# grok-search-mcp - Doramagic AI Context Pack

> 定位：安装前体验与判断资产。它帮助宿主 AI 有一个好的开始，但不代表已经安装、执行或验证目标项目。

## 充分原则

- **充分原则，不是压缩原则**：AI Context Pack 应该充分到让宿主 AI 在开工前理解项目价值、能力边界、使用入口、风险和证据来源；它可以分层组织，但不以最短摘要为目标。
- **压缩策略**：只压缩噪声和重复内容，不压缩会影响判断和开工质量的上下文。

## 给宿主 AI 的使用方式

你正在读取 Doramagic 为 grok-search-mcp 编译的 AI Context Pack。请把它当作开工前上下文：帮助用户理解适合谁、能做什么、如何开始、哪些必须安装后验证、风险在哪里。不要声称你已经安装、运行或执行了目标项目。

## Claim 消费规则

- **事实来源**：Repo Evidence + Claim/Evidence Graph；Human Wiki 只提供显著性、术语和叙事结构。
- **事实最低状态**：`supported`
- `supported`：可以作为项目事实使用，但回答中必须引用 claim_id 和证据路径。
- `weak`：只能作为低置信度线索，必须要求用户继续核实。
- `inferred`：只能用于风险提示或待确认问题，不能包装成项目事实。
- `unverified`：不得作为事实使用，应明确说证据不足。
- `contradicted`：必须展示冲突来源，不得替用户强行选择一个版本。

## 它最适合谁

- **正在使用 Claude/Codex/Cursor/Gemini 等宿主 AI 的开发者**：README 或插件配置提到多个宿主 AI。 证据：`README.md` Claim：`clm_0002` supported 0.86

## 它能做什么

- **命令行启动或安装流程**（需要安装后验证）：项目文档中存在可执行命令，真实使用需要在本地或宿主环境中运行这些命令。 证据：`README.md` Claim：`clm_0001` supported 0.86

## 怎么开始

- `curl -sS "http://127.0.0.1:8080/panel/v1/admin/operations/metrics" \` 证据：`README.md` Claim：`clm_0003` supported 0.86
- `curl -sS -X POST "http://127.0.0.1:8080/panel/v1/keys" \` 证据：`README.md` Claim：`clm_0004` supported 0.86
- `claude mcp add --transport http grok-search-mcp http://127.0.0.1:8080/mcp \` 证据：`README.md` Claim：`clm_0005` supported 0.86

## 继续前判断卡

- **当前建议**：需要管理员/安全审批
- **为什么**：继续前可能涉及密钥、账号、外部服务或敏感上下文，建议先经过管理员或安全审批。

### 30 秒判断

- **现在怎么做**：需要管理员/安全审批
- **最小安全下一步**：先跑 Prompt Preview；若涉及凭证或企业环境，先审批再试装
- **先别相信**：工具权限边界不能在安装前相信。
- **继续会触碰**：命令执行、本地环境或项目文件、环境变量 / API Key

### 现在可以相信

- **适合人群线索：正在使用 Claude/Codex/Cursor/Gemini 等宿主 AI 的开发者**（supported）：有 supported claim 或项目证据支撑，但仍不等于真实安装效果。 证据：`README.md` Claim：`clm_0002` supported 0.86
- **能力存在：命令行启动或安装流程**（supported）：可以相信项目包含这类能力线索；是否适合你的具体任务仍要试用或安装后验证。 证据：`README.md` Claim：`clm_0001` supported 0.86
- **存在 Quick Start / 安装命令线索**（supported）：可以相信项目文档出现过启动或安装入口；不要因此直接在主力环境运行。 证据：`README.md` Claim：`clm_0003` supported 0.86

### 现在还不能相信

- **工具权限边界不能在安装前相信。**（unverified）：MCP/tool 类项目通常会触碰文件、网络、浏览器或外部 API，必须真实检查权限和日志。
- **真实输出质量不能在安装前相信。**（unverified）：Prompt Preview 只能展示引导方式，不能证明真实项目中的结果质量。
- **宿主 AI 版本兼容性不能在安装前相信。**（unverified）：Claude、Cursor、Codex、Gemini 等宿主加载规则和版本差异必须在真实环境验证。
- **不会污染现有宿主 AI 行为，不能直接相信。**（inferred）：Skill、plugin、AGENTS/CLAUDE/GEMINI 指令可能改变宿主 AI 的默认行为。
- **可安全回滚不能默认相信。**（unverified）：除非项目明确提供卸载和恢复说明，否则必须先在隔离环境验证。
- **真实安装后是否与用户当前宿主 AI 版本兼容？**（unverified）：兼容性只能通过实际宿主环境验证。
- **项目输出质量是否满足用户具体任务？**（unverified）：安装前预览只能展示流程和边界，不能替代真实评测。
- **安装命令是否需要网络、权限或全局写入？**（unverified）：这影响企业环境和个人环境的安装风险。 证据：`README.md`

### 继续会触碰什么

- **命令执行**：包管理器、网络下载、本地插件目录、项目配置或用户主目录。 原因：运行第一条命令就可能产生环境改动；必须先判断是否值得跑。 证据：`README.md`
- **本地环境或项目文件**：安装结果、插件缓存、项目配置或本地依赖目录。 原因：安装前无法证明写入范围和回滚方式，需要隔离验证。 证据：`README.md`
- **环境变量 / API Key**：项目入口文档明确出现 API key、token、secret 或账号凭证配置。 原因：如果真实安装需要凭证，应先使用测试凭证并经过权限/合规判断。 证据：`README.md`, `README_CN.md`
- **宿主 AI 上下文**：AI Context Pack、Prompt Preview、Skill 路由、风险规则和项目事实。 原因：导入上下文会影响宿主 AI 后续判断，必须避免把未验证项包装成事实。

