open source grok bot. gawk bots automate your menial work via AI models and build you microapps to manage the outcome, so that you have a false sense of control.
Requires a passing catalog security scan. Resolve the flagged issues and resubmit to enable featuring.
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
# Add to your Claude Code skills
git clone https://github.com/najmuzzaman-mohammad/gawkbotGuides for using ai agents skills like gawkbot.
Last scanned: 8/26/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@secretlint/config-loader: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@secretlint/node: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@secretlint/secretlint-rule-pattern: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@secretlint/tester: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@vitest/coverage-v8: Vulnerability found",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "@vitest/mocker: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "ajv: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "esbuild: esbuild enables any website to send any requests to the development server and read the response",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "fast-uri: fast-uri vulnerable to host confusion via literal backslash authority delimiter",
"severity": "high"
},
{
"type": "npm-audit",
"message": "secretlint: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "vite: Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling",
"severity": "high"
},
{
"type": "npm-audit",
"message": "vite-node: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "vitest: Vulnerability found",
"severity": "critical"
}
],
"status": "FAILED",
"scannedAt": "2026-08-26T04:38:37.214Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}See how gawkbot compares with popular alternatives.
https://github.com/user-attachments/assets/84c4b8cf-fb5d-4e9b-b720-213648c2e20b
gawkbot lets anyone turn their manual workflows into microapps across 1200+ integrations in minutes. Describe the job in one sentence — or demo it once on a call — and your AI builds the bot that runs it: its own screen, its own schedule, its own tools, with a human approval gate on everything it sends. Runs local, on your machine, on your account.
gawkbots automate your menial work via AI models and build you microapps to manage the outcome, so that you have a false sense of control.
grok (verb) — to understand something profoundly and intuitively. gawk (verb) — to stare openly and stupidly.
It is named after the second one. Not after the bots. The bots are working. You are the one with the dashboard open.
gawkbot is an open source Grok Bot: always-on AI bots on your own machine instead of xAI's cloud, free, on the coding bot you already pay for, with an approval gate on every external action. The honest version, row by row:
| Grok Bot (xAI) | gawkbot | |
|---|---|---|
| Price | Bundled with SuperGrok and Cursor paid plans | Free. No account, no seats, no usage fees |
| Source | Closed | Public, Sustainable Use License |
| Runs on | xAI's cloud | Your machine, with your keys |
| Models | Grok, chosen for you | Claude Code, Codex, Opencode, local models, Hermes, OpenClaw |
| Bot computers | One per bot, in the cloud | Not yet. Per-bot directory and tool allowlist on your machine |
| Approvals | Bots act on your accounts around the clock | Every send, commit, purchase, and delete waits for your click |
Full comparison, where Grok Bot is better, and the other open source alternatives (Rakazo, OpenMausBot, OpenBot): gawk.bot/open-source-grok-bot. Website: gawk.bot.
Prerequisites: one bot CLI, signed in — Claude Code by default, or Codex CLI / Opencode. The first-run screen verifies your runtime before anything else happens.
npx gawkbot
That's it. The browser opens, you verify your runtime, name your office, and hand off your first workflow — you land on your first bot being built, live.
Prefer a global install?
npm install -g gawkbot && gawkbot
Building from source (requires Go and Bun):
git clone https://github.com/najmuzzaman-mohammad/gawkbot.git
cd gawkbot
cd web && bun install && bun run build && cd ..
go build -o gawkbot ./cmd/wuphf
./gawkbot
Routine execution runs on a small sidecar service (agent/). The broker
finds and supervises it automatically on source checkouts (set
WUPHF_AGENT_DIR to point elsewhere, or WUPHF_AGENT_URL if you manage it
yourself).
Every bot ships with all six. Not a chatbot in a trench coat.
| Part | What it is |
|---|---|
| The app | A real screen, built live in front of you. Reads and writes real workspace data. |
| Routines | "Every Monday 9:00." Versioned prompts, run history, a transcript per run. New bots get a starter weekly routine from the workflow you described. |
| Tools | Self-authored. "Score a lead." "Post to #ae-handoffs." Teach more in the bot's chat. |
| Knowledge | Wikipedia-style pages about the bot, every claim cited back to its source. |
| Data + integrations | Its own typed tables, plus 1200+ integrations. Connect once; every bot shares it. |
| Approval gate | Reads are free. Writes are held until you tap approve. Then it runs 24x7. |
If your workflow names a system that is not connected yet ("audit our HubSpot"), gawkbot asks before building — build against live workspace data now, or hold while you connect. It never silently re-scopes your job.
