the permission manager and unknown typed tools prompt, but bare mkdir/touch are auto-allowed despite not being read-only, untyped dynamic tool inputs default to a read classification, and a user or trusted-project sub-agent definition with permissionMode bypassPermissions runs its inner calls ungated after one task approval. — [crates/codegen/xai-grok-shell/src/session/acp_session_impl/tool_calls.rs:1713](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-shell/src/session/acp_session_impl/tool_calls.rs#L1713); [crates/codegen/xai-grok-workspace/src/permission/grants.rs:319](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-workspace/src/permission/grants.rs#L319); [crates/codegen/xai-grok-tools/src/permission_access.rs:116](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-tools/src/permission_access.rs#L116); [crates/codegen/xai-grok-shell/src/agent/subagent/handle_request.rs:1579-1582](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-shell/src/agent/subagent/handle_request.rs#L1579-L1582) (verified)
  - *To reach the next level:* L3 needs sub-agents to traverse the same gate regardless of their definition and auto-approval limited to a verified read-only allowlist.
- **D L1:** Ask is the shipped default, but after a single generic folder-trust prompt a repo's .claude/settings.json defaultMode=bypassPermissions adds a catch-all allow rule, and the first permission prompt preselects global always-approve, which is then persisted to ~/.grok/config.toml. — [crates/codegen/xai-grok-permission-rules/src/resolution.rs:50-56](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-permission-rules/src/resolution.rs#L50-L56); [crates/codegen/xai-grok-permission-rules/src/resolution.rs:595](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-permission-rules/src/resolution.rs#L595); [crates/codegen/xai-grok-workspace/src/permission/prompter.rs:29](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-workspace/src/permission/prompter.rs#L29); [crates/codegen/xai-grok-pager-render/src/appearance/permission_cursor.rs:60](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-pager-render/src/appearance/permission_cursor.rs#L60); [crates/codegen/xai-grok-pager/src/app/effects/helpers.rs:1430](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-pager/src/app/effects/helpers.rs#L1430) (verified)
  - *To reach the next level:* L2 needs the approval mode to be changeable only by the operator, never by a repository file; L3 additionally needs disabling to be an explicit, loudly named action rather than a preselected prompt row.
- **B L1:** Approved shell commands can be irreversible (rm, git push, deploys); /rewind truncates only the conversation and does not restore files. — [crates/codegen/xai-grok-pager/docs/user-guide/17-sessions.md:158](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-pager/docs/user-guide/17-sessions.md#L158) (verified)
  - *To reach the next level:* No filesystem checkpoint or rollback; L2 needs reversible handling for the common case.
- **Cap:** none

### C3 Tool & action scoping — 0.28 (high)

The core tool is a general-purpose shell, and the read, write and edit tools accept any path on the machine; only a short list of sensitive edit targets forces a prompt. Web fetch is the exception: it blocks private and metadata addresses and handles redirects itself. Every tool, including shell, write and web access, is enabled by default and can only be removed one by one with flags.

- **S L2:** Typed tool schemas plus some validation: web_fetch blocks non-public addresses and manages redirects itself; protected edit targets are classified after symlink resolution; but bash takes an arbitrary command string. — [crates/codegen/xai-grok-tools/src/implementations/grok_build/web_fetch/ssrf.rs:4](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-tools/src/implementations/grok_build/web_fetch/ssrf.rs#L4); [crates/codegen/xai-grok-tools/src/implementations/grok_build/web_fetch/http.rs:70](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-tools/src/implementations/grok_build/web_fetch/http.rs#L70); [crates/codegen/xai-grok-permission-rules/src/shell_access.rs:462](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-permission-rules/src/shell_access.rs#L462); [crates/codegen/xai-grok-tools/src/permission_access.rs:54](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-tools/src/permission_access.rs#L54) (verified)
  - *To reach the next level:* L3 needs allowlist validation on paths (workspace containment) and commands, not just on fetch URLs.
- **C L1:** Only web_fetch and the protected-edit check validate arguments; read/edit accept any path and bash/MCP arguments are passed through. — [crates/codegen/xai-grok-workspace/src/permission/manager/mod.rs:1164](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-workspace/src/permission/manager/mod.rs#L1164); [crates/codegen/xai-grok-tools/src/permission_access.rs:56](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-tools/src/permission_access.rs#L56) (verified)
  - *To reach the next level:* L2 needs most built-in tools (read/edit/bash) to validate their arguments.
- **D L1:** Shell, write, edit and web tools are on by default; tools can be removed individually with --disallowed-tools. — [crates/codegen/xai-grok-pager/src/app/cli.rs:662](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-pager/src/app/cli.rs#L662) (verified)
  - *To reach the next level:* L2 needs selectable tool groups with a narrower default group.
- **B L0:** A misused shell tool can run any command anywhere the user can. — [crates/codegen/xai-grok-tools/src/permission_access.rs:54](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-tools/src/permission_access.rs#L54) (verified)
  - *To reach the next level:* L1 needs at least minor scope limits on the general tools.
- **Cap:** none