### 最小安全下一步

- **先跑 Prompt Preview**：用安装前交互式试用判断工作方式是否匹配，不需要授权或改环境。（适用：任何项目都适用，尤其是输出质量未知时。）
- **只在隔离目录或测试账号试装**：避免安装命令污染主力宿主 AI、真实项目或用户主目录。（适用：存在命令执行、插件配置或本地写入线索时。）
- **不要使用真实生产凭证**：环境变量/API key 一旦进入宿主或工具链，可能产生账号和合规风险。（适用：出现 API、TOKEN、KEY、SECRET 等环境线索时。）
- **安装后只验证一个最小任务**：先验证加载、兼容、输出质量和回滚，再决定是否深用。（适用：准备从试用进入真实工作流时。）

### 退出方式

- **保留安装前状态**：记录原始宿主配置和项目状态，后续才能判断是否可恢复。
- **记录安装命令和写入路径**：没有明确卸载说明时，至少要知道哪些目录或配置需要手动清理。
- **准备撤销测试 API key 或 token**：测试凭证泄露或误用时，可以快速止损。
- **如果没有回滚路径，不进入主力环境**：不可回滚是继续前阻断项，不应靠信任或运气继续。

## 哪些只能预览

- 解释项目适合谁和能做什么
- 基于项目文档演示典型对话流程
- 帮助用户判断是否值得安装或继续研究

## 哪些必须安装后验证

- 真实安装 Skill、插件或 CLI
- 执行脚本、修改本地文件或访问外部服务
- 验证真实输出质量、性能和兼容性

## 边界与风险判断卡

- **把安装前预览误认为真实运行**：用户可能高估项目已经完成的配置、权限和兼容性验证。 处理方式：明确区分 prompt_preview_can_do 与 runtime_required。 Claim：`clm_0006` inferred 0.45
- **命令执行会修改本地环境**：安装命令可能写入用户主目录、宿主插件目录或项目配置。 处理方式：先在隔离环境或测试账号中运行。 证据：`README.md` Claim：`clm_0007` supported 0.86
- **待确认**：真实安装后是否与用户当前宿主 AI 版本兼容？。原因：兼容性只能通过实际宿主环境验证。
- **待确认**：项目输出质量是否满足用户具体任务？。原因：安装前预览只能展示流程和边界，不能替代真实评测。
- **待确认**：安装命令是否需要网络、权限或全局写入？。原因：这影响企业环境和个人环境的安装风险。

## 开工前工作上下文

### 加载顺序

- 先读取 how_to_use.host_ai_instruction，建立安装前判断资产的边界。
- 读取 claim_graph_summary，确认事实来自 Claim/Evidence Graph，而不是 Human Wiki 叙事。
- 再读取 intended_users、capabilities 和 quick_start_candidates，判断用户是否匹配。
- 需要执行具体任务时，优先查 role_skill_index，再查 evidence_index。
- 遇到真实安装、文件修改、网络访问、性能或兼容性问题时，转入 risk_card 和 boundaries.runtime_required。

### 任务路由

- **命令行启动或安装流程**：先说明这是安装后验证能力，再给出安装前检查清单。 边界：必须真实安装或运行后验证。 证据：`README.md` Claim：`clm_0001` supported 0.86

### 上下文规模

- 文件总数：212
- 重要文件覆盖：35/212
- 证据索引条目：35
- 角色 / Skill 条目：2

### 证据不足时的处理

- **missing_evidence**：说明证据不足，要求用户提供目标文件、README 段落或安装后验证记录；不要补全事实。
- **out_of_scope_request**：说明该任务超出当前 AI Context Pack 证据范围，并建议用户先查看 Human Manual 或真实安装后验证。
- **runtime_request**：给出安装前检查清单和命令来源，但不要替用户执行命令或声称已执行。
- **source_conflict**：同时展示冲突来源，标记为待核实，不要强行选择一个版本。

## Prompt Recipes

### 适配判断

- 目标：判断这个项目是否适合用户当前任务。
- 预期输出：适配结论、关键理由、证据引用、安装前可预览内容、必须安装后验证内容、下一步建议。

```text
请基于 grok-search-mcp 的 AI Context Pack，先问我 3 个必要问题，然后判断它是否适合我的任务。回答必须包含：适合谁、能做什么、不能做什么、是否值得安装、证据来自哪里。所有项目事实必须引用 evidence_refs、source_paths 或 claim_id。
```

### 安装前体验

- 目标：让用户在安装前感受核心工作流，同时避免把预览包装成真实能力或营销承诺。
- 预期输出：一段带边界标签的体验剧本、安装后验证清单和谨慎建议；不含真实运行承诺或强营销表述。

```text
请把 grok-search-mcp 当作安装前体验资产，而不是已安装工具或真实运行环境。

请严格输出四段：
1. 先问我 3 个必要问题。
2. 给出一段“体验剧本”：用 [安装前可预览]、[必须安装后验证]、[证据不足] 三种标签展示它可能如何引导工作流。
3. 给出安装后验证清单：列出哪些能力只有真实安装、真实宿主加载、真实项目运行后才能确认。
4. 给出谨慎建议：只能说“值得继续研究/试装”“先补充信息后再判断”或“不建议继续”，不得替项目背书。

硬性边界：
- 不要声称已经安装、运行、执行测试、修改文件或产生真实结果。
- 不要写“自动适配”“确保通过”“完美适配”“强烈建议安装”等承诺性表达。
- 如果描述安装后的工作方式，必须使用“如果安装成功且宿主正确加载 Skill，它可能会……”这种条件句。
- 体验剧本只能写成“示例台词/假设流程”：使用“可能会询问/可能会建议/可能会展示”，不要写“已写入、已生成、已通过、正在运行、正在生成”。
- Prompt Preview 不负责给安装命令；如用户准备试装，只能提示先阅读 Quick Start 和 Risk Card，并在隔离环境验证。
- 所有项目事实必须来自 supported claim、evidence_refs 或 source_paths；inferred/unverified 只能作风险或待确认项。