Paste this into Claude Code, Codex, or Cursor and let your bot drive the install:
Set up https://github.com/najmuzzaman-mohammad/gawkbot for me. Read `README.md`
first, then run `npx gawkbot` — the web UI opens at http://localhost:7891.
Walk the onboarding: verify the runtime, name the office, and start the first
workflow. Confirm you land on a bot being built (a live build feed beside a
chat), and that when it finishes the bot shows tabs for UI, Routines, Tools,
Data, Knowledge, and Integrations.
For agent conventions read `AGENTS.md`; for internals read `ARCHITECTURE.md`;
for forking read `FORKING.md`.
| Flag | What it does |
|---|---|
--provider <name> |
Runtime override (claude-code, codex, opencode, ollama, hermes-agent, openclaw-http) |
--no-open |
Don't auto-open the browser |
--web-port <n> |
Change the web UI port (default 7891) |
--workspace <name> |
Use a specific workspace for one command (does not change the active workspace) |
--unsafe |
Bypass bot permission checks (local dev only) |
For custom OpenAI-compatible endpoints (LiteLLM, local proxies, Ollama):
WUPHF_OLLAMA_BASE_URL="http://127.0.0.1:20128/v1" \
WUPHF_OLLAMA_MODEL="openai/gpt-5.4-mini" \
gawkbot --provider ollama --no-open
--provider opencode shells out to the opencode CLI binary; MLX-LM and
Ollama can be set up from the first-run screen with no cloud key at all.
Already running Hermes Bot
or an OpenClaw gateway? Point bots at them with
--provider hermes-agent (default http://127.0.0.1:8642/v1) or
--provider openclaw-http (default http://127.0.0.1:18789/v1). Endpoints,
models, and auth are overridable via WUPHF_HERMES_AGENT_* /
WUPHF_OPENCLAW_HTTP_* env vars or provider_endpoints in config.
gawkbot ships with built-in memory — no backend choice, no API key. Your
workspace state lives in local files you can cat: bot knowledge, run
transcripts, and the company brain under ~/.wuphf/. Knowledge pages are
synthesized with citations back to their sources, so you can check the
receipts on anything a bot claims.
gawkbot init # First-time setup
gawkbot share # Invite one team member over Tailscale/WireGuard
gawkbot shred # Delete workspace state and reopen onboarding
gawkbot workspace list # Run multiple isolated workspaces side by side
gawkbot workspace switch <name> # Flip the active workspace
Two ways to invite a teammate, both from the CLI:
Private network — Tailscale or WireGuard. Both machines on the same mesh; the invite never leaves the network:
gawkbot share
Public tunnel — no shared network needed. The broker can spin up a
Cloudflare quick tunnel (POST /api/share/tunnel/start; the trycloudflare
URL is paired with a 6-digit passcode, invites are one-use and expire in 24
hours, and the join handler is rate-limited per source IP). cloudflared
ships with the npm install (pinned SHA256 per platform). The one-click
button for this is being resurfaced in the operator shell — until then the
endpoint is the path.
For the full walkthrough, see Share gawkbot With a Team Member.
Bots act through two providers — pick whichever fits:
Either way, the approval gate holds every external write until you approve it.
gawkbot can send anonymous product analytics and session recordings (with typed text masked) to help us improve it. This is optional, controlled by you, and off unless a PostHog key is configured — a stock source build and every fork ship with no key, so they never phone home.
Two independent toggles (onboarding and Settings), both on by default, both reversible at any time:
maskAllInputs: true): passwords, API keys, and any form field are
obscured. We capture layout, clicks, and navigation to fix rough edges.No autocapture, no cookies (localStorage only). Self-hosted operators can
point at their own PostHog (WUPHF_POSTHOG_KEY / WUPHF_POSTHOG_HOST) or
leave the key unset to keep gawkbot fully dormant. Full taxonomy and policy:
docs/specs/product-analytics.md.
| One bot per workflow | Small enough to read in a minute, real enough to do the whole job — instead of one giant assistant that does everything badly. |
| You watch it get built | The build streams live: the screen, the routine, the tools, assembling in front of you. |
| **Honest |
gawkbot is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by najmuzzaman-mohammad. open source grok bot. gawk bots automate your menial work via AI models and build you microapps to manage the outcome, so that you have a false sense of control. It has 1,380 GitHub stars.
gawkbot failed SkillsLLM's automated security scan, which flagged one or more high-severity issues. Review the Security Report section carefully before using it.
Clone the repository with "git clone https://github.com/najmuzzaman-mohammad/gawkbot" and add it to your Claude Code skills directory (see the Installation section above).
gawkbot is primarily written in Go. It is open-source under najmuzzaman-mohammad on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh gawkbot against similar tools.
No comments yet. Be the first to share your thoughts!