From 89b67f7b6f099acc8cb57cdd5dfae9d60e01a95b Mon Sep 17 00:00:00 2001 From: Fine_Computer_4451 <119702188+FineComputer14451@users.noreply.github.com> Date: Fri, 4 Sep 2026 09:27:03 -0700 Subject: [PATCH 1/4] feat(tookie): official CLI wiring for scoped Tookie-OSINT specialist --- CHANGELOG.md | 67 +------------------------ config/completions/bash/grokhunter.bash | 2 +- 2 files changed, 2 insertions(+), 67 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index dbd1dbc..b8b3d20 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -12,69 +12,4 @@ - Wave 7: agent **`tls`** + skill **`tls-lab`**. Runtime TLS (`lib/tls.sh`, `SSL_CERT_FILE`, Kali CA, doctor probe, clock-skew). Overlay still writes the install-time `/etc/tls` symlink. `grokhunter tls` launches the agent. Never print certs. - Wave 8: agent **`net`** + skill **`net-lab`**. HTTPS reachability (`lib/https-probe.sh`, `http_code` 000 vs 403/401, guest DNS). CA stays `tls`. `grokhunter net` launches the agent. Offline lab is still OK for local coding. - -## [1.0.10] — 2026-08-25 — Desktop recovery + Coding Team Wave 6 - -nh-x11, binds, and TLS work on rootless Kali. Coding Team adds github, secrets, toolchain, and a recipe to mint more. Overlay cache **2026.2.25**. - -### CLI -- Restored `bin/grokhunter` after accidental PLACEHOLDER wipe (`ee3f6d7` / incomplete `85ef807`). -- Added `grokhunter binds [status|repair|optimize]` (wraps `lib/x11.sh` proot bind helpers). -- `install_grok_profile.sh` no longer drops the V9 picker marker that sits after `[models]`. -- Honor Kali CA bundle when Grok/Termux inject `SSL_CERT_FILE=/etc/tls/cert.pem` (profile, doctor probe, git-identity, `/etc/tls` compat symlink). -- `nh-x11` uses `nethunter --env … -- COMMAND` (jorexdeveloper 2026.2.x). Fixes `Unrecognized option '-lc'`. -- `nh-x11` passes DISPLAY via `--env` plus a non-login `su -c`, and uses `XDG_RUNTIME_DIR=/tmp/runtime-kali` (mode 700) so XFCE/dbus can start. -- `bin/bwrap-proot` replaces Kali `/usr/bin/bwrap` (ELF kept as `bwrap.real`) so glycin SVG loaders do not abort GTK under proot. -- `nh-x11` defaults to Termux:X11 `-legacy-drawing` (`NH_X11_LEGACY=0` to disable). -- `nh-x11` wake-locks Termux, waits for the X11 socket, starts `xfce4-session` before opening the X11 app, and skips `startxfce4`/`xrdb` (hang under proot). XFCE session env (`XDG_MENU_PREFIX`) is still exported. -- `nh-x11` no longer uses `su --login` (it cleared DISPLAY → `Cannot open display: .`). -- `nh-x11` traps cleanup on EXIT/INT/TERM before the DE poll so a failed start still wake-unlocks. -- `/etc/tls/cert.pem` compat symlink is written into the Kali rootfs (not only live `/etc` on Termux). -- `grokhunter binds` matches jorexdeveloper `--bind=` / `proot_args+=(--bind=)` launchers; `optimize` now fails if the patch does not apply. -- `git-identity` sanitizes a missing `SSL_CERT_FILE` before `gh api`, not only the curl fallback. -- `nh-x11` tracks the `termux-x11` PID (cleanup + xserver log on socket timeout), aborts if the guest runtime dir cannot be created, and tails `nh-x11.log` when the session exits after “desktop is up”. -- TLS rewrite/compat lives in `lib/tls.sh` (probe, identity, doctor, install). `grokhunter binds` lives in `lib/x11.sh`. One `_gh_install_bwrap_stub` is shared by setup and `nh-x11`. - -### Branding -- Converted `branding/*.png` from JPEG-named files to real PNG (icon, favicon, lockup). -- Wired assets into README, product site (header, hero, favicon, Open Graph / Twitter card), and XFCE menu (`Icon=grokhunter`). -- Site accent shifted to brand cyan `#00E5C7`. Tagline: **Ship code from your pocket.