The short answer

Grok Bot's documented protections are real but partial. Each user gets an isolated cloud computer, plugin tokens stay on Cursor's servers, and Privacy Mode keeps your data out of training. The risks sit closer to you: every Bot shares your logins, outside content can try to steer a Bot, and in October the in-chat password form leaked into page snapshots.

This page summarizes SpaceXAI's security, approvals and Team Bots documentation and Cursor's help pages as of October 7, 2026, plus attributed Cursor staff replies. It is not a security audit; we have not tested these controls ourselves.

Documentation: Grok Bot security FAQ ↗ Grok Bot security ↗ Approvals, security and privacy ↗ Forum: password filled by the Secure Form shown in a page snapshot (staff reply, October 5) ↗

RiskWhat the docs or staff sayWhat to do
Other users reaching your computerEach user gets a dedicated Firecracker microVM; one user cannot reach another'sNothing; this is Cursor's side
One of your Bots using another's loginAll your Bots share one computer, its files and browser sessions; Bots are not a security boundarySign in only to what any Bot may use; separate Cursor user for anything that must stay apart
Passwords in the in-chat formOctober 5: a Secure Form password appeared in a page snapshot; fix in progressChoose Open the screen and type passwords yourself
A web page steering a BotOutside content is marked untrusted; defenses reduce but do not eliminate the riskAsk first rules on sending, buying, deleting and publishing
Your data used for trainingNot with Privacy Mode on; Legacy Privacy Mode is unsupportedCheck your Cursor privacy setting
A Bot running commands on your own laptopOff unless you allow it; default is Ask every time; the docs recommend Never allowSet Execution on Local Computer to Never allow unless you need it

What a Bot can reach

Isolation is per user, not per Bot. The security FAQ says each user gets a dedicated Firecracker microVM with its own kernel, memory and virtual devices, and one user cannot reach another user's computer. Within your account, every Bot shares that computer, so a file, browser session or command-line credential on it is available to all of your Bots. A Bot has no identity of its own and cannot hold more access than you do.

A Cursor staff member said on October 2 that the team is working on letting an individual Bot keep its own browser session; until that ships, treat the shared computer as one trust zone. Plugins are account-wide too: an installed plugin is available to every Bot, and blocking a plugin does not block that service's website, which only Enterprise Network Controls can close. Our shared-computer guide has the details.

Documentation: Grok Bot security FAQ ↗ Approvals, security and privacy ↗ Computer and apps ↗ Forum: Bots are not a security boundary (staff reply, October 2) ↗

Logins, passwords and the Secure Form issue

The documented way to sign a Bot in is to take over its screen and type the password, passkey or code yourself; the docs say to avoid pasting passwords or one-time codes into chat. For keys, a secret request masks the value, keeps it out of the transcript and away from the model. When a page needs your input, a Bot can also show a form in the chat, the Secure Form, and fill your answers into the page.

That form is the open issue. On October 5 a user reported that after the Secure Form filled a password, the snapshot the Bot took before clicking Sign in showed it in plain text, putting it in the session's tool output. A Cursor staff member replied the same day that this should not happen, that a fix was in progress, and that the safest way to sign in meanwhile is to choose Open the screen and do it yourself. Version 0.68.1 (October 7) changed where Secure Forms fill but does not mention the snapshot.

1Password can connect from the app on a Mac (0.53.0) so a Bot signs in with your saved logins, asking first unless you turn on Auto fill. Staff described known issues on September 30: on some pages, including Instagram and Letterboxd, the card says Filled while the password stays empty, and the Google sign-in popup cannot be filled from 1Password. Hardware security keys work on macOS and Windows, with every use approved by you.

Documentation: Computer and apps ↗ Approvals, security and privacy ↗ Cursor help: store secrets securely ↗ Forum: password filled by the Secure Form shown in a page snapshot (staff reply, October 5) ↗ Grok Bot changelog ↗ Forum: 1Password autofill says Filled but the password stays empty (staff reply, September 30) ↗ Forum: Grok Bot will not log in to Google with 1Password (staff reply, September 30) ↗

Approvals and Auto Review

Approval cards show the proposed action: Allow once, Always allow (which can save a rule) or Deny. Auto Review is an independent review model that checks risky actions before they run, covering shell commands, plugin calls, computer use, changes to routines and triggers, and launching Cloud Agents or subagents. The docs say it does not review every side effect; memory writes and most settings changes are examples. An approval controls the proposed action; it does not reverse work already done.

Rules decide what stops. Ask first rules always stop matching actions for you; Allow automatically rules let actions through only if the review finds no other reason to stop; when both match, Ask first wins. Cursor's help says an approval raised by unattended work, such as a routine or another Bot, expires after about 10 minutes. On Team Bots, a conversation where nobody can answer an approval runs without Auto-review unless your team requires it. Our permission boundaries guide turns this into a worksheet.

Documentation: Grok Bot security ↗ Approvals, security and privacy ↗ Cursor help: how-tos (approval expiry) ↗ Team Bots ↗

Prompt injection

The security page is direct about it: content a Bot reads from the outside world, such as web pages, plugin results and command output, can try to steer it. Grok Bot layers Auto Review over controls that do not depend on a model's judgment, including the network policy, per-action approvals and per-user isolation, and marks outside content as untrusted. The docs say these controls reduce, but do not eliminate, the risk, which is the reason to keep consequential actions behind approval.