```

### 角色 / Skill 选择

- 目标：从项目里的角色或 Skill 中挑选最匹配的资产。
- 预期输出：候选角色或 Skill 列表，每项包含适用场景、证据路径、风险边界和是否需要安装后验证。

```text
请读取 role_skill_index，根据我的目标任务推荐 3-5 个最相关的角色或 Skill。每个推荐都要说明适用场景、可能输出、风险边界和 evidence_refs。
```

### 风险预检

- 目标：安装或引入前识别环境、权限、规则冲突和质量风险。
- 预期输出：环境、权限、依赖、许可、宿主冲突、质量风险和未知项的检查清单。

```text
请基于 risk_card、boundaries 和 quick_start_candidates，给我一份安装前风险预检清单。不要替我执行命令，只说明我应该检查什么、为什么检查、失败会有什么影响。
```

### 宿主 AI 开工指令

- 目标：把项目上下文转成一次对话开始前的宿主 AI 指令。
- 预期输出：一段边界明确、证据引用明确、适合复制给宿主 AI 的开工前指令。

```text
请基于 grok-search-mcp 的 AI Context Pack，生成一段我可以粘贴给宿主 AI 的开工前指令。这段指令必须遵守 not_runtime=true，不能声称项目已经安装、运行或产生真实结果。
```

## 角色 / Skill 索引

- 共索引 2 个角色 / Skill / 项目文档条目。

- **grok-search-mcp**（project_doc）：grok-search-mcp is an HTTP-only Model Context Protocol MCP https://modelcontextprotocol.io/ server that exposes Grok-powered real-time web search, X/Twitter search, and model discovery to MCP clients. 激活提示：当用户需要理解项目结构、安装方式或边界时参考。 证据：`README.md`
- **grok-search-mcp**（project_doc）：grok-search-mcp 是一个仅提供 HTTP 传输的 Model Context Protocol（MCP） https://modelcontextprotocol.io/ 服务端，将 Grok 的实时网页搜索、X/Twitter 搜索和模型发现能力暴露给 MCP 客户端。 激活提示：当用户需要理解项目结构、安装方式或边界时参考。 证据：`README_CN.md`

