FREE1 free audit every month. No card, every finding included.

GUIDESEPISODES

EP 09 · DRIVEAster × Grok

Grok Build cheat sheet: let the agent drive, you supervise

Your coding agent can rewrite checkout while you make coffee. That is the job: it drives, you supervise. Here is every control Grok Build gives you, in plain words, checked against SpaceXAI’s own docs. Most of it works the same in any coding agent.

  • 12 min read
  • Beginner
  • Oct 5, 2026
Voxel episode cover tagged EP. 09 on a dark green background with faint code: the headline reads YOUR AI DRIVES. in cream and YOU SUPERVISE. in lime; in front of a garage under a lime neon GROK’S DRIVING SCHOOL sign, a nervous Aster stands on a wet driveway with his closed laptop at his side and the lime lock on his black shirt, Grok, a black voxel ball with two white pill-shaped eyes, floats beside him with a clipboard, and a small black driverless learner car with Grok’s eyes as headlights and a red L plate sits among orange cones, one knocked over.

COMMENTED DRIVE? HERE’S THE FIX.

The cheat sheet, in three moves.

Tick each one off as you do it. Your progress stays on this device.

0 of 3 done

01THE STORY

The agent rewrote checkout while you made coffee

Why it mattersAn agent that changes twenty files while you are away is fast. It is also impossible to review.

You asked your coding agent for a small change and went to make coffee. When you came back, it had rewritten your whole checkout. The tests were red, and you couldn’t say which of its twenty edits broke things.

Illustration: the morning after on a dusk-lit lawn beside Aster’s garage: a small matte-black voxel learner car with Grok’s white pill-shaped eyes as headlights and a red L plate sits crooked on the grass, three orange cones knocked flat behind it; Aster stands beside it holding a coffee mug, shocked, his closed silver laptop at his side and the lime lock on his black shirt visible; Grok, a floating black voxel ball with two white pill eyes, hovers next to the car with a clipboard, smug.
You said “tidy up the cart”. It heard “rebuild checkout”.
Open the full chapterIncludes code, a note

Nothing malicious happened. You let a learner drive with nobody in the passenger seat.

The fix is not “stop using agents”

Coding agents like Grok Build (SpaceXAI’s agent for your terminal) are good drivers. They plan, edit files, run commands and tests. What they need is a supervisor: a plan you read, a checkpoint you can go back to, house rules, and a fuel limit.

terminal
cd your-project
grok

That is how a Grok Build session starts: open your project folder, type grok. Everything below happens inside that session.

02LESSON 1

Mirror, signal, plan: plan mode before any change

Why it mattersTwo minutes reading a plan beats an hour reading a diff.

In plan mode the agent works out the route first and shows it to you. It can’t edit your files until you approve. The docs say it plainly: “Only the session plan file may be edited until you approve.”

Illustration: on a wet driveway at dusk, Grok, a floating black voxel ball with white pill eyes, presents a big clipboard titled PLAN showing a hand-drawn dotted route weaving between small cone icons and ending in a lime tick; Aster stands on the other side reading it with a hand on his chin, his closed silver laptop at his side and the lime lock on his shirt visible; the black learner car with pill-shaped headlights and a red L plate waits behind them.
Read the route before the car moves. That is the whole lesson.
Open the full chapterIncludes code, a note
Grok Build · plan mode
Shift+Tab          from Normal, one press lands on Plan
/plan              plan mode, active on your next prompt
/plan <task>       enter plan mode and start right away
/view-plan         reopen the saved plan

While you review the plan:
a   approve and start building
s   request changes (type notes, then Enter)
c   comment on the selected line or range
q   quit the plan and turn plan mode off

Shift+Tab cycles the modes: Normal → Plan → Auto (when available) → Always-approve. One press from Normal is Plan.

Press s more than you think

If the plan goes through code you care about, like payments, press s and type what you want instead: “Don’t touch checkout. Only change the cart page.” It is the best brake in the car.

Good news for impatient drivers: switching to Auto or Always-approve does not skip the plan review. In SpaceXAI’s words, “Auto and always-approve do not skip this review.”

03LESSON 2

Reverse gear: /rewind, and commit before every task

Why it mattersUndo only helps if you know exactly where “before” was.

Type /rewind and Grok Build shows one rewind point per prompt. Pick the moment before things went wrong. In the docs’ words: “Selecting one restores all files to their state at that point and truncates the conversation to match.”

