Skip to content

feat(grok): full Grok Build compatibility + installer surface - #822

Merged
rafaelscosta merged 15 commits into
mainfrom
feat/grok-full-compatibility
Aug 10, 2026
Merged

rafaelscosta merged 15 commits into
mainfrom
feat/grok-full-compatibility

Conversation

@oalanicolas

@oalanicolas oalanicolas commented Aug 10, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Brings AIOX to full Grok Build compatibility and surfaces Grok in the install wizard as a recommended CLI (alongside Claude Code and Codex).

Grok-native surface (.grok/)

  • Agents, skills, roles, personas, rules with Grok frontmatter
  • Short skill aliases (/develop-story, /full-sdc, /commit, …)
  • Short agent spawn aliases (dev, po, qa, devops, aiox-ux, …)
  • Native hooks: git-push authority (Claude + Grok payloads), synapse, precompact
  • Active-agent bridge (.aiox/active-agent + UAP) so devops push works without env-only identity
  • npm run sync:skills:grok / validate:skills:grok

Installer

  • Grok Build listed and pre-checked in IDE multi-select
  • Install generates full .grok/ via grok-skills-sync
  • core-config / enterprise detector / upgrade manifest include Grok paths

Test plan

  • npm run lint
  • npm run typecheck
  • npm test — 378 suites, 9032 tests passed
  • npm run validate:skills:grok (strict)
  • npm run validate:port-denylist
  • Unit: IDE configs / selector / Grok install surface / authority hook (Grok toolInput + bridge)
  • Integration: wizard IDE flow including all 7 IDEs + Grok sync
  • Manual: npx aiox-core install shows Grok Build checked; post-install .grok/ present
  • Manual: grok inspect lists project agents/skills/hooks

Notes

  • Pre-push used GitHub noreply author email to satisfy GH007 privacy.
  • No force-push. Branch is 5 commits ahead of main.

Summary by CodeRabbit

  • New Features

    • Added Grok Build as a supported installer option with synchronized agents, skills, aliases, rules, hooks, and project configuration.
    • Added user-invocable workflow shortcuts, agent aliases, active-agent tracking, and remote Git authority controls.
    • Added strict, quiet, and JSON validation with drift and stale-file detection.
    • Added session digest and prompt-processing hooks.
  • Documentation

    • Expanded Grok setup, discovery, synchronization, validation, and workflow guidance.
  • Bug Fixes

    • Prevented duplicate aiox- prefixes during Claude skill generation.
    • Preserved existing managed rule content during synchronization.

Make AIOX self-sufficient under .grok without depending on Claude-only
hook I/O: dual-payload git-push authority (toolInput + tool_input),
project hooks/config, short workflow aliases, sync+validate pipeline,
and discovery fixes for aiox-master skill naming.
Re-audit max compatibility: resolve active agent from .aiox/synapse
bridge files (not only env), register identity on every /aiox-* activation,
add short spawn aliases (dev/po/qa/devops/…), native synapse+precompact
hooks under .grok/hooks, and expanded validation/tests.
Pre-push lint cleanliness for the Grok compatibility suite.
Surface Grok Build in the install wizard (pre-checked), generate
.grok/rules from the product template, and run grok-skills-sync so
installed projects get agents/skills/hooks without a manual post-step.
Align unit/integration IDE tests with the Grok entry (count 7,
optional agentFolder, recommended pre-check, full-flow Grok sync).
@vercel

vercel Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
aiox-core Ready Ready Preview Aug 10, 2026 10:58pm

Request Review

@github-actions github-actions Bot added type: test Test coverage and quality area: installer Installer and setup (packages/installer/) area: synapse SYNAPSE context engine area: docs Documentation (docs/) labels Aug 10, 2026
@coderabbitai

coderabbitai Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

The PR adds Grok Build as a supported IDE surface. It generates agents, skills, aliases, hooks, rules, and configuration. It adds validation, installer wiring, active-agent registration, and DevOps-only remote Git enforcement.

Changes

Grok Build integration

Layer / File(s) Summary
Synchronization and validation
.aiox-core/infrastructure/scripts/grok-skills-sync/*, .aiox-core/data/entity-registry.yaml, .aiox-core/install-manifest.yaml
The synchronizer generates Grok artifacts, aliases, harness files, configuration, and hooks. The validator checks generated files and authority behavior.
Agent and workflow surfaces
.grok/agents/*, .grok/skills/*, .grok/README.md, AGENTS.md
Agent activation registers active-agent state. Short aliases delegate to canonical AIOX agents and workflows.
Runtime governance hooks
.grok/hooks/*, .claude/hooks/*, .aiox-core/infrastructure/templates/grok-hooks/*, .grok/config.toml, .grok/rules/aiox-core.md
Hooks resolve payloads and active-agent identity. Remote Git operations are restricted to DevOps agents. Synapse and precompact hooks process events with bounded execution.
Installer integration and verification
packages/installer/src/*, packages/installer/tests/*, tests/*, bin/modules/env-config.js, package.json
The installer registers Grok, generates and validates the .grok surface, and exposes strict and soft validation commands. Tests cover configuration, synchronization, installation, and hook decisions.

Estimated code review effort: 4 (Complex) | ~60 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Installer
  participant GrokSkillsSync
  participant GrokValidator
  participant GrokSurface
  participant AuthorityHook
  Installer->>GrokSkillsSync: Generate Grok project artifacts
  GrokSkillsSync->>GrokSurface: Write agents, skills, aliases, hooks, and config
  Installer->>GrokValidator: Validate the generated surface
  GrokValidator->>GrokSurface: Inspect files and authority behavior
  GrokSurface->>AuthorityHook: Submit remote Git command payload
  AuthorityHook->>GrokSurface: Resolve active-agent identity
  AuthorityHook-->>GrokSurface: Allow DevOps or deny other agents
Loading

Possibly related PRs

Suggested labels: area: agents, area: workflows, area: core, area: cli

Suggested reviewers: pedrovaleriolopez, rafaelscosta

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 38.54% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely summarizes the main changes: full Grok Build compatibility and installer integration.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/grok-full-compatibility

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

📊 Coverage Report

Coverage report not available

📈 Full coverage report available in Codecov


Generated by PR Automation (Story 6.1)

Prevent double-prefix skill name aiox-aiox-master in Claude skill
sync, refresh entity-registry determinism, and apply npm audit fix
so Security Audit (critical) and IDE sync gates pass on PR.
coderabbitai[bot]
coderabbitai Bot previously requested changes Aug 10, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 20

🧹 Nitpick comments (4)
packages/installer/tests/unit/wizard/grok-install-surface.test.js (1)

13-18: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Use the repository absolute-import form for local modules.

Line 13, Line 17, and Line 18 use relative imports. Replace these paths with the configured absolute-import form.

As per coding guidelines, “Use imports absolutos no código JavaScript e TypeScript.”

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/installer/tests/unit/wizard/grok-install-surface.test.js` around
lines 13 - 18, Replace the relative local-module imports in the test for
ide-configs, ide-config-generator, and core-config-template with the
repository’s configured absolute-import form, preserving the existing imported
symbols and behavior.

Source: Coding guidelines

.aiox-core/infrastructure/scripts/grok-skills-sync/validate.js (1)

355-375: 🩺 Stability & Availability | 🔵 Trivial | ⚡ Quick win

Prefer process.exitCode over process.exit to avoid truncated output.

process.exit at Line 374 terminates the process immediately. When stdout is a pipe, such as in CI logs or npm run ... | tee, writes are asynchronous. Pending diagnostics from Line 360 and the loops at Lines 365-366 can be lost. The validator then reports a failure without the error list that explains it.

Set process.exitCode and let the event loop drain.

♻️ Proposed change
-  process.exit(result.ok ? 0 : 1);
+  process.exitCode = result.ok ? 0 : 1;
 }
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.aiox-core/infrastructure/scripts/grok-skills-sync/validate.js around lines
355 - 375, Update main so it assigns the validation status to process.exitCode
instead of calling process.exit(result.ok ? 0 : 1), allowing stdout and stderr
diagnostics emitted in the JSON output and warning/error loops to finish before
the process exits.
.aiox-core/infrastructure/scripts/grok-skills-sync/index.js (1)

1429-1447: 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick win

Short agent aliases can overwrite canonical agent profiles.

syncShortAgentAliases writes .grok/agents/<alias>.md after the canonical agent loop in syncGrok has already written .grok/agents/<skillId>.md. The alias aiox-ux produces the destination .grok/agents/aiox-ux.md. If an entry in AGENT_PROFILES ever uses the id ux, getSkillId('ux') returns aiox-ux and the alias silently replaces the canonical profile with a redirect stub.

No collision exists with the current agent ids. Add a guard so a later agent id cannot break the canonical profile.