## 证据索引

- 共索引 35 条证据。

- **grok-search-mcp**（documentation）：grok-search-mcp is an HTTP-only Model Context Protocol MCP https://modelcontextprotocol.io/ server that exposes Grok-powered real-time web search, X/Twitter search, and model discovery to MCP clients. 证据：`README.md`
- **License**（source_file）：Creative Commons Attribution-NonCommercial 4.0 International 证据：`LICENSE`
- **Main**（source_file）：package main ⋮---- import "context" "flag" "fmt" "log" "os" "os/signal" "syscall" "github.com/MapleMapleCat/Grok Search Mcp/internal/app" "github.com/MapleMapleCat/Grok Search Mcp/internal/config" "github.com/MapleMapleCat/Grok Search Mcp/internal/version" ⋮---- "context" "flag" "fmt" "log" "os" "os/signal" "syscall" ⋮---- "github.com/MapleMapleCat/Grok Search Mcp/internal/app" "github.com/MapleMapleCat/Grok Search Mcp/internal/config" "github.com/MapleMapleCat/Grok Search Mcp/internal/version" ⋮---- func main 证据：`cmd/grok-search-mcp/main.go`
- **Server**（source_file）：package app ⋮---- import "context" "crypto/rand" "errors" "fmt" "log" "math/big" "net" "net/http" "strings" "time" "github.com/MapleMapleCat/Grok Search Mcp/internal/auth" "github.com/MapleMapleCat/Grok Search Mcp/internal/config" "github.com/MapleMapleCat/Grok Search Mcp/internal/grok" "github.com/MapleMapleCat/Grok Search Mcp/internal/logx" mcpserver "github.com/MapleMapleCat/Grok Search Mcp/internal/mcp" "github.com/MapleMapleCat/Grok Search Mcp/internal/panel" "github.com/MapleMapleCat/Grok Search Mcp/internal/panelui" "github.com/MapleMapleCat/Grok Search Mcp/internal/quota" "github.com/MapleMapleCat/Grok Search Mcp/internal/ratelimit" "github.com/MapleMapleCat/Grok Search Mcp/internal… 证据：`internal/app/server.go`
- **Context**（source_file）：package auth ⋮---- import "context" "github.com/MapleMapleCat/Grok Search Mcp/internal/store" ⋮---- "context" ⋮---- "github.com/MapleMapleCat/Grok Search Mcp/internal/store" ⋮---- type ctxKey struct{} ⋮---- func WithAPIKey ctx context.Context, key store.APIKey context.Context ⋮---- func APIKeyFromContext ctx context.Context store.APIKey, bool 证据：`internal/auth/context.go`
- **Jwt**（source_file）：package auth ⋮---- import "errors" "net/http" "strings" "time" "github.com/MapleMapleCat/Grok Search Mcp/internal/store" "github.com/golang-jwt/jwt/v5" ⋮---- "errors" "net/http" "strings" "time" ⋮---- "github.com/MapleMapleCat/Grok Search Mcp/internal/store" "github.com/golang-jwt/jwt/v5" ⋮---- const defaultJWTExpiry = 12 time.Hour jwtIssuer = "grok-mcp" jwtAudience = "panel" ⋮---- type panelClaims struct { UserID string json:"uid" Username string json:"username" Role store.UserRole json:"role" TokenVersion int64 json:"tv" jwt.RegisteredClaims } ⋮---- func IssuePanelToken secret string, user store.User, ttl time.Duration string, time.Time, error ⋮---- func JWTMiddleware secret string, st Us… 证据：`internal/auth/jwt.go`
- **Middleware**（source_file）：package auth ⋮---- import "context" "errors" "log" "net/http" "strings" "github.com/MapleMapleCat/Grok Search Mcp/internal/keyhash" "github.com/MapleMapleCat/Grok Search Mcp/internal/store" ⋮---- "context" "errors" "log" "net/http" "strings" ⋮---- "github.com/MapleMapleCat/Grok Search Mcp/internal/keyhash" "github.com/MapleMapleCat/Grok Search Mcp/internal/store" ⋮---- type KeyLookup interface { GetKeyByHash ctx context.Context, hash string store.APIKey, error } ⋮---- type APIKeyStore interface { KeyLookup UserTierLoader } ⋮---- func bearerToken r http.Request string, bool ⋮---- // APIKeyResolver 解析 Bearer 令牌对应的 API Key 与所属用户（含 tier 限额）。 type APIKeyResolver interface { Resolve ctx context.C… 证据：`internal/auth/middleware.go`
- **Resolver Cache**（source_file）：package auth ⋮---- import "container/list" "context" "sync" "sync/atomic" "time" "github.com/MapleMapleCat/Grok Search Mcp/internal/store" ⋮---- "container/list" "context" "sync" "sync/atomic" "time" ⋮---- "github.com/MapleMapleCat/Grok Search Mcp/internal/store" ⋮---- const defaultAuthCacheTTL = 30 time.Second defaultAuthCacheMaxEntries = 4096 defaultAuthCacheShardCount = 32 defaultAuthNegativeCacheTTL = 2 time.Second authCacheCleanupInterval = time.Minute ⋮---- type cacheEntry struct { keyHash string key store.APIKey user AuthenticatedUser until time.Time listElement list.Element negative bool } ⋮---- type authCacheShard struct { mu sync.Mutex byHash map string cacheEntry recency list.Lis… 证据：`internal/auth/resolver_cache.go`
- **User Context**（source_file）：package auth ⋮---- import "context" "errors" "fmt" "strings" "github.com/MapleMapleCat/Grok Search Mcp/internal/store" ⋮---- "context" "errors" "fmt" "strings" ⋮---- "github.com/MapleMapleCat/Grok Search Mcp/internal/store" ⋮---- type UserLoader interface { GetUserByID ctx context.Context, id string store.User, error } ⋮---- type TierLoader interface { GetTierByID ctx context.Context, id string store.Tier, error } ⋮---- type UserTierLoader interface { UserLoader TierLoader } ⋮---- type AuthenticatedUser struct { store.User RPM int SuccessLimit int } ⋮---- type userCtxKey struct{} ⋮---- func WithUser ctx context.Context, user AuthenticatedUser context.Context ⋮---- func UserFromContext ctx c… 证据：`internal/auth/user_context.go`
