GrokHunter v1.0.10
Rootless · v1.0.10 Kali Linux NetHunter Grok 4.6 No root required Grok Build 1.0.5+ Marketplace + Connect Agents · personas · roles

Kali NetHunter Rootless powered by Grok Build

Turn unrooted Android into a full AI coding lab. Real Linux toolchains, Grok Build 1.0.5+ (TUI + headless) on grok-4.6, Coding Team multi-agents, marketplace plugins, Termux / Grok Build Connect bridges for Grok Bot, Aider, and XFCE — one installer, no root.

Quick install
bash <(curl -fsSL https://raw.githubusercontent.com/FineComputer14451/GrokHunter/main/install.sh)

No flags: TTY wizard (default coding-only nano). --yes skips it. Desktop is a toggle or --full --de xfce --with-x11.

Built on termux-nethunter / termux-distro by jorexdeveloper. Not affiliated with xAI, Offensive Security, or jorexdeveloper. Coding lab only.

install · rootless · 1.0.10
1.0.10 Product version
1.0.5+ Grok Build min
32 Runtime agents
28 Personas
29 Roles
0 Root required

A real lab on your phone

Learn languages, ship tools, and pair with Grok on device — without rooting Android.

Need What you get
Real Linux toolchain apt, gcc, python, node, rust, go inside Kali
No root Stock Android — rootless proot only
AI pair-programmer Grok Build 1.0.5+ TUI + headless, agents, skills, grok-4.6
Multi-agent coding Coding Team: design → build → harden + specialists
Git-native pair Aider via uv + managed Python 3.12 (works on Kali 3.13)
Desktop IDE feel XFCE + Termux:X11 (nh-x11)
Grok Bot bridge Termux Connect (:8765) + Grok Build Connect (:8766) over Cloudflare tunnel
Marketplace plugins grok plugin marketplace add FineComputer14451/GrokHunter
Default model grok-4.6 (legacy V9 pickers retired — models clean)
Portability Entire lab lives under Termux

Everything for an on-device coding agent

Overlay on official NetHunter — modular, idempotent, marketplace-ready, and wired for Grok Bot Connect bridges when you want the phone as a remote tool host.

Rootless first

Termux + proot only. Stock Android, warranty intact — no Magisk, recovery, or firmware modules.

Grok Build 1.0.5+

Official CLI with fullscreen TUI, headless -p, plan agent, skills, and stable channel defaults on grok-4.6 via the NetHunter profile.

Coding Team agents

Benjamin · Lucas · Harper plus lab specialists (desktop, overlay, github, secrets, toolchain, tls, net, tookie, …) for Design → Build → Harden. Thirty-two runtime agents (Coding Team + lab specialists).

Personas & roles

Tone overlays (mobile, design-card, …) and capability roles (architect, builder, …) for Grok Build 1.0.5+ subagent resolution.

Real Linux toolchains

Full Kali apt: gcc, python, node, rust, go — a real coding lab, not a toy shell.

Desktop via Termux:X11

XFCE + nh-x11 (legacy drawing on by default). grokhunter binds for X sockets; bwrap-proot for glycin/GTK.

Aider + xAI

aider-grok with secrets.env and grok-4.6. Installer uses uv + managed Python 3.12 so Kali 3.13 does not break Aider.

Doctor & status

grokhunter doctor checks binary, profile, skills, agents, personas, roles, PATH, secrets, and lab readiness.

Marketplace plugins

Install only what you need: grokhunter, grokhunter-full, Coding Team, lab specialists, Termux Connect, and Grok Build Connect packs.

Connect bridges

Termux Connect (:8765) exposes jailed lab tools; Grok Build Connect (:8766) proxies local grok. Bootstrap with --tunnel, add Bearer MCP at grok.com/connectors.

Overlay, not a fork

Sits on the official NetHunter rootfs. Idempotent install, clean uninstall, modular lib/.

Lab updates on main

Beyond the v1.0.10 release tag — pull main and run the upgrade paste to pick these up.