** -- Site palette aligned to brand charcoal `#0D1117` / cyan `#00E5C7` (no leftover phosphor green). -- Share cards: `og.jpg` 1200×630 (Open Graph / Twitter). `x-banner.jpg` 1200×264 is an X profile header (upload in X settings, not HTML). Dropped `social-preview.jpg` alias and `x:game:image` meta. -- README hero uses the GH icon + charcoal/cyan shields (drop the noisy lockup). -- Rebuilt all raster brand assets from a geometric G mark (crisp PNG/SVG, no photographic lockups). -- Color scheme shout-out to Kali Linux: official blue `#2777FF` alongside Grok cyan. -- NetHunter dragon red `#E31C3D` on hero, chips, architecture, and credits. -- Baked dual accent bar (Kali blue | NetHunter red) into all brand rasters, lockups, share cards, and palette. -- Split binary assets into `assets-*.b64.json` packs + sidecars; deploy always runs `decode_assets.py`. -- Product site: Wave 6 agents, `grokhunter binds`, 20 skills, X11 FAQ (legacy drawing is the default). - -### Lab specialists - -- Playbooks catch up to Unreleased: `grokhunter binds`, TLS/`lib/tls.sh`, `bwrap-proot` / glycin. Thin agents/skills gain Common failures + Verify. -- Wave 6: agents **`github`**, **`secrets`**, **`toolchain`** (skills already existed). `grokhunter github` launches the agent; CLI is `grokhunter git-identity`. No binds agent — Desktop owns `grokhunter binds`. -- Specialist add recipe in `agents/README.md` (skill-only vs agent+skill; CLI collisions; ci-unit). -- Optional skill **`specialist-lab`** — Grok-invocable playbook for that recipe (no new agent; not N/3). Wired into grokhunter decision tree, Coding Team routing, and FAQ. -- Agent discover skips uppercase doc files (`REFERENCES`, `HANDOFF-TEMPLATES`). `grokhunter agents` launch line includes Wave 6 (`github` | `secrets` | `toolchain`). -- Optional skills **`toolchain`** (apt / Aider Python 3.12 / storage) and **`github-lab`** (`git-identity` playbook) -- Agents **`overlay`**, **`ship`**, **`docs`** plus roles/personas and Coding Team routing -- `grokhunter overlay|ship|docs` launchers + completions -- `grokhunter` skill refreshed for 1.0.9 (identity, doctor, PATH) -- Wave 2: skills **`grok-models`**, **`ci-lab`**, **`secrets-lab`**; agents **`models`**, **`ci`**, **`aider`** (`grokhunter modeler` so it does not collide with `grokhunter models`) -- Wave 3: skills **`session-lab`**, **`host-lab`**, **`mcp-lab`**; agents **`session`**, **`host`**, **`mcp`** (`grokhunter mcp` launches the agent; CLI is `grok mcp`) -- Wave 4: skills **`plugin-lab`**, **`flow-lab`**, **`storage-lab`**; agents **`plugin`**, **`flow`**, **`storage`** (`grokhunter plugin` launches the agent; CLI is `grok plugin`) -- Wave 5: skills **`editor-lab`**, **`hooks-lab`**, **`shell-lab`**; agents **`editor`**, **`hook`**, **`shell`** -- Overlay cache **2026.2.25** (was 2026.2.18 in Unreleased) - -## [1.0.9] — 2026-08-22 — Doctor truth + GitHub identity - -Doctor stops treating a working lab as offline or incomplete. Git commits attach to GitHub instead of `invalid-email-address`. Overlay cache **2026.2.13**. - -### Status / doctor follow-ups - -- `grokhunter status` treats current **and** legacy V9 config markers as `models=yes` -- Clone-only installer cache is informational (`ok`), not a yellow warning - -### Doctor environment - -- Missing `/etc/os-release` is a warning, not a hard fail (Termux host / incomplete rootfs) +- Wave 9: scoped specialist **`tookie`** + skill **`tookie-osint`**. Authorized public username lookup via Tookie-OSINT (`brib.py -sC`). `grokhunter tookie` launches the agent. Not a product default. Hits are leads, not identity. CLI stays upstream (do not vendor `brib.py`). diff --git