Easter eggs, missing chapters & code-level secrets

Power-user archaeology

Easter eggs, missing chapters & code-level secrets

Four agents mined Grok Build skills, Web Build platform code, CLI community docs, and Imagine pipelines. This is what most manuals never ship.

HeavyMined from internal Build skills + platform kit + public CLI/Imagine power-user reports (Aug 2026). Verify live when something is rollout-gated.

Key information that was missing (now covered here)

GapWhy it matters
CLI memory: /flush /dream /remember /loopLong sessions and agent-as-cron without re-explaining context
grok wrap, /btw, Esc Esc, ! shell, @ filesDaily TUI speed that never appears in marketing
Web Build auth popup rules#1 footgun — React route on /auth/popup breaks sign-in
PGLite vs Neon, no .env, user_id TEXTPreview data dies on restart; UUID columns break auth users
P2P multiplayer at /api/rtc2–8 player co-op is built-in; competitive ranking is not
#FF00FF magenta asset pipelineWrong key color = broken sprites/maps forever
window.__controlsTest + ?qa=1Only reliable way to prove A = left before shipping games
Runtime XAI_API_KEY models (grok-4.5, TTS eve)In-app AI spends the owner's credits — must gate
OG cards via og.grok.me onlyNo custom /api/og; preview has no share card
Nitro only on build; 0.0.0.0:8080 contractWrong port or nitro-in-dev = blank live preview

CLI easter eggs most people miss

  • /loop [interval] prompt — recurring agent jobs (min ~60s; 5m / 1h / 1d). Acts like a smart cron. Auto-expires after ~7 days. Example: /loop 10m Check deploy health; stop if green three times.
  • Experimental memory — enable with --experimental-memory or GROK_MEMORY=1:
    • /flush — write session knowledge to memory before compact
    • /dream — consolidate logs into topics
    • /remember … — pin a note (workspace or global)
  • /btw question — side-channel Q&A that does not derail the main coding thread.
  • ! shell mode — type ! (or !git status) for shell without leaving the agent.
  • @file mentions — @src/main.ts attaches files into the prompt.
  • Esc Esc (~800ms) — clear draft or open rewind picker.
  • grok wrap ssh … — fixes OSC 52 clipboard through SSH/tmux/Docker.
  • grok inspect --json — every skill/MCP/hook/AGENTS.md with token cost. First command when “skill didn’t load.”
  • Worktree CLI — grok worktree list|show|rm|gc, session -w/--worktree, headless per-branch farms.
  • ACP + MCP dual stack — grok agent stdio for IDE bots; grok mcp doctor / TUI /mcps.
  • Claude migration — grok import, /import-claude, /resume-claude.
  • /help burns context — model-driven (~30s, ~7% context). Don’t spam mid-epic session; keep this manual open instead.
  • /yolo can persist across sessions — check before production monorepo work.
  • CI flags — --no-auto-update, --output-format json, optional --json-schema, sandbox modes workspace|read-only|strict|devbox.
Parallel bug-fix farm (worktree pattern)
grok worktree list
# one worktree per issue, headless always-approve only when safe
grok -w fix-auth --always-approve -p "Fix failing auth tests only"
grok -w fix-ui  --always-approve -p "Fix mobile overflow on /pricing"

Web Build Mode secrets (from the platform kit itself)

These are not documented in consumer marketing

They live in the Build agent’s skills and template code — the same stack that builds apps in your live preview.

  • Preview binds 0.0.0.0:8080 with strictPort — other ports are unreliable for the live preview proxy.
  • Nitro must not run in dev — only on production build. Nitro-in-dev opens a second port and blanks the preview.
  • startup.sh is revive insurance — hibernate/restore re-runs it; without an idempotent background start, preview dies.
  • PGLite in preview, Neon when DATABASE_URL exists — preview DB is wiped on restart; never invent a .env.
  • user_id columns must be TEXT — Better Auth ids + dev-user dev-user; UUID columns break inserts.
  • Never edit migrations/0001_auth.sql — app tables start at 0002_.
  • Auth is ON by default in preview — real Google/X via broker; no mock users. Off only with VITE_AUTH_ENABLED=false.
  • Only Google + X social — broker rejects other IdPs. Email/password: flip emailAndPasswordEnabled in one file only.
  • OG share cards — og.grok.me/v1/card.png?host=…&title=… only. No custom OG route. Live preview has no card (no hostname).
  • “Created with Grok” banner — hide via project settings, never by deleting the component. Remix needs forking + project id flags.
  • Blank production deploy classic — SPA fallback serving HTML for /assets/* causes wrong MIME. Verify production build, not only dev HMR.
  • npm install scripts blocked — native modules may need GROK_ALLOW_INSTALL_SCRIPTS=1; prefer pure JS.