Grok 4.6 default

Catalog stays on grok-4.6. Legacy V9 /model pickers are retired — grokhunter models clean strips them from ~/.grok/config.toml.

Termux Connect

HTTP MCP on port 8765 with Cloudflare tunnel bootstrap so Grok Bot can reach jailed lab tools on your phone (not native Local Computer).

Grok Build Connect

Second bridge on port 8766 for local grok CLI (version, plugins, MCP doctor, ask, read). Same tunnel + Bearer pattern.

Chat ↔ Build workflow

docs/GROK-46-WORKFLOW.md — Grok 4.6 chat vs on-device Grok Build. Chat picker Build is Build Mode (shareable grok.me apps), not the Termux CLI. Imagine map: incl. Agent Mode.

Marketplace packs

Modular Grok Build plugins: core, full, Coding Team, lab specialists, and both Connect packs — install only what you need with --trust for sources you chose.

Mobile-friendly copy

Site Copy buttons use a sync clipboard path first so mobile browsers keep the user gesture — fewer silent paste failures on Android.

Four layers under ~/.grok

Install once with grokhunter skills install or Grok Build plugins from this marketplace — skills, agents, personas, and roles land where Grok Build 1.0.5+ discovers them — or install packs from this marketplace.

Skills

~/.grok/skills

Twenty-nine lab playbooks (core N/3 plus *-lab specialists, Connect, overlay, and more).

skills-core=3/3
Agents

~/.grok/agents

Session types for /config-agents and spawn — Coding Team + specialists.

32 user agents
Personas

~/.grok/personas

Tone and card contracts: mobile, concise, design-card, build-card, harden-card, …

28 personas
Roles

~/.grok/roles

Capability defaults: architect, builder, reliability, mapper, surgical, …

29 roles
Mental model
agent  = who            (benjamin, lucas, scout, …)
role   = capabilities   (architect, builder, mapper, …)
persona = tone / cards  (mobile, design-card, concise, …)

Coding Team + lab specialists

Runtime Grok Build agents — pick in /config-agents or spawn by name.

Core loop

1scout (optional map)
2benjamin design
3lucas / fix build
4harper harden
5review (optional)
Agent Mode Role
coding-team full Orchestrator — Design → Build → Harden
benjamin plan / read-only Senior architect, security, mobile constraints
lucas full Rapid builder — small shippable increments
harper full Reliability — tests, edge cases, harden cards
scout read-only Fast codebase / install-flow map
review read-only Diff / change review
fix full Surgical one-bug patches
desktop full Termux:X11 / nh-x11 / proot binds
overlay · ship · docs mixed Install/cache · version/tag · README/site copy
models · ci · aider full grok-4.6 profile · ci-unit/Smoke · aider-grok
session · host · mcp full tmux/resume · Termux vs Kali · grok mcp
plugin · flow · storage full grok plugin · .rhai workflows · disk/cache
editor · hook · shell full nvim/micro · /hooks · profile.sh
github · secrets · toolchain full git-identity (CLI is git-identity) · secrets.env · apt/compilers
tls full Kali CA / SSL_CERT_FILE (never print certs)
net full x.ai probe / guest DNS (401/403 = reachable)
tookie full Authorized public username OSINT (scoped; hits are leads)
Try headless
grok --agent scout -p "Map install_aider"
grok --agent coding-team
grokhunter plan "Design overlay-only repair"

Overlays for tone and capability

Personas inject behavioral reminders; roles set capability mode and reasoning effort. Manage in TUI via /personas and /config-agents. Full set: 28 personas and 29 roles after grokhunter skills install (counts track main).

Personas
mobileNetHunter / Termux constraints
conciseShort, scannable output
shell-firstScripts & lab tooling bias
pairPair-programming tone
security-labSecrets & installer safety
design-cardBenjamin-style design card
build-cardLucas-style build card
harden-cardHarper-style harden card
Roles
architectread-only · high effort
builderfull · medium
reliabilityfull · high
mapperread-only · medium
code-reviewfull · high
surgicalfull · medium
x11-desktopfull · medium

One command, modular stack

Termux = full lab (rootfs + overlays). Desktop (Linux/macOS/WSL) = overlay-only GrokHunter coding tools. Termux from F-Droid or GitHub (not Play Store), Android 8+, aarch64 recommended; SuperGrok / X Premium+ or an XAI_API_KEY for Grok Build.