♻️ Proposed guard against destination collisions
 function syncShortAgentAliases(targets, options = {}) {
   const written = [];
+  const canonicalNames = new Set(
+    Object.keys(AGENT_PROFILES).map((id) => {
+      try {
+        return getSkillId(id);
+      } catch {
+        return null;
+      }
+    })
+  );
   for (const { alias, target, agentId } of SHORT_AGENT_ALIASES) {
     if (!SAFE_SKILL_ID_RE.test(alias) || !SAFE_SKILL_ID_RE.test(target)) {
       if (!options.quiet) {
         console.warn(`⚠️  Invalid agent alias ${alias} → ${target} — skipped`);
       }
       continue;
     }
+    if (canonicalNames.has(alias)) {
+      if (!options.quiet) {
+        console.warn(`⚠️  Alias ${alias} collides with a canonical agent profile — skipped`);
+      }
+      continue;
+    }
     const dest = resolveUnder(targets.agents, `${alias}.md`);
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.aiox-core/infrastructure/scripts/grok-skills-sync/index.js around lines
1429 - 1447, Update syncShortAgentAliases to guard against destinations already
occupied by canonical agent profiles, using the existing agent output or profile
identifiers available in syncGrok. Skip the alias when its resolved ${alias}.md
path collides with a canonical agent id, while preserving normal alias writing
and dry-run behavior for non-colliding aliases.
.grok/agents/aiox-ux.md (1)

17-25: 🗄️ Data Integrity & Integration | 🔵 Trivial | ⚡ Quick win

Keep active-agent registration owned by one layer. Both aliases load and follow canonical agent profiles, then define their own registration blocks. The UX canonical profile already contains the same registration, and the analyst profile requires confirmation.

  • .grok/agents/aiox-ux.md#L17-L25: Remove the duplicate alias registration and let .grok/agents/aiox-ux-design-expert.md own activation state.
  • .grok/agents/analyst.md#L17-L25: Verify .grok/agents/aiox-analyst.md; remove one registration path if both files write active-agent state.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.grok/agents/aiox-ux.md around lines 17 - 25, Remove the duplicate
active-agent registration from .grok/agents/aiox-ux.md lines 17-25, allowing
aiox-ux-design-expert.md to own activation state. Verify
.grok/agents/aiox-analyst.md against .grok/agents/analyst.md lines 17-25; if
both register active-agent state, remove one registration path and retain a
single owner.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.aiox-core/data/entity-registry.yaml:
- Line 18523: Regenerate the entity registry entry for grok-skills-sync-validate
so its dependencies reference grok-skills-sync-index rather than the Codex
index, and update the corresponding grok-skills-sync-index usedBy entry
consistently.

In @.aiox-core/infrastructure/scripts/grok-skills-sync/index.js:
- Around line 1464-1486: Update syncGrokHarnessFiles in
.aiox-core/infrastructure/scripts/grok-skills-sync/index.js:1464-1486 to copy
the synapse and precompact wrappers into .grok/hooks/, treat a missing authority
script as fatal or skip generating git-push-authority.json, and add paths to
written only when files are actually created while preserving dry-run
accounting. Update the generated command builders at
.aiox-core/infrastructure/scripts/grok-skills-sync/index.js:1331-1373 to
reference the copied .grok/hooks wrappers instead of .claude/hooks paths.
- Around line 1284-1304: Update buildGrokConfigToml so the generated
configuration does not claim ask-mode protection without applying a permission
setting: either add the concrete supported key under [permission], or remove the
empty [permission] table and revise the accompanying comment/documentation to
state the limitation accurately. Also update validate.js so validation checks
the effective permission configuration rather than merely matching the literal
“[permission]” header.

In @.claude/hooks/enforce-git-push-authority.cjs:
- Around line 185-194: Remove the wildcard suffix authorization from
isDevOpsAgent and rely exclusively on registered DEVOPS_AGENT_ALIASES entries,
preserving normalization and alias checks. Apply this change in
.claude/hooks/enforce-git-push-authority.cjs lines 185-194 and
.grok/hooks/enforce-git-push-authority.cjs lines 185-194.

In @.claude/skills/AIOX/agents/aiox-master/SKILL.md:
- Line 2: Update the migration gate inventory entry for the aiox-master agent to
use the current identifier “aiox-master” instead of “aiox-aiox-master,” while
preserving the surrounding contract documentation.

In @.grok/agents/aiox-analyst.md:
- Around line 19-25: Replace the self-asserted shared identity writes in the
activation blocks with the trusted, session-scoped registration contract,
ensuring the hook authenticates the session identity and rejects forged or stale
bridge state without relying on AIOX_ACTIVE_AGENT. Apply this to
.grok/agents/aiox-analyst.md lines 19-25, .grok/agents/aiox-architect.md lines
19-25, .grok/agents/aiox-data-engineer.md lines 19-25, .grok/agents/aiox-dev.md
lines 19-25, .grok/skills/aiox-sm/SKILL.md lines 18-24,
.grok/skills/aiox-squad-creator/SKILL.md lines 18-24, and
.grok/skills/aiox-ux-design-expert/SKILL.md lines 18-24; update .grok/README.md
lines 40-55 to document only identity sources the hook can authenticate.

In @.grok/agents/architect.md:
- Around line 18-24: Update the active-agent bridge registration in
.grok/agents/architect.md, .grok/agents/data-engineer.md, .grok/agents/dev.md,
.grok/agents/devops.md, .grok/agents/master.md, .grok/agents/pm.md,
.grok/agents/po.md, .grok/agents/qa.md, .grok/agents/sm.md,
.grok/agents/squad-creator.md, and .grok/agents/ux-design-expert.md at lines
18-24: serialize activation with bridge reads, stage and validate the agent
marker and both JSON records, atomically replace all three shared files, and
export AIOX_ACTIVE_AGENT only after every replacement succeeds; on any failure,
do not export or leave a partially updated bridge.

In @.grok/agents/master.md:
- Around line 18-24: Update the active-agent registration instructions around
the bridge-file writes so all three files are created or replaced
transactionally under a shared lock, with temporary files and atomic renames as
needed. Validate that their IDs and metadata match before completing activation;
on any failure, remove or preserve no partially updated bridge state and do not
export AIOX_ACTIVE_AGENT. Export the variable only after successful validation
and release of the lock.

In @.grok/hooks/enforce-git-push-authority.cjs:
- Around line 27-40: Update REMOTE_OPERATION_PATTERNS and the surrounding
command-detection logic to parse Git arguments and recognize push when global
options such as -C or --git-dir appear before it. Ensure these forms enter the
same authorization path as plain git push, and add regression coverage for both
option forms while preserving existing PR detection.

In @.grok/hooks/git-push-authority.json:
- Around line 3-13: Update both denial paths in enforce-git-push-authority.cjs
to exit with status 2 after emitting the deny JSON, and adjust the corresponding
tests to assert the new exit status while preserving the existing deny payload.

In @.grok/hooks/precompact.json:
- Line 8: Provide self-contained hook dependencies for Grok-only installations:
update .grok/hooks/precompact.json at lines 8-8 to reference a supplied wrapper
and precompact-session-digest.cjs or a Grok-local implementation, and update
.grok/hooks/synapse-prompt.json at lines 8-8 to reference a supplied wrapper and
synapse-engine.cjs or a Grok-local implementation.

In @.grok/skills/aiox-devops/SKILL.md:
- Around line 38-47: Remove the caller-controlled AIOX_ACTIVE_AGENT=devops
authorization path from the Remote Git instructions. Update the remote-operation
hook to validate a trusted, session-bound DevOps identity instead of accepting
environment values, and revise the governance tests to reject spoofed
AIOX_ACTIVE_AGENT values while preserving legitimate registered-agent
operations.
- Around line 18-25: Update
.aiox-core/infrastructure/scripts/grok-skills-sync/index.js to generate all
activation blocks in .grok/skills/aiox-devops/SKILL.md (lines 18-25),
.grok/agents/aiox-devops.md (lines 19-26), .grok/agents/aiox-master.md (lines
19-26), .grok/agents/aiox-pm.md (lines 19-26), .grok/agents/aiox-po.md (lines
19-26), .grok/agents/aiox-qa.md (lines 19-26),
.grok/skills/aiox-analyst/SKILL.md (lines 18-25),
.grok/skills/aiox-architect/SKILL.md (lines 18-25),
.grok/skills/aiox-data-engineer/SKILL.md (lines 18-25), and
.grok/skills/aiox-dev/SKILL.md (lines 18-25) through one shared
registration/cleanup helper using temporary files and atomic renames, stopping
and revoking on failure. Update enforce-git-push-authority.cjs to require
matching, non-expired session data and revoke the bridge on *exit; regenerate
these committed artifacts and add coverage for stale, partial, and bridge-only
identity states.

In `@AGENTS.md`:
- Around line 64-65: Update the command lists in AGENTS.md to document both
/wave-execute and /aiox-wave-execute, preserving the existing workflow and alias
entries.
- Around line 67-68: Update the `/aiox-*` activation workflow documentation to
require writing `.aiox/active-agent` before invoking alias workflows, including
the active agent identity and activation timestamp. Update the hook validation
guidance to reject missing, stale, or agent-inconsistent bridge records before
authorizing remote Git operations, rather than trusting the bridge id alone.

In `@packages/installer/src/config/templates/core-config-template.js`:
- Around line 54-58: Keep the default Grok selection consistent with its
configuration flag by updating configs.grok in the core config template to
enable it when selectedIDEs is empty, while preserving explicit selection
behavior. In packages/installer/src/config/templates/core-config-template.js
lines 54-58, make this change; in
packages/installer/tests/unit/wizard/grok-install-surface.test.js lines 40-44,
assert that the default generated YAML contains grok: true.

