GUI for Grok Build & Muse Code
GUI for Grok Build (incl. Grok 4.7) and Muse Code — and for Codex and Claude Code in the same window. Remote Control from your phone, voice control, multiple sessions, images and videos, Mermaid diagrams, and LaTeX. Works with SuperGrok, X Premium+, and xAI API key. Fair Source (FSL-1.1-MIT). Not affiliated with or endorsed by SpaceXAI (formerly xAI), Meta, OpenAI or Anthropic.
- Created
- 5 months ago
- Last commit
- 5 days ago
- Latest release
- v4.13.16 days ago
Security Findings
14Dynamic exec of remote content (VSX)
SuspiciousScannerDownload-and-execute in media/chat.js: irm https://dev.meta.ai/install.ps1 | iex
media/chat.js
Dynamic exec of remote content (VSX)
SuspiciousScannerDownload-and-execute in out/muse-install.js: irm https://dev.meta.ai/install.ps1 | iex
out/muse-install.js
Dynamic exec of remote content (VSX)
SuspiciousScannerFetched content reaches a dynamic exec sink in media/mermaid/mermaid.min.js: fetch(
media/mermaid/mermaid.min.js
Hardcoded secrets/API keys2×
SuspiciousScannerSecret Keyword: OPENA...****
Secret Keyword: CODEX...****
node_modules/@agentclientprotocol/codex-acp/dist/index.js
Hardcoded secrets/API keys2×
SuspiciousScannerSecret Keyword: https...****
Secret Keyword: _STRI...****
node_modules/@anthropic-ai/claude-agent-sdk/sdk.mjs
Hardcoded secrets/API keys
SuspiciousScannerSecret Keyword: grok....****
out/mcp-connectors.js
Hardcoded secrets/API keys
SuspiciousScannerSecret Keyword: strin...****
out/mcp-connector-oauth.js
Sensitive file access2×
SuspiciousScannerAccess to sensitive file: /etc/passwd
Access to sensitive file: ~/.ssh
Dangerous security bypass flags3×
SuspiciousScannerBypass flag in content: --no-sandbox
Bypass flag in content: --trust
Gatekeeper bypass in content: xattr -dr com.apple.quarantine