Rootless first
Termux + proot only. Stock Android, warranty intact — no Magisk, recovery, or firmware modules.
Turn unrooted Android into a full AI coding lab. Real Linux toolchains, Grok Build 1.0.5+ (TUI + headless) on grok-4.6, Coding Team multi-agents, marketplace plugins, Termux / Grok Build Connect bridges for Grok Bot, Aider, and XFCE — one installer, no root.
bash <(curl -fsSL https://raw.githubusercontent.com/FineComputer14451/GrokHunter/main/install.sh)
No flags: TTY wizard (default coding-only nano). --yes skips it. Desktop is a toggle or --full --de xfce --with-x11.
Built on termux-nethunter / termux-distro by jorexdeveloper. Not affiliated with xAI, Offensive Security, or jorexdeveloper. Coding lab only.
Why this stack
Learn languages, ship tools, and pair with Grok on device — without rooting Android.
| Need | What you get |
|---|---|
| Real Linux toolchain | apt, gcc, python, node, rust, go inside Kali |
| No root | Stock Android — rootless proot only |
| AI pair-programmer | Grok Build 1.0.5+ TUI + headless, agents, skills, grok-4.6 |
| Multi-agent coding | Coding Team: design → build → harden + specialists |
| Git-native pair | Aider via uv + managed Python 3.12 (works on Kali 3.13) |
| Desktop IDE feel | XFCE + Termux:X11 (nh-x11) |
| Grok Bot bridge | Termux Connect (:8765) + Grok Build Connect (:8766) over Cloudflare tunnel |
| Marketplace plugins | grok plugin marketplace add FineComputer14451/GrokHunter |
| Default model | grok-4.6 (legacy V9 pickers retired — models clean) |
| Portability | Entire lab lives under Termux |
Features
Overlay on official NetHunter — modular, idempotent, marketplace-ready, and wired for Grok Bot Connect bridges when you want the phone as a remote tool host.
Termux + proot only. Stock Android, warranty intact — no Magisk, recovery, or firmware modules.
Official CLI with fullscreen TUI, headless -p, plan agent, skills, and
stable channel defaults on grok-4.6 via the NetHunter profile.
Benjamin · Lucas · Harper plus lab specialists (desktop, overlay, github, secrets, toolchain, tls, net, tookie, …) for Design → Build → Harden. Thirty-two runtime agents (Coding Team + lab specialists).
Tone overlays (mobile, design-card, …) and capability roles (architect, builder, …) for Grok Build 1.0.5+ subagent resolution.
Full Kali apt: gcc, python, node, rust, go — a real coding lab, not a toy shell.
XFCE + nh-x11 (legacy drawing on by default).
grokhunter binds for X sockets; bwrap-proot for glycin/GTK.
aider-grok with secrets.env and grok-4.6. Installer uses uv + managed
Python 3.12 so Kali 3.13 does not break Aider.
grokhunter doctor checks binary, profile, skills, agents, personas,
roles, PATH, secrets, and lab readiness.
Install only what you need: grokhunter, grokhunter-full,
Coding Team, lab specialists, Termux Connect, and Grok Build Connect packs.
Termux Connect (:8765) exposes jailed lab tools; Grok Build Connect
(:8766) proxies local grok. Bootstrap with --tunnel, add Bearer MCP at
grok.com/connectors.
Sits on the official NetHunter rootfs. Idempotent install, clean uninstall, modular
lib/.
What's new
Beyond the v1.0.10
release tag — pull main and run the upgrade paste to pick these up.
Catalog stays on grok-4.6. Legacy V9 /model pickers are retired —
grokhunter models clean strips them from ~/.grok/config.toml.
HTTP MCP on port 8765 with Cloudflare tunnel bootstrap so Grok Bot can reach jailed lab tools on your phone (not native Local Computer).
Second bridge on port 8766 for local grok CLI (version, plugins,
MCP doctor, ask, read). Same tunnel + Bearer pattern.
docs/GROK-46-WORKFLOW.md
— Grok 4.6 chat vs on-device Grok Build. Chat picker Build is
Build Mode (shareable grok.me apps), not the Termux CLI.
Imagine map:
incl. Agent Mode.
Modular Grok Build plugins: core, full, Coding Team, lab specialists, and both Connect
packs — install only what you need with --trust for sources you chose.