In `@packages/installer/src/enterprise/enterprise-upgrade-manifest.yaml`:
- Around line 150-169: Update the enterprise upgrade manifest’s Grok
IDE-surfaces entries to include .grok/roles/**, .grok/personas/**, and
.grok/README.md, using the same group and copy-if-missing policy as the existing
entries so all outputs generated by syncGrok are allowlisted.

In `@packages/installer/src/wizard/ide-config-generator.js`:
- Around line 721-737: Update the Grok generation flow around generateGrokSkills
to retain and process its written paths, registering only files and empty
directories created during this invocation for rollback. Remove the broad
createdFolders entries for the pre-existing .grok subdirectories, and ensure the
catch cleanup removes only those tracked paths without deleting existing .grok
content.

In `@packages/installer/src/wizard/index.js`:
- Around line 701-726: Update the final installation validation flow, using the
existing expectedSkillDirs and validation symbols, to include
path.join(targetProjectRoot, '.grok', 'skills') whenever answers.selectedIDEs
includes 'grok'. Prefer invoking validateGrok for selected Grok installations so
agents, roles, personas, hooks, rules, and config.toml are validated before
completion is reported, while preserving existing Claude and Codex validation.

In `@tests/unit/config/ide-configs.test.js`:
- Around line 60-64: Update the agentFolder validation in the IDE configuration
test so every IDE key except Grok must define a string agentFolder; retain the
optional behavior only for the Grok configuration by adding an explicit
key-based exception.

---

Nitpick comments:
In @.aiox-core/infrastructure/scripts/grok-skills-sync/index.js:
- Around line 1429-1447: Update syncShortAgentAliases to guard against
destinations already occupied by canonical agent profiles, using the existing
agent output or profile identifiers available in syncGrok. Skip the alias when
its resolved ${alias}.md path collides with a canonical agent id, while
preserving normal alias writing and dry-run behavior for non-colliding aliases.

In @.aiox-core/infrastructure/scripts/grok-skills-sync/validate.js:
- Around line 355-375: Update main so it assigns the validation status to
process.exitCode instead of calling process.exit(result.ok ? 0 : 1), allowing
stdout and stderr diagnostics emitted in the JSON output and warning/error loops
to finish before the process exits.

In @.grok/agents/aiox-ux.md:
- Around line 17-25: Remove the duplicate active-agent registration from
.grok/agents/aiox-ux.md lines 17-25, allowing aiox-ux-design-expert.md to own
activation state. Verify .grok/agents/aiox-analyst.md against
.grok/agents/analyst.md lines 17-25; if both register active-agent state, remove
one registration path and retain a single owner.

In `@packages/installer/tests/unit/wizard/grok-install-surface.test.js`:
- Around line 13-18: Replace the relative local-module imports in the test for
ide-configs, ide-config-generator, and core-config-template with the
repository’s configured absolute-import form, preserving the existing imported
symbols and behavior.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 3417c3b2-3c5b-40e8-9bd4-a7936847362d

📥 Commits

Reviewing files that changed from the base of the PR and between 0b32b68 and 03ff1e9.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (80)
  • .aiox-core/data/entity-registry.yaml
  • .aiox-core/infrastructure/scripts/grok-skills-sync/README.md
  • .aiox-core/infrastructure/scripts/grok-skills-sync/index.js
  • .aiox-core/infrastructure/scripts/grok-skills-sync/validate.js
  • .aiox-core/infrastructure/scripts/ide-sync/transformers/claude-code.js
  • .aiox-core/install-manifest.yaml
  • .aiox-core/product/templates/ide-rules/grok-rules.md
  • .claude/hooks/enforce-git-push-authority.cjs
  • .claude/skills/AIOX/agents/aiox-master/SKILL.md
  • .grok/README.md
  • .grok/agents/aiox-analyst.md
  • .grok/agents/aiox-architect.md
  • .grok/agents/aiox-data-engineer.md
  • .grok/agents/aiox-dev.md
  • .grok/agents/aiox-devops.md
  • .grok/agents/aiox-master.md
  • .grok/agents/aiox-pm.md
  • .grok/agents/aiox-po.md
  • .grok/agents/aiox-qa.md
  • .grok/agents/aiox-sm.md
  • .grok/agents/aiox-squad-creator.md
  • .grok/agents/aiox-ux-design-expert.md
  • .grok/agents/aiox-ux.md
  • .grok/agents/analyst.md
  • .grok/agents/architect.md
  • .grok/agents/data-engineer.md
  • .grok/agents/dev.md
  • .grok/agents/devops.md
  • .grok/agents/master.md
  • .grok/agents/pm.md
  • .grok/agents/po.md
  • .grok/agents/qa.md
  • .grok/agents/sm.md
  • .grok/agents/squad-creator.md
  • .grok/agents/ux-design-expert.md
  • .grok/config.toml
  • .grok/hooks/enforce-git-push-authority.cjs
  • .grok/hooks/git-push-authority.json
  • .grok/hooks/precompact.json
  • .grok/hooks/synapse-prompt.json
  • .grok/rules/aiox-core.md
  • .grok/skills/aiox-analyst/SKILL.md
  • .grok/skills/aiox-architect/SKILL.md
  • .grok/skills/aiox-data-engineer/SKILL.md
  • .grok/skills/aiox-dev/SKILL.md
  • .grok/skills/aiox-devops/SKILL.md
  • .grok/skills/aiox-handoff/SKILL.md
  • .grok/skills/aiox-master/SKILL.md
  • .grok/skills/aiox-pm/SKILL.md
  • .grok/skills/aiox-po/SKILL.md
  • .grok/skills/aiox-qa/SKILL.md
  • .grok/skills/aiox-quality-gates/SKILL.md
  • .grok/skills/aiox-sdc/SKILL.md
  • .grok/skills/aiox-sm/SKILL.md
  • .grok/skills/aiox-squad-creator/SKILL.md
  • .grok/skills/aiox-ux-design-expert/SKILL.md
  • .grok/skills/apply-qa-fixes/SKILL.md
  • .grok/skills/close-story/SKILL.md
  • .grok/skills/commit/SKILL.md
  • .grok/skills/develop-story/SKILL.md
  • .grok/skills/full-sdc/SKILL.md
  • .grok/skills/review-story/SKILL.md
  • .grok/skills/validate-story-draft/SKILL.md
  • .grok/skills/wave-execute/SKILL.md
  • AGENTS.md
  • bin/modules/env-config.js
  • package.json
  • packages/installer/src/config/ide-configs.js
  • packages/installer/src/config/templates/core-config-template.js
  • packages/installer/src/enterprise/enterprise-detector.js
  • packages/installer/src/enterprise/enterprise-upgrade-manifest.yaml
  • packages/installer/src/wizard/ide-config-generator.js
  • packages/installer/src/wizard/ide-selector.js
  • packages/installer/src/wizard/index.js
  • packages/installer/tests/unit/wizard/grok-install-surface.test.js
  • tests/claude/subagent-governance.test.js
  • tests/integration/wizard-ide-flow.test.js
  • tests/unit/config/ide-configs.test.js
  • tests/unit/grok/grok-skills-sync.test.js
  • tests/unit/wizard/ide-selector.test.js

Comment thread .aiox-core/data/entity-registry.yaml Outdated
Comment thread .aiox-core/infrastructure/scripts/grok-skills-sync/index.js
Comment thread .aiox-core/infrastructure/scripts/grok-skills-sync/index.js
Comment thread .claude/hooks/enforce-git-push-authority.cjs
Comment thread .claude/skills/AIOX/agents/aiox-master/SKILL.md
Comment thread packages/installer/src/config/templates/core-config-template.js Outdated
Comment thread packages/installer/src/enterprise/enterprise-upgrade-manifest.yaml
Comment thread packages/installer/src/wizard/ide-config-generator.js Outdated
Comment thread packages/installer/src/wizard/index.js
Comment thread tests/unit/config/ide-configs.test.js Outdated
Harden publication authority (git options / gh flags / API mutations),
vendor synapse/precompact wrappers under .grok/hooks, guard alias
collisions, align default IDE flags, expand enterprise allowlist, and
validate Grok surface after install.
coderabbitai[bot]
coderabbitai Bot previously requested changes Aug 10, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
tests/claude/subagent-governance.test.js (1)

182-232: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Execute the Grok cases through the Grok hook.

runAuthorityHook is fixed to .claude/hooks/enforce-git-push-authority.cjs. These cases validate a Grok-shaped payload against the Claude hook, not .grok/hooks/enforce-git-push-authority.cjs.

Parameterize the hook path and run the authority cases against both hook files. This prevents a Grok-only regression from passing this test.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@tests/claude/subagent-governance.test.js` around lines 182 - 232,
Parameterize the authority hook path used by the Grok-related tests in
subagent-governance.test.js, including the cases around the Grok-native payload
and active-agent bridge. Execute those cases against both the Claude and Grok
hook files, preserving the existing assertions and test setup so Grok-only
regressions are covered.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.grok/hooks/enforce-git-push-authority.cjs:
- Around line 248-253: Change the empty-input branch in the hook’s stdin
handling to emit the standard deny decision instead of returning silently,
ensuring absent payloads remain fail-closed for non-DevOps sessions. Update the
corresponding empty-input test to assert the same denial outcome as other
unauthorized requests.