- **Config**（source_file）：package config ⋮---- import "fmt" "net/url" "os" "strconv" "strings" "time" "github.com/MapleMapleCat/Grok Search Mcp/internal/settings" "github.com/MapleMapleCat/Grok Search Mcp/internal/store" ⋮---- "fmt" "net/url" "os" "strconv" "strings" "time" ⋮---- "github.com/MapleMapleCat/Grok Search Mcp/internal/settings" "github.com/MapleMapleCat/Grok Search Mcp/internal/store" ⋮---- const defaultBaseURL = "http://127.0.0.1:8317" defaultModel = "grok-4.3" defaultUpstreamProtocol = UpstreamProtocolResponses defaultTimeout = 120 time.Second defaultHTTPAddr = ":8080" defaultDBPath = "./grok-search-mcp.db" defaultUsageRawRetention = 7 24 time.Hour defaultUsageHourlyRetention = 90 24 time.Hour defaultU… 证据：`internal/config/config.go`
- **Anthropic Messages**（source_file）：package grok ⋮---- import "bytes" "context" "encoding/json" "fmt" "io" "strings" ⋮---- "bytes" "context" "encoding/json" "fmt" "io" "strings" ⋮---- const anthropicDefaultMaxTokens = 4096 ⋮---- const anthropicXSearchInstruction = "Search public posts on X x.com only. " + ⋮---- type anthropicMessagesRequest struct { Model string json:"model" MaxTokens int json:"max tokens" Messages anthropicMessage json:"messages" Tools anthropicTool json:"tools" Stream bool json:"stream" } ⋮---- type anthropicMessage struct { Role string json:"role" Content string json:"content" } ⋮---- type anthropicTool struct { Type string json:"type,omitempty" Name string json:"name" Description string json:"description,… 证据：`internal/grok/anthropic_messages.go`
- **Client**（source_file）：package grok ⋮---- import "bytes" "context" "crypto/tls" "fmt" "io" "net" "net/http" "net/http/httptrace" "net/url" "strings" "sync" "time" "github.com/MapleMapleCat/Grok Search Mcp/internal/config" "github.com/MapleMapleCat/Grok Search Mcp/internal/logx" ⋮---- "bytes" "context" "crypto/tls" "fmt" "io" "net" "net/http" "net/http/httptrace" "net/url" "strings" "sync" "time" ⋮---- "github.com/MapleMapleCat/Grok Search Mcp/internal/config" "github.com/MapleMapleCat/Grok Search Mcp/internal/logx" ⋮---- const upstreamIdleConnectionPoolSize = 100 maxUpstreamErrorBodyBytes int64 = 64 1024 ⋮---- type Client struct { mu sync.RWMutex baseURL string apiKey string protocol config.UpstreamProtocol defau… 证据：`internal/grok/client.go`
- **Request**（source_file）：package grok ⋮---- import "encoding/json" "fmt" "net/netip" "strings" "github.com/MapleMapleCat/Grok Search Mcp/internal/config" ⋮---- "encoding/json" "fmt" "net/netip" "strings" ⋮---- "github.com/MapleMapleCat/Grok Search Mcp/internal/config" ⋮---- func validateModel model string error ⋮---- func validateSearchRequest req SearchRequest SearchRequest, error ⋮---- func normalizeDomainFilters fieldName string, rawDomains string string, error ⋮---- func normalizeDomainFilter rawDomain string string, error ⋮---- func buildToolDef req SearchRequest toolDef ⋮---- func buildSearchRequestBody req SearchRequest, defaultModel string string, byte, error 证据：`internal/grok/request.go`
- **Response**（source_file）：package grok ⋮---- import "bytes" "encoding/json" "fmt" "strings" ⋮---- "bytes" "encoding/json" "fmt" "strings" ⋮---- type citationCollector struct { citations string sources Source seen map string struct{} ⋮---- func newCitationCollector citationCollector ⋮---- func c citationCollector add url, title string ⋮---- func c citationCollector addRaw raw json.RawMessage ⋮---- var items json.RawMessage ⋮---- var url string ⋮---- type citationExtension struct { URL string json:"url" URI string json:"uri" SourceURL string json:"source url" Title string json:"title" Name string json:"name" URLCitation json.RawMessage json:"url citation" Citation json.RawMessage json:"citation" Source json.RawMessage… 证据：`internal/grok/response.go`
- **Stream**（source_file）：package grok ⋮---- import "bytes" "encoding/json" "fmt" "io" "github.com/MapleMapleCat/Grok Search Mcp/internal/logx" ⋮---- "bytes" "encoding/json" "fmt" "io" ⋮---- "github.com/MapleMapleCat/Grok Search Mcp/internal/logx" ⋮---- type searchRoundTracker struct { nextRound int seen map string struct{} ⋮---- func newSearchRoundTracker searchRoundTracker ⋮---- func t searchRoundTracker emitSearchRound eventType string, item streamOutputItem, onRound func SearchRound , log logx.Logger error ⋮---- func parseSearchStream body io.Reader, onRound func SearchRound , log logx.Logger SearchResult, error ⋮---- var completedBody byte ⋮---- var event streamEvent ⋮---- var completed streamEvent ⋮---- func i… 证据：`internal/grok/stream.go`
