Prompt Library

Grok Bot plugin prompts: connect, fall back, do not paste keys

21 copy-paste prompts

Prefer a plugin. Fall back to the cloud browser when the connector is missing. Staff-confirmed: no local or stdio MCP. Secrets go on the secret card. Never into chat.

In short: This page contains 21 copy-paste ready prompts, organized into 5 categories with a description and pro tip for each. The first 5 prompts are free instantly, no signup needed. Hand-curated and tested by the AI Academy team.

Louis Corneloup
By Louis Corneloup ยท Founder, Techpresso
Last updated ยทHand-curated & tested by the AI Academy team

Connect the right way

5 prompts

Prefer plugin, else browser

1/21

โœจ What it does

The Bot checks Settings for a plugin or remote connection that can handle [JOB], and uses the cloud browser only if nothing fits. You decide whether to install that plugin or let it keep using the browser.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: For [JOB], check for a plugin or remote MCP first. If none, use the cloud browser. Say which path you took. Sources: Settings โ†’ Plugins, [JOB]. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not install a plugin until I pick it. Do not paste API keys into chat. Deliverable: Plugin exists / missing, recommended path, permissions it wants. Review point: I install or I let you use the browser.

๐Ÿ’ก

Pro tip: Ask it to check Settings โ†’ Plugins before it starts clicking a site like a raccoon.

Install from the marketplace with a permission read

2/21

โœจ What it does

The Bot finds a marketplace plugin for [JOB] and lists every permission it wants, plus why you might skip it. You click Connect only after you have read that list.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: Find a plugin for [JOB] in the marketplace. List permissions and risks. Do not connect until I say so. Sources: Settings โ†’ Plugins / marketplace. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not click Connect. Deliverable: Name, permissions, why we might skip it, browser fallback. Review point: I connect.

๐Ÿ’ก

Pro tip: xAI plugin marketplace exists. A 219-listing scrape is not a security review. You still read permissions.

Remote HTTP MCP only

3/21

โœจ What it does

The Bot tries to add [REMOTE MCP URL] only when it is a remote web connection, and stops if the tool lives on your laptop. You add the remote server if that path is supported.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: Set up [REMOTE MCP URL] if it is remote HTTP. If this is local/stdio, stop and say it is not supported. Sources: The URL I paste, Settings โ†’ Plugins. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not try to tunnel a local stdio server. Do not paste tokens into chat. Use the secret card. Deliverable: Connected / not supported, and the fallback. Review point: I add the remote server if supported.

๐Ÿ’ก

Pro tip: If someone says "just add my local Workflowy MCP", the answer is no. Use remote HTTP or the browser.

Re-authenticate, do not Connect again

4/21

โœจ What it does

The Bot uses Re-authenticate on the stuck [PLUGIN] card instead of starting a second install. You finish any browser consent screen it cannot complete.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: For [PLUGIN] stuck on OAuth, use Re-authenticate, not Connect again. Do not start a second install. Sources: The plugin card. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not create a second OAuth app. Do not paste client secrets into chat. Deliverable: What you clicked, whether OAuth succeeded, screenshot of the connected state. Review point: I complete any browser consent.

๐Ÿ’ก

Pro tip: Invalid redirect_uri loops are usually a stuck account token, not a dead plugin.

X plugin is broken across surfaces

5/21

โœจ What it does

The Bot checks the official X plugin and, if it says connected but has no tools, stops and switches [JOB] to the cloud browser. You pick that fallback instead of spending an hour reconnecting.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: Check the official X plugin. If it shows connected but tools=0, stop and use the cloud browser for [JOB] instead. Sources: The X plugin card. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not paste an X token into chat. Deliverable: Plugin state, fallback plan. Review point: I pick the fallback.

๐Ÿ’ก

Pro tip: If tools=0 while it says connected, do not spend an hour reconnecting. Use the browser or wait for the fix.

Secrets

4 prompts

Secret card, never chat

6/21

โœจ What it does

The Bot stores [SECRET NAME] on the secret card so the value never has to appear in this thread. You take over the computer to type the value yourself.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: Store [SECRET NAME] on the secret card. Confirm I never have to paste it into this thread. Sources: Secret card UI. I will take over to enter the value. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not echo the secret back. Do not write it to a file in /workspace. Deliverable: Stored (yes/no), which Bots can use it, rotation reminder. Review point: I enter the value via takeover.

๐Ÿ’ก

Pro tip: If a skill asks for a key in the prompt, refuse and move it to the secret card.

Hunt keys already in chat or files

7/21

โœจ What it does

The Bot searches this computer and recent threads for strings that look like API keys, and lists the paths without printing the secrets. You rotate anything that was sitting in chat.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: Search this computer and recent threads for strings that look like API keys. List paths. Do not print the secrets. Sources: /workspace, ~/.config if present, this conversation. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not print the secret values. Do not commit them. Deliverable: Path, what it looks like (vendor), recommended move to secret card. Review point: I rotate anything that was in chat.

๐Ÿ’ก

Pro tip: Shared computer. One leaked .env is every Bot's .env.