Site Copy buttons use a sync clipboard path first so mobile browsers keep the user gesture — fewer silent paste failures on Android.
Stack
Install once with grokhunter skills install or Grok Build plugins from this marketplace — skills, agents, personas, and
roles land where Grok Build 1.0.5+ discovers them — or install packs from this marketplace.
Twenty-nine lab playbooks (core N/3 plus *-lab specialists, Connect, overlay, and more).
skills-core=3/3
Session types for /config-agents and spawn — Coding Team + specialists.
32 user agents
Tone and card contracts: mobile, concise, design-card, build-card, harden-card, …
28 personas
Capability defaults: architect, builder, reliability, mapper, surgical, …
29 roles
agent = who (benjamin, lucas, scout, …) role = capabilities (architect, builder, mapper, …) persona = tone / cards (mobile, design-card, concise, …)
Agents
Runtime Grok Build agents — pick in /config-agents or spawn by name.
| Agent | Mode | Role |
|---|---|---|
coding-team |
full | Orchestrator — Design → Build → Harden |
benjamin |
plan / read-only | Senior architect, security, mobile constraints |
lucas |
full | Rapid builder — small shippable increments |
harper |
full | Reliability — tests, edge cases, harden cards |
scout |
read-only | Fast codebase / install-flow map |
review |
read-only | Diff / change review |
fix |
full | Surgical one-bug patches |
desktop |
full | Termux:X11 / nh-x11 / proot binds |
overlay · ship · docs |
mixed | Install/cache · version/tag · README/site copy |
models · ci · aider |
full | grok-4.6 profile · ci-unit/Smoke · aider-grok |
session · host · mcp |
full | tmux/resume · Termux vs Kali · grok mcp |
plugin · flow · storage |
full | grok plugin · .rhai workflows · disk/cache |
editor · hook · shell |
full | nvim/micro · /hooks · profile.sh |
github · secrets · toolchain |
full | git-identity (CLI is git-identity) · secrets.env · apt/compilers |
tls |
full | Kali CA / SSL_CERT_FILE (never print certs) |
net |
full | x.ai probe / guest DNS (401/403 = reachable) |
tookie |
full | Authorized public username OSINT (scoped; hits are leads) |
grok --agent scout -p "Map install_aider"
grok --agent coding-team
grokhunter plan "Design overlay-only repair"
Personas & roles
Personas inject behavioral reminders; roles set capability mode and reasoning effort.
Manage in TUI via /personas and /config-agents.
Full set: 28 personas and 29 roles after grokhunter skills install (counts track main).
| Personas | |
|---|---|
mobile | NetHunter / Termux constraints |
concise | Short, scannable output |
shell-first | Scripts & lab tooling bias |
pair | Pair-programming tone |
security-lab | Secrets & installer safety |
design-card | Benjamin-style design card |
build-card | Lucas-style build card |
harden-card | Harper-style harden card |
| Roles | |
|---|---|
architect | read-only · high effort |
builder | full · medium |
reliability | full · high |
mapper | read-only · medium |
code-review | full · high |
surgical | full · medium |
x11-desktop | full · medium |
Install
Termux = full lab (rootfs + overlays). Desktop (Linux/macOS/WSL) =
overlay-only GrokHunter coding tools. Termux from F-Droid or GitHub (not Play Store), Android 8+,
aarch64 recommended; SuperGrok / X Premium+ or an XAI_API_KEY for Grok Build.
bash <(curl -fsSL https://raw.githubusercontent.com/FineComputer14451/GrokHunter/main/install.sh)
TTY wizard if you pass no flags. Default is nano coding-only, not the full desktop stack. On Linux/macOS/WSL use the desktop overlay one-liner below.
bash <(curl -fsSL https://raw.githubusercontent.com/FineComputer14451/GrokHunter/main/install.sh) \
--overlay-only --with-grok --with-completions
No NetHunter rootfs on desktop — coding tools, Grok, completions only.