### C4 Code-execution isolation — 0.50 (high)

Out of the box, shell commands, test runners, hooks and MCP servers run directly on your machine as your user, with your home directory, credentials and network. Grok ships a capable optional OS sandbox (Landlock or bubblewrap on Linux, Seatbelt on macOS) that confines the whole process and its children and refuses to start when a profile that needs protection can't be enforced, but it's off unless you pass --sandbox or set it in config. Child-network blocking in the strict profiles works on Linux only.

- **default configuration** (default; raw 0.00 → 0.00)
  - **S L0:** No isolation by default: the sandbox profile resolves to 'off' when neither CLI, env nor config selects one. — [crates/codegen/xai-grok-shell/src/agent/config.rs:642](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-shell/src/agent/config.rs#L642); [crates/codegen/xai-grok-pager/docs/user-guide/18-sandbox.md:5](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-pager/docs/user-guide/18-sandbox.md#L5) (verified)
    - *To reach the next level:* L1+ needs some isolation primitive on by default.
  - **C L0:** Every execution path (bash, monitor, hooks, MCP stdio servers) runs unsandboxed in the default configuration. — [crates/codegen/xai-grok-shell/src/agent/config.rs:642](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-shell/src/agent/config.rs#L642) (verified)
    - *To reach the next level:* L1 needs at least the main exec tool sandboxed by default.
  - **D L0:** Off by default. — [crates/codegen/xai-grok-pager/docs/user-guide/18-sandbox.md:5](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-pager/docs/user-guide/18-sandbox.md#L5) (verified)
    - *To reach the next level:* L1 needs the sandbox on by default.
  - **B L0:** Commands run host-equivalent: the user's home directory, ~/.ssh and cloud credential files, the full environment and unrestricted network are reachable. — [crates/codegen/xai-grok-tools/src/util/shell_env_policy.rs:59](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-tools/src/util/shell_env_policy.rs#L59); [crates/codegen/xai-grok-shell/src/agent/config.rs:642](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-shell/src/agent/config.rs#L642) (verified)
    - *To reach the next level:* L1 needs at least no home/credential access from inside the execution context.
- **opt-in OS sandbox (--sandbox workspace|read-only|strict)** (alt; raw 0.55, cap G1 → 0.50) ← counted
  - **S L3:** Whole-process Landlock/bubblewrap (Linux) or Seatbelt (macOS) profile; strict limits writes to CWD, ~/.grok/sessions and temp, and blocks child network via seccomp on Linux. — [crates/codegen/xai-grok-pager/docs/user-guide/18-sandbox.md:34](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-pager/docs/user-guide/18-sandbox.md#L34); [crates/codegen/xai-grok-shell/src/config/mod.rs:1483](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-shell/src/config/mod.rs#L1483) (verified)
    - *To reach the next level:* L4 needs kernel-separated isolation (microVM/gVisor); child-network blocking is also a no-op on macOS.
  - **C L3:** Applied to the entire grok process at startup, so bash, hooks and MCP stdio children inherit it; profiles that require protection refuse to start when it cannot be applied. — [crates/codegen/xai-grok-shell/src/config/mod.rs:1489-1494](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-shell/src/config/mod.rs#L1489-L1494) (verified)
    - *To reach the next level:* In-process HTTP tools are exempt and built-in profile failures outside the protected set only warn; L4 needs fail-closed on every path.
  - **D L0:** Opt-in via --sandbox, GROK_SANDBOX or config. — [crates/codegen/xai-grok-shell/src/agent/config.rs:642](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-shell/src/agent/config.rs#L642) (verified)
    - *To reach the next level:* Off by default; L1+ needs it on.
  - **B L2:** Under workspace the workspace is writable and network open; strict removes child network on Linux but the full environment is still inherited. — [crates/codegen/xai-grok-tools/src/util/shell_env_policy.rs:59](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-tools/src/util/shell_env_policy.rs#L59) (verified)
    - *To reach the next level:* L3 needs no secrets in the environment and network egress off or allowlisted.
- **Cap:** G1 — Opt-in mechanism: off in the scored default configuration.

