Grok Bot
xAI · docs.x.ai/grok-bot/overview
Grok Bot is a hosted, proprietary agent running on a provider-managed cloud computer with provider-selected models and no documented export, so it fails most portability and verifiability tests. It offers runtime-enforced approvals, masked credential handling, custom MCP servers and editable skills and routines, but stronger audit, network and halt controls are Enterprise-only, and data and training handling follow Cursor account settings.
- Runtime-enforced approvals (Allow once / Deny / Always allow, Auto-review)
- OAuth tokens held off the agent computer; masked secret entry
- Custom MCP servers (remote and stdio) and plugins
- Skills and routines are natural-language, editable and pausable
- Enterprise action recording with OpenTelemetry/SIEM export
- No documented export of a complete Bot
- Provider-managed model selection; no model picker
- Proprietary runtime; no way for recipients to verify its messages, and no tamper-evident action record
- Audit, network allowlists and computer termination are Enterprise-only
- Deleting a Bot leaves shared files and sign-ins; backend retention per Cursor terms
- Requires data storage; Legacy Privacy Mode unsupported
All 34 findings
Grok Bot beta launched 11 Aug 2026, assessed from docs.x.ai state as of Sept 2026; individual (paid Cursor or linked SuperGrok) and Teams/Enterprise plans. Distinct from the Grok chat app: separate app, persistent cloud computer (Firecracker microVM), multiple named Bots, skills and routines.
Portable · Can you leave, and take the whole agent with you?
0%- P1Round-trip portability
Incomplete and not restorable: no export of a Bot is documented, and template links, which stay hosted by xAI, recreate only its profile, settings, skills and routines, excluding memory, history, files, computer access and logins.
Fail - P2Complete export
No export is documented; memory, routines, files and sign-ins stay on the provider's cloud computer and backend, and template links carry only part of the configuration.
Fail - P3Independent execution
Bots execute only on hosted computers in Cursor's cloud; no open-source runtime is available.
Fail - P4Identity continuity
Bots are tied to the user's Cursor account, and nothing lets others verify a Bot is the same agent without the provider.
Fail - P5No kill switch
Bots cannot run outside the provider's service; admins and the provider can terminate computers, and access depends on a paid plan.
Fail - P6Capability independence
Routines, triggers, connectors and memory depend on the hosted service and Cursor account integrations, and the provider manages model selection, so no capability survives a model swap.
Fail
Transparent · Can you see everything the agent is, with ordinary tools?
17%- T1Open storage format
Files reside in /workspace on the cloud computer, but the storage format of memory, conversations and routines is not documented.
Unverified - T2No hidden instructions
Owner-set descriptions, skills and Team Rules are visible, but the provider's system instructions and model orchestration are not published or exposed to users.
Fail - T3No shadow memory
Backend data follows Cursor retention terms, action records are kept internally for 90 days, and Enterprise analytics derive conversation insights outside the owner-inspectable Bot state.
Fail - T4Complete action history
Conversations show proposed operations and routines keep success and failure history. A detailed record of tool calls, shell commands and browsing can be streamed to the organization's own collector, but only on Enterprise, off by default and admin-facing.
Partial - T5Readable logic
Skills and routines are natural-language instructions with steps and decision rules that owners can read and edit; the agent runtime itself is not available as source.
Partial - T6No third-party influence channel
No advertising or sponsored placement in Bot context is documented, nor any explicit commitment against it.
Unverified
Auditable · Can you reconstruct exactly what the agent did?
20%- A1No unrecorded actions
Approvals gate actions before execution and Enterprise Action Recording captures tool calls, commands and browsing, but it is off by default and the docs do not say an action is blocked when it cannot be recorded.
Unverified - A2Tamper evidence
Enterprise Action Recording and Audit Logs exist, but the docs do not say whether edits to or deletions from these records would be detectable.
Unverified - A3Separation from the audited
On Enterprise, the platform records Bot actions on its backend and can stream them to the organization's own collector, outside the Bot's cloud computer. The docs do not state this as a protection, and other plans have no such record.
Partial - A4Readable with ordinary tools
Enterprise teams can stream recorded actions via OpenTelemetry to their own collectors and audit logs to a SIEM; individual and Teams plans have no documented log export.
Partial - A5Corroborated interactions
Bots share one cloud computer and can coordinate, but no way to match one side's record of an exchange against the other's is documented.
Unverified
Verifiable · Can you prove the agent runs what it claims?
0%- V1Open, reproducible runtime
The runtime is proprietary; the vendor has not published its orchestration code or reproducible builds.
Fail - V2Active config is inspectable config
The model and system configuration are provider-managed and not inspectable; only owner and team-authored rules, skills and settings are visible.
Fail - V3Attributable messages
Bots act through signed-in accounts and shared static egress IPs; recipients have no documented way to verify a message came from this Bot under its owner's authority.
Fail - V4Independently checkable record
No documented procedure or open tool lets the owner check the integrity of the action record independently of the provider.
Fail - V5Comparable state
The docs describe no way for the owner to verify whether a Bot's memory, routines and computer state changed between two points in time.
Unverified
Modifiable · Can you change anything, without asking?
33%- M1Instructions
Owners edit a Bot's name, description and routine instructions; provider system instructions are not editable, and on team plans Team Rules are non-negotiable for members.
Partial - M2Memory
Bots retain preferences, facts and summaries, but no interface to view, edit or delete individual memory items is documented beyond deleting the whole Bot.
Unverified - M3Logic
Owners can create skills in natural language, teach tasks by demonstration, and edit, pause or delete routines; the runtime logic is not modifiable.
Partial - M4Tools and permissions
Owners can add plugins and custom remote or stdio MCP servers and set local execution to ask, always or never; per-Bot credential scoping is not available because Bots share one computer, and team MCP policy applies.
Partial - M5Model choice
Model selection is managed by the provider with no customer-facing model picker or local model option documented.
Fail - M6No gatekeeping
The product requires a paid Cursor or SuperGrok plan, and controls such as network allowlists, enforced Auto-review, action recording and computer management are Enterprise-only.
Partial
Controllable · Is your word final?
50%- C1Communication boundaries
Enterprise admins can restrict network destinations to an allowlist and trust specific MCP servers, enforced by the platform. Individual owners rely on per-action approvals and cannot set in advance whom a Bot may contact.
Partial - C2Approval gates
Sensitive actions are held for approval (Allow once, Deny, Always allow) before execution, with Auto-review rules that teams can enforce; local execution defaults to ask every time.
Pass - C3Immediate halt
Owners can send a stop message and pause routines; a hard computer termination is available only to Enterprise organization admins.
Partial - C4Data sovereignty
All work runs on provider infrastructure, Grok Bot requires data storage and does not support Legacy Privacy Mode, and non-training depends on Cursor Privacy Mode settings rather than an explicit opt-in.
Fail - C5Credential custody
Connector OAuth tokens stay on Cursor's backend, never on the computer or with the model, and secrets are entered through masked requests; credentials remain provider-held and do not travel with the Bot.
Partial - C6Full deletion
Deleting a Bot removes its profile, conversation and routines but not shared computer files or sign-ins; backend data is deleted within 30 days after service ends, and daily encrypted backups exist.
Partial
Vendors and the public can dispute any finding with evidence. Disputes and their resolutions are published.