⚒️ Grok Forge — the unofficial Grok app for VS CodeForge whatever you decide you want to make. Images through Imagine. Code through Grok Build. All from friendly chat tabs in VS Code — running on your own Grok subscription, with the terminal kept completely out of sight.
🆕 What's new in 1.3 — "Say It Once"Plan mode plans, and Accept means accept. Picking Plan on a chat that was already running could leave Grok in its normal mode — Forge blocked the edit, but no plan ever arrived. And when a plan did arrive, Forge had already answered it with "the user wants to revise", so Grok asked what to change right above the Approve button. Both are fixed: your click is now Grok's answer, and Accept starts the build in the same turn — watched working in a real editor. Forge says each thing once. The transcript stops filling with connection notices and cleanup receipts. The Ask-first and Plan disclosures come from one source and sit in one banner for the mode you are actually in, instead of a stack of amber boxes that included one for a mode you had already left. The part of each disclosure that admits what Forge cannot see is no longer the part that gets cut off. A new MCP server can be approved. Vet & approve on a never-approved server did nothing at all; it now vets and approves. The Plugins & MCP panel no longer shows disabled plugins as live, and a plugin's server row says exactly what Forge can do about it: disable the whole plugin, not that one server. Your X-High effort setting is kept when Forge can't identify the model, instead of being dropped with an explanation that wasn't true. Agent lanes keep their real names when Grok runs a helper in the foreground — those used to stay labelled "Subagent 1". And a plan left waiting 30 minutes says it expired instead of leaving an Accept button that looked live. Still true, still stated: Grok's own shell can read files Forge refuses, Ask first does not mean every command asks, and MCP servers are not inside Forge's sandbox. The changelog lists these rather than leaving them for you to find. 🆕 What's new in 1.2 — "Nothing Disappears"Deleting a chat asks first, and can be undone. Every row in Recent used to carry a delete button that was invisible until you hovered, sat inside the row you click to open the chat, and destroyed it on a single click — no confirmation, no undo, no trash. It ate a real transcript mid-session, which is how it was found. The button is now visible at rest, the first click asks and names the chat it will destroy, and deleted chats stay recoverable for 30 days with an Undo offered the moment one goes. A step you refused stops looking like a crash. Expanding a turn marked blocked showed a red ✗ beside the step you had just declined — reporting your own decision back to you as a failure. It now shows a muted ⊘ that matches the badge above it. A genuine failure keeps its red ✗. Plan mode's disclosure fits on the screen, and is accurate. The part that admits Grok auto-runs
some commands Forge never sees was being clipped mid-sentence, so you read the promise and none of
the exception. It now sits in a banner that wraps and cannot be missed — and it no longer says
"directory-level", because a bare A missing file is reported as a missing file. A failed read used to say "that folder wasn't found" and blame a tool that never ran. Eight defects, six of them found by a person using the product rather than by the 2,007 unit and 614 browser tests — including two inside the fix for the first one. The changelog says which, and why the tests missed them. 🆕 What's new in 1.1 — "See It Work"Turn a generated sprite into a transparent PNG. Ask for game art in one of the 2D modes and
the lightbox offers Remove background — it previews the result on a checkerboard so you can
actually judge it, then Rename / Add to assets/ writes it into your project with a row in
The keyer cuts a matte, not a hole. Anti-aliased and JPEG-compressed edges used to survive as a bright ring of key colour around the sprite — measured at 14.7% of the visible subject on a real generated sprite. Forge now recovers how much of each edge pixel is background and unmixes the key back out, taking that to 1.94% with ~30,000 genuinely soft edge pixels where there were none. See what each subagent actually said. Run two agents in parallel and every lane gets a toggle that opens onto its own words — its reasoning, its tool calls and what it wrote — instead of a step count. Plan mode says what it actually does. It now names exactly what it blocks (file edits and
content-writing shell commands), names the exception it cannot see (simple shell commands that
create files and folders — Limits worth knowing before you install. An MCP server's question now renders and answers, and agent lane transcripts now survive reopening a chat — both were limits here in 1.1 and both were fixed and verified in a real editor. What remains: a required field on an MCP question will still accept an empty answer, and Plan mode has a second gate inside Grok that refuses edits without explaining itself. Both are written up in the changelog rather than left for you to discover — as is the larger one, that Grok auto-runs some simple commands Forge never sees at all. 🆕 What's new in 0.9 — "Parity II"Plan mode — read the plan before Grok edits your files. A Plan pill in the
chat title bar flips Grok into planning: it investigates your code and writes up what
it intends to do instead of doing it. The plan arrives as a card you can actually
read, and Forge blocks file edits and content-writing shell commands until you approve
it — then Grok switches back and carries it out. Reading and searching still work, so
Grok can research first. Toggle it mid-conversation for the one risky change and come
straight back out. Connect your own tools (MCP) with the new Manage MCP
Servers command — Forge connects to each server itself first, reads back every
tool it offers, and shows you the list to approve; a server you add reaches Grok
only once you approve it, and if it later changes its tools the approval is void. (A
Grok plugin can also bring its own MCP server, which bypasses that flow entirely —
the Plugins & MCP panel shows you those and says so.) Grok reads your
🆕 What's new in 0.8 — "Checkpoints & Speed"Checkpoints — a safety net for letting Grok edit. Every message you send now
snapshots your project first. A clock button in the chat title bar lists every
turn; click one and your files roll back to exactly how they were before it — an
edit undone, a deleted file restored, a file Grok created removed. It reverts
files only (your conversation with Grok stays exactly as it is) and never
touches your own Git history or your 🆕 What's new in 0.7.5 — "Polish"A bigger, cleaner media viewer. Open a tall image or clip in a wide window and the viewer now splits into three columns — actions on the left, the media centred and filling the full height, caption and Refine on the right — instead of a narrow strip with wide black margins. The clip gets about two-thirds more area, the description shows in full, and it flips back to the familiar stacked layout on narrow panels automatically as you resize. Plus a history button in the chat title bar to jump straight to any past conversation, a Stop button that stays reachable from inside the viewer, and a round of security hardening — Grok no longer inherits your whole environment (including your SSH agent). Full details on the Changelog tab. 🆕 What's new in 0.7Video. Every generated image now carries a ▶ badge — click it, pick 6 or 10 seconds, and watch the video appear right where you're looking: a spinner with a live second-count runs on the image itself, then the finished clip replaces it in place. Nothing closes, nothing kicks you back to the chat, and the conversation stays clean — no repeated photos, no restated requests. Open a clip and describe the motion in plain English ("camera cranes up", "360° orbit") to re-animate it, or use the ✨ Suggestions picker (Camera · Lighting · Mood · Style) in either composer. A photo and everything made from it now share one gallery tile: the grid shows the newest version, ‹ › flips across tiles and ↑ ↓ walks a tile's history back to the original. 0.7 also ships a security hardening pass: credential files ( Security, stated plainly. Grok Forge runs a real coding agent on your machine — that
is the point of it — and it is the only way to run Grok Build with an OS-level sandbox in
front of it. Forge launches Grok under a kernel profile that denies We would rather tell you where it stops. All three are open, all three are upstream, and all three were re-verified against grok 1.0.13 on 2026-08-29 rather than assumed:
We publish what we have measured, including the parts that make us look worse. A tool that hides its own holes is a tool you cannot calibrate against. Full detail, measured against this build rather than assumed: docs/SECURITY.md. What you get
Getting started
Settings
How it worksGrok Forge speaks the Agent Client Protocol (ACP) to a persistent LicenseMIT. Not affiliated with xAI — see the disclaimer above. |