Prompt Library

Grok Bot security prompts: approvals, secrets, shared computer

21 copy-paste prompts

Official: Bots do not see passwords. Draw the approval line on irreversible actions and 2FA. Isolation is per user, not per Bot. These prompts make that explicit in every description.

In short: This page contains 21 copy-paste ready prompts, organized into 5 categories with a description and pro tip for each. The first 5 prompts are free instantly, no signup needed. Hand-curated and tested by the AI Academy team.

Louis Corneloup
By Louis Corneloup · Founder, Techpresso
Last updated ·Hand-curated & tested by the AI Academy team

Approvals

5 prompts

Irreversible-action list

1/21

✨ What it does

The Bot writes the irreversible-action list for this computer (send, pay, delete, publish, production) and the approval card text you want to see. You paste that list into every Bot.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: Write the irreversible-action list for this computer and the approval card text I want to see. Sources: My tools [LIST], my hard rules. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not perform any of these actions. Deliverable: Action, why it is irreversible, approval text. Review point: I paste it into every Bot.

💡

Pro tip: If it is not written, a helpful Bot will eventually do it.

Takeover for 2FA and CAPTCHA

2/21

✨ What it does

The Bot hands you the computer when [APP] asks for a second-factor code, a CAPTCHA, or a passkey, and will not ask for the code in chat. You enter the code yourself.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: If [APP] asks for 2FA, CAPTCHA, or a passkey, hand me the computer. Do not ask for the code in chat. Sources: [APP] login. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not store backup codes in /workspace. Deliverable: Handover, then resume steps after I return control. Review point: I enter the code.

💡

Pro tip: Never paste an OTP into chat. The transcript is sent each turn.

Passkeys: try another way

3/21

✨ What it does

The Bot stops on a passkey prompt at [SITE], hands you the computer, and suggests Try another way. You finish the login.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: On passkey prompts, stop, hand me the computer, and suggest Try another way. Sources: [SITE]. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not create a new passkey on the Bot VM unless I say so. You may not be able to use it later. Deliverable: What I will see, what I should click. Review point: I finish login.

💡

Pro tip: If Take over never appears, say: hand me your computer.

Local command auto-review

4/21

✨ What it does

The Bot shows you the exact local command and waits before it runs, and does not treat Always allow as always. You approve each command until you trust a narrow skill.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: Before any local-computer command, show me the exact command and wait. Do not assume Always allow means always. Sources: Local permission state. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not run a command I have not seen on the card. Deliverable: The command, why, what it touches. Review point: I approve per command until I trust a narrow skill.

💡

Pro tip: Read the card. Always allow is not always (forum: ExternalShell still blocked).

Team ceiling coming

5/21

✨ What it does

The Bot writes a local-execution ceiling for this roster (Never, Ask every time, or Always) per command class, using your comfort line [READ ALWAYS, WRITE ASK, NETWORK NEVER]. You paste that table into the descriptions.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: Write a local-execution ceiling for this roster: Never / Ask every time / Always, per command class. Sources: My comfort: [E.G. READ ALWAYS, WRITE ASK, NETWORK NEVER]. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not change actual OS permissions. Deliverable: Ceiling table for the descriptions. Review point: I paste it.

💡

Pro tip: Until it ships, write your own ceiling in the Bot description.

Shared computer

4 prompts

Bots are not a fence

6/21

✨ What it does

The Bot audits this computer as one security domain and lists data that should not live here if an intern Bot also runs here. You move the hot data off this computer.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: Audit this computer as one security domain. List data that should not live here if an intern Bot also runs here. Sources: Files, browser sessions, plugins. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not delete files yet. Do not Reset. Deliverable: Too-hot-for-this-VM list and where it should live instead (my laptop, vault, not-here). Review point: I move the hot data.

💡

Pro tip: Do not put "confidential HR" on Bot A and "intern" on Bot B and call it isolation.

X login lock is real

7/21

✨ What it does

The Bot stops if X or [SITE] locks the computer login, and will not retry in a loop. You unlock it or skip that site.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: If X (or [SITE]) locks the Bot computer's login, stop. Do not retry in a loop. Tell me to take over or use another path. Sources: The lock screen. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not fire more login attempts. Deliverable: What you saw, stop reason, human options. Review point: I unlock or I skip.

💡

Pro tip: Forum: X login lock on the Bot computer. Plan a takeover, not a brute force.

WhatsApp and refresh

8/21

✨ What it does

The Bot lists which sessions die on a computer refresh, such as linked phones, versus what should survive. You export what you need before anyone hits refresh.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: List sessions that will die on a computer refresh (linked devices, etc.) vs what should survive. Sources: Official staff note, what we have linked. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not refresh. Deliverable: Survives / dies, and what I should export first. Review point: I export.