Rotate after a Reset scare

8/21

โœจ What it does

The Bot lists secrets and logins you should rotate after a Reset or a computer refresh. You pick which ones to rotate; it does not rotate them for you.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: List secrets and logins I should rotate if we Reset or refreshed the computer. Sources: Secret card, plugin list, browser logged-in sites. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not Reset. Do not rotate until I pick one. Deliverable: Rotate / leave, reason. Review point: I rotate.

๐Ÿ’ก

Pro tip: Refresh keeps some state and drops other (WhatsApp link sessions). Treat tokens as dirty if you are unsure.

Vendor token least privilege

9/21

โœจ What it does

The Bot reads [VENDOR] docs and recommends the smallest token scopes that still cover [JOB], preferring read-only when that is enough. You create the token.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: For [VENDOR], recommend the least-privilege token scopes for [JOB]. Read-only if that is enough. Sources: [VENDOR DOCS] in the browser. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not create the token. Do not paste it. Deliverable: Scopes, why, and what the Bot must still not do. Review point: I create the token.

๐Ÿ’ก

Pro tip: A Grok Bot with a write-all Stripe key is a finance incident waiting for a confused routine.

Common connectors

4 prompts

Gmail: list vs download

10/21

โœจ What it does

The Bot uses the Gmail plugin only to find messages for [EMAIL JOB], then pulls attachments through the browser or Drive and stores them at [PATH]. You approve that plan before it starts fetching files.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: For [EMAIL JOB], use the Gmail connector only to find messages. Pull attachments via the browser or Drive. Sources: Gmail plugin, cloud browser. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not claim you downloaded bytes via the connector if you did not. Deliverable: Plan: find via plugin, fetch via browser, store at [PATH]. Review point: I approve the plan.

๐Ÿ’ก

Pro tip: Plan the job for the browser or Drive, not the connector download tool that does not exist.

Slack plugin vs Slack event wake-up

11/21

โœจ What it does

The Bot explains whether you need the Slack plugin for reading and drafting, or a phrase trigger for [PHRASE], and sets up only the path you named. You install it, and nothing posts without your approval.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: Explain and then set up the path we need: Slack plugin for reading/posting drafts, or an event trigger for [PHRASE]. Do not post without approval. Sources: Settings, Slack. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not post to Slack. Do not install into a workspace I did not name. Deliverable: Which path, which workspace, approval line. Review point: I install.

๐Ÿ’ก

Pro tip: Connecting multiple workspaces is its own flow. Do not assume one install covers them.

Vercel / deploy plugin

12/21

โœจ What it does

The Bot connects Vercel or [HOST] so it can read logs for [PROJECT], and it will not trigger a production deploy. You read the logs.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: Connect Vercel (or [HOST]) to read logs for [PROJECT]. Do not trigger a production deploy. Sources: Plugin marketplace, [PROJECT]. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not deploy to production. Do not change domains. Deliverable: Connected, last deploy visible, log snippet path. Review point: I read the logs.

๐Ÿ’ก

Pro tip: Pair with the forum thread on OAuth redirect failures. Re-authenticate if it loops.

Coolify or self-host inspect

13/21

โœจ What it does

The Bot uses the Coolify or [PAAS] plugin to inspect [APP] status, last deploy, and errors, without restarting anything. You click restart if it is actually needed.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: Use the Coolify (or [PAAS]) plugin to inspect [APP]. Do not restart or redeploy. Sources: The plugin, [APP NAME]. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not restart, redeploy, or change env vars. Deliverable: Status, last deploy, error if any, links. Review point: I restart if needed.

๐Ÿ’ก

Pro tip: Inspect first. Restart is a human click.

Like these prompts? There are full tutorials behind them.

Learn the workflows, not just the prompts. 300+ easy-to-follow tutorials inside AI Academy โ€” and growing every week.

Try AI Academy Free

Browser as first-class tool

4 prompts

No API, click the site

14/21

โœจ What it does

The Bot does [JOB] on [SITE] in the cloud browser the way a person would, with no programming interface required. You take over for login and confirm the result.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: Do [JOB] on [SITE] in the cloud browser like a person. No API required. Sources: [SITE], takeover for login. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not ask me to paste the password. Stop at irreversible clicks. Deliverable: What you clicked, screenshots, result file. Review point: I confirm the result.

๐Ÿ’ก

Pro tip: If there is no clean API, that is not a blocker. It is the product.

Chrome DevTools for a broken page

15/21

โœจ What it does

The Bot opens [URL] and captures console and network errors that help explain [BUG], without changing the site. You file the ticket.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: Open [URL] and capture console and network errors that explain [BUG]. Do not change the site. Sources: Cloud browser, DevTools if available. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not run random snippets on production. Deliverable: Errors, HAR or screenshot paths, likely cause vs hypothesis. Review point: I file the ticket.

๐Ÿ’ก

Pro tip: Use it for a repro pack, not to "fix prod".