The #FF00FF easter egg (sprite/map pipeline)

Grok Build’s 2D art pipeline is not “any green screen.” Chroma scripts flood-fill from corners and hard-require solid flat #FF00FF magenta.

  • Sprite sheets, prop packs, map bases — same rule
  • Empty prop cells: prompt phrase empty magenta cell
  • Video→sprite: walk in place, camera locked, magenta background preserved; export 8/16/24/48 frames
  • Magic handoff phrase after the agent reads an image: use the image just shown as the visual reference (path strings alone do not count)
  • Do not raw-generate mixed “idle/run/attack” atlases — generate per-action grids, QC, then assemble
  • Hero body shrink over about 10–15% vs idle equals fail (wide FX on body sheets)
  • Maps: foundation terrain only first, then at most 9 props as separate assets + collision — never one baked screenshot map
  • Side-scroll default canvas when unknown: 1536×864

Game control easter egg: window.__controlsTest

Screenshot-only QA is explicitly insufficient for vehicles/flight. Wire a probe in DEV or with ?qa=1:

Minimal probe
// window.__controlsTest in DEV or ?qa=1
{
  getYaw: () => number,   // radians
  getSpeed: () => number,
  setSteer?: (v: number) => void, // -1..1
}

// Basis: yaw=0 faces -Z; forward = (-sin(yaw), 0, -cos(yaw))
// A while moving forward must INCREASE yaw (nose left on chase cam)
// Canonical bug: KeyA → steer -= 1  // ships inverted

Reverse gear still needs “left feels left”: multiply yaw delta by reverse = speed >= 0 ? 1 : -1.

Multiplayer easter egg: free P2P mesh

Web Build can ship 2–8 player casual co-op without a game server. Game packets are browser-to-browser; only handshake hits /api/rtc.

  • Client: P2PRoom from multiplayer kit
  • You add signaling once at route /api/rtc
  • broadcast() = unreliable state (positions); send() = reliable events — never stream game-rate on send
  • Late join: only the smallest selfId among already-present peers answers with full state
  • Default room = first DNS label of hostname (max 64 chars)
  • About 10–20% of NAT pairs fail — surface connection failed in UI
  • Never competitive ranking / anti-cheat on P2P — peers can lie; IPs are visible during ICE
  • STUN override: VITE_STUN_URLS comma-separated

Runtime xAI API (your app calls Grok)

When building apps, XAI_API_KEY may be injected server-side — the app owner’s credits.

UseModel / endpoint
Chat defaultgrok-4.5 → POST /v1/chat/completions
Image qualitygrok-imagine-image-quality
Image cheapergrok-imagine-image
Video (async poll)grok-imagine-video (~15s clips)
TTS default voicePOST /v1/tts voice_id: "eve"
Base URLhttps://api.x.ai/v1 (OpenAI-compatible)
Spend trap

Never call on page load, every keystroke, or in a loop. Gate media gen behind sign-in. Never put the key in VITE_* or the browser.

Imagine craft easter eggs

  • @-tag references in prompts so each slot has a role (@face, @outfit, @location).
  • Edit-chain for stills: one master → all variants via edit; keep style words every time or faces drift photoreal.
  • Viewer-relative asymmetry tables for turnarounds (“sleeved arm is viewer’s RIGHT in front”).
  • Charts / exact text → code (HTML/CSS), never image_gen.
  • Real people → image_edit + real reference only.
  • Assemble video with ffmpeg -c copy — never re-encode if resolutions match.
  • Voice reference on API may be sales-gated; consumer UI for Heavy/Plus first.

The #1 Web Build footgun

Never do this
// WRONG — creates a React page that paints the full app inside the OAuth popup
src/routes/auth/popup.tsx

// RIGHT — /auth/popup is already handled by Vite middleware (popup.server.ts)
// signIn() must open the popup on the same tick as the click (no await first)

Live preview is an iframe with partitioned cookies → popup + bearer in sessionStorage, not a full-page redirect. Cookie name prefix __Host- blocks sibling grok.me cookie tosses.

Unfair combos only Heavy users usually run

  1. /skillify studio design → every Web Build inherits taste
  2. Magenta sprite sheets → game → Imagine trailer with same character bible
  3. Worktree farm + /loop monitor + headless -p overnight
  4. P2P party game + TTS voice eve for announcer lines (server-side)
  5. /flush before compact on long CLI epics so decisions survive
  6. Hostinger Cloud Startup: dedicated IP A-record + staging + on-demand backup + LSCache + CDN after Grok static export
Tip

Related chapters: Hidden powers · Cheat sheet · CLI · Games · Video