4.14.1

    GUI for Grok Build & Muse Code

    GUI for Grok Build (incl. Grok 4.7) and Muse Code — and for Codex and Claude Code in the same window. Remote Control from your phone, voice control, multiple sessions, images and videos, Mermaid diagrams, and LaTeX. Works with SuperGrok, X Premium+, and xAI API key. Fair Source (FSL-1.1-MIT). Not affiliated with or endorsed by SpaceXAI (formerly xAI), Meta, OpenAI or Anthropic.

    Rank#-596
    Publisher PawelHurynRegistry openvsx133,700Last scanned Sep 30, 2026, 06:06 PMRegistryHomepageGitHub
    Created
    5 months ago
    Last commit
    5 days ago
    Latest release
    v4.13.16 days ago

    Security Findings

    14

    Dynamic exec of remote content (VSX)

    SuspiciousScanner

    Download-and-execute in media/chat.js: irm https://dev.meta.ai/install.ps1 | iex

    media/chat.js

    Dynamic exec of remote content (VSX)

    SuspiciousScanner

    Download-and-execute in out/muse-install.js: irm https://dev.meta.ai/install.ps1 | iex

    out/muse-install.js

    Dynamic exec of remote content (VSX)

    SuspiciousScanner

    Fetched content reaches a dynamic exec sink in media/mermaid/mermaid.min.js: fetch(

    media/mermaid/mermaid.min.js

    Hardcoded secrets/API keys2×

    SuspiciousScanner

    Secret Keyword: OPENA...****

    Secret Keyword: CODEX...****

    node_modules/@agentclientprotocol/codex-acp/dist/index.js

    Hardcoded secrets/API keys2×

    SuspiciousScanner

    Secret Keyword: https...****

    Secret Keyword: _STRI...****

    node_modules/@anthropic-ai/claude-agent-sdk/sdk.mjs

    Hardcoded secrets/API keys

    SuspiciousScanner

    Secret Keyword: grok....****

    out/mcp-connectors.js

    Hardcoded secrets/API keys

    SuspiciousScanner

    Secret Keyword: strin...****

    out/mcp-connector-oauth.js

    Sensitive file access2×

    SuspiciousScanner

    Access to sensitive file: /etc/passwd

    Access to sensitive file: ~/.ssh

    Dangerous security bypass flags3×

    SuspiciousScanner

    Bypass flag in content: --no-sandbox

    Bypass flag in content: --trust

    Gatekeeper bypass in content: xattr -dr com.apple.quarantine