GUIDESEPISODES
Grok Build cheat sheet: let the agent drive, you supervise
Your coding agent can rewrite checkout while you make coffee. That is the job: it drives, you supervise. Here is every control Grok Build gives you, in plain words, checked against SpaceXAI’s own docs. Most of it works the same in any coding agent.

COMMENTED DRIVE? HERE’S THE FIX.
The cheat sheet, in three moves.
Tick each one off as you do it. Your progress stays on this device.
0 of 3 done
A free audit can take a second look at the rest of your code.
01THE STORY
The agent rewrote checkout while you made coffee
Why it mattersAn agent that changes twenty files while you are away is fast. It is also impossible to review.
You asked your coding agent for a small change and went to make coffee. When you came back, it had rewritten your whole checkout. The tests were red, and you couldn’t say which of its twenty edits broke things.

Open the full chapterIncludes code, a note
Nothing malicious happened. You let a learner drive with nobody in the passenger seat.
The fix is not “stop using agents”
Coding agents like Grok Build (SpaceXAI’s agent for your terminal) are good drivers. They plan, edit files, run commands and tests. What they need is a supervisor: a plan you read, a checkpoint you can go back to, house rules, and a fuel limit.
cd your-project
grokThat is how a Grok Build session starts: open your project folder, type grok. Everything below happens inside that session.
02LESSON 1
Mirror, signal, plan: plan mode before any change
Why it mattersTwo minutes reading a plan beats an hour reading a diff.
In plan mode the agent works out the route first and shows it to you. It can’t edit your files until you approve. The docs say it plainly: “Only the session plan file may be edited until you approve.”

Open the full chapterIncludes code, a note
Shift+Tab from Normal, one press lands on Plan
/plan plan mode, active on your next prompt
/plan <task> enter plan mode and start right away
/view-plan reopen the saved plan
While you review the plan:
a approve and start building
s request changes (type notes, then Enter)
c comment on the selected line or range
q quit the plan and turn plan mode offShift+Tab cycles the modes: Normal → Plan → Auto (when available) → Always-approve. One press from Normal is Plan.
Press s more than you think
If the plan goes through code you care about, like payments, press s and type what you want instead: “Don’t touch checkout. Only change the cart page.” It is the best brake in the car.
Good news for impatient drivers: switching to Auto or Always-approve does not skip the plan review. In SpaceXAI’s words, “Auto and always-approve do not skip this review.”
03LESSON 2
Reverse gear: /rewind, and commit before every task
Why it mattersUndo only helps if you know exactly where “before” was.
Type /rewind and Grok Build shows one rewind point per prompt. Pick the moment before things went wrong. In the docs’ words: “Selecting one restores all files to their state at that point and truncates the conversation to match.”

Open the full chapterIncludes code, a note
/rewind pick the moment before it went wrong
Esc Esc same thing, on an empty prompt onlyEsc Esc only opens rewind when the prompt is empty. With text in the box, it clears the text instead.
The habit: one commit before every task
Before you hand the agent a new task, save where you are. It takes five seconds, and it works no matter which agent you use.
git add -A
git commit -m "checkpoint before agent work"If the agent wrecks things, /rewind or a plain git reset brings you back here. The agent prompt at the top of this page does this step for you.
04LESSON 3
House rules: write them once in AGENTS.md
Why it mattersAn agent forgets your last chat. It never forgets a file it loads every time.
An AGENTS.md file at the root of your repo holds your house rules. Grok Build “loads into context for every session” every rules file it finds, so you don’t have to repeat yourself.

Open the full chapterIncludes code, a table, a note
# House rules
- Ask me before editing checkout, payments or login code.
- Never put API keys or secrets in code. They live in .env files that git ignores.
- Run the tests before you say you're done.
- Show me a plan before any change that touches more than one file.Four lines is enough. The docs: “short, specific instructions are followed more reliably than long ones.”
What Grok Build reads
| Where | What gets loaded |
|---|---|
| Any folder in your project | AGENTS.md, Agents.md, AGENT.md, CLAUDE.md, Claude.md, CLAUDE.local.md |
.grok/rules/ | Every *.md file in it |
.claude/rules/ and .cursor/rules/ | Read too, for compatibility |
~/.grok/ in your home folder | Global rules, loaded first |
A nested AGENTS.md | Applies only to its own folder and below |
Files your .gitignore ignores | Skipped |
So if you already have a CLAUDE.md from Claude Code, Grok Build reads it too. To see what it actually found, run this:
grok inspect # lists every rules file Grok Build found, with its path and size in tokens05LESSON 4
Who pays for the gas: prepaid credits and a $0 limit
Why it mattersA bug that loops at 3 a.m. should cost you the credits you chose, not your rent.
If your app calls Grok through the API, set up billing so a runaway loop can’t run up your spend. In the SpaceXAI console it lives under Billing → API spend management.