Logged-in session reuse

16/21

โœจ What it does

The Bot lists sites this computer is already signed into that [JOB] needs, and does not sign into extra sites. You take over for any missing logins.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: List sites this computer is signed into that [JOB] needs. Do not sign into extra sites. Sources: The browser profile on the computer. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not log out of sessions I did not name. Do not log into new ones without takeover. Deliverable: Site, signed-in (yes/no/unknown), which Bot should use it. Review point: I take over for missing logins.

๐Ÿ’ก

Pro tip: That is a feature and a warning. A shopping login is also the finance Bot's login.

Passkeys and "try another way"

17/21

โœจ What it does

The Bot stops when [SITE] asks for a passkey, hands you the computer, and offers Try another way instead of looping. You finish the login.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: If [SITE] wants a passkey, stop and hand me the computer. Offer Try another way. Do not sit in a loop. Sources: [SITE] login. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not guess passwords. Do not store passkeys you cannot use later. Deliverable: Hand-over, what I need to do, then resume steps. Review point: I finish login.

๐Ÿ’ก

Pro tip: If the Bot never surfaces Take over, ask: hand me your computer.

Team and enterprise

4 prompts

Team marketplace vs personal plugins

18/21

โœจ What it does

The Bot lists every plugin on this computer and marks which ones look personal versus team-approved, using [TEAM POLICY IF ANY] when you have one. You remove the ones that should not live on a shared computer.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: List plugins on this computer and mark personal vs team-approved. Recommend removals. Sources: Plugin list, [TEAM POLICY IF ANY]. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not uninstall until I pick one. Deliverable: Keep / remove / ask-admin. Review point: I remove.

๐Ÿ’ก

Pro tip: Do not install a personal random plugin on a team computer that every Bot shares.

SSO and the Linux VM

19/21

โœจ What it does

The Bot writes a login plan for [SSO APP] that does not assume a device-trust app on the Bot computer. You do the company sign-in yourself.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: For [SSO APP], plan a login that does not assume FastPass on the Bot VM. I will take over for device trust. Sources: [APP], [IDP]. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not bypass SSO. Do not store my password. Deliverable: Login plan, where I take over, what session should persist after. Review point: I do the SSO dance.

๐Ÿ’ก

Pro tip: Official teams docs: configure the computer to your policies. Plan for takeover on SSO.

What plugins Bots never get

20/21

โœจ What it does

The Bot writes a list of plugins this computer must never install, covering [BANKS, PAYROLL, PROD DEPLOY, IDP ADMIN]. You paste that list into the roster note.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: Write a plugin denylist for this computer: [BANKS, PAYROLL, PROD DEPLOY, IDP ADMIN]. Sources: My rules, current plugin list. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not install anything on the denylist. Deliverable: Denylist plus the browser-read-only fallback if we only need to look. Review point: I paste it into the roster note.

๐Ÿ’ก

Pro tip: If the plugin can move money or ship prod, it is a human plugin.

Remote HTTP MCP, not local stdio

21/21

โœจ What it does

The Bot tells you whether [TOOL] has a remote web plugin or whether you should use the cloud browser, and will not invent a local laptop setup. You connect the path that actually works.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: For [TOOL], tell me whether a remote HTTP plugin exists, or whether I should use the browser. Do not invent a local MCP setup. Sources: Marketplace, [TOOL DOCS], my notes: [WHAT I NEED]. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not ask me to run a stdio MCP on the cloud computer as if it were local. Deliverable: Plugin / browser / cannot, plus the connect steps that stay on the secret card. Review point: I connect.

๐Ÿ’ก

Pro tip: If the tool is only on your laptop, use the cloud browser or a remote HTTP server.

Free tool

Prompt Optimizer

Turn a rough idea into a structured, professional AI prompt.

Try it free โ†’

Frequently Asked Questions

Grok Bot is an always-on AI teammate from xAI / SpaceXAI that runs on a persistent cloud computer (browser, files, terminal). You message it like a coworker and it finishes work inside the apps you already use. Grok on grok.com or in the X app is a chat assistant with live search and Grok Imagine. These pages are only for the teammate product. For chat and Imagine prompts, use the Grok prompts library.
Yes. Official docs are explicit: isolation is per user, not per Bot. Files, browser logins, and plugins on the computer are visible to every Bot on your account. Do not treat a second Bot as a security boundary. Put irreversible actions (send, pay, delete, production changes) behind approval.
Access has expanded since the August 2026 launch. It is included with SuperGrok plans and with Cursor Pro and Cursor Teams, plus a limited free trial for everyone else at times. Plans and weekly usage change. Check the official Grok Bot plans page before you buy a seat for this product.
Staff-confirmed: Grok Bot cannot attach local or stdio MCP. Use a remote HTTP MCP server, or use the cloud browser. If a tool only talks stdio on your laptop, it will not attach to the Bot computer.
On the secret card. Official Cursor help: never paste API keys into the Bot chat. Keys in chat land in the transcript, and the transcript is sent each turn. Shared computer means every Bot can see files you drop in the workspace.

Prompts are the starting line. Tutorials are the finish.

A growing library of 300+ hands-on tutorials on ChatGPT, Claude, Midjourney, and 50+ AI tools. New tutorials added every week.

7-day free trial. Cancel anytime.