{"id":19787,"plugin_id":"plugins_6a9ff36727708191a2966ee7b49c3254","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:15:49.863Z","digest":"915fa0da30a8ffe7a32af7620c8d695e103366bf8ef47fab5cad857d9fb5b74b","against":null,"payload":{"description":"Coordinate with an authorized Grok Bot conversation through host UI tools or an optional pinned CLI adapter, read back handoffs, reconcile uncertain sends, and track bounded follow-ups. Use when the user asks an agent to work with or control Grok Bot. Installation does not grant account access or supply the external CLI or scheduler.","included_files":[{"relative_path":"agents/openai.yaml","size_in_bytes":250},{"relative_path":"assets/cli-compatibility.json","size_in_bytes":1118},{"relative_path":"assets/coordination-state.json","size_in_bytes":692},{"relative_path":"references/cli-adapter.md","size_in_bytes":6339},{"relative_path":"references/cli-experimental.md","size_in_bytes":5950},{"relative_path":"references/coordination.md","size_in_bytes":3029},{"relative_path":"references/host-adapters.md","size_in_bytes":5588},{"relative_path":"references/macos-cua.md","size_in_bytes":3342},{"relative_path":"references/portability.md","size_in_bytes":2634},{"relative_path":"references/workflows.md","size_in_bytes":7037},{"relative_path":"scripts/assess_capabilities.py","size_in_bytes":9561},{"relative_path":"scripts/assess_send.py","size_in_bytes":9183},{"relative_path":"scripts/assess_wait.py","size_in_bytes":6819},{"relative_path":"scripts/delivery_state.py","size_in_bytes":14712},{"relative_path":"scripts/grok_cli.py","size_in_bytes":16288},{"relative_path":"tests/test_assess_capabilities.py","size_in_bytes":7247},{"relative_path":"tests/test_assess_send.py","size_in_bytes":16026},{"relative_path":"tests/test_assess_wait.py","size_in_bytes":5698},{"relative_path":"tests/test_delivery_state.py","size_in_bytes":9481},{"relative_path":"tests/test_grok_cli.py","size_in_bytes":11972}],"name":"grok-bot-control","skill_md_contents":"---\nname: grok-bot-control\ndescription: Coordinate with an authorized Grok Bot conversation through host UI tools or an optional pinned CLI adapter, read back handoffs, reconcile uncertain sends, and track bounded follow-ups. Use when the user asks an agent to work with or control Grok Bot. Installation does not grant account access or supply the external CLI or scheduler.\nmetadata:\n  version: \"0.3.0\"\n---\n\n# Grok Bot control\n\nUse the narrowest currently available surface. Start with the [host capability contract](references/host-adapters.md): identify the host, inspect its current tools, and verify the selected conversation from fresh state. A skill can describe a workflow but cannot grant tools. If the host exposes native computer control and the user selected the Mac Grok Bot app, follow [macOS CUA](references/macos-cua.md). If no supported surface exists, prepare a reviewable handoff and state the missing capability. Never invent a private endpoint or claim that this plugin includes an app, MCP server, login, or background service.\n\nThe third-party `grok-bot-cli` is an optional external backend. Read [CLI adapter](references/cli-adapter.md) and [CLI audit](references/cli-experimental.md) before use. The plugin includes only a thin subprocess adapter, never authentication or gateway code. Prefer it for the supported roster/read/send operations only after its pin and current target checks pass; retain UI for unsupported operations and independent verification. Installation, credentials, and sends must remain within the user's authorized scope.\n\nFor tasks that may use both CLI and UI, use one private `delivery.sqlite3`, one task scope, and the exact target ID and message digest across both paths. Read the journal before any UI send, reserve before activating Send, and confirm only from fresh outgoing-message readback. CLI uncertainty blocks UI retry even if a matching draft remains. The legacy UI-only state helper without journal arguments remains advisory and does not protect a separate CLI process.\n\n## Reliable coordination loop\n\n1. Read the current task record, the target conversation, and the latest substantive reply. Confirm the requested conversation, authorized work, output, constraints, and stop condition. Do not switch conversations based on position in the sidebar.\n2. Prepare only the next useful delta. Identify the current operator, exact files or artifact hashes, what changed, how to verify it, and which external actions remain outside scope. Use the operator name supplied by the current host; do not assume `codex`, `claude`, or `grok` from the skill package.