---

Outside diff comments:
In `@tests/claude/subagent-governance.test.js`:
- Around line 182-232: Parameterize the authority hook path used by the
Grok-related tests in subagent-governance.test.js, including the cases around
the Grok-native payload and active-agent bridge. Execute those cases against
both the Claude and Grok hook files, preserving the existing assertions and test
setup so Grok-only regressions are covered.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: c7c349f6-572c-418e-863e-92c413997e1b

📥 Commits

Reviewing files that changed from the base of the PR and between 03ff1e9 and d6244e9.

📒 Files selected for processing (21)
  • .aiox-core/data/entity-registry.yaml
  • .aiox-core/infrastructure/scripts/grok-skills-sync/index.js
  • .aiox-core/infrastructure/scripts/grok-skills-sync/validate.js
  • .aiox-core/install-manifest.yaml
  • .claude/CLAUDE.md
  • .claude/hooks/enforce-git-push-authority.cjs
  • .grok/config.toml
  • .grok/hooks/enforce-git-push-authority.cjs
  • .grok/hooks/precompact-session-digest.cjs
  • .grok/hooks/precompact-wrapper.cjs
  • .grok/hooks/precompact.json
  • .grok/hooks/synapse-engine.cjs
  • .grok/hooks/synapse-prompt.json
  • .grok/hooks/synapse-wrapper.cjs
  • AGENTS.md
  • packages/installer/src/config/templates/core-config-template.js
  • packages/installer/src/enterprise/enterprise-upgrade-manifest.yaml
  • packages/installer/src/wizard/index.js
  • packages/installer/tests/unit/wizard/grok-install-surface.test.js
  • tests/claude/subagent-governance.test.js
  • tests/unit/config/ide-configs.test.js
🚧 Files skipped from review as they are similar to previous changes (9)
  • .grok/hooks/precompact.json
  • packages/installer/src/enterprise/enterprise-upgrade-manifest.yaml
  • AGENTS.md
  • .grok/hooks/synapse-prompt.json
  • packages/installer/src/config/templates/core-config-template.js
  • packages/installer/src/wizard/index.js
  • tests/unit/config/ide-configs.test.js
  • .aiox-core/infrastructure/scripts/grok-skills-sync/validate.js
  • .claude/hooks/enforce-git-push-authority.cjs

Comment thread .grok/hooks/enforce-git-push-authority.cjs Outdated
Address final CodeRabbit review: deny empty PreToolUse stdin and
run Grok payload/bridge cases against both Claude and Grok hook copies.
Resolve sourceDir/grokRoot from caller projectRoot, fail if agents dir
missing, detect orphan .grok artifacts under strict validate, and assert
fresh sync trees pass validation before merge.
Keep entity-registry and install-manifest aligned with the hardened
sync/validate sources so determinism gates pass on PR.
@oalanicolas
oalanicolas dismissed stale reviews from coderabbitai[bot] and coderabbitai[bot] August 10, 2026 21:29

Addressed actionable findings in d6244e9/ce87eb2b/4174fa6f; remaining items accepted as follow-up debt.

@oalanicolas

Copy link
Copy Markdown
Collaborator Author

Pre-merge review complete (Gage / @devops)

Head: 7c5fcad3 · Required CI: all green (Validation Summary, ESLint, TS, Jest 18–25)

Shipped

  • Native .grok/ surface (agents, skills, roles, personas, hooks, rules, config)
  • Dual-payload authority hook (Claude + Grok identical): exact DevOps allowlist, git/gh option coverage, API PR mutations, fail-closed empty stdin
  • Installer: Grok as 7th recommended CLI, configs.grok default, post-install validateGrok, enterprise allowlist for .grok/**
  • Sync hardenings: projectRoot resolution, missing sourceDir guard, orphan detection under strict validate
  • Registry + install-manifest checksums aligned

Local gates (pre-merge)

lint · typecheck · parity · ide-sync (109/109) · portable paths · critical unit suites — PASS

CodeRabbit

Actionable security/correctness items addressed in follow-up commits. Remaining notes are session-trust identity model / installer rollback debt (accepted).

Blocker

Ruleset main-branch-protection requires code owner review from @Pedrovaleriolopez (author cannot self-approve; org-admin bypass only). Review requested.

Ready to squash-merge on approval.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (2)
tests/claude/subagent-governance.test.js (1)

227-256: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Always remove the temporary workspace.

Lines 254-255 can throw before Line 256 runs. A failed assertion then leaves an aiox-gov-bridge-* directory in the system temporary directory. Wrap the test body after fs.mkdtempSync in try/finally.

Proposed cleanup change
       const tmp = fs.mkdtempSync(path.join(os.tmpdir(), 'aiox-gov-bridge-'));
-      fs.mkdirSync(path.join(tmp, '.aiox'), { recursive: true });
-      fs.writeFileSync(path.join(tmp, '.aiox', 'active-agent'), 'devops\n');
+      try {
+        fs.mkdirSync(path.join(tmp, '.aiox'), { recursive: true });
+        fs.writeFileSync(path.join(tmp, '.aiox', 'active-agent'), 'devops\n');

-      const env = { ...process.env };
-      // ...
-      expect(result.status).toBe(0);
-      expect(result.stdout).toBe('');
-      fs.rmSync(tmp, { recursive: true, force: true });
+        const env = { ...process.env };
+        // ...
+        expect(result.status).toBe(0);
+        expect(result.stdout).toBe('');
+      } finally {
+        fs.rmSync(tmp, { recursive: true, force: true });
+      }
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@tests/claude/subagent-governance.test.js` around lines 227 - 256, Wrap the
temporary workspace setup and test assertions after fs.mkdtempSync in a
try/finally block, placing fs.rmSync(tmp, { recursive: true, force: true }) in
the finally clause. Update the test body around the existing spawnSync and
expectations so cleanup runs even when an assertion or other operation throws.
tests/unit/grok/grok-skills-sync.test.js (1)

81-93: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Test the orphan-artifact failure path.

This test validates only a clean tree. It does not verify the new orphan detection in validateGrok.

Create an unexpected file or skill directory after sync. Assert that normal validation reports a warning. Assert that strict validation fails.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@tests/unit/grok/grok-skills-sync.test.js` around lines 81 - 93, Extend the
sync test after generating the tree to create an unexpected file or skill
directory under the synced Grok root. Call validateGrok with normal settings and
assert it reports a warning, then call it with strict: true and assert ok is
false, covering the orphan-artifact detection path while preserving the existing
clean-tree assertions.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@tests/claude/subagent-governance.test.js`:
- Around line 227-256: Wrap the temporary workspace setup and test assertions
after fs.mkdtempSync in a try/finally block, placing fs.rmSync(tmp, { recursive:
true, force: true }) in the finally clause. Update the test body around the
existing spawnSync and expectations so cleanup runs even when an assertion or
other operation throws.

In `@tests/unit/grok/grok-skills-sync.test.js`:
- Around line 81-93: Extend the sync test after generating the tree to create an
unexpected file or skill directory under the synced Grok root. Call validateGrok
with normal settings and assert it reports a warning, then call it with strict:
true and assert ok is false, covering the orphan-artifact detection path while
preserving the existing clean-tree assertions.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: b3122390-c344-4267-8627-7fd45665b0c7

📥 Commits

Reviewing files that changed from the base of the PR and between d6244e9 and 7c5fcad.

📒 Files selected for processing (9)
  • .aiox-core/data/entity-registry.yaml
  • .aiox-core/infrastructure/scripts/grok-skills-sync/index.js
  • .aiox-core/infrastructure/scripts/grok-skills-sync/validate.js
  • .aiox-core/install-manifest.yaml
  • .claude/hooks/enforce-git-push-authority.cjs
  • .grok/README.md
  • .grok/hooks/enforce-git-push-authority.cjs
  • tests/claude/subagent-governance.test.js
  • tests/unit/grok/grok-skills-sync.test.js
🚧 Files skipped from review as they are similar to previous changes (5)
  • .grok/README.md
  • .claude/hooks/enforce-git-push-authority.cjs
  • .aiox-core/install-manifest.yaml
  • .grok/hooks/enforce-git-push-authority.cjs
  • .aiox-core/infrastructure/scripts/grok-skills-sync/index.js

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 5

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.aiox-core/infrastructure/scripts/grok-skills-sync/index.js:
- Around line 1292-1310: Update syncShortWorkflowAliases to receive or reuse the
set of canonical skill IDs successfully created by
syncDevelopmentWorkflowSkills, and skip aliases whose target is absent from that
set while preserving quiet, dry-run, and written-result behavior. Update
validateGrok to treat an alias target missing from the synced canonical skills
as a validation error, including in non-strict mode, rather than only warning
about the missing source.

In @.aiox-core/infrastructure/scripts/grok-skills-sync/validate.js:
- Around line 22-30: Update the destructured import used by validate.js to
replace require('./index') with the repository’s established absolute module
path for the same index module, preserving all imported symbols and behavior.
- Around line 182-190: Update the requiredFiles list in the validation script to
include the native hook wrapper paths hooks/synapse-wrapper.cjs and
hooks/precompact-wrapper.cjs alongside their existing JSON registrations, so
validation fails when either referenced wrapper is missing.

In `@tests/claude/subagent-governance.test.js`:
- Around line 141-153: Update the tests around the blocked-command loop and
allowed DevOps command to iterate over every path in authorityHookPaths. Pass
each hook path to runAuthorityHook so the standard-payload assertions cover
Claude and Grok hooks, including global-flag, GitHub API, and environment-based
DevOps cases.