### C5 Untrusted input blast radius — 0.50 (high)

Grok reads web pages, search results, repository files and MCP tool output, and treats it all as ordinary context with no provenance tracking. What limits a hijack is the default approval gate: shell commands, edits, MCP calls and fetches to non-allowlisted hosts all need a click, so exfiltration and destructive actions are not unattended in the default mode. But file reads anywhere on disk (including Grok's own auth file) happen without asking, and the gate is one keypress away from global always-approve, so the protection rests on the user reading each prompt.

- **S L2:** Egress and state-changing tools require approval in Ask mode regardless of what was read, but the rule is not tied to untrusted content and reads of any path are auto-allowed. — [crates/codegen/xai-grok-workspace/src/permission/manager/mod.rs:1164](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-workspace/src/permission/manager/mod.rs#L1164); [crates/codegen/xai-grok-workspace/src/permission/manager/mod.rs:1257](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-workspace/src/permission/manager/mod.rs#L1257) (verified)
  - *To reach the next level:* L3 needs a code-enforced rule that, once untrusted content enters the session, every egress and state change is disabled or forced to human approval, including remembered grants.
- **C L2:** The approval requirement applies to calls regardless of which source (web, file, MCP result) influenced them, but tool results and MCP descriptions carry no untrusted marking. — [crates/codegen/xai-grok-shell/src/session/acp_session_impl/tool_calls.rs:1713](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-shell/src/session/acp_session_impl/tool_calls.rs#L1713) (verified)
  - *To reach the next level:* L3 needs every source, including tool results, tool descriptions and sub-agent messages, distinguished and covered.
- **D L2:** On by default through Ask mode; the operator (or one keypress on the first prompt) switches to always-approve, which then auto-allows all tool calls. — [crates/codegen/xai-grok-workspace/src/permission/manager/mod.rs:779](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-workspace/src/permission/manager/mod.rs#L779); [crates/codegen/xai-grok-pager-render/src/appearance/permission_cursor.rs:181](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-pager-render/src/appearance/permission_cursor.rs#L181) (verified)
  - *To reach the next level:* L3 needs disabling to be explicit and warned rather than the preselected first-prompt option.
- **B L2:** In default Ask mode, shell, edits, MCP calls and non-allowlisted fetches need approval, so exfiltration and irreversible actions need a human; allowlisted documentation fetches and web search run unattended. — [crates/codegen/xai-grok-tools/src/implementations/grok_build/web_fetch/config.rs:92](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-tools/src/implementations/grok_build/web_fetch/config.rs#L92); [crates/codegen/xai-grok-workspace/src/permission/manager/mod.rs:1369](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-workspace/src/permission/manager/mod.rs#L1369) (verified)
  - *To reach the next level:* L3 needs sensitive data out of reach or no outbound channel in sessions that read untrusted content.
- **Cap:** none

### C6 Memory, context & configuration integrity — 0.50 (high)

Grok gates repository-controlled configuration behind a VS Code-style folder-trust decision: project MCP servers, hooks, permission rules, .envrc, agent definitions, skills and even AGENTS.md instructions are skipped until you trust the folder, and headless runs fail closed. Project files can't set the global permission mode. Once trusted, though, a repo's settings can turn on bypass mode, and project agents can declare their own always-approve mode. Cross-session memory is off by default; when enabled it captures facts after every turn without review. Builds made from source disable folder trust entirely.