01 One-liner
bash <(curl -fsSL https://raw.githubusercontent.com/FineComputer14451/GrokHunter/main/install.sh)

TTY wizard if you pass no flags. Default is nano coding-only, not the full desktop stack. On Linux/macOS/WSL use the desktop overlay one-liner below.

02 Desktop overlay (Linux / macOS / WSL)
bash <(curl -fsSL https://raw.githubusercontent.com/FineComputer14451/GrokHunter/main/install.sh) \
  --overlay-only --with-grok --with-completions

No NetHunter rootfs on desktop — coding tools, Grok, completions only.

03 Recommended full stack
bash install.sh --full --de xfce --browser chromium \
  --with-grok --with-x11 --with-aider --with-completions
04 Clone (audit-friendly)
git clone https://github.com/FineComputer14451/GrokHunter.git
cd GrokHunter
bash install.sh --full --de xfce --with-grok --with-x11
05 Overlay-only (no rootfs re-download)
bash install.sh --overlay-only --with-grok --with-x11 --with-aider

Installer flags

  • -f, --fullFull installation (includes desktop)
  • -m, --miniMini (essential packages)
  • -n, --nanoNano (minimal footprint)
  • --de <desktop>e17 | gnome | i3 | kde | lxde | mate | xfce
  • --browser <name>chromium | firefox | both
  • --with-grokGrok Build ≥ 1.0.5 + profile
  • --with-x11Termux:X11 + nh-x11 helper
  • --with-aiderAider (uv + Python 3.12)
  • --with-v9-modelsDeprecated no-op (V9 pickers removed)
  • --with-completionsShell completions + profile
  • --overlay-onlyOverlays only (no rootfs download)
  • --no-de / --no-grok / --no-x11Skip those stages

After install

  • nethunter — enter Kali shell
  • nh-x11 — low-latency desktop
  • grok — Grok Build TUI
  • grokhunter doctor — health report
  • grokhunter skills install — agents · personas · roles
  • aider-grok — git-native pair

Grok Build marketplace + Connect bridges

This repo is a Grok Build marketplace. Install only the packs you need, or bridge Grok Bot over authenticated HTTP MCP: Termux Connect (lab tools, port 8765) and Grok Build Connect (local grok CLI, port 8766).

01 Add marketplace
grok plugin marketplace add FineComputer14451/GrokHunter
grok plugin install grokhunter --trust
grok plugin install grokhunter-coding-team --trust
grok plugin install grokhunter-termux-connect --trust
grok plugin install grokhunter-grok-build-connect --trust
# or everything: grok plugin install grokhunter-full --trust

Catalog lives in .grok-plugin/marketplace.json · see docs/MARKETPLACE.md. Use --trust only for a source you named.

02 Termux Connect (Grok Bot bridge)
curl -fsSL https://raw.githubusercontent.com/FineComputer14451/GrokHunter/main/skills/termux-connect/scripts/bootstrap.sh | bash -s -- --tunnel

Or from a checkout: bash skills/termux-connect/scripts/bootstrap.sh --tunnel. Starts MCP in tmux session tc, installs cloudflared, opens a quick tunnel in tun. Path-jailed tools + allowlisted shell. Bearer token at ~/.grokhunter-termux-connect/token (mode 600) — never paste into chat.

03 Grok Build Connect (grok CLI bridge)
curl -fsSL https://raw.githubusercontent.com/FineComputer14451/GrokHunter/main/skills/grok-build-connect/scripts/bootstrap.sh | bash -s -- --tunnel

Termux or desktop. MCP on 8766 (tmux gbc / gbc-tun). Tools: version, plugin/mcp list, doctor, grok_ask, jailed files. Token: ~/.grokhunter-grok-build-connect/token — never paste into chat. Also: grok plugin install grokhunter-grok-build-connect --trust.