- **Keycrypt**（source_file）：package keycrypt ⋮---- import "crypto/aes" "crypto/cipher" "crypto/hmac" "crypto/rand" "crypto/sha256" "encoding/base64" "fmt" "io" "strings" ⋮---- "crypto/aes" "crypto/cipher" "crypto/hmac" "crypto/rand" "crypto/sha256" "encoding/base64" "fmt" "io" "strings" ⋮---- const encryptionVersion = 1 ⋮---- type Cipher struct { aead cipher.AEAD } ⋮---- func New applicationSecret string Cipher, error ⋮---- func c Cipher Encrypt plaintext, recordIdentity string ciphertext string, nonce string, version int, err error ⋮---- func c Cipher Decrypt ciphertext, nonce, recordIdentity string, version int string, error 证据：`internal/keycrypt/keycrypt.go`
- **Instructions**（source_file）：package mcpserver ⋮---- const ServerInstructions = Grok MCP exposes three read-only tools: - grok web search: use for real-time public web search through Grok web search. - grok x search: use for real-time X post search through Grok x search. - grok list models: use to fetch Grok model IDs from upstream /v1/models. The server filters upstream results and exposes only model IDs containing the grok keyword while excluding imagine/video models. Usage: - query is required for both tools and should contain the search request text. - model is optional. If omitted, the server uses the GROK MODEL environment variable. - model lists are always filtered by the grok keyword and exclude model IDs conta… 证据：`internal/mcp/instructions.go`
- **Tools**（source_file）：package mcpserver ⋮---- import "context" "fmt" "strings" "github.com/MapleMapleCat/Grok Search Mcp/internal/grok" "github.com/MapleMapleCat/Grok Search Mcp/internal/logx" "github.com/MapleMapleCat/Grok Search Mcp/internal/usage" "github.com/modelcontextprotocol/go-sdk/mcp" ⋮---- "context" "fmt" "strings" ⋮---- "github.com/MapleMapleCat/Grok Search Mcp/internal/grok" "github.com/MapleMapleCat/Grok Search Mcp/internal/logx" "github.com/MapleMapleCat/Grok Search Mcp/internal/usage" "github.com/modelcontextprotocol/go-sdk/mcp" ⋮---- const webSearchToolName = "grok web search" webSearchToolTitle = "Grok Web Search" webSearchToolDescription = "Search the public web in real time via Grok web searc… 证据：`internal/mcp/tools.go`
- **Middleware**（source_file）：package quota ⋮---- import "context" "errors" "net/http" "github.com/MapleMapleCat/Grok Search Mcp/internal/auth" "github.com/MapleMapleCat/Grok Search Mcp/internal/store" "github.com/MapleMapleCat/Grok Search Mcp/internal/usage" ⋮---- "context" "errors" "net/http" ⋮---- "github.com/MapleMapleCat/Grok Search Mcp/internal/auth" "github.com/MapleMapleCat/Grok Search Mcp/internal/store" "github.com/MapleMapleCat/Grok Search Mcp/internal/usage" ⋮---- type SuccessQuotaReserver interface { ReserveSuccessCall ctx context.Context, userID string, successLimit int store.SuccessQuotaReservation, error } ⋮---- func MCPMiddleware reserver SuccessQuotaReserver func http.Handler http.Handler 证据：`internal/quota/middleware.go`
- **Runtime**（source_file）：package settings ⋮---- import "fmt" ⋮---- type UpstreamProtocol string ⋮---- const UpstreamProtocolResponses UpstreamProtocol = "responses" UpstreamProtocolChatCompletions UpstreamProtocol = "chat completions" UpstreamProtocolAnthropicMessages UpstreamProtocol = "anthropic messages" ⋮---- type RegistrationMode string ⋮---- const RegistrationModeFree RegistrationMode = "free" RegistrationModeInvite RegistrationMode = "invite" RegistrationModeDisabled RegistrationMode = "disabled" ⋮---- func NormalizeRegistrationMode mode RegistrationMode RegistrationMode, error ⋮---- type Runtime struct { CPABaseURL string CPAAPIKey string json:"-" UpstreamProtocol UpstreamProtocol Model string TimeoutSecond… 证据：`internal/settings/runtime.go`
- **Sqlite**（source_file）：package store ⋮---- import "database/sql" "fmt" "github.com/MapleMapleCat/Grok Search Mcp/internal/keycrypt" "modernc.org/sqlite" ⋮---- "database/sql" "fmt" ⋮---- "github.com/MapleMapleCat/Grok Search Mcp/internal/keycrypt" ⋮---- "modernc.org/sqlite" ⋮---- const sqliteReadPoolSize = 4 ⋮---- const sqliteCommonPragmas = "& pragma=busy timeout 5000 & pragma=synchronous NORMAL " ⋮---- type SQLiteStore struct { db sql.DB readDB sql.DB debugDB sql.DB secretCipher keycrypt.Cipher metrics sqliteMetrics } ⋮---- func OpenSQLite path string SQLiteStore, error ⋮---- func s SQLiteStore Close error ⋮---- var firstCloseErr error 证据：`internal/store/sqlite.go`
- **Sqlite Debug**（source_file）：package store ⋮---- import "context" "database/sql" "fmt" "io" "os" "strings" "time" ⋮---- "context" "database/sql" "fmt" "io" "os" "strings" "time" ⋮---- const debugCleanupTimeout = 5 time.Second ⋮---- const debugDatabaseSuffix = ".debug.sqlite" ⋮---- func debugDatabasePath mainDatabasePath string string ⋮---- func openDebugSQLite mainDatabasePath string sql.DB, error ⋮---- func s SQLiteStore deleteUsageDebugByKeyIDsBestEffort keyIDs string ⋮---- const maxPersistedDebugBodyBytes int64 = 1 << 20 ⋮---- func readBoundedDebugBody path string byte, int64, bool, error ⋮---- func boolAsInteger value bool int ⋮---- func s SQLiteStore persistUsageDebugRecord ctx context.Context, usageID int64, reco… 证据：`internal/store/sqlite_debug.go`