💡

Pro tip: Linked-device sessions can vanish on refresh. Plan for that.

Trial end does not delete

9/21

✨ What it does

The Bot helps you export [FILES] from Computer view when usage or a trial is exhausted, and will not Reset. You export first.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: If usage or trial is exhausted, help me export [FILES] from Computer view. Do not Reset. Sources: Computer view. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not Reset. Do not create new Bots in a first-run window. Deliverable: Export paths and a "wait vs Reset" note. Review point: I export.

💡

Pro tip: Export first. Do not Reset in a panic.

Secrets and transcripts

4 prompts

Full transcript each turn

10/21

✨ What it does

The Bot audits this thread for secrets without repeating them, and tells you whether to abandon the thread. You rotate the leaked values and start a clean Bot.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: Audit this thread for secrets. If you find any, tell me to rotate and to start a new Bot for future work. Do not repeat the secret. Sources: This conversation. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not print the secret. Do not store it in a file. Deliverable: Dirty (yes/no), what to rotate, whether to abandon this thread. Review point: I rotate and I start clean.

💡

Pro tip: That is why OTP in chat is forever. Start a new Bot if a thread is dirty.

Secret card only

11/21

✨ What it does

The Bot moves [KEY NAME] to the secret card and checks that it is not in this thread or in /workspace. You take over to enter the value.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: Move [KEY NAME] to the secret card. Confirm it is not in this thread or /workspace. Sources: Secret card, workspace search (names only). Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - I enter the value via takeover. Deliverable: Moved / still-leaked-in-files (paths only). Review point: I enter it.

💡

Pro tip: If a community skill says "paste your key", that skill is wrong.

No passwords in Teach a task

12/21

✨ What it does

The Bot splits the upcoming Teach a task of [WORKFLOW] into login (takeover, not recorded) and the workflow (recorded). You follow that two-phase plan.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: For the upcoming Teach a task of [WORKFLOW], split login (takeover, not recorded) from the workflow (recorded). Sources: [WORKFLOW]. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not start recording until login is done and the screen is clean. Deliverable: Two-phase plan. Review point: I follow it.

💡

Pro tip: Take over for login, then start the recording.

Customer data ban

13/21

✨ What it does

The Bot writes a production-customer-data ban for this computer: no exports, no tickets with personal data copied to /workspace, no production database. You paste that ban into the descriptions.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: Write a production-customer-data ban for this computer: no exports, no tickets with PII copied to /workspace, no prod DB. Sources: My data policy. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not export any customer list as part of this task. Deliverable: Ban text and examples of allowed staging fixtures. Review point: I paste it.

💡

Pro tip: Write it into eng and CS Bots. Shared computer will otherwise download a CSV "to help".

Like these prompts? There are full tutorials behind them.

Learn the workflows, not just the prompts. 300+ easy-to-follow tutorials inside AI Academy — and growing every week.

Try AI Academy Free

Break-glass and recovery

4 prompts

Export before Reset

14/21

✨ What it does

The Bot stages exports of [FILES] and lists what Reset will destroy, without Resetting. You Reset only if you still need to.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: Stage exports of [FILES] and list what Reset will destroy. Do not Reset. Sources: Computer filesystem, official recovery note. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not Reset. If a Reset dialog is open and hidden, tell me about Tab-then-Enter only if I ask. Deliverable: Export paths, destroy list, wait-vs-Reset. Review point: I Reset only if I still need to.

💡

Pro tip: Hidden Reset dialog on some versions opened behind Settings. Do not double-Reset.

Orphaned Cursor link

15/21

✨ What it does

The Bot stops if Grok Bot cannot relink because a Cursor account was deleted, looks at [PASTE], and writes the human options. You contact support if you still need to.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: If Grok Bot cannot relink because a Cursor account was deleted, stop and write the human options. Do not create a maze of new accounts. Sources: What I see: [PASTE]. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not delete more accounts. Deliverable: Likely cause, who to contact (Cursor / xAI), what not to do. Review point: I contact support if needed.

💡

Pro tip: Do not delete Cursor as a cleanup trick.

VPN and cursorvm.com

16/21

✨ What it does

The Bot diagnoses why chat works but the computer looks offline, and puts VPN or firewall blocks to cursorvm.com ahead of Reset. You change the network first.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: If chat works but the computer is offline, check VPN/firewall to cursorvm.com before Reset. I will change network. You diagnose only. Sources: Symptoms I paste. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not Reset as step 1. Deliverable: Network checklist, then app checklist, then Reset as last. Review point: I try DNS/VPN first.

💡

Pro tip: Chat can work while the computer is "offline". That split is a clue.