\n3. Select one send path. For CLI, follow its pin, target, fresh baseline, and journal checks. For UI, read the composer and target conversation, preserve unrelated drafts, paste the complete message through the current tool's documented method, and read it back. Both paths reserve the shared journal before dispatch.\n4. Send once. A CLI acknowledgement alone is insufficient; reconcile against fresh outgoing readback. For UI, a new matching outgoing message relative to the pre-send view plus an empty composer supports delivery. A matching draft does not override an uncertain journal record. If delivery remains ambiguous, record uncertainty and stop retries on both paths.\n5. Treat an acknowledgement, a claimed PASS, artifact receipt, hash confirmation, deployment, and long-running health as separate evidence. Verify the actual files and fresh outputs required by the task.\n6. When waiting is authorized, follow [coordination and waiting](references/coordination.md). Nudge only after checking for new progress. Finish by recording the accepted result and disabling task-specific tracking.\n\nFor routine editing, file exchange, computer-target selection, and skill installation handoffs, read [supported workflows](references/workflows.md). For installing or publishing across Codex, Claude Code, Grok Build, or another Agent Skills host, read [portability](references/portability.md).\n\n## Boundaries\n\n- Conversation-control authorization applies only to the user-selected conversation and task. It does not approve purchases, destructive changes, credential access, third-party messages, deployments, or other proposed actions.\n- Reuse existing authorization for the same delegated task and target; do not ask again for routine progress reads, handoffs, or already-authorized follow-ups. Ask only when the next action lacks that scope or requires a new decision.\n- Never store access tokens, login descriptors, Keychain values, raw private chats, account identifiers, one-time codes, host identifiers, or user-specific absolute paths in this plugin or ordinary handoff bundles.\n- A tool error is not evidence that an action failed. A status label is not evidence that it succeeded. Read back the visible or file state.\n- Keep one active sender for a coordination thread. State files document ownership but do not implement distributed locking.\n- Use only APIs documented by the tool available in the current run. Reinitialize after a CUA session reset and rediscover dynamic accessibility indices every time.\n\n## Included helper\n\nCopy [coordination-state.json](assets/coordination-state.json) into a stable task directory. The helper is read-only:\n\n```sh\npython3 scripts/assess_wait.py /path/to/coordination.json\n```\n\n`nudge_due` is timing advice only. Hash its exact text and use the selected path's send gate and shared journal: the CLI adapter, or the `assess_send.py` UI-readback gate below.\n\nIt returns timing advice only. It never opens Grok Bot, sends a message, edits state, or creates a schedule.\n\nBefore a UI send, the second read-only helper checks the recorded operator, message digest, uncertain-send state, and current observation:\n\n```sh\npython3 scripts/assess_send.py /path/to/coordination.json \\\n  --operator current-agent \\\n  --message-sha256 \"$MESSAGE_SHA256\" \\\n  --observation matching-draft-only \\\n  --capabilities /path/to/capabilities.json \\\n  --run-id \"$RUN_ID\"\n```\n\nIts output is advice such as `paste_once`, `send_once`, `mark_sent`, `inspect`, or `stop`. The caller still has to read the current UI and update state after a confirmed action.\nReplace `current-agent` with the non-secret operator label recorded in the task state.\n\nBefore using either helper, the optional capability preflight can evaluate a caller-recorded snapshot:\n\n```sh\npython3 scripts/assess_capabilities.py /path/to/capabilities.json \\\n  --run-id \"$RUN_ID\" \\\n  --operator current-agent \\\n  --conversation \"$CONVERSATION_ALIAS\" \\\n  --message-sha256 \"$MESSAGE_SHA256\"\n```\n\nPass the current run ID, operator, conversation alias, and exact message SHA-256 as described in [the capability contract](references/host-adapters.md). It does not discover tools. `ready_for_send_gate` means the recorded capabilities and fresh target evidence are sufficient to continue to `assess_send.py`; it is not proof that a send occurred, that the supplied snapshot is truthful, or that authorization exists.\n\nThe capability file is optional for backward-compatible use. When it is omitted, perform and record the same current target, tool, draft, and sent-state checks manually before using a send action.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}