GROK BOT / vet-a-marketplace-bot-before-adding

Grok Bot

Vet a Marketplace Bot before adding

Review a Marketplace Bot’s job, skills, routines, and requested integrations on the public page and in the Grok Bot app before you create a copy on your account, so you know what tools and behavior you are inviting onto your shared computer. Official Share a Bot docs warn that a public link exposes identity, description, skills, and routines, and that adding accepts third-party bot terms (Create and manage Bots). Matt Palmer’s staff guide says to evaluate templates the way you evaluate skills or software and to read context and integrations before Add Bot (Templates for Grok Bot).

What you need

A Marketplace listing or x.ai/bot/… preview, the Grok Bot app for the in-app review step, and a clear job you want the Bot to own so a vague description is an easy reject. Neighboring jobs include Add a Bot from the Grok Bot Marketplace for the install path after review, What a Marketplace Bot copy carries for include/exclude boundaries, and Toggle public template sharing for Grok Bot when your team admin controls outbound template publishing. More Grok Bot jobs live on the Grok Bot hub.

Vet on the public page

  1. Open the Bot from x.ai/bot/marketplace or from a shared https://x.ai/bot/… link. Confirm the host is x.ai before you proceed.
  2. Read the name, creator byline, and short job blurb. Prefer a concrete outcome (“fact-check with live search”, “writer-ready SEO briefs”) over a vague general helper.
  3. Read the longer instruction / skill list on the Marketplace Bot page. Note every tool, CLI, data source, or external account it expects, and every action it claims it will never take without your yes.
  4. Check for routines or scheduled work called out in the listing. Decide whether you want those triggers on your account before you enable them after install.
  5. Reject the install when the page asks for broad production access, unclear send permissions, or secrets you would not put in a public document — Share a Bot tells creators to strip those before publishing, and a listing that still demands them is a warning.

Vet again inside Grok Bot

When you choose Import Bot / Add to Grok Bot, finish the handoff in the app and stop on the review screen. Confirm the context, memories, and integrations match the public page. Add the Bot only when that list matches the job you want. After the copy lands, set Ask-first Auto-review rules for sending, publishing, deleting, purchasing, and production changes (Approvals, security, and privacy), reconnect plugins with your own accounts, and run one supervised task before you leave it on a routine.

Pitfalls

Treating “listed on Marketplace” as a security audit skips the review the staff guide requires. Approving every connector on first chat expands a third-party recipe across your shared Grok Bot computer, which every Bot on the account can reach. Enabling routines immediately after install can schedule work before you have tested the Bot’s send and publish boundaries.