bash install.sh --full --de xfce --browser chromium \
--with-grok --with-x11 --with-aider --with-completions
git clone https://github.com/FineComputer14451/GrokHunter.git
cd GrokHunter
bash install.sh --full --de xfce --with-grok --with-x11
bash install.sh --overlay-only --with-grok --with-x11 --with-aider
-f, --fullFull installation (includes desktop)-m, --miniMini (essential packages)-n, --nanoNano (minimal footprint)--de <desktop>e17 | gnome | i3 | kde | lxde | mate | xfce--browser <name>chromium | firefox | both--with-grokGrok Build ≥ 1.0.5 + profile--with-x11Termux:X11 + nh-x11 helper--with-aiderAider (uv + Python 3.12)--with-v9-modelsDeprecated no-op (V9 pickers removed)--with-completionsShell completions + profile--overlay-onlyOverlays only (no rootfs download)--no-de / --no-grok / --no-x11Skip those stagesAfter install
Plugins
This repo is a Grok Build marketplace. Install only the packs you need,
or bridge Grok Bot over authenticated HTTP MCP:
Termux Connect (lab tools, port 8765) and
Grok Build Connect (local grok CLI, port 8766).
grok plugin marketplace add FineComputer14451/GrokHunter
grok plugin install grokhunter --trust
grok plugin install grokhunter-coding-team --trust
grok plugin install grokhunter-termux-connect --trust
grok plugin install grokhunter-grok-build-connect --trust
# or everything: grok plugin install grokhunter-full --trust
Catalog lives in .grok-plugin/marketplace.json · see
docs/MARKETPLACE.md.
Use --trust only for a source you named.
curl -fsSL https://raw.githubusercontent.com/FineComputer14451/GrokHunter/main/skills/termux-connect/scripts/bootstrap.sh | bash -s -- --tunnel
Or from a checkout:
bash skills/termux-connect/scripts/bootstrap.sh --tunnel.
Starts MCP in tmux session tc, installs cloudflared, opens
a quick tunnel in tun. Path-jailed tools + allowlisted shell. Bearer
token at ~/.grokhunter-termux-connect/token (mode 600) — never paste
into chat.
curl -fsSL https://raw.githubusercontent.com/FineComputer14451/GrokHunter/main/skills/grok-build-connect/scripts/bootstrap.sh | bash -s -- --tunnel
Termux or desktop. MCP on 8766 (tmux gbc /
gbc-tun). Tools: version, plugin/mcp list, doctor,
grok_ask, jailed files. Token:
~/.grokhunter-grok-build-connect/token — never paste into chat.
Also: grok plugin install grokhunter-grok-build-connect --trust.
https://<trycloudflare-host>/mcpConnector URL (each Connect has its own host)Authorization: Bearer …Matching token file (8765 vs 8766)Where to add the connector
Quick tunnels change hostname when Termux is force-closed — update the connector URL. Prefer a named Cloudflare tunnel for a stable host.
CLI
Also: grok-nethunter fullscreen launcher ·
grok native TUI · aliases via profile (ghd,
ghp, ghsu, …)
grokhunterInteractive fullscreen TUIgrokhunter statusShort status linegrokhunter doctorFull health reportgrokhunter bindsProot binds (status|repair|optimize)grokhunter git-identityGitHub-attributable git user.name / emailgrokhunter setupOne-shot: ensure + skills + doctorgrokhunter ensureGrok Build ≥ 1.0.5 + NetHunter profilegrokhunter skills installSkills, agents, personas, roles + wrappersgrokhunter teamLaunch Coding Team agentgrokhunter scout|review|fix|desktopSpecialist agent launchersgrokhunter overlay|ship|docsLab specialists (install / release / docs)grokhunter modeler|ci|aiderModels agent (grok-4.6), CI, Aider (`modeler` ≠ `models` CLI)grokhunter session|host|mcptmux/resume, Termux vs Kali, MCP (`mcp` ≠ `grok mcp`)grokhunter plugin|flow|storageplugins (`plugin` ≠ `grok plugin`), workflows, diskgrokhunter editor|hook|shellnvim/micro, Grok hooks, profile/completionsgrokhunter github|secrets|toolchain|tls|net|tookiegit-identity agent (≠ git-identity CLI), secrets.env, apt/compilers, CA, HTTPS, scoped OSINTgrokhunter agents statusInstalled Coding Team agentsgrokhunter models cleanRemove legacy V9 pickers (default: grok-4.6)grokhunter ai-smokeSpaceXAI API smoke testgrokhunter install [args]Installer (supports --overlay-only)grokhunter plan "…"Built-in plan agent (1.0.5)grokhunter -p "…"Headless one-shotbash scripts/install_aider.shRepair Aider (uv + 3.12)bash scripts/ci-unit.shLocal unit checksUpgrade to 1.0.10
Already installed? Pull main, overlay-refresh, ensure Grok Build 1.0.5+, strip legacy V9 pickers,
refresh skills/agents, Kali menu, then doctor.
