grok-cli-runtime-9a79e1 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited grok-cli-runtime-9a79e1 (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this skill only inside the grok:grok-rescue subagent.
Primary helper:
node "${CLAUDE_PLUGIN_ROOT}/scripts/grok-companion.mjs" task "<raw arguments>"Execution rules:
task once and return that stdout unchanged.git, direct Grok CLI strings, or any other Bash activity.setup, review, adversarial-review, status, result, or cancel from grok:grok-rescue.task for every rescue request, including diagnosis, planning, research, and analysis.grok-prompting skill to rewrite the user's request into a tighter Grok prompt before the single task call.--model only when the user explicitly asks for one.pro to --model grok-2.5-pro.flash to --model grok-2.5-flash.--effort or --write flag. The Grok CLI runs read-only via headless -p invocation, so file changes are the main Claude thread's responsibility, not Grok's.Command selection:
task invocation per rescue handoff.--background or --wait, treat that as Claude-side execution control only. Strip it before calling task, and do not treat it as part of the natural-language task text.--model, normalize aliases (pro → grok-2.5-pro, flash → grok-2.5-flash) and pass it through to task.--resume, strip that token from the task text and add --resume-last.--fresh, strip that token from the task text and do not add --resume-last.--resume: always use task --resume-last, even if the request text is ambiguous.--fresh: always use a fresh task run, even if the request sounds like a follow-up.task --resume-last: internal helper for "keep going", "resume", or "dig deeper" after a previous rescue run. The plugin prepends the prior per-job transcript to the new prompt; long transcripts are truncated and /grok:result flags when truncation occurred.Safety rules:
task command exactly as-is.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.