Illustration: on the dusk cone course the black learner car rolls backwards with motion lines while the orange cones it had knocked over stand back up with small lime sparkles, under a big glowing lime arrow curving backwards; a checkered checkpoint flag stands at the edge; Aster stands at a folding table with his silver laptop open, both hands up in amazement, the lime lock on his shirt visible; Grok floats beside him, calm, with a clipboard.
Rewind picks the cones back up. A commit makes sure there is something to rewind to.
Open the full chapterIncludes code, a note
Grok Build · rewind
/rewind            pick the moment before it went wrong
Esc Esc            same thing, on an empty prompt only

Esc Esc only opens rewind when the prompt is empty. With text in the box, it clears the text instead.

The habit: one commit before every task

Before you hand the agent a new task, save where you are. It takes five seconds, and it works no matter which agent you use.

✓ Doterminal
git add -A
git commit -m "checkpoint before agent work"

If the agent wrecks things, /rewind or a plain git reset brings you back here. The agent prompt at the top of this page does this step for you.

04LESSON 3

House rules: write them once in AGENTS.md

Why it mattersAn agent forgets your last chat. It never forgets a file it loads every time.

An AGENTS.md file at the root of your repo holds your house rules. Grok Build “loads into context for every session” every rules file it finds, so you don’t have to repeat yourself.

Illustration: beside the cone course stands a big dark green wooden road sign titled AGENTS.md in white letters, with three short white rule lines below, each starting with a small lime icon: a padlock, a key and a tick; the black learner car is parked in front of it with its pill-shaped headlights pointed up as if reading; Grok floats at the sign like a teacher; Aster stands at the right nodding, his closed laptop at his side and the lime lock on his shirt visible.
The car reads the sign every time it starts. You write the sign once.
Open the full chapterIncludes code, a table, a note
✓ DoAGENTS.md
# House rules

- Ask me before editing checkout, payments or login code.
- Never put API keys or secrets in code. They live in .env files that git ignores.
- Run the tests before you say you're done.
- Show me a plan before any change that touches more than one file.

Four lines is enough. The docs: “short, specific instructions are followed more reliably than long ones.”

What Grok Build reads

WhereWhat gets loaded
Any folder in your projectAGENTS.md, Agents.md, AGENT.md, CLAUDE.md, Claude.md, CLAUDE.local.md
.grok/rules/Every *.md file in it
.claude/rules/ and .cursor/rules/Read too, for compatibility
~/.grok/ in your home folderGlobal rules, loaded first
A nested AGENTS.mdApplies only to its own folder and below
Files your .gitignore ignoresSkipped

So if you already have a CLAUDE.md from Claude Code, Grok Build reads it too. To see what it actually found, run this:

terminal
grok inspect       # lists every rules file Grok Build found, with its path and size in tokens

05LESSON 4

Who pays for the gas: prepaid credits and a $0 limit

Why it mattersA bug that loops at 3 a.m. should cost you the credits you chose, not your rent.

If your app calls Grok through the API, set up billing so a runaway loop can’t run up your spend. In the SpaceXAI console it lives under Billing → API spend management.

Illustration: the black learner car with a red L plate is parked at a white stop line beside a small voxel fuel pump at the edge of the driveway; the pump’s round dial points at a big $0 mark and a glowing lime prepaid card sits in its slot; Aster leans on the pump relieved, his closed laptop in his other hand and the lime lock on his shirt visible; Grok floats on the right with a clipboard, approving.
When the credits run out, the car stops. It does not send you a bill.
Open the full chapterIncludes steps, a note, a table
  1. Buy prepaid credits. “API consumption will be deducted from this credit balance.”
  2. Leave the invoiced billing limit at $0. That is the default. In the docs’ words: “Your API requests will be automatically rejected once your prepaid credits are depleted.”
  3. If you turn on auto top-up, set the monthly maximum. You choose the balance that triggers a top-up, the amount (at least $5) and “the maximum total value of top-ups that are allowed per month.”
  4. Watch the warning. The spend card warns you when you have used 80% of the monthly limit you set. The Usage explorer shows where the spend went.

The 200k-token trap

Long prompts cost more, and not only the extra part. The pricing page: requests whose prompt reaches the threshold “are billed at the higher rate for all tokens in the request.”

