grok
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [REMOTE_CODE_EXECUTION]: The documentation includes a command to download and execute an installation script from the official x.ai domain. This is provided as a standard installation method for the CLI tool.
- [EXTERNAL_DOWNLOADS]: The skill recommends installing the official '@xai-official/grok' package from the public npm registry as the preferred installation path.
- [COMMAND_EXECUTION]: The skill uses shell commands through the terminal tool to manage the Grok CLI, including headless execution, session persistence, and interactive sessions via tmux.
- [CREDENTIALS_UNSAFE]: The instructions involve checking for local authentication state in the '~/.grok/auth.json' file and support the use of the 'XAI_API_KEY' environment variable for service access.
Audit Metadata