In practice, the riskiest setups combine broad reading with unattended writing: a routine that reads every new email or every message in a busy channel and can also send, pay or delete. Keep listeners narrow, keep drafts on, and give a routine a stop-if-nothing-changed rule. A forum question asking for more detail on prompt-injection protection, from August 30, had no staff reply when we checked.

Documentation: Grok Bot security ↗ Forum: security isolation and prompt injection protection (no staff reply) ↗

Your data: training, retention and location

Grok Bot uses Cursor's sign-in and data settings. It requires data storage, so Legacy Privacy Mode is not supported. Training opt-out follows your Cursor privacy settings, and with Privacy Mode on, customer data is not used for training; x.ai/bot says the cloud computer is encrypted in transit and at rest. The docs say zero data retention follows Cursor's existing provider agreements, though providers may run abuse classifiers and store flagged data for investigation.

Your computer keeps files and browser sessions on a durable disk; idle computers hibernate, which is not deletion. Under Cursor's DPA, data is deleted or returned within 30 days of written direction after the service ends, and Cursor's help says deleting your account removes all data within 30 days. Enterprise teams can turn on Action Recording, which keeps scrubbed Bot actions for 90 days. Computers run in the United States today, and Anysphere, the company behind Cursor, holds ISO/IEC 27001 and 42001 certifications that include Grok Bot.

Documentation: Grok Bot security ↗ Grok Bot FAQ ↗ Approvals, security and privacy ↗ Grok Bot product page and FAQ ↗ Cursor help: delete your Grok Bot account ↗ Forum: privacy and terms of use with a Cursor account (staff reply, August 12) ↗

Team Bots and shared conversations

Team Bots keep each teammate's chat private, and a plugin that needs a sign-in uses the account of whoever is talking, so one person's access is never lent to another. Two things are shared by design: team memory, read by every teammate's conversation, and the Bot's secrets, which it can use in anyone's chat. Slack channels and threads share one computer for that Bot, so do not post anything there the whole channel should not see. See our Team Bots guide.

Documentation: Team Bots ↗

A safer setup in ten minutes

These steps come from the docs' least-privilege advice and the issues above. They do not make a Bot safe on their own; they limit what a mistake can reach.

Documentation: Approvals, security and privacy ↗ Grok Bot security ↗

  1. Check your Cursor privacy setting, and keep Privacy Mode on if training opt-out matters to you.
  2. Add Ask first rules in Settings → General → Auto-review for sending messages, purchases, deletions and publishing.
  3. Leave email and Slack drafts on, so you review a draft card before anything goes out.
  4. Set Execution on Local Computer to Never allow unless a Bot needs your local files.
  5. Prefer plugins to browser logins; connect only the accounts a task needs, and revoke them in the source service when it is done.
  6. Type passwords on the Bot's screen yourself rather than in the Secure Form until Cursor confirms the snapshot fix.
  7. Keep anything that must stay separate, such as banking or a work admin account, off the shared computer.
  8. When a project ends, pause its routines, sign out of its sites, and remove its files from /workspace; deleting a Bot does not remove them.

Quick answers

Does Grok Bot train on my data?

Not with Privacy Mode on. The docs say training opt-out follows your Cursor account and privacy settings, and that with Privacy Mode enabled customer data is not used for training. A Cursor staff member said on August 12 that with Privacy Mode on, Grok Bot data is not used for training by Cursor or any model provider, including xAI. Legacy Privacy Mode, which stores nothing, does not work with Grok Bot at all.

Is it safe to type a password into the Grok Bot Secure Form?

Not for now. On October 5 a Cursor staff member confirmed a report that a password filled by the in-chat Secure Form appeared in plain text in a page snapshot, said a fix was in progress, and advised choosing Open the screen and typing the password yourself. The 0.68.1 notes on October 7 do not mention a fix. If you already used the form for a password, change it.

Can I keep one Bot away from my bank or email login?

Not with Bot boundaries. Every Bot on your account shares one cloud computer, with its files, browser sessions and command-line credentials, and the docs say not to use separate Bots as a security boundary. If a login must stay isolated, keep it off Grok Bot or use a separate Cursor user, which gets its own computer.

Where is my Grok Bot data stored?

In Cursor's cloud. The docs say Grok Bot computers run in the United States today, which is not the same as Cursor's US-only data residency program, and that your computer keeps files and browser sessions on a durable disk across sessions. Plugin tokens stay on Cursor's backend and are never stored on the computer.

Can a web page trick my Bot into doing something?

It can try. The docs say content a Bot reads, such as web pages, plugin results and command output, can try to steer it, and that Grok Bot's defenses reduce but do not eliminate that risk. Keep sending, buying, deleting and publishing behind Ask first rules so a steered Bot still has to stop for you.

Bots for this job

Directory listings that match this guide, read from each creator's public share page. They are not tested picks: check what a Bot can reach before you add it.

Browse: Bots for security

  • Box Inspector by @suddenlyjon ♞: Inspects a Grok bot's share link before you let it into your account
  • SniffBot by Kacper Rutkiewicz: Screens a candidate template link before anything is installed, reporting what the bot would actually be permitted to do once it is inside your account. The…
  • Security Warden by Mayur Darji: Gates another bot's risky moves like outbound messages, deletions, and shell, checking for secrets and personal data before they run

Sources & next steps

Capabilities are grounded in the documentation below. The workflow design and acceptance checks are editorial suggestions.

Build your own workflow brief ↗