- **Sqlite Helpers**（source_file）：package store ⋮---- import "crypto/rand" "fmt" "time" ⋮---- "crypto/rand" "fmt" "time" ⋮---- const timeLayout = "2006-01-02 15:04:05" ⋮---- func randomID string, error ⋮---- func parseTime s string time.Time, error ⋮---- func formatTime t time.Time string ⋮---- func normalizePanelPageLimit limit int int 证据：`internal/store/sqlite_helpers.go`
- **Sqlite Keys**（source_file）：package store ⋮---- import "context" "crypto/rand" "database/sql" "encoding/hex" "fmt" "strings" "time" "github.com/MapleMapleCat/Grok Search Mcp/internal/keycrypt" "github.com/MapleMapleCat/Grok Search Mcp/internal/keyhash" ⋮---- "context" "crypto/rand" "database/sql" "encoding/hex" "fmt" "strings" "time" ⋮---- "github.com/MapleMapleCat/Grok Search Mcp/internal/keycrypt" "github.com/MapleMapleCat/Grok Search Mcp/internal/keyhash" ⋮---- func s SQLiteStore ConfigureAPIKeyEncryption applicationSecret string error ⋮---- func apiKeyRecordIdentity keyID, userID string string ⋮---- func generateRawKey string, error ⋮---- func scanAPIKey row interface ⋮---- var k APIKey var enabled int var created… 证据：`internal/store/sqlite_keys.go`
- **Sqlite Metrics**（source_file）：package store ⋮---- import "database/sql" "errors" "strings" "sync/atomic" "time" ⋮---- "database/sql" "errors" "strings" "sync/atomic" "time" ⋮---- type SQLiteOperationMetrics struct { Attempts uint64 json:"attempts" Errors uint64 json:"errors" BusyOrLockedErrors uint64 json:"busy or locked errors" TotalDurationMs float64 json:"total duration ms" AverageDurationMs float64 json:"average duration ms" LastDurationMs float64 json:"last duration ms" MaximumDurationMs float64 json:"maximum duration ms" } ⋮---- type SQLiteConnectionPoolMetrics struct { MaximumOpenConnections int json:"maximum open connections" OpenConnections int json:"open connections" InUseConnections int json:"in use connectio… 证据：`internal/store/sqlite_metrics.go`
- **Sqlite Metrics Test**（source_file）：package store ⋮---- import "context" "reflect" "testing" ⋮---- "context" "reflect" "testing" ⋮---- func TestSQLiteMetricsAreDisabledByDefault t testing.T ⋮---- func TestSQLiteMetricsCollectOnlyWhileEnabled t testing.T ⋮---- func TestSQLiteMetricsCountRejectedQuotaReleaseAsError t testing.T 证据：`internal/store/sqlite_metrics_test.go`
- **Middleware**（source_file）：package usage ⋮---- import "bytes" "context" "encoding/json" "errors" "io" "log" "net/http" "strings" "time" "github.com/MapleMapleCat/Grok Search Mcp/internal/auth" "github.com/MapleMapleCat/Grok Search Mcp/internal/store" ⋮---- "bytes" "context" "encoding/json" "errors" "io" "log" "net/http" "strings" "time" ⋮---- "github.com/MapleMapleCat/Grok Search Mcp/internal/auth" "github.com/MapleMapleCat/Grok Search Mcp/internal/store" ⋮---- type SuccessQuotaReleaser interface { ReleaseSuccessCall ctx context.Context, reservation store.SuccessQuotaReservation error } ⋮---- type DebugState interface { Enabled bool } ⋮---- type UsageStore interface { SuccessQuotaReleaser } ⋮---- type toolNameCtxKey… 证据：`internal/usage/middleware.go`
- **Version**（source_file）：package version ⋮---- var Version = "0.2.1" 证据：`internal/version/version.go`
- **grok-search-mcp**（documentation）：grok-search-mcp 是一个仅提供 HTTP 传输的 Model Context Protocol（MCP） https://modelcontextprotocol.io/ 服务端，将 Grok 的实时网页搜索、X/Twitter 搜索和模型发现能力暴露给 MCP 客户端。 证据：`README_CN.md`
- **Local environment and secrets.**（source_file）：Local environment and secrets. .env .env.local .mcp.json 证据：`.dockerignore`
- **grok-search-mcp Linux 本地运行配置示例。复制为 .env 并填入真实值：**（source_file）：grok-search-mcp Linux 本地运行配置示例。复制为 .env 并填入真实值： cp .env.example .env mkdir -p data 注意：.env 已在 .gitignore 中排除，真实凭证不会进入版本库。 证据：`.env.example`
- **编译产物**（source_file）：编译产物 /grok-search-mcp /grok-mcp /bin/ /dist/ /.local-release/ .so 证据：`.gitignore`
- **---- build stage ----**（source_file）：---- build stage ---- Production defaults use immutable multi-platform image-index digests. Override these build arguments only when intentionally testing replacement images. ARG GO IMG=golang:1.25.12-alpine@sha256:56961d79ea8129efddcc0b8643fd8a5416b4e6228cfd477e3fd61deb2672c587 ARG RUNTIME IMG=alpine:3.20@sha256:d9e853e87e55526f6b2917df91a2115c36dd7c696a35be12163d44e6e2a4b6bc 证据：`Dockerfile`
- **Docker Compose**（source_file）：services: grok-search-mcp: build: context: . dockerfile: Dockerfile args: GO IMG: "${GO IMG:-golang:1.25.12-alpine@sha256:56961d79ea8129efddcc0b8643fd8a5416b4e6228cfd477e3fd61deb2672c587}" RUNTIME IMG: "${RUNTIME IMG:-alpine:3.20@sha256:d9e853e87e55526f6b2917df91a2115c36dd7c696a35be12163d44e6e2a4b6bc}" GOPROXY: "${GOPROXY:-https://proxy.golang.org,direct}" image: grok-search-mcp:latest container name: grok-search-mcp restart: unless-stopped ports: - "8080:8080" environment: CPA BASE URL: "${CPA BASE URL:-http://host.docker.internal:8317}" CPA API KEY: "${CPA API KEY:-}" GROK UPSTREAM PROTOCOL: "${GROK UPSTREAM PROTOCOL:-responses}" GROK JWT SECRET: "${GROK JWT SECRET:?GROK JWT SECRET is req… 证据：`docker-compose.yml`
- **Go**（source_file）：module github.com/MapleMapleCat/Grok Search Mcp 证据：`go.mod`