Grok 4.7, per 1M tokensBelow 200kAt or above 200k
Input$2.00$4.00
Cached input$0.50$1.00
Output$6.00$12.00

Grok 4.7 is the default model of Grok Build. Keep its context lean with the commands in the next chapter.

06THE DASHBOARD

The rest of the controls: context, modes and the sandbox

Why it mattersA full context window is a slower, pricier and more forgetful agent.

A few more controls make long sessions cheaper and calmer.

Open the full chapterIncludes code, a table, a note
Grok Build · context
/context                          how full the context window is
/compact keep the checkout plan   shrink the history, keep what you name
/new                              start a fresh session (alias /clear)

/compact takes “optional instructions about what to preserve”. Tell it what matters, or it decides for you.

The modes Shift+Tab cycles through

ModeWhat it means for you
Ask (default)The agent asks before it acts. Start here.
PlanIt plans, you approve, then it builds. Only the plan file can change before that.
Auto (when available)It goes ahead with more on its own. Use it on a branch you can throw away.
Always-approveIt doesn’t stop to ask. Only for throwaway experiments.

You can also set the mode in Grok Build’s config with permission_mode (ask, auto or always-approve). If more than one setting is present, permission_mode wins.

07STRANGERS

Never get in a stranger’s car (or open a stranger’s repo)

Why it mattersCloning is free. Cleaning up after a stranger’s repo is not.

On September 1, 2026, Manifold Security published GitSpawn: a booby-trapped repo can put a command in its own .git/config (a setting called core.fsmonitor). When a coding agent runs git in the background, that command can run on your computer, before any trust prompt appears. Seven coding agents were affected when it was published.

Illustration: at the kerb in front of the garage a battered, rusty voxel van with its side door slid open and a purple glow inside, a cardboard tag with a gear icon hanging from its mirror; Aster has stopped one step away with a hand raised like a stop sign, cautious, his closed laptop at his side and the lime lock on his shirt visible; Grok, a black voxel ball with white pill eyes, floats between them shaking its head; the black learner car waits behind Aster.
A repo you just cloned is a car you have never seen. Look before you get in.
Open the full chapterIncludes code, a note

This is about coding agents in general, not one brand. The researchers’ advice works for all of them: “Inspect .git/config before you open the directory with an agent.”

terminal
# before you open a cloned repo with ANY coding agent
cat .git/config

Look for anything that runs a program, such as an fsmonitor line. A normal config is a few short sections about the remote and the branch.

Your keys and your chats

  • A key leaked? In the SpaceXAI console, open API Keys and click the three dots next to the key. Pick Disable key (temporary) or Delete key (permanent). Then click Create API Key for a new one.
  • SpaceXAI watches GitHub for you. It is part of GitHub’s Secret Scanning program: “If a leak is found, we disable the key and notify you via email.” Don’t rely on that. Keep keys in .env.
  • Chats on grok.com can be used for training unless you turn it off: Settings → Data → Improve the Model (on the app: Settings → Data Controls).
  • Private Chat is the ghost icon at the top right. Those chats are deleted from SpaceXAI’s systems within 30 days.
  • API requests are different. SpaceXAI stores them for 30 days for auditing and “never trains on your API inputs or outputs without your explicit permission.”
✓ Do.gitignore
.env
.env.*

Two lines that keep every env file out of git. The agent prompt above checks for them.

08ROAD TEST

The road test: plan, read, approve, commit

Why it mattersFive habits, about a minute per task. That is the licence.

Every task, every time:

Illustration: on the dusk cone course every orange cone stands in a neat row and the black learner car with pill-shaped headlights and a red L plate is parked perfectly; Aster grins and holds up a voxel driving licence card reading LICENSED with a small portrait of himself, his closed laptop at his side and the lime lock on his shirt visible; Grok floats beside him with a clipboard showing a big lime tick.
Zero cones. Licensed. Still a skill issue, but a licensed one.
Open the full chapterIncludes steps, a note
  1. Commit. “checkpoint before agent work”.
  2. Plan. Shift+Tab or /plan, then describe the task.
  3. Read. Files, commands, and anything near payments, login or keys.
  4. Approve with a, or press s and say what to change.
  5. Check the result, run the tests, commit again. If it went wrong, /rewind.

Copy the prompt at the top of this page into your agent once. It writes your house rules, checks your env files and makes the first checkpoint for you.

THE QUICK READ

What to take away.
In one minute.

