Highlights
X works out of the box on Grok Bot
Grok Bot users now get X results in /last30days with zero setup. The bot fetches posts through its own built-in X tools (free, no plugin, key, or X API credits), then falls back to the X for Grok Bot connector and the official X API keys. Busy topics get a popular pass across the whole window, so reports surface the month's most-engaged posts instead of only the last few minutes of chatter. The footer reads "via Grok Bot X". (#1235)
In live runs on Grok Bot across 7 topics: 186 X posts, 100% with likes, reposts, replies, and quotes, and 79% judged on-topic in a blind review.
Host-fetched X (--x-posts) on any host can now fill the same topic budget as the engine's own two X fetches (24 posts at default depth, up from 12).
Security
- Bearer tokens in
github.pyandtranscribe.pyare now dropped on cross-origin redirects. (#1154) - Grok X research runs behind an audited agent profile with no local tools; topics enter the prompt as escaped JSON literals. (#1161)
- Private corpus titles no longer appear in published library briefs, indexes, or feeds. (#1204)
- Reading browser cookies through Chrome debugging sessions now requires explicit, saved consent. (#1208)
Also in this release
- The skill now loads its instructions by research stage and mode, keeping the entry point short. (#1231)
- 36 fixes, including deadline-bounded X searches and source waits, MCP cancellation and orphan-process cleanup, preserved date windows for Reddit and X, watchlist budget accounting, slash topics such as
CI/CDno longer triggering comparisons, and Serper's recent results no longer being dropped. Full list in CHANGELOG.md.
Update: grok plugin update last30days, claude plugin update last30days, or re-run npx skills add mvanhorn/last30days-skill -g -y.
What's Changed
- chore(deps): bump astral-sh/setup-uv from 10.1.0 to 10.2.0 by @dependabot[bot] in #1203
- chore(deps): bump github/codeql-action/upload-sarif from 4.38.0 to 4.38.2 by @dependabot[bot] in #1202
- chore(deps): bump trufflesecurity/trufflehog from 3.97.4 to 3.97.9 by @dependabot[bot] in #1200
- chore(deps): bump google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml from 2.5.1 to 2.6.0 by @dependabot[bot] in #1174
- chore(deps): bump github.com/mark3labs/mcp-go from 1.0.0 to 1.1.1 in /mcp by @dependabot[bot] in #1201
- fix(mcp): separate topic from engine flags by @iliaal in #1162
- fix(cookies): require complete pairs before accepting by @iliaal in #1163
- fix: require durable consent for browser cookie discovery by @iliaal in #1208
- fix(pipeline): isolate discovery worker config by @iliaal in #1160
- fix(pipeline): harden failure classification by @iliaal in #1164
- fix(x): report handle-lane failures instead of silent no-results by @iliaal in #1116
- fix: honor source selection in supplemental X searches by @iliaal in #1210
- fix: preserve requested Reddit search date windows by @iliaal in #1213
- fix: preserve complete job boards in hiring signals by @iliaal in #1212
- fix: preserve slash topics outside comparison mode by @iliaal in #1211
- fix: keep private briefing titles out of public libraries by @iliaal in #1204
- fix: preserve watchlist settings when saving research by @iliaal in #1206
- fix: preserve shared research when removing watchlist topics by @iliaal in #1207
- fix: retain normalized community comments in rerank prompts by @iliaal in #1218
- fix: bind evaluation caches to their complete judge inputs by @iliaal in #1219
- fix: use the resolved skill directory in HTML export commands by @iliaal in #1221
- fix: respect host and tool instructions in research output by @iliaal in #1220
- fix(mcp): bundle the research persistence module by @iliaal in #1205
- fix(mcp): serialize concurrent engine cache publication by @iliaal in #1215
- fix(ci): tighten coverage source and engine sync guards by @iliaal in #1167
- fix: apply Bird end dates to every X query by @iliaal in #1216
- fix: account for watchlist spending before scheduling more topics by @iliaal in #1214
- fix: preserve earlier HTML briefs during repeated exports by @iliaal in #1222
- fix: resolve slash-command save paths through engine configuration by @iliaal in #1217
- fix: retain consented Chromium authentication after setup by @iliaal in #1209
- fix(mcp): terminate descendant groups on timeout by @iliaal in #1166
- fix(pipeline): bound X-chain and stream waits with deadlines by @iliaal in #1165
- fix(grok): escape the X topic and strip non-X tools from the privileged grok run by @iliaal in #1161
- fix(discovery): preserve coverage warnings across protocol legs by @iliaal in #1223
- fix(http): strip credentials on cross-origin redirect for github.py and transcribe.py too (#1062 follow-up) by @ahhhdum in #1154
- docs: use --plan tmpfile form consistently (fixes #1194) by @TTNAN in #1196
- fix(env): read
export KEY=value.env lines as KEY (#930) by @OSideMedia in #1152 - fix: keep the runtime preflight intact under Claude Code argument substitution by @alexandercroft in #1141
- fix: honor XAI_BASE_URL and OPENROUTER_BASE_URL on the X search and Sonar paths by @superbiche in #1181
- docs: qualify no-key-sharing claim with TikTok legacy fallback (fixes #1185) by @TTNAN in #1197
- fix(ci): resolve the changelog guard's base at job time by @ahhhdum in #1153
- fix(tests): stop the developer's own xurl token store leaking into tests by @ahhhdum in #1158
- fix(grounding): parse Serper's relative dates instead of dropping the results by @sunnyseed in #1156
- fix(hackernews): attach top comments by calling enrich_top_stories by @MohammadHijjawi97 in #1170
- test: enforce offline transport isolation by default by @iliaal in #1228
- test: make privacy and authentication fixtures discriminate by @iliaal in #1224
- fix: isolate competitor context and exercise real orchestration by @iliaal in #1227
- test: strengthen numeric, payload, and concurrency oracles by @iliaal in #1225
- fix: repair remaining test oracles and manual comparison outcomes by @iliaal in #1226
- fix: bound doctor and Reddit transport lifetimes by @iliaal in #1229
- refactor(skill): load instructions by stage and mode by @iliaal in #1231
- feat(x): give Grok Bot users X with zero setup via its built-in X tools by @mvanhorn in #1235
- chore(release): bump version to 3.27.0 by @github-actions[bot] in #1236
New Contributors
- @TTNAN made their first contribution in #1196
- @OSideMedia made their first contribution in #1152
- @alexandercroft made their first contribution in #1141
- @superbiche made their first contribution in #1181
- @sunnyseed made their first contribution in #1156
- @MohammadHijjawi97 made their first contribution in #1170
Full Changelog: v3.26.0...v3.27.0