Open the full chapterIncludes steps, a note, a table
- Buy prepaid credits. “API consumption will be deducted from this credit balance.”
- Leave the invoiced billing limit at $0. That is the default. In the docs’ words: “Your API requests will be automatically rejected once your prepaid credits are depleted.”
- If you turn on auto top-up, set the monthly maximum. You choose the balance that triggers a top-up, the amount (at least $5) and “the maximum total value of top-ups that are allowed per month.”
- Watch the warning. The spend card warns you when you have used 80% of the monthly limit you set. The Usage explorer shows where the spend went.
The 200k-token trap
Long prompts cost more, and not only the extra part. The pricing page: requests whose prompt reaches the threshold “are billed at the higher rate for all tokens in the request.”
| Grok 4.7, per 1M tokens | Below 200k | At or above 200k |
|---|---|---|
| Input | $2.00 | $4.00 |
| Cached input | $0.50 | $1.00 |
| Output | $6.00 | $12.00 |
Grok 4.7 is the default model of Grok Build. Keep its context lean with the commands in the next chapter.
06THE DASHBOARD
The rest of the controls: context, modes and the sandbox
Why it mattersA full context window is a slower, pricier and more forgetful agent.
A few more controls make long sessions cheaper and calmer.
Open the full chapterIncludes code, a table, a note
/context how full the context window is
/compact keep the checkout plan shrink the history, keep what you name
/new start a fresh session (alias /clear)/compact takes “optional instructions about what to preserve”. Tell it what matters, or it decides for you.
The modes Shift+Tab cycles through
| Mode | What it means for you |
|---|---|
| Ask (default) | The agent asks before it acts. Start here. |
| Plan | It plans, you approve, then it builds. Only the plan file can change before that. |
| Auto (when available) | It goes ahead with more on its own. Use it on a branch you can throw away. |
| Always-approve | It doesn’t stop to ask. Only for throwaway experiments. |
You can also set the mode in Grok Build’s config with permission_mode (ask, auto or always-approve). If more than one setting is present, permission_mode wins.
07STRANGERS
Never get in a stranger’s car (or open a stranger’s repo)
Why it mattersCloning is free. Cleaning up after a stranger’s repo is not.
On September 1, 2026, Manifold Security published GitSpawn: a booby-trapped repo can put a command in its own .git/config (a setting called core.fsmonitor). When a coding agent runs git in the background, that command can run on your computer, before any trust prompt appears. Seven coding agents were affected when it was published.

Open the full chapterIncludes code, a note
This is about coding agents in general, not one brand. The researchers’ advice works for all of them: “Inspect .git/config before you open the directory with an agent.”
# before you open a cloned repo with ANY coding agent
cat .git/configLook for anything that runs a program, such as an fsmonitor line. A normal config is a few short sections about the remote and the branch.
Your keys and your chats
- A key leaked? In the SpaceXAI console, open API Keys and click the three dots next to the key. Pick Disable key (temporary) or Delete key (permanent). Then click Create API Key for a new one.
- SpaceXAI watches GitHub for you. It is part of GitHub’s Secret Scanning program: “If a leak is found, we disable the key and notify you via email.” Don’t rely on that. Keep keys in
.env. - Chats on grok.com can be used for training unless you turn it off: Settings → Data → Improve the Model (on the app: Settings → Data Controls).
- Private Chat is the ghost icon at the top right. Those chats are deleted from SpaceXAI’s systems within 30 days.
- API requests are different. SpaceXAI stores them for 30 days for auditing and “never trains on your API inputs or outputs without your explicit permission.”
.env
.env.*Two lines that keep every env file out of git. The agent prompt above checks for them.
08ROAD TEST
The road test: plan, read, approve, commit
Why it mattersFive habits, about a minute per task. That is the licence.
Every task, every time:

