ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      blueberrywoodsym

      Safety Report

      xAI / Grok

      @blueberrywoodsym

      Chat with Grok models via xAI API. Supports Grok-3, Grok-3-mini, vision, and more.

      9,637Downloads
      0Installs
      14Stars
      3Versions
      API Integration4,971Customer Support1,744AI & Machine Learning1,383Networking & DNS1,102

      Security Analysis

      high confidence
      Clean

      The skill's code, runtime instructions, and required environment variables are consistent with a Grok/xAI client: it only needs node and an XAI_API_KEY and talks to api.x.ai for chat, vision, and X search functionality.

      Feb 21, 20267 files
      Purpose & Capabilityok

      The name/description (xAI / Grok) aligns with the included scripts: chat.js, models.js, and search-x.js. Requested binary (node) and primary env var (XAI_API_KEY) are exactly what a client for xAI would need.

      Instruction Scopeok

      SKILL.md and the scripts limit behavior to sending prompts/images to api.x.ai and listing models; image uploads are constrained to specific extensions. The scripts do not read arbitrary config files or extra environment variables beyond XAI_API_KEY/XAI_MODEL. There are no instructions to transmit data to endpoints other than api.x.ai.

      Install Mechanismok

      No install spec — code files are bundled and executed via node. No downloads or archive extraction are performed by the skill itself; risk from installation is low.

      Credentialsok

      Only XAI_API_KEY (and optional XAI_MODEL) are required. These credentials are proportional and necessary for the described functionality; no unrelated secrets or config paths are requested.

      Persistence & Privilegeok

      The skill does not request always:true and declares disable-model-invocation:true (no autonomous invocation). It does not modify other skills or system-wide config and does not persist credentials itself.

      Guidance

      This skill appears coherent and limited to acting as an xAI/Grok client. Before installing: (1) confirm you trust the skill source (the repository owner is unknown here); (2) only provide a dedicated xAI API key (avoid reusing broad or admin keys) and consider key rotation; (3) review the bundled scripts yourself if you have doubts — they read any image path you pass (so avoid sending sensitive images); (4) be aware network requests go to api.x.ai (inspect network policy if you require allowlists). If you need autonomous agent invocation, note this skill disables it by default.

      Latest Release

      v1.0.2

      - Added a prominent link to external installation and use instructions at the top of the setup section. - No changes to functionality or commands; documentation update only.

      Popular Skills

      self-improving-agent

      @pskoett · 1,456 stars

      Gog

      @steipete · 672 stars

      Tavily Web Search

      @arun-8687 · 620 stars

      Find Skills

      @JimLiuxinghai · 529 stars

      Proactive Agent

      @halthelobster · 426 stars

      Summarize

      @summarize · 415 stars

      Published by @blueberrywoodsym on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]