Four Bots on security hygiene. Reports privately, changes nothing.
Security posture team
Watches the boring security surface that gets ignored until it does not: keys, permissions, and exposed endpoints.
Security posture team
Watches the boring security surface that gets ignored until it does not: keys, permissions, and exposed endpoints.
Bots
- Secrets Grok Bot
- Access Grok Bot
- Exposed Grok Bot
- Deps Grok Bot
Security desk group chat
- Secrets Grok Bot
- Access Grok Bot
- Exposed Grok Bot
- Deps Grok Bot
Cloudflare
GitHub
1Password
Snyk
Job
Secrets Grok BotGrok Bot
Finds credentials committed to a repository or left in a log.
GitHub
Access Grok BotGrok Bot
Lists accounts with more access than their role needs.
1Password
Exposed Grok BotGrok Bot
Names endpoints reachable without authentication that should not be.
Cloudflare
Deps Grok BotGrok Bot
Reports vulnerable dependencies by whether they are actually reachable.
Snyk
Routines2
Secret scan
Scan for credentials in commits and logs since yesterday. Report privately. Never post a secret in chat.
Access review
List accounts with access beyond their role. Never change a permission.
Skills2
find-skills by vercel-labs… · Fetch at run · View on Skillselion
handoff by mattpocock… · Fetch at run · View on Skillselion
Notes
Sidebar section
Infrastructure
Prompt Installer for Grok Bot
Paste the prompt into Grok Bot. This is not one-click OAuth and nothing is installed on this site.
# Grok Bot Teams installer
Set up a team for me called Security posture team. Create the named Bots, then the group chat, then save the routines.
Ask me only for things you cannot see. Do not start OAuth. If a connector is missing, tell me to connect it in Settings, then Plugins.
From https://botteams.ai (infra-security). Source: https://github.com/ellelion/botteams.
## 1. Create these Bots
Create each Bot below. Use the names exactly, including any prefix. After create, set Name, Title, and Description on the profile, then tell me to set the avatar.
A Bot is a single persistent, named agent. Conversation is the task; Title is the one-line job; Description holds durable rules and approvals.
### Security posture · Secrets Grok Bot
(Named "Security · