Desktop harness · xAI

Grok Bot

Persistent AI teammates reached through a desktop client and executed on a hosted computer.

ProductGrok BotxAIDesktop · 35/114 current cells reviewed

Catalog twins:MarkdownJSON

Surface
Desktop
Execution
hosted
Target type
hosted observation
Default environment
hosted default
Tracks
Current
Latest current evidence
2026-08-28

Description and scope

About this harness

This profile represents one exact product surface—not every product from xAI.

Grok Bot appears here as a distinct Desktop harness because it is not the same surface as the consumer Grok web chat. The reviewed documentation requires the macOS or Windows app, while each Bot’s browser, filesystem, terminal, tools, and durable state live on a hosted computer.

Current documentation limits access to eligible SuperGrok or Cursor plans and says Linux has no desktop app. All Bots for one account share that account’s cloud computer, including its files, browser sessions, and command-line credentials; separate Bots are therefore not separate security boundaries. Access to the operator’s local computer is a separate, approval-controlled capability.

Capability cells cite dated public sources and retain plan, platform, runtime, and policy qualifications; unreviewed cells remain unknown.

Current-track snapshot

Support at a glance

35 of 114 atomic capabilities have a reviewed current status.

Research coverage31%
9 unique public sources on the current track
Supported
27
Public evidence supports the current claim.
Partial
5
Supported with a documented condition or limit.
Unsupported
3
A current source explicitly says no.
Unknown
79
No sufficiently scoped public evidence is published yet.
Unknown is not “unsupported.” It means this exact product-and-capability cell has not passed the catalog’s evidence bar. Conditions such as plan, platform, preview access, policy, and runtime stay attached to individual rows below.

Provider and standards provenance

Reviewed public references

These links support individual capability cells. They are not a product-wide certification.

Atomic capability ledger

Capability support

Open a capability record for its full notes, qualifiers, targets, and source links.

114 capabilities
CapabilityCurrentCurrent evidence and conditions
InterfacesAgent Plugins failure isolation

Reject invalid components narrowly without disabling valid components in the same package.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesAgent Plugins packaged MCP

Load MCP server configuration contained in an Agent Plugins package.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Agent Plugins compatible-client listing
  • transport: the listing names stdio, Streamable HTTP, and legacy SSE
  • runtime: support is registry-listed and was not independently conformance-tested by Can My Agent Use
Evidence and notes →
InterfacesAgent Plugins packaged skills

Load portable Agent Skills contained in an Agent Plugins package.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Agent Plugins compatible-client listing
  • runtime: support is registry-listed and was not independently conformance-tested by Can My Agent Use
Evidence and notes →
InterfacesAgent Plugins portable manifest

Load the published portable plugin.json manifest and its core components.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Agent Plugins compatible-client listing
  • runtime: support is registry-listed and was not independently conformance-tested by Can My Agent Use
Evidence and notes →
RuntimeAgent Skills core and discovery

Recognize, discover, and load reusable instruction packages centered on SKILL.md.

YSupported2 public referencesLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation and compatible-client listing
  • runtime: saved skills are available across Bots and packaged or private skills are managed through the desktop Plugins area
  • policy: connector or login prerequisites and per-Bot enablement can limit a skill at runtime
Evidence and notes →
RuntimeAgent Skills manual invocation

Let a user or agent explicitly select and activate a named skill.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
RuntimeAgent Skills progressive loading

Load skill metadata first and defer full instructions or resources until relevant.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
RuntimeAgent Skills references and assets

Resolve supporting reference files, templates, and assets from a skill package.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
RuntimeAgent Skills scripts

Resolve and execute optional scripts included with an Agent Skill under explicit runtime policy.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesAGENTS.md root instructions

Discover and apply the cross-agent AGENTS.md convention at repository scope.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
CollaborationArtifact export

Download generated files and other documented outputs.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • runtime: supported generated files can be previewed and saved from conversation cards; a complete workspace archive or repository transfer is not documented
  • policy: citations, action logs, and source links must be requested or produced by the workflow and are not guaranteed metadata on every artifact
Evidence and notes →
Files and mediaAudio file input

Upload recorded audio for use as model input.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • runtime: audio is a supported attachment up to 25 MB, but transcript, speaker, timing, and acoustic semantics are not documented on the reviewed page
Evidence and notes →
Security and privacyAudit logs

Record security-relevant activity in an administrative audit log.

NUnsupportedplanned1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • runtime: spend and usage are visible today; the documented Bot-action audit view is not yet available
Evidence and notes →
Models and contextAutomatic context compaction

Continue long sessions by automatically summarizing or pruning older context.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
RuntimeBackground agents

Keep a run going after the operator leaves the session.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • runtime: work runs on an account-scoped hosted computer and can continue after the desktop preview or operator laptop is closed
  • plan: an eligible SuperGrok or Cursor plan is required
Evidence and notes →
ToolsBrowser automation

Control a browser for navigation, clicks, forms, and page reading.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • runtime: automation runs in the persistent cloud computer's browser rather than the operator's local browser
  • policy: passwords, passkeys, verification codes, CAPTCHAs, payments, and human-required steps should use operator takeover
Evidence and notes →
ToolsCode execution

Run generated code in a documented execution environment.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
RuntimeComputer use

Inspect and act on a visual interface through screenshots and input actions.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • runtime: computer use runs on an account-scoped hosted Linux VM; all Bots for the account share its files, sessions, and credentials
  • policy: one Bot can run one computer-use task on its screen at a time; sensitive steps should use operator takeover
Evidence and notes →
RuntimeConcurrent subagents

Run multiple child-agent tasks concurrently with explicit queue and fan-out limits.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
ToolsConnectors

Connect to external services authorized by the user or organization.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • auth: installed connectors may require browser authentication
  • policy: installed connectors are account-wide and may be required, restricted, or disabled by an organization administrator
Evidence and notes →
Models and contextContext compaction controls

Trigger, inspect, configure, or disable context compaction.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Models and contextContext usage

Inspect consumed or remaining context budget during a conversation or run.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Models and contextContext window

Record the documented context-window limit by product, model, and mode.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
CollaborationConversation export

Export conversation history in a documented format.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
CollaborationConversation sharing

Share a conversation through a documented link or invitation.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesCustom instructions

Persist instructions at user or project scope.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Security and privacyData residency

Select or document geographic storage or processing regions.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Security and privacyData retention controls

Configure or document retention and deletion for covered product data.

PPartial1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • policy: operators can separately remove routines, connectors, shared files, browser sessions, Bots, and the account; deleting one Bot does not remove account-shared computer state
  • runtime: configurable retention periods, backup expiry, legal exceptions, and verified deletion-completion timelines are not established by the reviewed page
Evidence and notes →
ToolsDiffs and patches

Propose or apply file changes as diffs or patches.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Files and mediaDocument input

Upload common document formats for use as model input.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • runtime: desktop composer accepts up to six attachments per message and documents a 25 MB limit per document
  • policy: large, encrypted, damaged, or unusual files may not be readable; exact office-feature fidelity is not documented
Evidence and notes →
Security and privacyEncryption key management

Record documented encryption key ownership, scope, rotation, and revocation.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Files and mediaFile upload limits

Record numeric attachment size, count, page, duration, storage, and rolling quotas.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • runtime: six attachments per desktop message; 25 MB each for documents, images, and audio; 200 MB each for video
  • policy: page, duration, project storage, rolling quota, and remaining-quota visibility are not established by the reviewed page
Evidence and notes →
RuntimeHuman approval

Pause before a tool action or file change until a person confirms.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • policy: Auto Review is model-based and complements rather than replaces explicit approval boundaries and least privilege
  • runtime: local-computer execution defaults to asking every time and is configured separately from cloud-computer actions
Evidence and notes →
Files and mediaImage input

Attach, paste, or select an image for use as model input.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • runtime: desktop composer accepts up to six attachments per message and documents a 25 MB limit per image
  • policy: damaged or unusually formatted files may not be readable
Evidence and notes →
Models and contextLocal models

Run against a model hosted on the operator's machine.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
RuntimeLong-term memory

Persist notes across sessions.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • runtime: stable preferences, facts, and summaries persist with the named Bot; shared files and sign-ins belong to the account-scoped computer
  • policy: memory is not an authoritative source and can become stale
Evidence and notes →
InterfacesMCP Apps

Render an interactive interface returned by an MCP server inside the product.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP cancellation

Cancel an in-flight MCP request and handle cancellation correctly.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP client role

Consume capabilities exposed by MCP servers.

YSupported2 public referencesLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation and compatible-client listing
  • policy: team MCP allowlists, denylists, member-install policy, and network allowlists can disable a server
  • auth: hosted MCP authentication is shared across Cursor and Grok Bot for the account
Evidence and notes →
InterfacesMCP elicitation

Handle structured user-input requests initiated by an MCP server.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP legacy HTTP and SSE

Connect through the superseded HTTP plus SSE transport when migration compatibility is required.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Agent Plugins compatible-client listing
  • runtime: superseded transport support is registry-listed and was not independently tested by Can My Agent Use
  • policy: organization server and network allowlists can block a remote server
Evidence and notes →
InterfacesMCP list-changed notifications

Refresh capability lists when a server announces dynamic changes.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP logging

Receive structured log messages emitted by an MCP server.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP OAuth authorization

Complete the MCP authorization flow for protected remote servers.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP progress notifications

Receive progress updates for long-running requests.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP prompt-list notifications

Refresh prompt templates after a server announces changes.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP prompts

Invoke reusable MCP prompt templates.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP Registry metadata

Discover MCP servers and metadata through the official registry model.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP resource subscriptions

Subscribe to resource changes and receive update notifications.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP resources

Read MCP resources as live context.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP revision compatibility

Implement or negotiate the exact dated MCP revision.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP roots

Provide filesystem or workspace roots to an MCP server.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP sampling

Handle server requests for model sampling through the client.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP server instructions

Consume server-provided instructions during initialization.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP server role

Expose capabilities from the harness as an MCP server.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP stdio transport

Connect to a local MCP server over standard input and output.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Agent Plugins compatible-client listing
  • runtime: transport support is registry-listed and was not independently tested by Can My Agent Use
Evidence and notes →
InterfacesMCP Streamable HTTP

Connect to an MCP server over the current Streamable HTTP transport.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Agent Plugins compatible-client listing
  • runtime: transport support is registry-listed and was not independently tested by Can My Agent Use
  • policy: organization server and network allowlists can block a remote server
Evidence and notes →
InterfacesMCP task listing

List and page through tasks exposed by the task utility.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP tasks

Create, inspect, and manage long-running MCP tasks.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP tools

Invoke operations exposed by a Model Context Protocol server.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • policy: team MCP allowlists, denylists, member-install policy, and network allowlists can disable a server
  • auth: sign-in tokens for hosted MCP servers remain with the backend that runs tool calls on the computer's behalf
Evidence and notes →
Models and contextModel fallback

Switch to another model after a documented failure condition.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • runtime: automatic failover is documented and the serving model appears in usage analytics, but the operator cannot configure, select, or prevent fallback
Evidence and notes →
Models and contextModel selection

Choose the model or documented model class used for a run.

NUnsupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • runtime: model choice is fully managed by the product; neither members nor administrators receive a model picker
Evidence and notes →
ToolsMulti-file edit

Edit multiple files during one task.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesNative plugin system

Install and load a product-specific extension package.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesNested AGENTS.md instructions

Apply nested AGENTS.md files with directory-sensitive precedence.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
RuntimeNested subagents

Allow a child agent to delegate further work to another child agent.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Security and privacyOffline operation

Run a documented workflow without a required network connection.

NUnsupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • runtime: the desktop client depends on hosted execution and required cloud data storage; it is not a local-only or offline harness
Evidence and notes →
Security and privacyOrganization policy controls

Centrally configure and enforce product settings for an organization.

PPartial1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot team documentation observation
  • plan: enterprise availability is rolling out and controls vary by organization plan
  • policy: documented controls cover cloud agents, privacy mode, MCP and plugins, team rules, network allowlists, and local execution; full model, upload, sharing, retention, and subagent fan-out policy is not established
Evidence and notes →
Models and contextOutput token limit

Record the maximum generated response budget by exact model and harness mode.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Files and mediaPDF input

Upload a PDF for use as model input.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • runtime: desktop composer accepts up to six attachments per message and documents a 25 MB limit per document
  • policy: encrypted, damaged, unusually formatted, or very large files may not be readable
Evidence and notes →
RuntimePer-subagent model selection

Choose or constrain each child agent's model independently of the parent.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Pricing, usage, and limitsPlans and pricing

Compare documented plan, seat, included-usage, credit, and overage pricing by exact product.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesPlugin marketplace

Discover and install extensions through a documented registry or marketplace.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • policy: organization policy can require, restrict, or disable marketplace plugins
  • runtime: the marketplace covers supported connectors and packaged skills; private skills are managed under Yours
Evidence and notes →
InterfacesPlugin vendor extensions

Preserve namespaced host-specific behavior without representing it as portable core support.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesProject rules

Load persistent or path-scoped instructions from a documented product rule format.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
RuntimeProject-scoped Agent Skills

Discover skills installed for a repository or workspace.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Models and contextPrompt cache controls

Mark, retain, refresh, or invalidate cached prompt context.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Models and contextPrompt cache telemetry

Inspect cache hits, misses, token counts, latency, or billing effects.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Models and contextPrompt caching

Reuse eligible repeated prompt content under documented caching behavior.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
ToolsPull request integration

Open or review pull requests through a documented integration.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Pricing, usage, and limitsRate limits and quotas

Record documented product usage limits and reset periods.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Files and mediaRealtime voice

Speak and listen over a live audio session.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Models and contextReasoning effort controls

Choose a documented reasoning depth, effort, or budget for a run.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
CollaborationRole-based access control (RBAC)

Assign and enforce permissions through documented roles.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
RuntimeSandbox network access

Allow, deny, or restrict outbound network access from a tool sandbox.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
RuntimeScheduled runs

Start a task on a schedule without a new human prompt.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • runtime: each Bot can own up to 50 routines and the app keeps the 20 most recent run records per routine
  • policy: unattended routines may be paused after a long absence and consequential actions should remain approval-gated
Evidence and notes →
Files and mediaScreenshots

Capture a screen, window, or browser page for use as model input.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Security and privacySecrets management

Store and provide credentials through a documented secrets feature.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Pricing, usage, and limitsSession resume

Continue a previously saved product session.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
CollaborationShared projects

Share a product-defined project workspace with other people.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesStreaming output

Show text or tool events as they arrive during a run.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesStructured outputs

Return JSON or schema-constrained output through a documented product feature.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
RuntimeSubagent context

Define which conversation, instructions, files, memory, and tools a child receives.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
RuntimeSubagent delegation

Delegate a bounded task to another agent process.

PPartial1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • runtime: delegation uses distinct persistent named Bots with asynchronous messages and visible handoffs, rather than documented ephemeral child sessions
  • policy: all Bots for an account share one hosted computer, so delegation does not create a separate filesystem, login, or credential security boundary
Evidence and notes →
RuntimeSubagent management

List, inspect, and control child-agent tasks.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
RuntimeSubagent MCP access

Allow a child agent to use MCP tools or declare its own MCP servers.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
RuntimeSubagent permissions

Control child-agent tools, inherited permissions, and approval behavior.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
RuntimeSubagent results

Return a child agent's findings or work to the parent.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • runtime: visible asynchronous messages and shared files preserve useful handoff context, but Bot-to-group handoff messages are text-only and no typed result schema is documented
  • policy: shared files live on one account-scoped computer and do not create an isolated provenance boundary
Evidence and notes →
RuntimeSubagent write access

Allow a child agent to create or modify project files.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
ToolsTerminal commands

Propose or execute shell commands in a project environment.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • runtime: commands run on the account-scoped hosted computer by default; credentials and files there are shared across the account's Bots
  • policy: commands on the operator's local Mac or Windows computer are separately controlled and default to asking every time
Evidence and notes →
Security and privacyTraining data controls

Control or document model-training and service-improvement use of product content.

PPartial1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • policy: training opt-out follows Cursor account and privacy settings, and an organization's privacy mode governs team members
  • runtime: the reviewed page does not fully distinguish foundation-model training, evaluation, safety review, feedback, human review, and third-party subprocessors
Evidence and notes →
Pricing, usage, and limitsUsage metering

Inspect documented product usage such as requests, tokens, or cost.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
RuntimeUser-scoped Agent Skills

Discover personal or global skills outside the current project.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Files and mediaVideo input

Upload or select a video for use as model input.

YSupported1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • runtime: video is accepted up to 200 MB, but frame, audio, transcript, timing, metadata, and sampling semantics are not documented on the reviewed page
Evidence and notes →
ToolsWeb fetch

Retrieve live web pages or APIs during a run.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesWebMCP declarative form tools

Expose semantic HTML forms as structured tools through WebMCP annotations.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesWebMCP execution cancellation

Cancel pending tool registration or execution through abort signals and lifecycle rules.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesWebMCP imperative tools

Register JavaScript-backed tools through document.modelContext.registerTool().

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesWebMCP permissions policy

Gate tool exposure across documents and origins through the tools permissions policy.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesWebMCP security annotations

Communicate read-only and untrusted-content hints across the site-to-agent boundary.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesWebMCP tool discovery

Expose the active page tool list and schemas to a WebMCP-aware agent.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesWebMCP tool execution

Invoke a page tool with structured arguments and return its result to the agent.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
ToolsWorkspace files

Read or edit files inside a user-selected project.

PPartial1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Grok Bot desktop documentation observation
  • runtime: the documented workspace is a durable hosted `/workspace` shared across all Bots on one account, not an isolated user-selected local project
  • policy: access to the operator's local files is separately controlled and requires local-computer permission
Evidence and notes →
ToolsWorkspace search

Search file names, text, or symbols across a workspace.

?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →