Evidence record / grok-build

A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.

2026-09-21-grok-build-folder-trust-now-gates-project-permission-rules-instructions-and-skills-previously-applied

Folder trust now gates project permission rules, instructions, and skills (previously applied with no trust prompt). Before about 1.0.24, a cloned repo could ship .grok/config.toml or .claude/settings.json allow rules that took effect without any trust prompt. Now they wait for folder trust, and headless runs need --trust.

Channel: tagged-release (in the build joined to sync 75810042ca27, crate 1.0.24); not in any release note. Half: defect. Date: between 2026-09-01 and 2026-09-08 (builds 1.0.17 to 1.0.24).

Operator consequence: Upgrade past 1.0.24. Headless CI that relied on repo-local allow rules will now need --trust; add it only for repos you control. Anyone who ran grok in an untrusted checkout on 1.0.16 or earlier should assume the repo’s own allow rules were live. No advisory was published for this; the only record is the doc diff.

Receipt

Finding metadata

Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0

Finding ID: 2026-09-21-grok-build-folder-trust-now-gates-project-permission-rules-instructions-and-skills-previously-applied

Profile citations

  • grok-build / claim / folder-trust-gates-project-rules

Source links

Primary links, including exact changelog lines when available.

Versioned source: run artifact