cd ~/GrokHunter && git pull
bash install.sh --overlay-only --with-completions
grokhunter ensure # binary ≥ 1.0.5 + profile
grokhunter skills install # skills · agents · personas · roles
grokhunter git-identity set # GitHub noreply (no gh CLI required)
grokhunter menu install # Applications → GrokHunter (XFCE)
grokhunter models clean # strip legacy V9 pickers (default grok-4.6)
grokhunter doctor
grokhunter credits # upstream attribution
Architecture
Design goals: rootless first, coding focus, official Grok binary, idempotent install, mobile-first UX.
No Magisk, HID, or custom recovery
Never rebuilds Kali rootfs or kernels
Safe to re-run; uninstall keeps your projects
FAQ
Add this repo as a marketplace:
grok plugin marketplace add FineComputer14451/GrokHunter, then
grok plugin install grokhunter --trust (or grokhunter-full).
Details: docs/MARKETPLACE.md.
Not via native Local Computer (Mac/Windows only). Use
Termux Connect (lab tools, :8765) or
Grok Build Connect (local grok CLI, :8766):
bootstrap with --tunnel, then add
https://<host>/mcp with Bearer auth at
grok.com/connectors or desktop Grok Bot.
Android Grok Bot currently has no custom-MCP settings screen.
No. Chat picker Build is Build Mode
(in-chat sites/apps/games → *.grok.me). Terminal
Grok Build (grok / grokhunter) edits your lab repo.
See
GROK-46-WORKFLOW.md
and
xAI Build Mode.
Retired. Default catalog is grok-4.6. Run
grokhunter models clean to strip legacy pickers from
~/.grok/config.toml. --with-v9-models is a deprecated no-op.
No. GrokHunter is rootless Termux + proot only. Use Termux from F-Droid or GitHub — not the Play Store.
GrokHunter 1.0.10 targets Grok Build 1.0.5+ (stable). Run
grokhunter ensure to upgrade and apply the NetHunter profile.
SuperGrok / X Premium+ login via grok, or put
XAI_API_KEY in ~/.grok/secrets.env (mode 600). Never commit
secrets.
Expected with plain pip. Use
bash scripts/install_aider.sh — uv installs managed Python 3.12 +
aider-chat. Then aider-grok.
nh-x11 already defaults to legacy drawing. Confirm the Termux:X11 APK
(sharedUid with GitHub Termux), run grokhunter binds status, and see
docs/X11-PERFORMANCE.md. GPU path: NH_X11_LEGACY=0 nh-x11. Agent:
desktop.
The product focus is a coding lab. Optional
nethunter-recon skill is scoped for authorized lab/CTF only — not default.
Use Grok 4.6 chat for planning and review; run Grok Build in Termux for agents, skills, and edits. See docs/GROK-46-WORKFLOW.md. For Imagine / Agent Mode model IDs, use the Imagine models map.
The Cloudflare quick tunnel died or the MCP process stopped. Re-attach
tmux a -t tun / gbc-tun (or re-run bootstrap --tunnel),
confirm local /healthz is 200, then update the connector URL if the host changed.
On current main: about 29 skills, 32 agents,
28 personas, and 29 roles (counts move as Wave packs land).
Prefer marketplace plugins if you only want a subset.
Credits
GrokHunter is an overlay for an AI coding lab. The rootless NetHunter install path depends on work by jorexdeveloper — please support those projects.
| Author / project | Contribution |
|---|---|
| jorexdeveloper | termux-nethunter · termux-distro — rootless NetHunter install + shared engine (GPL-3.0) |
| Termux team |
termux.dev
· app, packages, proot host ·
Termux:X11
for nh-x11
|
| Kali Linux / Offensive Security | Official NetHunter rootfs images + Kali package ecosystem (coding-lab use) |
| xAI | Grok Build agent · Grok models / API · docs.x.ai |
Full statement: CREDITS.md · Not affiliated with xAI, Offensive Security, Termux, or jorexdeveloper — we gratefully build upon their work.
Clone the repo, run the installer, open Grok on grok-4.6. Coding Team, marketplace plugins, Connect bridges, Aider, and a full Linux toolchain — ready on unrooted Android.