Wire Grok Bot

  • Native Local Computer is Mac/Windows only — Android uses MCP + tunnel
  • https://<trycloudflare-host>/mcpConnector URL (each Connect has its own host)
  • Authorization: Bearer …Matching token file (8765 vs 8766)
  • Keep tmux sessions up — force-close kills quick tunnels

Where to add the connector

  • Desktop Grok Bot — tell the bot to add the MCP URL (chat-managed)
  • Browser — grok.com/connectors → New → Custom
  • Android app — no custom-MCP settings screen today; use browser or desktop

Quick tunnels change hostname when Termux is force-closed — update the connector URL. Prefer a named Cloudflare tunnel for a stable host.

grokhunter commands

Also: grok-nethunter fullscreen launcher · grok native TUI · aliases via profile (ghd, ghp, ghsu, …)

grokhunterInteractive fullscreen TUI
grokhunter statusShort status line
grokhunter doctorFull health report
grokhunter bindsProot binds (status|repair|optimize)
grokhunter git-identityGitHub-attributable git user.name / email
grokhunter setupOne-shot: ensure + skills + doctor
grokhunter ensureGrok Build ≥ 1.0.5 + NetHunter profile
grokhunter skills installSkills, agents, personas, roles + wrappers
grokhunter teamLaunch Coding Team agent
grokhunter scout|review|fix|desktopSpecialist agent launchers
grokhunter overlay|ship|docsLab specialists (install / release / docs)
grokhunter modeler|ci|aiderModels agent (grok-4.6), CI, Aider (`modeler` ≠ `models` CLI)
grokhunter session|host|mcptmux/resume, Termux vs Kali, MCP (`mcp` ≠ `grok mcp`)
grokhunter plugin|flow|storageplugins (`plugin` ≠ `grok plugin`), workflows, disk
grokhunter editor|hook|shellnvim/micro, Grok hooks, profile/completions
grokhunter github|secrets|toolchain|tls|net|tookiegit-identity agent (≠ git-identity CLI), secrets.env, apt/compilers, CA, HTTPS, scoped OSINT
grokhunter agents statusInstalled Coding Team agents
grokhunter models cleanRemove legacy V9 pickers (default: grok-4.6)
grokhunter ai-smokeSpaceXAI API smoke test
grokhunter install [args]Installer (supports --overlay-only)
grokhunter plan "…"Built-in plan agent (1.0.5)
grokhunter -p "…"Headless one-shot
bash scripts/install_aider.shRepair Aider (uv + 3.12)
bash scripts/ci-unit.shLocal unit checks

Stay current on main

Already installed? Pull main, overlay-refresh, ensure Grok Build 1.0.5+, strip legacy V9 pickers, refresh skills/agents, Kali menu, then doctor.

Paste-ready
cd ~/GrokHunter && git pull
bash install.sh --overlay-only --with-completions
grokhunter ensure              # binary ≥ 1.0.5 + profile
grokhunter skills install      # skills · agents · personas · roles
grokhunter git-identity set    # GitHub noreply (no gh CLI required)
grokhunter menu install        # Applications → GrokHunter (XFCE)
grokhunter models clean        # strip legacy V9 pickers (default grok-4.6)
grokhunter doctor
grokhunter credits             # upstream attribution
Grok Build docs

GROK-BUILD-1.0.md

Coding Team

CODING-TEAM.md

4.6 workflow

Chat ↔ Build map

Imagine models

Incl. Agent Mode

Overlay on a living rootfs

Design goals: rootless first, coding focus, official Grok binary, idempotent install, mobile-first UX.

