Install
$ agentstack add skill-sfourdrinier-grok-skills-reason ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
How to run (transparent)
- Take the absolute Base directory for this skill from the Skill tool
(the folder that contains this skill's SKILL.md and run.mjs).
- Set
SKILL_BASEto that path. Do not invent versioned cache paths. - Always invoke the companion only through this skill's runner:
SKILL_BASE=''
# Required for completion notifications (plugin/references/execution-context.md):
export GROK_COMPANION_EXECUTION_CONTEXT=foreground # or background
node "$SKILL_BASE/run.mjs" [args...]
run.mjs finds the plugin install from its own location and runs scripts/grok-companion.mjs. No CLAUDE_PLUGIN_ROOT / PLUGIN_ROOT required.
If the host already exported CLAUDE_PLUGIN_ROOT or PLUGIN_ROOT, you may call node "$CLAUDE_PLUGIN_ROOT/scripts/grok-companion.mjs" instead; prefer "$SKILL_BASE/run.mjs" whenever the Skill tool loaded this skill.
Return companion stdout verbatim. Never put free-text in --task "..."; use --task-file - with a single-quoted heredoc.
Run a Grok reason consultation through the hardened wrapper and relay its result envelope. reason works in a fresh private temp dir OUTSIDE the repo with no automatic rule discovery: only the files you name with --input or --rules-file are supplied. It is the cheapest, most deterministic mode - prefer it over review whenever the task does not depend on neighboring repo files or repo-wide rules.
Raw slash-command arguments: $ARGUMENTS
Required wrapper flags (copy exactly, substitute only placeholder values):
- Exactly one of
--taskor--task-fileis required. --inputand--rules-filemay each be repeated to name the
artifacts and rule files Grok should see.
- Preserve the user's arguments exactly. Do not strip, add, or reorder flags.
Do not invent a flag that is not in the argument-hint.
- Shell-injection safety for
--task: the task is free text you must NEVER
place in a shell-evaluated position. $(...)/backticks inside a double-quoted --task "..." run locally BEFORE the wrapper validates them. When the arguments carry a --task , deliver that text on STDIN with --task-file - and a SINGLE-QUOTED heredoc so the shell passes it byte-for-byte; the companion stages it into a temp file for the wrapper.
- Shell-injection safety for flag VALUES (each
--input, each `--rules-file
, a --task-file , --schema, --model, --timeout, --max-turns, and EVERY other value you substitute from $ARGUMENTS): wrap each substituted value in SINGLE quotes, for example --input ''. Single quotes stop the shell from evaluating $(...)/backticks, so a hostile value reaches the companion as one literal argv token and the wrapper validates it (input/rules path resolution + escape guards). An unquoted OR double-quoted value would be command-substituted locally BEFORE the wrapper ever sees it -- the same injection class as an unsafe --task "...". The bare --web` flag carries no value to quote.
--web passthrough:
- Web tools are OFF by default. Pass
--webonly when the reasoning genuinely
depends on current external practices, current library or software versions, or living external documentation the named inputs cannot answer. Do not add --web otherwise.
Run it as one Bash call and relay the result. When the arguments carry a --task , route that text through STDIN so it is never shell-evaluated:
export GROK_COMPANION_EXECUTION_CONTEXT=foreground
node "$SKILL_BASE/run.mjs" reason [--input '' ...] [--rules-file '' ...] [other non-task flags from $ARGUMENTS, each substituted value single-quoted] --task-file -
GROK_TASK
When the arguments already use --task-file (or only non-task flags), drop the heredoc and pass every flag as single-quoted argv tokens:
export GROK_COMPANION_EXECUTION_CONTEXT=foreground
node "$SKILL_BASE/run.mjs" reason [--input '' ...] [--rules-file '' ...] --task-file '' [other non-task flags from $ARGUMENTS, each substituted value single-quoted]
- Return the command stdout envelope VERBATIM. Do not paraphrase, summarize, or
add commentary before or after it. Preserve the exit status. If you want to add your own take, do it separately and clearly labeled, AFTER the raw envelope.
If the companion prints an actionable "could not locate the Grok wrapper" message instead of an envelope, tell the user to run /grok:setup.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: sfourdrinier
- Source: sfourdrinier/grok-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.