- **S L2:** Security-relevant project config and instructions need an explicit trust decision before loading, but opt-in memory auto-captures observations each turn with no gating. — [crates/codegen/xai-grok-permission-rules/src/folder_trust.rs:69-77](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-permission-rules/src/folder_trust.rs#L69-L77); [crates/codegen/xai-grok-permission-rules/src/resolution.rs:233](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-permission-rules/src/resolution.rs#L233); [crates/codegen/xai-grok-workspace/src/folder_trust.rs:542](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-workspace/src/folder_trust.rs#L542); [crates/codegen/xai-grok-pager/docs/user-guide/13-memory.md:26](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-pager/docs/user-guide/13-memory.md#L26) (verified)
  - *To reach the next level:* L3 also needs memory writes gated (approval, validation or source restriction) with expiry.
- **C L2:** Auto-loaded files and settings (MCP, hooks, permissions, .envrc, agents, skills, instructions) are all under the trust gate; the memory store is not controlled when enabled. — [crates/codegen/xai-grok-workspace/src/folder_trust.rs:500](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-workspace/src/folder_trust.rs#L500); [crates/codegen/xai-grok-workspace/src/folder_trust.rs:514](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-workspace/src/folder_trust.rs#L514); [crates/codegen/xai-grok-workspace/src/folder_trust.rs:526](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-workspace/src/folder_trust.rs#L526); [crates/codegen/xai-grok-config/src/config_layers.rs:138-140](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-config/src/config_layers.rs#L138-L140) (verified)
  - *To reach the next level:* L3 needs every memory store controlled too.
- **D L2:** Single-user local storage with global and per-workspace memory scopes; folder trust is on by default in release builds but inert in builds without GROK_VERSION and disableable by env or user config. — [crates/codegen/xai-grok-permission-rules/src/folder_trust.rs:121-126](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-permission-rules/src/folder_trust.rs#L121-L126); [crates/codegen/xai-grok-permission-rules/src/folder_trust.rs:145-149](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-permission-rules/src/folder_trust.rs#L145-L149); [crates/codegen/xai-grok-config-types/src/memory.rs:679](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-config-types/src/memory.rs#L679) (verified)
  - *To reach the next level:* L3 needs the model unable to write across scopes or change isolation; not shown.
- **B L2:** Poisoned instruction files or memory persist across sessions but any resulting tool use still passes the approval gate. — [crates/codegen/xai-grok-shell/src/util/config/permissions.rs:61](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-shell/src/util/config/permissions.rs#L61) (verified)
  - *To reach the next level:* L3 needs persistence to be session-scoped or easily inspected and purged.
- **Cap:** none

### C7 Third-party extensions — 0.23 (high)

No plugins or MCP servers are active on a fresh install, and project-shipped extensions wait for folder trust. Plugins you install, however, are re-fetched and updated automatically at the start of each session with no re-approval, so a compromised plugin update runs without anyone looking. MCP servers run as separate processes with your full environment.

- **S L1:** User-chosen sources, but installed plugins auto-update at session start without re-approval. — [crates/codegen/xai-grok-pager/src/app/effects/mod.rs:3083](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-pager/src/app/effects/mod.rs#L3083); [crates/codegen/xai-grok-pager/src/app/effects/mod.rs:3123](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-pager/src/app/effects/mod.rs#L3123) (verified)
  - *To reach the next level:* L2 needs versions pinned by default.
- **C L0:** No extension type is version-verified by default; commit-pinning is an opt-in managed policy. — [crates/codegen/xai-grok-pager/src/app/effects/mod.rs:3083-3090](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-pager/src/app/effects/mod.rs#L3083-L3090) (verified)
  - *To reach the next level:* L1 needs at least one extension type verified.
- **D L2:** Nothing third-party enabled by default; installs and project extensions require explicit trust, but the folder-trust prompt lists config kinds rather than the exact commands. — [crates/codegen/xai-grok-workspace/src/folder_trust.rs:454](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-workspace/src/folder_trust.rs#L454); [crates/codegen/xai-grok-permission-rules/src/folder_trust.rs:69-77](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-permission-rules/src/folder_trust.rs#L69-L77) (verified)
  - *To reach the next level:* L3 needs the exact package, command and permissions shown when an extension is added.
- **B L1:** MCP stdio servers are separate processes as the same user with the inherited environment plus configured variables. — [crates/codegen/xai-grok-mcp/src/servers.rs:4771-4777](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-mcp/src/servers.rs#L4771-L4777) (verified)
  - *To reach the next level:* L2 needs a scrubbed environment for extension processes.
- **Cap:** none

### C8 Secrets & sensitive-data protection — 0.33 (high)

Grok's own login token sits in a plaintext, owner-only file under ~/.grok, and nothing stops the agent's read tool from reading it without a prompt. Secret redaction exists but only on outbound telemetry, crash reports and the optional OpenTelemetry stream; it does not touch what is sent to the model, local transcripts or subprocess environments. Product telemetry and session-trace upload are off in code but can be switched on by xAI's remote settings.