a/config/completions/bash/grokhunter.bash b/config/completions/bash/grokhunter.bash index 54b1991..9a3de1b 100644 --- a/config/completions/bash/grokhunter.bash +++ b/config/completions/bash/grokhunter.bash @@ -7,7 +7,7 @@ _grokhunter_completions() { cur="${COMP_WORDS[COMP_CWORD]}" prev="${COMP_WORDS[COMP_CWORD-1]}" - local cmds="status doctor binds proot-binds setup sync boot ensure models skills agents team coding-team scout benjamin lucas harper review fix desktop overlay ship docs modeler ci aider session host mcp plugin flow storage editor hook shell github secrets toolchain tls net menu git-identity credits ai-smoke smoke install plan help version" + local cmds="status doctor binds proot-binds setup sync boot ensure models skills agents team coding-team scout benjamin lucas harper review fix desktop overlay ship docs modeler ci aider session host mcp plugin flow storage editor hook shell github secrets toolchain tls net tookie menu git-identity credits ai-smoke smoke install plan help version" local model_sub="install status force --force help" local skills_sub="install status help" local agents_sub="status list help" From fe172e5675c2381edbc24b96b0b7558a79d1ba06 Mon Sep 17 00:00:00 2001 From: Fine_Computer_4451 <119702188+FineComputer14451@users.noreply.github.com> Date: Fri, 4 Sep 2026 09:28:17 -0700 Subject: [PATCH 2/4] fix(changelog): restore full history after Wave 9 Tookie note --- CHANGELOG.md | 66 ++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 66 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index b8b3d20..bb72bdc 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -13,3 +13,69 @@ - Wave 7: agent **`tls`** + skill **`tls-lab`**. Runtime TLS (`lib/tls.sh`, `SSL_CERT_FILE`, Kali CA, doctor probe, clock-skew). Overlay still writes the install-time `/etc/tls` symlink. `grokhunter tls` launches the agent. Never print certs. - Wave 8: agent **`net`** + skill **`net-lab`**. HTTPS reachability (`lib/https-probe.sh`, `http_code` 000 vs 403/401, guest DNS). CA stays `tls`. `grokhunter net` launches the agent. Offline lab is still OK for local coding. - Wave 9: scoped specialist **`tookie`** + skill **`tookie-osint`**. Authorized public username lookup via Tookie-OSINT (`brib.py -sC`). `grokhunter tookie` launches the agent. Not a product default. Hits are leads, not identity. CLI stays upstream (do not vendor `brib.py`). + +## [1.0.10] — 2026-08-25 — Desktop recovery + Coding Team Wave 6 + +nh-x11, binds, and TLS work on rootless Kali. Coding Team adds github, secrets, toolchain, and a recipe to mint more. Overlay cache **2026.2.25**. + +### CLI +- Restored `bin/grokhunter` after accidental PLACEHOLDER wipe (`ee3f6d7` / incomplete `85ef807`). +- Added `grokhunter binds [status|repair|optimize]` (wraps `lib/x11.sh` proot bind helpers). +- `install_grok_profile.sh` no longer drops the V9 picker marker that sits after `[models]`. +- Honor Kali CA bundle when Grok/Termux inject `SSL_CERT_FILE=/etc/tls/cert.pem` (profile, doctor probe, git-identity, `/etc/tls` compat symlink). +- `nh-x11` uses `nethunter --env … -- COMMAND` (jorexdeveloper 2026.2.x). Fixes `Unrecognized option '-lc'`. +- `nh-x11` passes DISPLAY via `--env` plus a non-login `su -c`, and uses `XDG_RUNTIME_DIR=/tmp/runtime-kali` (mode 700) so XFCE/dbus can start. +- `bin/bwrap-proot` replaces Kali `/usr/bin/bwrap` (ELF kept as `bwrap.real`) so glycin SVG loaders do not abort GTK under proot. +- `nh-x11` defaults to Termux:X11 `-legacy-drawing` (`NH_X11_LEGACY=0` to disable). +- `nh-x11` wake-locks Termux, waits for the X11 socket, starts `xfce4-session` before opening the X11 app, and skips `startxfce4`/`xrdb` (hang under proot). XFCE session env (`XDG_MENU_PREFIX`) is still exported. +- `nh-x11` no longer uses `su --login` (it cleared DISPLAY → `Cannot open display: .`). +- `nh-x11` traps cleanup on EXIT/INT/TERM before the DE poll so a failed start still wake-unlocks. +- `/etc/tls/cert.pem` compat symlink is written into the Kali rootfs (not only live `/etc` on Termux). +- `grokhunter binds` matches jorexdeveloper `--bind=` / `proot_args+=(--bind=)` launchers; `optimize` now fails if the patch does not apply. +- `git-identity` sanitizes a missing `SSL_CERT_FILE` before `gh api`, not only the curl fallback. +- `nh-x11` tracks the `termux-x11` PID (cleanup + xserver log on socket timeout), aborts if the guest runtime dir cannot be created, and tails `nh-x11.log` when the session exits after “desktop is up”. +- TLS rewrite/compat lives in `lib/tls.sh` (probe, identity, doctor, install). `grokhunter binds` lives in `lib/x11.sh`. One `_gh_install_bwrap_stub` is shared by setup and `nh-x11`. + +### Branding +- Converted `branding/*.png` from JPEG-named files to real PNG (icon, favicon, lockup). +- Wired assets into README, product site (header, hero, favicon, Open Graph / Twitter card), and XFCE menu (`Icon=grokhunter`). +- Site accent shifted to brand cyan `#00E5C7`. Tagline: **Ship code from your pocket.** +- Site palette aligned to brand charcoal `#0D1117` / cyan `#00E5C7` (no leftover phosphor green). +- Share cards: `og.jpg` 1200×630 (Open Graph / Twitter). `x-banner.jpg` 1200×264 is an X profile header (upload in X settings, not HTML). Dropped `social-preview.jpg` alias and `x:game:image` meta. +- README hero uses the GH icon + charcoal/cyan shields (drop the noisy lockup). +- Rebuilt all raster brand assets from a geometric G mark (crisp PNG/SVG, no photographic lockups). +- Color scheme shout-out to Kali Linux: official blue `#2777FF` alongside Grok cyan. +- NetHunter dragon red `#E31C3D` on hero, chips, architecture, and credits. +- Baked dual accent bar (Kali blue | NetHunter red) into all brand rasters, lockups, share cards, and palette. +- Split binary assets into `assets-*.b64.json` packs + sidecars; deploy always runs `decode_assets.py`. +- Product site: Wave 6 agents, `grokhunter binds`, 20 skills, X11 FAQ (legacy drawing is the default). + +### Lab specialists + +- Playbooks catch up to Unreleased: `grokhunter binds`, TLS/`lib/tls.sh`, `bwrap-proot` / glycin. Thin agents/skills gain Common failures + Verify. +- Wave 6: agents **`github`**, **`secrets`**, **`toolchain`** (skills already existed). `grokhunter github` launches the agent; CLI is `grokhunter git-identity`. No binds agent — Desktop owns `grokhunter binds`. +- Specialist add recipe in `agents/README.md` (skill-only vs agent+skill; CLI collisions; ci-unit). +- Optional skill **`specialist-lab`** — Grok-invocable playbook for that recipe (no new agent; not N/3). Wired into grokhunter decision tree, Coding Team routing, and FAQ. +- Agent discover skips uppercase doc files (`REFERENCES`, `HANDOFF-TEMPLATES`). `grokhunter agents` launch line includes Wave 6 (`github` | `secrets` | `toolchain`). +- Optional skills **`toolchain`** (apt / Aider Python 3.12 / storage) and **`github-lab`** (`git-identity` playbook) +- Agents **`overlay`**, **`ship`**, **`docs`** plus roles/personas and Coding Team routing +- `grokhunter overlay|ship|docs` launchers + completions +- `grokhunter` skill refreshed for 1.0.9 (identity, doctor, PATH) +- Wave 2: skills **`grok-models`**, **`ci-lab`**, **`secrets-lab`**; agents **`models`**, **`ci`**, **`aider`** (`grokhunter modeler` so it does not collide with `grokhunter models`) +- Wave 3: skills **`session-lab`**, **`host-lab`**, **`mcp-lab`**; agents **`session`**, **`host`**, **`mcp`** (`grokhunter mcp` launches the agent; CLI is `grok mcp`) +- Wave 4: skills **`plugin-lab`**, **`flow-lab`**, **`storage-lab`**; agents **`plugin`**, **`flow`**, **`storage`** (`grokhunter plugin` launches the agent; CLI is `grok plugin`) +- Wave 5: skills **`editor-lab`**, **`hooks-lab`**, **`shell-lab`**; agents **`editor`**, **`hook`**, **`shell`** +- Overlay cache **2026.2.25** (was 2026.2.18 in Unreleased) + +## [1.0.9] — 2026-08-22 — Doctor truth + GitHub identity + +Doctor stops treating a working lab as offline or incomplete. Git commits attach to GitHub instead of `invalid-email-address`. Overlay cache **2026.2.13**. + +### Status / doctor follow-ups + +- `grokhunter status` treats current **and** legacy V9 config markers as `models=yes` +- Clone-only installer cache is informational (`ok`), not a yellow warning + +### Doctor environment + +- Missing `/etc/os-release` is a warning, not a hard fail (Termux host / incomplete rootfs) From f4228e024b7cc06ec31802c43b6a4c45f73e97e4 Mon Sep 17 00:00:00 2001 From: Fine_Computer_4451 <119702188+FineComputer14451@users.noreply.github.com> Date: Fri, 4 Sep 2026 09:29:09 -0700 Subject: [PATCH 3/4] feat(tookie): credits, playbooks, completions, handoff card --- CREDITS.md | 1 + skills/PLAYBOOKS.md | 1 + 2 files changed, 2 insertions(+) diff --git a/CREDITS.md b/CREDITS.md index 4662c2c..344abad 100644 --- a/CREDITS.md +++ b/CREDITS.md @@ -92,6 +92,7 @@ Support: [x.ai](https://x.ai) · [x.ai/cli](https://x.ai/cli) |---------|--------| | **Aider** | Optional git-native pair tool — [aider.chat](https://aider.chat) | | **Astral uv** | Used by the Aider install path for managed Python — [astral.sh/uv](https://github.com/astral-sh/uv) | +| **Tookie-OSINT** | Optional scoped username lookup (`tookie-osint` / `brib.py`) — [github.com/Alfredredbird/tookie-osint](https://github.com/Alfredredbird/tookie-osint) | --- diff --git a/skills/PLAYBOOKS.md b/skills/PLAYBOOKS.md index 6af530a..db62a99 100644 --- a/skills/PLAYBOOKS.md +++ b/skills/PLAYBOOKS.md @@ -72,6 +72,7 @@ grokhunter models install grokhunter git-identity set grokhunter tls grokhunter net +grokhunter tookie grokhunter ai-smoke bash scripts/ci-unit.sh nh-x11 # legacy drawing on; NH_X11_LEGACY=0 to disable From aeb5b63fbc0ff488670e9729d880ce79cb90a2d7 Mon Sep 17 00:00:00 2001 From: Fine_Computer_4451 <119702188+FineComputer14451@users.noreply.github.com> Date: Fri, 4 Sep 2026 09:30:47 -0700 Subject: [PATCH 4/4] feat(tookie): zsh completion + Tookie handoff card --- agents/HANDOFF-TEMPLATES.md | 13 +++++++++++++ config/completions/zsh/_grokhunter | 1 + 2 files changed, 14 insertions(+) diff --git a/agents/HANDOFF-TEMPLATES.md b/agents/HANDOFF-TEMPLATES.md index 7fd4ba7..2320770 100644 --- a/agents/HANDOFF-TEMPLATES.md +++ b/agents/HANDOFF-TEMPLATES.md @@ -335,3 +335,16 @@ overlay | desktop | toolchain ## Commands ## Verify (doctor x.ai — never print bodies) ``` + +--- + +## Tookie card (tookie) + +```markdown +## Username +## Authorization +## Command +## Hits +## Uncertain +## Next public checks +``` diff --git a/config/completions/zsh/_grokhunter b/config/completions/zsh/_grokhunter index 35c0514..2b4c2a0 100644 --- a/config/completions/zsh/_grokhunter +++ b/config/completions/zsh/_grokhunter @@ -43,6 +43,7 @@ _grokhunter() { 'toolchain:Launch apt/compiler agent' 'tls:Launch TLS/CA agent' 'net:Launch HTTPS/DNS agent' + 'tookie:Launch Tookie-OSINT agent' 'benjamin:Launch benjamin architect agent' 'lucas:Launch lucas builder agent' 'harper:Launch harper reliability agent'