Overbooked is not my account

17/21

✨ What it does

The Bot reads the error and tells you that overbooked or failed to respond is usually service load, not your meter. You wait instead of Reset-spamming.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: If you see overbooked or Bot failed to respond, tell me it is likely service-side load. Do not Reset in a loop. Sources: The error text. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not Reset repeatedly. Do not create replacement Bots. Deliverable: Wait / try later / then these three steps. Review point: I wait.

💡

Pro tip: Waiting beats Reset-spam.

Policies to paste

4 prompts

Universal Bot footer

18/21

✨ What it does

The Bot writes a six-to-eight-line footer for every Bot on this account: shared computer, no secrets in chat, no send or pay, takeover for second-factor, fail closed, only you create routines. You paste it everywhere.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: Write a 6-8 line footer for every Bot on this account. Sources: Official approvals and privacy page, our never-do. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. Deliverable: Footer text. Review point: I paste it everywhere.

💡

Pro tip: Shared computer, no secrets in chat, no send/pay/delete/prod, takeover for 2FA, fail closed, only I create routines.

Incident note if a Bot did the wrong thing

19/21

✨ What it does

The Bot writes a checklist for a Bot that sent, paid, or leaked: preserve evidence, revoke access, notify people, Reset last. You keep that checklist somewhere the Bot cannot delete.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: Write an incident checklist for "a Bot sent / paid / leaked". Do not Reset as step 1. Sources: Our tools. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not Reset now. This is a checklist only. Deliverable: Preserve, revoke, notify, then Reset if needed. Review point: I keep the checklist offline too.

💡

Pro tip: Evidence first. Reset second. Rotation third.

What security Bots never do

20/21

✨ What it does

The Bot writes a never-do list for any Bot that talks about security: no identity-admin access, no production keys, no customer personal-data exports. You paste that list.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: Write never-do for any Bot that talks about security: no IDP admin, no production keys, no customer PII exports. Sources: My rules. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. Deliverable: Never-do list. Review point: I paste it.

💡

Pro tip: Security work on this computer is policy and review, not becoming the IDP admin.

Bots are not a security boundary

21/21

✨ What it does

The Bot writes a one-page memo you can paste into every Bot description: they share one computer, what that means, and where approval still sits with you. You paste the memo.

You are a Grok Bot on my shared cloud computer (browser, files, terminal). This is a standing job, not a grok.com chat. Outcome: Write a one-page memo I can paste into every Bot description: shared computer, what that means, and the approval line. Sources: My tools: [LIST]. Secrets already on the computer: [LIST OR UNKNOWN]. Constraints: - Do not send messages, enroll anyone, make payments, delete records, or change production settings. - If a login, 2FA, passkey, or CAPTCHA appears, ask me to take over the computer. Never ask me to paste a password or API key into chat. - If a source is missing or stale, say so. Do not invent numbers or contacts. - Do not rotate secrets. Do not log out of apps. Deliverable: Memo plus 5 "this is not isolated" examples. Review point: I paste it.

💡

Pro tip: A "finance-only" Bot is a name, not a fence. Approvals are the fence.

Free tool

Prompt Optimizer

Turn a rough idea into a structured, professional AI prompt.

Try it free →

Frequently Asked Questions

Grok Bot is an always-on AI teammate from xAI / SpaceXAI that runs on a persistent cloud computer (browser, files, terminal). You message it like a coworker and it finishes work inside the apps you already use. Grok on grok.com or in the X app is a chat assistant with live search and Grok Imagine. These pages are only for the teammate product. For chat and Imagine prompts, use the Grok prompts library.
Yes. Official docs are explicit: isolation is per user, not per Bot. Files, browser logins, and plugins on the computer are visible to every Bot on your account. Do not treat a second Bot as a security boundary. Put irreversible actions (send, pay, delete, production changes) behind approval.
Access has expanded since the August 2026 launch. It is included with SuperGrok plans and with Cursor Pro and Cursor Teams, plus a limited free trial for everyone else at times. Plans and weekly usage change. Check the official Grok Bot plans page before you buy a seat for this product.
Official docs: Bots do not see passwords. You take over the computer for password, passkey, 2FA, and CAPTCHA. Do not paste those into chat. The full transcript is sent each turn, and there is no compact/new-session control on desktop or iOS.
No. Official overview: isolation is per user, not per Bot. Files, browser sessions, and plugins are shared. Forum consensus: Bots are not a security boundary. If you would not give an intern that login, do not leave it on this computer.

Prompts are the starting line. Tutorials are the finish.

A growing library of 300+ hands-on tutorials on ChatGPT, Claude, Midjourney, and 50+ AI tools. New tutorials added every week.

7-day free trial. Cancel anytime.