## 宿主 AI 必须遵守的规则

- **把本资产当作开工前上下文，而不是运行环境。**：AI Context Pack 只包含证据化项目理解，不包含目标项目的可执行状态。 证据：`README.md`, `LICENSE`, `cmd/grok-search-mcp/main.go`
- **回答用户时区分可预览内容与必须安装后才能验证的内容。**：安装前体验的消费者价值来自降低误装和误判，而不是伪装成真实运行。 证据：`README.md`, `LICENSE`, `cmd/grok-search-mcp/main.go`

## 用户开工前应该回答的问题

- 你准备在哪个宿主 AI 或本地环境中使用它？
- 你只是想先体验工作流，还是准备真实安装？
- 你最在意的是安装成本、输出质量、还是和现有规则的冲突？

## 验收标准

- 所有能力声明都能回指到 evidence_refs 中的文件路径。
- AI_CONTEXT_PACK.md 没有把预览包装成真实运行。
- 用户能在 3 分钟内看懂适合谁、能做什么、如何开始和风险边界。

---

## Doramagic Context Augmentation

下面内容用于强化 Repomix/AI Context Pack 主体。Human Manual 只提供阅读骨架；踩坑日志会被转成宿主 AI 必须遵守的工作约束。

## Human Manual 骨架

使用规则：这里只是项目阅读路线和显著性信号，不是事实权威。具体事实仍必须回到 repo evidence / Claim Graph。

宿主 AI 硬性规则：
- 不得把页标题、章节顺序、摘要或 importance 当作项目事实证据。
- 解释 Human Manual 骨架时，必须明确说它只是阅读路线/显著性信号。
- 能力、安装、兼容性、运行状态和风险判断必须引用 repo evidence、source path 或 Claim Graph。

- **系统总览与架构**：importance `high`
  - source_paths: README.md, cmd/grok-search-mcp/main.go, internal/app/server.go, internal/config/config.go, internal/settings/runtime.go
- **MCP 工具与上游协议集成**：importance `high`
  - source_paths: internal/mcp/tools.go, internal/mcp/instructions.go, internal/grok/client.go, internal/grok/request.go, internal/grok/response.go
- **认证、配额与限流**：importance `high`
  - source_paths: internal/auth/context.go, internal/auth/jwt.go, internal/auth/middleware.go, internal/auth/resolver_cache.go, internal/auth/user_context.go
- **数据持久化、使用量与运维**：importance `high`
  - source_paths: internal/store/sqlite.go, internal/store/sqlite_debug.go, internal/store/sqlite_helpers.go, internal/store/sqlite_keys.go, internal/store/sqlite_metrics.go

## Repo Inspection Evidence / 源码检查证据

- repo_clone_verified: true
- repo_inspection_verified: true
- repo_commit: `94960aceac9a3de06219fffb72944e5e784a5cf3`
- inspected_files: `Dockerfile`, `README.md`, `docker-compose.yml`

宿主 AI 硬性规则：
- 没有 repo_clone_verified=true 时，不得声称已经读过源码。
- 没有 repo_inspection_verified=true 时，不得把 README/docs/package 文件判断写成事实。
- 没有 quick_start_verified=true 时，不得声称 Quick Start 已跑通。

## Doramagic Pitfall Constraints / 踩坑约束

这些规则来自 Doramagic 发现、验证或编译过程中的项目专属坑点。宿主 AI 必须把它们当作工作约束，而不是普通说明文字。

### Constraint 1: 需要 API Key 或环境变量

- Trigger: 项目说明中出现 API Key / 环境变量相关需求。
- Host AI rule: 提取必需 env 列表，确认是否有最小无密钥试用路径。
- Why it matters: 用户必须准备账号、额度或密钥；密钥配置错误会导致运行失败或泄漏风险。
- Evidence: packet_text.keyword_scan | https://github.com/MapleMapleCat/Grok_Search_Mcp | matched api key / env var keyword
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

### Constraint 2: 依赖 Docker 环境

- Trigger: 安装/运行入口包含 Docker 命令：docker run -d --name grok-search-mcp --restart unless-stopped --env-file .env -p 8080:8080 -v grok-search-mcp-data:/app/data maplemaplecat/grok-search-mcp:v0.2.1
- Host AI rule: 标注 Docker 前置条件，并提供非 Docker 路径或失败提示。
- Why it matters: 非工程用户可能没有 Docker，启动成本明显增加。
- Evidence: identity.distribution | https://github.com/MapleMapleCat/Grok_Search_Mcp | docker run -d --name grok-search-mcp --restart unless-stopped --env-file .env -p 8080:8080 -v grok-search-mcp-data:/app/data maplemaplecat/grok-search-mcp:v0.2.1
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

### Constraint 3: 能力判断依赖假设

- Trigger: README/documentation is current enough for a first validation pass.
- Host AI rule: 将假设转成下游验证清单。
- Why it matters: 假设不成立时，用户拿不到承诺的能力。
- Evidence: capability.assumptions | https://github.com/MapleMapleCat/Grok_Search_Mcp | README/documentation is current enough for a first validation pass.
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

### Constraint 4: 维护活跃度未知

- Trigger: 未记录 last_activity_observed。
- Host AI rule: 补 GitHub 最近 commit、release、issue/PR 响应信号。
- Why it matters: 新项目、停更项目和活跃项目会被混在一起，推荐信任度下降。
- Evidence: evidence.maintainer_signals | https://github.com/MapleMapleCat/Grok_Search_Mcp | last_activity_observed missing
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

- Trigger: no_demo
- Evidence: downstream_validation.risk_items | https://github.com/MapleMapleCat/Grok_Search_Mcp | no_demo; severity=medium
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

### Constraint 6: 存在评分风险

- Trigger: no_demo
- Why it matters: 风险会影响是否适合普通用户安装。
- Evidence: risks.scoring_risks | https://github.com/MapleMapleCat/Grok_Search_Mcp | no_demo; severity=medium
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

### Constraint 7: issue/PR 响应质量未知

- Trigger: issue_or_pr_quality=unknown。
- Host AI rule: 抽样最近 issue/PR，判断是否长期无人处理。
- Why it matters: 用户无法判断遇到问题后是否有人维护。
- Evidence: evidence.maintainer_signals | https://github.com/MapleMapleCat/Grok_Search_Mcp | issue_or_pr_quality=unknown
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

### Constraint 8: 发布节奏不明确

- Trigger: release_recency=unknown。
- Host AI rule: 确认最近 release/tag 和 README 安装命令是否一致。
- Why it matters: 安装命令和文档可能落后于代码，用户踩坑概率升高。
- Evidence: evidence.maintainer_signals | https://github.com/MapleMapleCat/Grok_Search_Mcp | release_recency=unknown
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。