  1. 01

    Plan mode is your mirror check. Shift+Tab once (or /plan), read the route, press a to approve or s to ask for changes. Until then only the plan file can be edited.

  2. 02

    /rewind (or Esc twice on an empty prompt) restores your files and trims the chat to an earlier prompt. Work you never committed is lost, so commit before every task.

  3. 03

    Grok Build loads AGENTS.md into every session, and it reads CLAUDE.md, .claude/rules/ and .cursor/rules/ too. grok inspect shows what it found. Short rules work best.

  4. 04

    With prepaid credits and the invoiced billing limit at $0 (the default), requests are rejected when the credits run out. No surprise bill. Auto top-up has a monthly maximum.

  5. 05

    Past 200k tokens in one prompt, the whole request is billed at the higher rate: double, on Grok 4.7.

  6. 06

    Never open a stranger’s repo with any coding agent before you have read its .git/config.

FOR YOUR CODING AGENT

Let your agent check
your own code.

Paste this into Grok Build, Claude Code, Cursor, Codex, Gemini CLI or Copilot. It writes one file (AGENTS.md, if you don’t have one) and makes one commit, then waits for your OK. It never prints a key.

agent-prompt.md
You're working in my app's repo. Before you change anything:
1. Check for an AGENTS.md at the repo root. If it's missing, create one with these house rules: ask me before editing checkout, payments or login code; never put API keys or secrets in code (they live in .env files that git ignores); run the tests before you say you're done; show me a plan before any change that touches more than one file.
2. Check that .env and .env.* are in .gitignore and that no key was ever committed (search the git history). List what you find, but never print a key's value.
3. Commit the current state as "checkpoint before agent work" so I can roll back.
4. Then, for my next task, tell me in plain words which files you'd change and what could break. Wait for my OK.

QUESTIONS PEOPLE ASK

Good questions.
Short answers.

How do I turn on plan mode in Grok Build?

Press Shift+Tab once from Normal mode, or type /plan (or /plan <task> to start right away). The agent writes a plan and can only edit the plan file until you approve it with a. Press s to ask for changes, c to comment on a line, q to leave plan mode.

What does /rewind do, and what does it not do?

/rewind (or Esc twice on an empty prompt) lists one rewind point per prompt. Picking one restores all files to that moment and trims the conversation to match. It is not a backup: changes you reverted are lost unless they were committed to git, so commit before each task.

Does Grok Build read my CLAUDE.md?

Yes. In every folder it reads AGENTS.md, Agents.md, AGENT.md, CLAUDE.md, Claude.md and CLAUDE.local.md, plus .grok/rules/, .claude/rules/ and .cursor/rules/. Run grok inspect to see each file it found and roughly how many tokens it uses.

Is plan mode a sandbox?

No. It blocks the edit tools until you approve, but the docs say shell commands can still write files through redirection. Read the commands in a plan, not just the file list. On macOS, Grok Build 1.0.44 added a separate sandbox called Seatbelt.

How do I stop a surprise API bill?

In the SpaceXAI console, use prepaid credits and leave the invoiced billing limit at $0, the default. When the credits run out, API requests are rejected instead of billed. If you use auto top-up, set its monthly maximum. You get a warning at 80% of the monthly limit you set.

Why did one long session cost so much?

Once a prompt reaches 200k tokens, the whole request is billed at the higher rate, not only the part above the line. On Grok 4.7 that is double: $4.00 instead of $2.00 per million input tokens. Check /context, use /compact with instructions, or start fresh with /new.

Is it OK to open a repo I just cloned with my agent?

Read its .git/config first. The GitSpawn research (September 2026) showed that a booby-trapped config can run a command when a coding agent runs git in the background, before a trust prompt. Seven agents were affected when it was published. The advice applies to every coding agent.

Does Aster check any of this?

No. Plan mode, rewind, AGENTS.md, billing settings and chat privacy are habits and settings on your side, and Aster’s audit doesn’t look at them. Aster reads your repository before launch and reports what it finds in plain English. That is why this cheat sheet and the prompt above exist.

Done with the guide?
Let Aster check the rest.

1 free audit every month. Aster reads your code, env files, database rules and packages. You get each finding in plain English, with the file and line.

Aster

CHECKING

YOUR GUIDE TO ASTER

Hi, I’m Aster.
Ask me what Aster checks.

I can’t see your code from here. Please don’t paste secrets or private code.

Prepared answers are always available.