In `@tests/unit/grok/grok-skills-sync.test.js`:
- Around line 7-15: Move the repoRoot declaration before the imports in the test
setup, then replace the relative require paths for the grok-skills-sync index
and validate modules with absolute paths built via path.join(repoRoot, ...).
Preserve the existing imported symbols and module targets.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: fd4b46de-cbae-4cd0-802c-997e53f801cb

📥 Commits

Reviewing files that changed from the base of the PR and between 0b32b68 and 7c5fcad.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (85)
  • .aiox-core/data/entity-registry.yaml
  • .aiox-core/infrastructure/scripts/grok-skills-sync/README.md
  • .aiox-core/infrastructure/scripts/grok-skills-sync/index.js
  • .aiox-core/infrastructure/scripts/grok-skills-sync/validate.js
  • .aiox-core/infrastructure/scripts/ide-sync/transformers/claude-code.js
  • .aiox-core/install-manifest.yaml
  • .aiox-core/product/templates/ide-rules/grok-rules.md
  • .claude/CLAUDE.md
  • .claude/hooks/enforce-git-push-authority.cjs
  • .claude/skills/AIOX/agents/aiox-master/SKILL.md
  • .grok/README.md
  • .grok/agents/aiox-analyst.md
  • .grok/agents/aiox-architect.md
  • .grok/agents/aiox-data-engineer.md
  • .grok/agents/aiox-dev.md
  • .grok/agents/aiox-devops.md
  • .grok/agents/aiox-master.md
  • .grok/agents/aiox-pm.md
  • .grok/agents/aiox-po.md
  • .grok/agents/aiox-qa.md
  • .grok/agents/aiox-sm.md
  • .grok/agents/aiox-squad-creator.md
  • .grok/agents/aiox-ux-design-expert.md
  • .grok/agents/aiox-ux.md
  • .grok/agents/analyst.md
  • .grok/agents/architect.md
  • .grok/agents/data-engineer.md
  • .grok/agents/dev.md
  • .grok/agents/devops.md
  • .grok/agents/master.md
  • .grok/agents/pm.md
  • .grok/agents/po.md
  • .grok/agents/qa.md
  • .grok/agents/sm.md
  • .grok/agents/squad-creator.md
  • .grok/agents/ux-design-expert.md
  • .grok/config.toml
  • .grok/hooks/enforce-git-push-authority.cjs
  • .grok/hooks/git-push-authority.json
  • .grok/hooks/precompact-session-digest.cjs
  • .grok/hooks/precompact-wrapper.cjs
  • .grok/hooks/precompact.json
  • .grok/hooks/synapse-engine.cjs
  • .grok/hooks/synapse-prompt.json
  • .grok/hooks/synapse-wrapper.cjs
  • .grok/rules/aiox-core.md
  • .grok/skills/aiox-analyst/SKILL.md
  • .grok/skills/aiox-architect/SKILL.md
  • .grok/skills/aiox-data-engineer/SKILL.md
  • .grok/skills/aiox-dev/SKILL.md
  • .grok/skills/aiox-devops/SKILL.md
  • .grok/skills/aiox-handoff/SKILL.md
  • .grok/skills/aiox-master/SKILL.md
  • .grok/skills/aiox-pm/SKILL.md
  • .grok/skills/aiox-po/SKILL.md
  • .grok/skills/aiox-qa/SKILL.md
  • .grok/skills/aiox-quality-gates/SKILL.md
  • .grok/skills/aiox-sdc/SKILL.md
  • .grok/skills/aiox-sm/SKILL.md
  • .grok/skills/aiox-squad-creator/SKILL.md
  • .grok/skills/aiox-ux-design-expert/SKILL.md
  • .grok/skills/apply-qa-fixes/SKILL.md
  • .grok/skills/close-story/SKILL.md
  • .grok/skills/commit/SKILL.md
  • .grok/skills/develop-story/SKILL.md
  • .grok/skills/full-sdc/SKILL.md
  • .grok/skills/review-story/SKILL.md
  • .grok/skills/validate-story-draft/SKILL.md
  • .grok/skills/wave-execute/SKILL.md
  • AGENTS.md
  • bin/modules/env-config.js
  • package.json
  • packages/installer/src/config/ide-configs.js
  • packages/installer/src/config/templates/core-config-template.js
  • packages/installer/src/enterprise/enterprise-detector.js
  • packages/installer/src/enterprise/enterprise-upgrade-manifest.yaml
  • packages/installer/src/wizard/ide-config-generator.js
  • packages/installer/src/wizard/ide-selector.js
  • packages/installer/src/wizard/index.js
  • packages/installer/tests/unit/wizard/grok-install-surface.test.js
  • tests/claude/subagent-governance.test.js
  • tests/integration/wizard-ide-flow.test.js
  • tests/unit/config/ide-configs.test.js
  • tests/unit/grok/grok-skills-sync.test.js
  • tests/unit/wizard/ide-selector.test.js
🚧 Files skipped from review as they are similar to previous changes (68)
  • .aiox-core/infrastructure/scripts/ide-sync/transformers/claude-code.js
  • bin/modules/env-config.js
  • .grok/skills/aiox-quality-gates/SKILL.md
  • .grok/hooks/precompact.json
  • packages/installer/src/enterprise/enterprise-detector.js
  • .grok/agents/aiox-ux.md
  • tests/unit/wizard/ide-selector.test.js
  • .grok/agents/aiox-analyst.md
  • .claude/CLAUDE.md
  • .aiox-core/infrastructure/scripts/grok-skills-sync/README.md
  • .grok/agents/devops.md
  • packages/installer/src/config/templates/core-config-template.js
  • .grok/agents/aiox-architect.md
  • .grok/agents/master.md
  • .grok/hooks/synapse-prompt.json
  • .grok/agents/aiox-devops.md
  • .grok/agents/data-engineer.md
  • .grok/skills/aiox-po/SKILL.md
  • .grok/agents/dev.md
  • .grok/agents/pm.md
  • .grok/agents/analyst.md
  • .grok/hooks/git-push-authority.json
  • .grok/skills/aiox-devops/SKILL.md
  • .grok/skills/aiox-dev/SKILL.md
  • .grok/agents/qa.md
  • packages/installer/src/wizard/ide-config-generator.js
  • .grok/agents/aiox-sm.md
  • .grok/hooks/precompact-wrapper.cjs
  • .grok/skills/aiox-handoff/SKILL.md
  • .grok/agents/aiox-pm.md
  • tests/unit/config/ide-configs.test.js
  • .grok/agents/sm.md
  • .grok/config.toml
  • .grok/rules/aiox-core.md
  • .grok/agents/ux-design-expert.md
  • .grok/agents/aiox-qa.md
  • .grok/skills/aiox-architect/SKILL.md
  • .grok/skills/aiox-data-engineer/SKILL.md
  • tests/integration/wizard-ide-flow.test.js
  • .grok/agents/aiox-po.md
  • .grok/skills/aiox-squad-creator/SKILL.md
  • .grok/skills/aiox-analyst/SKILL.md
  • packages/installer/src/enterprise/enterprise-upgrade-manifest.yaml
  • .grok/skills/aiox-pm/SKILL.md
  • .grok/skills/aiox-qa/SKILL.md
  • .grok/agents/squad-creator.md
  • packages/installer/src/config/ide-configs.js
  • .grok/hooks/synapse-wrapper.cjs
  • .grok/README.md
  • .grok/agents/aiox-data-engineer.md
  • .grok/agents/aiox-squad-creator.md
  • .grok/agents/aiox-ux-design-expert.md
  • packages/installer/src/wizard/index.js
  • .aiox-core/product/templates/ide-rules/grok-rules.md
  • .aiox-core/install-manifest.yaml
  • .grok/hooks/synapse-engine.cjs
  • .grok/skills/aiox-master/SKILL.md
  • AGENTS.md
  • .grok/hooks/enforce-git-push-authority.cjs
  • .grok/agents/aiox-master.md
  • packages/installer/tests/unit/wizard/grok-install-surface.test.js
  • .grok/skills/aiox-ux-design-expert/SKILL.md
  • package.json
  • packages/installer/src/wizard/ide-selector.js
  • .grok/agents/architect.md
  • .grok/hooks/precompact-session-digest.cjs
  • .grok/agents/po.md
  • .claude/hooks/enforce-git-push-authority.cjs

Comment thread .aiox-core/infrastructure/scripts/grok-skills-sync/index.js
Comment thread .aiox-core/infrastructure/scripts/grok-skills-sync/validate.js
Comment thread .aiox-core/infrastructure/scripts/grok-skills-sync/validate.js
Comment thread tests/claude/subagent-governance.test.js Outdated
Comment thread tests/unit/grok/grok-skills-sync.test.js
@oalanicolas

Copy link
Copy Markdown
Collaborator Author

Resolution summary for CodeRabbit findings (commit 9caba7a)

Fixed in code:

  • Exit status on deny (.grok/hooks/git-push-authority.json): every deny path in enforce-git-push-authority.cjs now exits 2 with the reason on stderr (Grok Build blocks only on non-zero exit; Claude Code blocks on exit 2 as well). Governance tests + validate.js smoke tests assert the new contract.
  • Stale bridge authorization (AGENTS.md): bridge files (.aiox/active-agent, .aiox/active-agent.json, .synapse/sessions/_active-agent.json) older than 8h are now ignored by the hook; a leftover devops bridge can no longer authorize remote Git ops in a later session. Covered by a new governance test.
  • Rollback blast radius (ide-config-generator.js): the Grok branch now tracks the exact written file list from syncGrok and only registers directories that did not exist before the invocation — pre-existing .grok content survives a later IDE failure.
  • Install validation (wizard/index.js): validateGrok runs post-install (added earlier in d6244e9); with the wrapper sources now shipped in HOOKS_FREE, fresh installs validate clean. Grok-only installs copy the canonical hook sources before sync, so Article II enforcement exists without the Claude surface.
  • Entity registry dependency: resolver now maps require('./index') to the sibling file's scoped id — grok-skills-sync-validate depends on grok-skills-sync-index. Registry regenerated deterministically.
  • Empty [permission] table: removed in an earlier commit; config.toml is comment-only and points at the hook as the enforcer.
  • Migration inventory (PRO-14.5): updated to the aiox-master contract (double-prefix retired).
  • wave-execute docs (AGENTS.md): both /wave-execute and /aiox-wave-execute are listed (lines 64–65).