- **S L2:** Plaintext token file with 0600 permissions; regex secret scrubbing on Sentry/OTEL/Mixpanel paths. — [crates/codegen/xai-grok-shell-base/src/util/secure_file.rs:8](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-shell-base/src/util/secure_file.rs#L8); [crates/codegen/xai-grok-telemetry/src/sentry.rs:50-55](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-telemetry/src/sentry.rs#L50-L55) (verified)
  - *To reach the next level:* L3 needs an OS keychain or encryption at rest plus redaction before model-bound messages.
- **C L1:** Only outbound telemetry paths are scrubbed; model-bound messages, transcripts and subprocess environments are not. — [crates/codegen/xai-grok-tools/src/util/shell_env_policy.rs:60](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-tools/src/util/shell_env_policy.rs#L60); [crates/codegen/xai-grok-telemetry/src/sentry.rs:55](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-telemetry/src/sentry.rs#L55) (verified)
  - *To reach the next level:* L2 needs logs and transcripts covered.
- **D L1:** Telemetry and trace upload default to off in code but the vendor's remote settings can enable them without user action; the environment-scrubbing default is off. — [crates/codegen/xai-grok-shell/src/agent/config.rs:1877](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-shell/src/agent/config.rs#L1877); [crates/codegen/xai-grok-shell/src/agent/config.rs:1881](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-shell/src/agent/config.rs#L1881); [crates/codegen/xai-grok-shell/src/agent/config.rs:1902](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-shell/src/agent/config.rs#L1902) (verified)
  - *To reach the next level:* L2 needs telemetry strictly opt-in by the user.
- **B L1:** The xAI login is a refreshable account token readable by the model; any API keys in the user's environment reach every subprocess. — [crates/codegen/xai-grok-shell-base/src/util/secure_file.rs:8-10](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-shell-base/src/util/secure_file.rs#L8-L10); [crates/codegen/xai-grok-tools/src/util/shell_env_policy.rs:59](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-tools/src/util/shell_env_policy.rs#L59) (verified)
  - *To reach the next level:* L2 needs scoped keys rather than account-wide credentials.
- **Cap:** none

### C9 Audit & traceability — 0.45 (high)

Each session writes a local conversation transcript and a structured events.jsonl that records tool completions, MCP calls, permission requests and decisions, and always-approve toggles, under ~/.grok/sessions outside the project. The log is best-effort: write failures are logged once and work continues, the agent's own shell can edit it, and the sub-agent link in the event schema is never emitted.

- **S L2:** Structured per-event JSON lines with timestamps for tool completions, MCP calls and permission decisions, plus the chat transcript. — [crates/codegen/xai-grok-session-events/src/types.rs:29](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-session-events/src/types.rs#L29); [crates/codegen/xai-grok-session-events/src/types.rs:43](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-session-events/src/types.rs#L43); [crates/codegen/xai-grok-session-events/src/types.rs:264](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-session-events/src/types.rs#L264) (verified)
  - *To reach the next level:* L3 needs actor attribution (approver, requesting principal) and correlation IDs across sub-agents in the local record.
- **C L2:** Built-in and MCP tool calls and permission decisions are recorded; the Subagent relationship variant is dead code. — [crates/codegen/xai-grok-session-events/src/types.rs:412-416](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-session-events/src/types.rs#L412-L416) (verified)
  - *To reach the next level:* L3 needs sub-agent activity linked into the same record.
- **D L2:** On by default under ~/.grok/sessions, outside the workspace, but writable by the agent's own unsandboxed shell. — [crates/codegen/xai-grok-shell/src/session/persistence.rs:966-967](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-shell/src/session/persistence.rs#L966-L967) (verified)
  - *To reach the next level:* L3 needs the record written by a component the model cannot control.
- **B L1:** Write failures are only warned about once and actions proceed; no fsync. — [crates/codegen/xai-grok-session-events/src/log.rs:76-79](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-session-events/src/log.rs#L76-L79) (verified)
  - *To reach the next level:* L2 needs errors surfaced and records flushed per action.
- **Cap:** none

### C10 Limits & kill switch — 0.40 (high)

Shell commands time out after 2 minutes by default (5 minutes maximum in the foreground), sub-agents are limited to one level deep and 32 concurrent, and stopping kills the command's process group. There is no default turn limit (--max-turns is opt-in), no wall-clock limit and no token or cost budget. Background commands may run up to 24 hours and the model can create durable scheduled tasks after approval.