1
Androidstock / unrooted
2
TermuxF-Droid or GitHub (not Play Store)
3
proot → Kali NetHunternano / mini / full rootfs
4
GrokHunter overlay Grok CLI · agents · personas · roles · nh-x11 · doctor · skills
No root

No Magisk, HID, or custom recovery

Not a fork

Never rebuilds Kali rootfs or kernels

Idempotent

Safe to re-run; uninstall keeps your projects

Common questions

How do Grok Build plugins work?

Add this repo as a marketplace: grok plugin marketplace add FineComputer14451/GrokHunter, then grok plugin install grokhunter --trust (or grokhunter-full). Details: docs/MARKETPLACE.md.

Can Grok Bot use my phone as a local computer?

Not via native Local Computer (Mac/Windows only). Use Termux Connect (lab tools, :8765) or Grok Build Connect (local grok CLI, :8766): bootstrap with --tunnel, then add https://<host>/mcp with Bearer auth at grok.com/connectors or desktop Grok Bot. Android Grok Bot currently has no custom-MCP settings screen.

Is Chat Build the same as Grok Build on Termux?

No. Chat picker Build is Build Mode (in-chat sites/apps/games → *.grok.me). Terminal Grok Build (grok / grokhunter) edits your lab repo. See GROK-46-WORKFLOW.md and xAI Build Mode.

What about V9 /model pickers?

Retired. Default catalog is grok-4.6. Run grokhunter models clean to strip legacy pickers from ~/.grok/config.toml. --with-v9-models is a deprecated no-op.

Do I need root?

No. GrokHunter is rootless Termux + proot only. Use Termux from F-Droid or GitHub — not the Play Store.

Which Grok Build version?

GrokHunter 1.0.10 targets Grok Build 1.0.5+ (stable). Run grokhunter ensure to upgrade and apply the NetHunter profile.

How do I auth Grok?

SuperGrok / X Premium+ login via grok, or put XAI_API_KEY in ~/.grok/secrets.env (mode 600). Never commit secrets.

Aider failed on Kali Python 3.13?

Expected with plain pip. Use bash scripts/install_aider.sh — uv installs managed Python 3.12 + aider-chat. Then aider-grok.

Black screen on nh-x11?

nh-x11 already defaults to legacy drawing. Confirm the Termux:X11 APK (sharedUid with GitHub Termux), run grokhunter binds status, and see docs/X11-PERFORMANCE.md. GPU path: NH_X11_LEGACY=0 nh-x11. Agent: desktop.

Is this for penetration testing?

The product focus is a coding lab. Optional nethunter-recon skill is scoped for authorized lab/CTF only — not default.

How do chat and on-device Build work together?

Use Grok 4.6 chat for planning and review; run Grok Build in Termux for agents, skills, and edits. See docs/GROK-46-WORKFLOW.md. For Imagine / Agent Mode model IDs, use the Imagine models map.

Tunnel shows Error 1033 / 530?

The Cloudflare quick tunnel died or the MCP process stopped. Re-attach tmux a -t tun / gbc-tun (or re-run bootstrap --tunnel), confirm local /healthz is 200, then update the connector URL if the host changed.

How many skills / agents ship?

On current main: about 29 skills, 32 agents, 28 personas, and 29 roles (counts move as Wave packs land). Prefer marketplace plugins if you only want a subset.

Built on open-source shoulders

GrokHunter is an overlay for an AI coding lab. The rootless NetHunter install path depends on work by jorexdeveloper — please support those projects.

Author / project Contribution
jorexdeveloper termux-nethunter · termux-distro — rootless NetHunter install + shared engine (GPL-3.0)
Termux team termux.dev · app, packages, proot host · Termux:X11 for nh-x11
Kali Linux / Offensive Security Official NetHunter rootfs images + Kali package ecosystem (coding-lab use)
xAI Grok Build agent · Grok models / API · docs.x.ai

Full statement: CREDITS.md · Not affiliated with xAI, Offensive Security, Termux, or jorexdeveloper — we gratefully build upon their work.

Ship code from your pocket

Clone the repo, run the installer, open Grok on grok-4.6. Coding Team, marketplace plugins, Connect bridges, Aider, and a full Linux toolchain — ready on unrooted Android.