By design (documented, not a regression of this PR):

  • The active-agent identity (env var / command prefix / bridge files) is a cooperative governance guardrail, not a security boundary — this is now stated explicitly in the hook header. AIOX agents run in the user's own workspace with the user's credentials; a session-scoped trusted-identity broker is tracked as follow-up hardening (STORY-CORE-SU.D2). This PR narrows the practical gap with: strict devops allowlist (no wildcard suffixes), global-flag-tolerant command matching (git -C … push, gh --repo … pr create, gh api PR mutations), fail-closed parsing, exit-2 deny, and the 8h bridge TTL.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 5

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (2)
.aiox-core/infrastructure/scripts/grok-skills-sync/validate.js (1)

101-180: 🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy lift

Detect managed-content drift in strict mode.

Strict mode checks only selected markers. A modified generated agent, skill, role, persona, workflow, or alias can retain those markers and pass validation.

Regenerate the expected projection. Compare every managed artifact byte-for-byte. Compare only AIOX-managed sections for .grok/rules/aiox-core.md.

This is required by AC 4 in STORY-CORE-SU.D2-GROK-INTEGRATION-HARDENING.md.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.aiox-core/infrastructure/scripts/grok-skills-sync/validate.js around lines
101 - 180, Extend the strict validation flow in validate.js to regenerate the
expected managed projection and compare every managed agent, skill, role,
persona, workflow, and alias artifact byte-for-byte, reporting drift as
validation errors. For .grok/rules/aiox-core.md, compare only the AIOX-managed
sections rather than the entire file. Preserve the existing marker checks while
adding these complete drift checks.
tests/claude/subagent-governance.test.js (1)

2-23: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Assert both authority hook paths before the shared loop.

If a hook is missing, filter(fs.existsSync) removes it. The empty-input test can then pass without testing that hook when run in isolation.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@tests/claude/subagent-governance.test.js` around lines 2 - 23, Update the
authority hook setup in subagent governance tests to assert that both
claudeAuthorityHookPath and grokAuthorityHookPath exist before constructing
authorityHookPaths or entering the shared test loop. Do not filter missing
paths, so isolated runs fail when either required hook is absent.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.aiox-core/infrastructure/scripts/grok-skills-sync/index.js:
- Around line 1236-1239: The syncGrok flow must inspect and validate rulesPath
before writing agent, skill, alias, or hook files, or preserve and roll back all
paths recorded in written when that read fails. Update the
rulesPath/rulesManagedByWizard handling and generateGrokSkills error path so
unreadable or directory rules files cannot leave a partial .grok tree, while
retaining comprehensive error handling.
- Around line 1237-1245: Update rulesManagedByWizard to require a complete,
matching AIOX-managed marker pair rather than only AIOX-MANAGED-START, so
truncated rules files still trigger buildRulesMarkdown() regeneration. Add a
test covering a truncated marker file and verify it is regenerated.

In @.grok/hooks/enforce-git-push-authority.cjs:
- Around line 169-175: Update isBridgeFresh to calculate the file age and
require it to be between zero and BRIDGE_TTL_MS inclusive, returning false for
future-dated mtimeMs values. Add a regression test covering a future timestamp
while preserving the existing behavior for fresh, expired, and missing files.

In `@packages/installer/src/wizard/ide-config-generator.js`:
- Around line 1400-1407: Update the catch handling for syncGrok so
synchronization failures are re-thrown when Grok installation is selected,
instead of returning skipped: true. Preserve the existing sync result handling
for non-selected cases, and include the source-path failure context in the
installer error propagated to the caller.
- Around line 723-737: Update the Grok-only hook setup around
authorityHookSource and copyClaudeHooksFolder so it no longer creates, reads
from, or depends on .claude/hooks. Resolve canonical hook sources from the
framework or an existing Grok-native source, and write the generated hook
artifacts directly into .grok/hooks while preserving createdFiles and spinner
reporting.

---

Outside diff comments:
In @.aiox-core/infrastructure/scripts/grok-skills-sync/validate.js:
- Around line 101-180: Extend the strict validation flow in validate.js to
regenerate the expected managed projection and compare every managed agent,
skill, role, persona, workflow, and alias artifact byte-for-byte, reporting
drift as validation errors. For .grok/rules/aiox-core.md, compare only the
AIOX-managed sections rather than the entire file. Preserve the existing marker
checks while adding these complete drift checks.

In `@tests/claude/subagent-governance.test.js`:
- Around line 2-23: Update the authority hook setup in subagent governance tests
to assert that both claudeAuthorityHookPath and grokAuthorityHookPath exist
before constructing authorityHookPaths or entering the shared test loop. Do not
filter missing paths, so isolated runs fail when either required hook is absent.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 04259ab4-276f-444d-b621-d6ae34095c36

📥 Commits

Reviewing files that changed from the base of the PR and between 7c5fcad and 9caba7a.

📒 Files selected for processing (11)
  • .aiox-core/data/entity-registry.yaml
  • .aiox-core/development/scripts/populate-entity-registry.js
  • .aiox-core/infrastructure/scripts/grok-skills-sync/index.js
  • .aiox-core/infrastructure/scripts/grok-skills-sync/validate.js
  • .aiox-core/install-manifest.yaml
  • .claude/hooks/enforce-git-push-authority.cjs
  • .grok/hooks/enforce-git-push-authority.cjs
  • docs/framework/epics/core-super-update/STORY-CORE-SU.D2-GROK-INTEGRATION-HARDENING.md
  • docs/migration/PRO-14.5-legacy-slash-command-shim-retirement.md
  • packages/installer/src/wizard/ide-config-generator.js
  • tests/claude/subagent-governance.test.js
🚧 Files skipped from review as they are similar to previous changes (2)
  • .claude/hooks/enforce-git-push-authority.cjs
  • .aiox-core/install-manifest.yaml

Comment thread .aiox-core/infrastructure/scripts/grok-skills-sync/index.js Outdated
Comment thread .aiox-core/infrastructure/scripts/grok-skills-sync/index.js Outdated
Comment thread .grok/hooks/enforce-git-push-authority.cjs
Comment thread packages/installer/src/wizard/ide-config-generator.js Outdated
Comment thread packages/installer/src/wizard/ide-config-generator.js Outdated
rafaelscosta
rafaelscosta previously approved these changes Aug 10, 2026

@rafaelscosta rafaelscosta left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Aprovado quanto ao escopo e à direção da integração Grok. Merge condicionado à CI verde (atualizar as expectativas de artifact-copy-pipeline para os novos wrappers synapse-wrapper.cjs e precompact-wrapper.cjs) e à conclusão do CodeRabbit.

Unblocks Jest CI on PR #822 after synapse/precompact wrappers joined
HOOKS_FREE:

- HOOK_EVENT_MAP maps synapse-wrapper.cjs and precompact-wrapper.cjs to
  event: null — they ship only as vendoring sources for .grok/hooks;
  registering them in settings.local.json would double-execute SYNAPSE
  and run the precompact digest on every prompt
- createClaudeSettingsLocal skips event-less hooks instead of falling
  back to UserPromptSubmit
- artifact-copy-pipeline tier tests expect the wrappers in the copied
  set while keeping registration counts unchanged
- Canonical grok-hooks template vendored under
  .aiox-core/infrastructure/templates/ stays byte-identical with the
  .claude/.grok hook copies (parity gate)
- Registry + install-manifest regenerated

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 9

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/installer/src/wizard/ide-config-generator.js (1)

741-742: 🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy lift

Preserve the complete pre-existing .grok tree during rollback.

syncGrok overwrites existing files and removes stale files from the previous manifest. originalFiles records only IDE config paths. A later IDE failure can therefore delete or fail to restore existing .grok content. Snapshot all existing .grok files before generateGrokSkills, including root files such as README.md, config.toml, and aiox-managed.json. Restore the snapshot and remove only paths absent from it. Use a Node 18-compatible traversal because the package supports Node >=18.0.0, while Dirent.parentPath is unavailable on older Node 18.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/installer/src/wizard/ide-config-generator.js` around lines 741 -
742, Update the rollback flow around generateGrokSkills and syncGrok to snapshot
every existing file in the complete .grok tree before generation, including root
files such as README.md, config.toml, and aiox-managed.json. Use a Node
18-compatible recursive traversal that does not rely on Dirent.parentPath.
Restore the snapshot on IDE failure and remove only .grok paths absent from the
snapshot; do not limit restoration to originalFiles or IDE configuration paths.
🧹 Nitpick comments (1)
.aiox-core/infrastructure/templates/grok-hooks/precompact-session-digest.cjs (1)

77-86: 🗄️ Data Integrity & Integration | 🔵 Trivial | ⚡ Quick win

Derive provider from the Grok hook context.