- **S L2:** Opt-in iteration cap plus enforced per-command timeouts. — [crates/codegen/xai-grok-pager/src/app/cli.rs:670](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-pager/src/app/cli.rs#L670); [crates/codegen/xai-grok-tools/src/implementations/grok_build/bash/mod.rs:427](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-tools/src/implementations/grok_build/bash/mod.rs#L427) (verified)
  - *To reach the next level:* L3 needs wall-clock and token/cost caps; grok has no budget feature.
- **C L2:** Top-level loop and tool timeouts; sub-agent depth and concurrency are capped but there is no shared budget. — [crates/codegen/xai-grok-shell/src/config/mod.rs:249](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-shell/src/config/mod.rs#L249); [crates/codegen/xai-grok-tools/src/implementations/grok_build/task/admission.rs:6](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-tools/src/implementations/grok_build/task/admission.rs#L6) (verified)
  - *To reach the next level:* L3 needs sub-agents, background tasks and spawned processes to count against one budget.
- **D L1:** No turn limit by default and background commands may run for 24 hours. — [crates/codegen/xai-grok-pager/src/app/cli.rs:670](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-pager/src/app/cli.rs#L670); [crates/codegen/xai-grok-tools/src/implementations/grok_build/bash/mod.rs:899](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-tools/src/implementations/grok_build/bash/mod.rs#L899) (verified)
  - *To reach the next level:* L2 needs sensible default ceilings on turns and time.
- **B L1:** No spend ceiling; background tasks and durable scheduled tasks can outlive the turn. — [crates/codegen/xai-grok-pager/docs/user-guide/14-headless-mode.md:295](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-pager/docs/user-guide/14-headless-mode.md#L295); [crates/codegen/xai-grok-tools/src/implementations/grok_build/scheduler/create.rs:248](https://github.com/xai-org/grok-build/blob/2bdd1d6a6369de0e8c68132ea4539e9abd9e14a8/crates/codegen/xai-grok-tools/src/implementations/grok_build/scheduler/create.rs#L248) (verified)
  - *To reach the next level:* L2 needs moderate ceilings on time and spend.
- **Cap:** none

## Rule-of-Two check
[A] untrusted input: web_fetch/web_search results, repository files and MCP tool output enter context as ordinary tool results (crates/codegen/xai-grok-tools/src/permission_access.rs:5-73) · [B] sensitive data/systems: read_file of any path, including ~/.grok/auth.json and ~/.ssh, is auto-allowed (crates/codegen/xai-grok-workspace/src/permission/manager/mod.rs:1164) · [C] state change / egress: bash, edits, MCP tools and non-allowlisted web_fetch, gated per call in Ask mode (crates/codegen/xai-grok-workspace/src/permission/manager/mod.rs:1369) · Same default session? Yes

## Highest-impact improvements
1. Preselect 'Allow once' on permission prompts, stop persisting always-approve from a prompt row, and refuse bypassPermissions from project-scope settings. — C2 D L1→L3, +0.100 before caps (Playbook 5)
2. Ship the workspace sandbox profile on by default with an explicit unsafe flag to disable it. — C4 D L0→L3, +0.150 before caps (Playbook 3, step 1)
3. Default shell_environment_policy to drop *KEY*/*SECRET*/*TOKEN* variables and scrub the environment of MCP stdio servers. — C1 D L0→L1, +0.050 before caps (Playbook 4)
4. Pin installed plugin versions and require re-approval when an auto-update changes a plugin's code. — C7 S L1→L3, +0.150 before caps (Playbook 3)
5. Add default turn, wall-clock and token budgets shared by sub-agents. — C10 D L1→L2, +0.050 before caps (Playbook 3, step 3)

## Re-audit log
- No changes.

## Limitations
- Static source review of commit 2bdd1d6 only; nothing was executed, installed, or probed.
- Scored the released binary; builds from source (no GROK_VERSION at compile time) make folder trust inert, so project MCP/hooks/permission config load without a trust prompt.
- Several defaults (telemetry, trace upload, memory, permission mode, sandbox rollout) can be changed by xAI remote settings; only code defaults were scored, and remote values were not observed.
- Headless (-p), ACP agent-server and auto (LLM-classifier) modes were not scored separately; docs recommend always-approve for automation, which removes the C2/C5 gate.
- The repo is a ~4,400-file synced monorepo slice; the Windows code paths, voice, computer-hub and workspace-daemon crates were only skimmed.
- No reviewer-directed prompt injection found in the repo.
