Bread implements Grok's documented command-hook contract, but Grok Build has not yet completed Bread's live CLI release gate. Treat every Grok capability below as implementation coverage that requires a disposable sandbox check before relying on it for enforcement.
| Capability | Status | Behavior |
|---|---|---|
| Project hooks | Implemented; live validation pending | .grok/hooks/bread.json; requires /hooks-trust or --trust |
| User hooks | Implemented; live validation pending | ~/.grok/hooks/bread.json via explicit bread install grok-user |
| SessionStart | Implemented; live validation pending | Starts the shared daemon through the normal hook path |
| PreToolUse | Implemented; live validation pending | Restricted Edit/Write/apply_patch paths return decision=deny; exit 2 |
| PostToolUse | Implemented, observe-only | No stdout mutation; native result remains untouched |
updatedInput | Unsupported | Pass-through |
| Result replacement | Unsupported | Pass-through |
| Prompt injection | Unsupported | Pass-through |
| ACP | Not a hook surface | Test separately; Bread does not speak ACP |
Grok treats only explicit decision: deny as blocking. Hook crashes,
timeouts, malformed output, and other non-zero failures are fail-open in the
documented contract. Bread therefore emits no synthetic success payload and
does not claim rewrite or result-substitution support.
User-hook lifecycle and compatibility
bread install grok-user writes Bread's hook configuration to
~/.grok/hooks/bread.json and keeps any prior file at
~/.bread/grok-hooks.backup. bread uninstall grok-user restores that backup
when it exists; otherwise it removes the Bread-owned file. Project hooks use
the same layout under the target repository and keep their backup in that
repository's .bread/ directory. Workspace indexes and daemon state remain
workspace-local; a user hook does not move source content into HOME.
The generated manifest binds SessionStart, PreToolUse for
Edit|Write|apply_patch, and observe-only PostToolUse for
Read|Edit|Write|apply_patch. Review that manifest through Grok's trust flow
before enabling it.
No Grok Build CLI version is live-validated yet. Record the exact CLI version and output format in the disposable sandbox, and treat an unsuccessful or unrun check as unsupported for enforcement-sensitive workflows.
Disposable validation
Use scripts/cli-sandbox for live tests. Run them in this order: Codex CLI,
Claude Code CLI, Grok Build CLI. Use the cheapest capable model and record the
CLI version, model, output format, trust state, and exit status. Authentication
must happen only inside the named sandbox.
The deterministic fixture uses grok -p with --output-format json or
streaming-json, --no-auto-update, and a pinned --model. ACP smoke is a
separate stdout-integrity check and must not be mixed with hook JSON.
Sources checked 2026-07-14:
- Grok Build hooks
- Grok Build headless and scripting
- Grok Build skills, plugins, and marketplaces
- AgentBench, for multi-dimensional agent evaluation and failure analysis