Grok PreCompact payloads provide workspaceRoot, and Grok hooks receive GROK_WORKSPACE_ROOT. The wrapper passes this environment unchanged, while the digest currently always sends provider: 'claude' to extractSessionDigest. Derive the provider from these fields, extend the provider contract to include grok, and map Grok's camelCase sessionId and hookEventName; the current snake_case reads leave these values undefined.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.aiox-core/infrastructure/templates/grok-hooks/precompact-session-digest.cjs
around lines 77 - 86, Update the context construction around
extractSessionDigest to derive provider from the Grok payload/environment rather
than hardcoding claude. Extend the provider contract to accept grok, use
workspaceRoot or GROK_WORKSPACE_ROOT to identify Grok, and map Grok’s camelCase
sessionId and hookEventName fields while retaining the existing Claude mappings.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.aiox-core/infrastructure/scripts/grok-skills-sync/index.js:
- Around line 1229-1230: Update syncGrok around readManagedManifest so invalid
JSON or a foreign generator marker is caught and treated as an absent previous
manifest instead of aborting. Emit a warning containing the manifest read
failure, then continue generation while preserving the safe behavior that skips
stale-file removal when no valid manifest is available.

In @.aiox-core/infrastructure/scripts/grok-skills-sync/validate.js:
- Line 397: Update both authority-hook smoke tests’ spawnSync calls to include a
short timeout, and check and handle result.error before evaluating
result.status. Preserve the existing deny-path exit-2 and allow-path exit-0
assertions and output behavior.

In @.aiox-core/infrastructure/scripts/validate-parity.js:
- Line 12: Update the validateGrok import in validate-parity.js to use the
repository’s absolute module path instead of the relative
'./grok-skills-sync/validate' path, preserving the existing validateGrok usage.

In @.aiox-core/infrastructure/templates/grok-hooks/synapse-engine.cjs:
- Around line 17-20: Update synapse-engine’s top-level hook-runtime resolution
to probe both the project-local .aiox-core runtime and the installed
node_modules/aiox-core/.aiox-core runtime, matching the candidate order used by
precompact-session-digest.cjs. Wrap the resolution and require so missing or
invalid runtime files do not throw during module load, then guard main() with
the same silent-exit behavior required by the file header for any resolution or
execution error.

In @.github/workflows/ci.yml:
- Around line 398-399: Update the failure-report handling for the “Validate Grok
projection” workflow step to identify Grok projection validation failures and
include the corresponding synchronization or validation command, alongside the
existing IDE command-drift report. Ensure failures from npm run
validate:skills:grok clearly state the remediation command.

In @.grok/rules/aiox-core.md:
- Around line 66-74: Update the Agent shortcuts section for every listed /aiox-*
shortcut to require activation responses that confirm the selected agent,
present 3–6 primary commands including *help, and maintain that agent persona
until *exit.

In `@docs/ide-integration.md`:
- Line 35: Update the Beginner Decision Guide and Practical Consequences
sections in the IDE integration documentation to include Grok Build, matching
the existing decision and capability wording and preserving its documented
support as a working CLI.

In `@packages/installer/src/wizard/index.js`:
- Around line 737-741: Update the strict-validation error construction in the
grokValidation branch to include both validation errors and warnings, so
warning-only failures report their actual issue count and remediation details
instead of “0 issue(s).” Preserve the existing fatal behavior and message
context in the surrounding installation flow.

In `@tests/claude/subagent-governance.test.js`:
- Around line 66-71: Add a length assertion before the loop in the “keeps Claude
and Grok authority hooks equal to the canonical source” test, requiring
authorityHookPaths to contain exactly two discovered hooks before validating
their contents.

---

Outside diff comments:
In `@packages/installer/src/wizard/ide-config-generator.js`:
- Around line 741-742: Update the rollback flow around generateGrokSkills and
syncGrok to snapshot every existing file in the complete .grok tree before
generation, including root files such as README.md, config.toml, and
aiox-managed.json. Use a Node 18-compatible recursive traversal that does not
rely on Dirent.parentPath. Restore the snapshot on IDE failure and remove only
.grok paths absent from the snapshot; do not limit restoration to originalFiles
or IDE configuration paths.

---

Nitpick comments:
In
@.aiox-core/infrastructure/templates/grok-hooks/precompact-session-digest.cjs:
- Around line 77-86: Update the context construction around extractSessionDigest
to derive provider from the Grok payload/environment rather than hardcoding
claude. Extend the provider contract to accept grok, use workspaceRoot or
GROK_WORKSPACE_ROOT to identify Grok, and map Grok’s camelCase sessionId and
hookEventName fields while retaining the existing Claude mappings.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 1896e6f4-07dd-464d-be80-74a5cf2d3562

📥 Commits

Reviewing files that changed from the base of the PR and between 9caba7a and 9ae6475.

📒 Files selected for processing (27)
  • .aiox-core/data/entity-registry.yaml
  • .aiox-core/infrastructure/contracts/compatibility/aiox-4.0.4.yaml
  • .aiox-core/infrastructure/scripts/grok-skills-sync/index.js
  • .aiox-core/infrastructure/scripts/grok-skills-sync/validate.js
  • .aiox-core/infrastructure/scripts/validate-parity.js
  • .aiox-core/infrastructure/templates/grok-hooks/enforce-git-push-authority.cjs
  • .aiox-core/infrastructure/templates/grok-hooks/precompact-session-digest.cjs
  • .aiox-core/infrastructure/templates/grok-hooks/precompact-wrapper.cjs
  • .aiox-core/infrastructure/templates/grok-hooks/synapse-engine.cjs
  • .aiox-core/infrastructure/templates/grok-hooks/synapse-wrapper.cjs
  • .aiox-core/install-manifest.yaml
  • .claude/hooks/enforce-git-push-authority.cjs
  • .github/workflows/ci.yml
  • .grok/README.md
  • .grok/aiox-managed.json
  • .grok/hooks/enforce-git-push-authority.cjs
  • .grok/rules/aiox-core.md
  • docs/ide-integration.md
  • packages/installer/src/wizard/ide-config-generator.js
  • packages/installer/src/wizard/index.js
  • packages/installer/tests/unit/artifact-copy-pipeline/artifact-copy-pipeline.test.js
  • packages/installer/tests/unit/wizard/grok-install-surface.test.js
  • tests/claude/subagent-governance.test.js
  • tests/integration/wizard-ide-flow.test.js
  • tests/unit/grok/grok-skills-sync.test.js
  • tests/unit/validate-parity.test.js
  • tests/unit/wizard/ide-config-generator.test.js
🚧 Files skipped from review as they are similar to previous changes (4)
  • .grok/README.md
  • tests/integration/wizard-ide-flow.test.js
  • .grok/hooks/enforce-git-push-authority.cjs
  • .claude/hooks/enforce-git-push-authority.cjs

Comment thread .aiox-core/infrastructure/scripts/grok-skills-sync/index.js Outdated
Comment thread .aiox-core/infrastructure/scripts/grok-skills-sync/validate.js
Comment thread .aiox-core/infrastructure/scripts/validate-parity.js
Comment thread .aiox-core/infrastructure/templates/grok-hooks/synapse-engine.cjs Outdated
Comment thread .github/workflows/ci.yml
Comment thread .grok/rules/aiox-core.md
Comment thread docs/ide-integration.md
Comment thread packages/installer/src/wizard/index.js
Comment thread tests/claude/subagent-governance.test.js
Addresses remaining CI/review blockers on feat/grok-full-compatibility:

- Shared canonical hook entrypoints under templates/grok-hooks so Claude
  and Grok definitions dedupe at runtime instead of double-firing
- Safer synapse/precompact project-root resolution (cwd, templates,
  node_modules) with silent fail on missing runtime
- Bridge TTL rejects future-dated mtimes; authority hooks stay byte-equal
- Matcher Bash|run_terminal_command for dual Claude/Grok shell tools
- Recoverable managed-manifest + validate timeouts/required entrypoints
- Installer reports strict-validation warnings; CI failure text covers
  Grok projection remediation
- Jest maps shared deps to root node_modules for mock identity

Validated: unit suites (78), validate:skills:grok, validate:parity,
validate:manifest, registry-determinism, lint.
- Require .grok/skills in post-install expected skill dirs when Grok is selected
- Document /aiox-* activation response contract in Grok rules template
- Raise synapse-engine thin-wrapper line budget after layout-aware resolution
- Refresh registry + install-manifest checksums
@oalanicolas

Copy link
Copy Markdown
Collaborator Author

@coderabbitai review

All CI checks are green on 8d57c8e (45 pass / 0 fail) and every review thread has been addressed and resolved — fixes landed in 9caba7a, 9ae6475, b4de61a, and 8d57c8e; design-decision threads carry their rationale and the follow-up story reference (STORY-CORE-SU.D2). Please re-review the current head.

