GrokInstall

A single binary, no service, no model

Your context already has
the answer. Install it for the cases
that need a runtime.

GrokInstall answers one question honestly: when an agent is told to use a capability, does it need installing at all? If not, it stops. If so, it provisions, verifies and confines. If the safest route needs more authority than the safe policy allows, it refuses and changes nothing.

bat.review 432 B

Three answers, and only three.

Most "set this up" instructions do not need an installation. GrokInstall is built to notice that, and to be unembarrassed about saying so.

A refusal is a feature.

Asked to make click callable, the only safe route was a Python install whose build backend may execute packaging code. GrokInstall refused, named the blocker, and registered nothing. This is the real output:

To proceed deliberately, you name the risk class. There is no generic --yes.

registered
nothing
system state
unchanged
staging residue
none
to override
--allow-install-scripts

Verify before you run it.

Download the binary and the checksum file from the release. Check the checksum first. There is no install script to trust.

Download

gh release download v0.1.1 \
  -p 'grokinstall_0.1.1_darwin_arm64' -p SHA256SUMS

Verify

shasum -a 256 -c SHA256SUMS

Checksums are cross-checked with an independent implementation before publishing.

Use

./grokinstall_0.1.1_darwin_arm64 inspect \
  https://github.com/sharkdp/bat

Published checksums

    Prefer a package manager? go install github.com/M4G3LL4N0/grokinstall/cmd/grokinstall@latest

    What was actually run.

    Figures come from the published binary on darwin/arm64, not from a development build. Development builds identify themselves as such.