Open the full chapterIncludes steps, a note
- Commit. “checkpoint before agent work”.
- Plan. Shift+Tab or
/plan, then describe the task. - Read. Files, commands, and anything near payments, login or keys.
- Approve with
a, or presssand say what to change. - Check the result, run the tests, commit again. If it went wrong,
/rewind.
Copy the prompt at the top of this page into your agent once. It writes your house rules, checks your env files and makes the first checkpoint for you.
THE QUICK READ
What to take away.
In one minute.
- 01
Plan mode is your mirror check. Shift+Tab once (or
/plan), read the route, pressato approve orsto ask for changes. Until then only the plan file can be edited. - 02
/rewind(or Esc twice on an empty prompt) restores your files and trims the chat to an earlier prompt. Work you never committed is lost, so commit before every task. - 03
Grok Build loads
AGENTS.mdinto every session, and it readsCLAUDE.md,.claude/rules/and.cursor/rules/too.grok inspectshows what it found. Short rules work best. - 04
With prepaid credits and the invoiced billing limit at $0 (the default), requests are rejected when the credits run out. No surprise bill. Auto top-up has a monthly maximum.
- 05
Past 200k tokens in one prompt, the whole request is billed at the higher rate: double, on Grok 4.7.
- 06
Never open a stranger’s repo with any coding agent before you have read its
.git/config.
FOR YOUR CODING AGENT
Let your agent check
your own code.
Paste this into Grok Build, Claude Code, Cursor, Codex, Gemini CLI or Copilot. It writes one file (AGENTS.md, if you don’t have one) and makes one commit, then waits for your OK. It never prints a key.
You're working in my app's repo. Before you change anything: 1. Check for an AGENTS.md at the repo root. If it's missing, create one with these house rules: ask me before editing checkout, payments or login code; never put API keys or secrets in code (they live in .env files that git ignores); run the tests before you say you're done; show me a plan before any change that touches more than one file. 2. Check that .env and .env.* are in .gitignore and that no key was ever committed (search the git history). List what you find, but never print a key's value. 3. Commit the current state as "checkpoint before agent work" so I can roll back. 4. Then, for my next task, tell me in plain words which files you'd change and what could break. Wait for my OK.
QUESTIONS PEOPLE ASK
Good questions.
Short answers.
How do I turn on plan mode in Grok Build?
Press Shift+Tab once from Normal mode, or type /plan (or /plan <task> to start right away). The agent writes a plan and can only edit the plan file until you approve it with a. Press s to ask for changes, c to comment on a line, q to leave plan mode.
What does /rewind do, and what does it not do?
/rewind (or Esc twice on an empty prompt) lists one rewind point per prompt. Picking one restores all files to that moment and trims the conversation to match. It is not a backup: changes you reverted are lost unless they were committed to git, so commit before each task.
Does Grok Build read my CLAUDE.md?
Yes. In every folder it reads AGENTS.md, Agents.md, AGENT.md, CLAUDE.md, Claude.md and CLAUDE.local.md, plus .grok/rules/, .claude/rules/ and .cursor/rules/. Run grok inspect to see each file it found and roughly how many tokens it uses.
Is plan mode a sandbox?
No. It blocks the edit tools until you approve, but the docs say shell commands can still write files through redirection. Read the commands in a plan, not just the file list. On macOS, Grok Build 1.0.44 added a separate sandbox called Seatbelt.
How do I stop a surprise API bill?
In the SpaceXAI console, use prepaid credits and leave the invoiced billing limit at $0, the default. When the credits run out, API requests are rejected instead of billed. If you use auto top-up, set its monthly maximum. You get a warning at 80% of the monthly limit you set.
Why did one long session cost so much?
Once a prompt reaches 200k tokens, the whole request is billed at the higher rate, not only the part above the line. On Grok 4.7 that is double: $4.00 instead of $2.00 per million input tokens. Check /context, use /compact with instructions, or start fresh with /new.
Is it OK to open a repo I just cloned with my agent?
Read its .git/config first. The GitSpawn research (September 2026) showed that a booby-trapped config can run a command when a coding agent runs git in the background, before a trust prompt. Seven agents were affected when it was published. The advice applies to every coding agent.
Does Aster check any of this?
No. Plan mode, rewind, AGENTS.md, billing settings and chat privacy are habits and settings on your side, and Aster’s audit doesn’t look at them. Aster reads your repository before launch and reports what it finds in plain English. That is why this cheat sheet and the prompt above exist.
Let the agent drive. Plan first, commit before every task, write your house rules once and keep the fuel prepaid. Shipping faster still needs a check before launch, and your first Aster repository audit is free.
Source notebook13 links
- SpaceXAI Docs: Grok Build overview
- SpaceXAI Docs: Grok Build Plan Mode (Shift+Tab, /plan, a / s / c / q)
- SpaceXAI Docs: Grok Build sessions (/rewind, /compact)
- SpaceXAI Docs: Grok Build keyboard shortcuts (Esc Esc)
- SpaceXAI Docs: Grok Build project rules (AGENTS.md, CLAUDE.md, grok inspect)
- SpaceXAI Docs: Console billing (prepaid credits, invoiced billing limit, auto top-up)
- SpaceXAI Docs: Models and pricing (the 200k-token rate)
- SpaceXAI Docs: Grok Build modes and commands (/context, /new)
- SpaceXAI Docs: Grok Build permissions (Ask, Auto, Always-approve)
- GitHub: xai-org/grok-build (open-source code and changelogs)
- Manifold Security: GitSpawn, AI coding agents and .git/config (September 1, 2026)
- SpaceXAI Docs: API key security FAQ (disable, delete, GitHub secret scanning)
- SpaceXAI: Grok consumer FAQ (Improve the Model, Private Chat)