@coderabbitai

coderabbitai Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

@oalanicolas I will review the current head of #822, including the reported follow-up fixes.

✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/installer/src/wizard/ide-config-generator.js (1)

723-759: 🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy lift

Preserve overwritten Grok files during rollback.

syncGrok() returns every output in written, including paths that existed before this invocation. Line 741 registers those paths as created, but originalFiles only contains ide.configFile from Line 559. If Grok generation succeeds and a later IDE fails, Lines 753-759 remove existing .grok files such as managed rules, hooks, and the manifest.

Snapshot each grokResult.written path before generateGrokSkills(), then restore overwritten files during rollback. Alternatively, make syncGrok() return separate created and overwritten path sets.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/installer/src/wizard/ide-config-generator.js` around lines 723 -
759, Update the Grok generation flow around generateGrokSkills and the rollback
loop to snapshot the contents of every existing path in grokResult.written
before generation, while retaining newly created paths separately. Ensure
rollback restores overwritten pre-existing Grok files and removes only files
created by this invocation, including managed rules, hooks, and manifests; do
not rely solely on originalFiles, which currently tracks only ide.configFile.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.aiox-core/infrastructure/templates/grok-hooks/synapse-engine.cjs:
- Around line 56-82: Update the shared hook-runtime dependency resolution used
by resolveHookRuntime so session-manager.js and engine.js can be loaded from the
installed node_modules/aiox-core layout as well as the project-local layout.
Then synchronize the wrapper logic at
.aiox-core/infrastructure/templates/grok-hooks/synapse-engine.cjs:56-82,
.claude/hooks/synapse-engine.cjs:56-82, and .grok/hooks/synapse-engine.cjs:56-82
with that contract, ensuring installed-layout hooks still emit Synapse context.

In
`@docs/framework/epics/core-super-update/STORY-CORE-SU.D2-GROK-INTEGRATION-HARDENING.md`:
- Around line 62-72: Update the QA result near the “Gate atual” status to
reflect the completion record that all AC9 gates passed. Replace the stale FAIL
status with the current passing validation state, keeping the completion notes
and other QA details consistent.
- Around line 74-113: Update the “File List” section of
STORY-CORE-SU.D2-GROK-INTEGRATION-HARDENING.md to include every modified path,
specifically tests/synapse/hook-entry.test.js and all generated .grok/agents and
.grok/skills artifacts, while preserving the existing entries and keeping the
list complete.

In `@packages/installer/tests/unit/wizard/grok-install-surface.test.js`:
- Around line 141-189: Add a 60-second Jest timeout to both new tests around the
generateIDEConfigs calls: “preserves brownfield Grok rules through installer and
sync” and “fails a Grok install when canonical hook sources are absent.” Match
the neighboring installer test’s timeout configuration without changing test
behavior.

---

Outside diff comments:
In `@packages/installer/src/wizard/ide-config-generator.js`:
- Around line 723-759: Update the Grok generation flow around generateGrokSkills
and the rollback loop to snapshot the contents of every existing path in
grokResult.written before generation, while retaining newly created paths
separately. Ensure rollback restores overwritten pre-existing Grok files and
removes only files created by this invocation, including managed rules, hooks,
and manifests; do not rely solely on originalFiles, which currently tracks only
ide.configFile.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 5fd9f372-1d25-4d2d-b645-fcb35a1da36b

📥 Commits

Reviewing files that changed from the base of the PR and between 9caba7a and 8d57c8e.

📒 Files selected for processing (40)
  • .aiox-core/data/entity-registry.yaml
  • .aiox-core/infrastructure/contracts/compatibility/aiox-4.0.4.yaml
  • .aiox-core/infrastructure/scripts/grok-skills-sync/index.js
  • .aiox-core/infrastructure/scripts/grok-skills-sync/validate.js
  • .aiox-core/infrastructure/scripts/validate-parity.js
  • .aiox-core/infrastructure/templates/grok-hooks/enforce-git-push-authority.cjs
  • .aiox-core/infrastructure/templates/grok-hooks/precompact-session-digest.cjs
  • .aiox-core/infrastructure/templates/grok-hooks/precompact-wrapper.cjs
  • .aiox-core/infrastructure/templates/grok-hooks/synapse-engine.cjs
  • .aiox-core/infrastructure/templates/grok-hooks/synapse-wrapper.cjs
  • .aiox-core/install-manifest.yaml
  • .aiox-core/product/templates/ide-rules/grok-rules.md
  • .claude/hooks/enforce-git-push-authority.cjs
  • .claude/hooks/precompact-session-digest.cjs
  • .claude/hooks/synapse-engine.cjs
  • .claude/settings.json
  • .github/workflows/ci.yml
  • .grok/README.md
  • .grok/aiox-managed.json
  • .grok/config.toml
  • .grok/hooks/enforce-git-push-authority.cjs
  • .grok/hooks/git-push-authority.json
  • .grok/hooks/precompact-session-digest.cjs
  • .grok/hooks/precompact.json
  • .grok/hooks/synapse-engine.cjs
  • .grok/hooks/synapse-prompt.json
  • .grok/rules/aiox-core.md
  • docs/framework/epics/core-super-update/STORY-CORE-SU.D2-GROK-INTEGRATION-HARDENING.md
  • docs/ide-integration.md
  • jest.config.js
  • packages/installer/src/wizard/ide-config-generator.js
  • packages/installer/src/wizard/index.js
  • packages/installer/tests/unit/artifact-copy-pipeline/artifact-copy-pipeline.test.js
  • packages/installer/tests/unit/wizard/grok-install-surface.test.js
  • tests/claude/subagent-governance.test.js
  • tests/integration/wizard-ide-flow.test.js
  • tests/synapse/hook-entry.test.js
  • tests/unit/grok/grok-skills-sync.test.js
  • tests/unit/validate-parity.test.js
  • tests/unit/wizard/ide-config-generator.test.js
🚧 Files skipped from review as they are similar to previous changes (22)
  • .grok/hooks/precompact.json
  • .aiox-core/infrastructure/scripts/validate-parity.js
  • .grok/config.toml
  • .aiox-core/infrastructure/templates/grok-hooks/precompact-wrapper.cjs
  • .grok/hooks/synapse-prompt.json
  • .grok/hooks/git-push-authority.json
  • .aiox-core/infrastructure/contracts/compatibility/aiox-4.0.4.yaml
  • .github/workflows/ci.yml
  • tests/unit/validate-parity.test.js
  • .aiox-core/product/templates/ide-rules/grok-rules.md
  • .grok/aiox-managed.json
  • .grok/hooks/precompact-session-digest.cjs
  • docs/ide-integration.md
  • packages/installer/src/wizard/index.js
  • .aiox-core/install-manifest.yaml
  • .aiox-core/infrastructure/templates/grok-hooks/synapse-wrapper.cjs
  • tests/integration/wizard-ide-flow.test.js
  • .grok/rules/aiox-core.md
  • .aiox-core/infrastructure/templates/grok-hooks/enforce-git-push-authority.cjs
  • .grok/README.md
  • .claude/hooks/enforce-git-push-authority.cjs
  • .grok/hooks/enforce-git-push-authority.cjs

Comment thread .aiox-core/infrastructure/templates/grok-hooks/synapse-engine.cjs
Comment thread packages/installer/tests/unit/wizard/grok-install-surface.test.js Outdated
- hook-runtime.js resolves session-manager/engine from the project
  .aiox-core first and falls back to its own distribution siblings, so
  node_modules-only installations get Synapse context instead of a
  silent no-op (synapse-engine wrappers unchanged, same contract)
- 60s timeouts on the two new async Grok installer tests (parity with
  the neighboring generateIDEConfigs test)
- STORY-CORE-SU.D2: QA gate aligned to PASS with the completion record;
  File List completed (hook-entry test, grok-hooks template, regenerated
  .grok surface, registry, manifest)
- Registry + install-manifest regenerated

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@github-actions github-actions Bot added the area: core Core framework (.aios-core/core/) label Aug 10, 2026
@oalanicolas

Copy link
Copy Markdown
Collaborator Author

@coderabbitai approve

All review threads are resolved, every finding was either fixed (rounds in 9caba7a, 9ae6475, b4de61a, 8d57c8e, 3c646fe) or documented as a design decision with a tracked follow-up (STORY-CORE-SU.D2), and CI is fully green on the current head (45 pass / 0 fail).

@coderabbitai

coderabbitai Bot commented Aug 10, 2026

Copy link
Copy Markdown

@oalanicolas Approved. The reported review fixes are resolved, and the remaining identity-model item has a documented follow-up in STORY-CORE-SU.D2.

✅ Action performed

Comments resolved and changes approved.

@rafaelscosta rafaelscosta left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reaprovado no commit 3c646fe após CI completa verde e CodeRabbit aprovado.

@rafaelscosta
rafaelscosta merged commit e8ba5e6 into main Aug 10, 2026
50 checks passed
@rafaelscosta
rafaelscosta deleted the feat/grok-full-compatibility branch August 10, 2026 23:55
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 5.4.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

This branch was successfully deployed

1 active deployment
Preview — 3c646fef Deployed Aug 10, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: core Core framework (.aios-core/core/) area: devops CI/CD, GitHub Actions (.github/) area: docs Documentation (docs/) area: installer Installer and setup (packages/installer/) area: synapse SYNAPSE context engine released type: test Test coverage and quality

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants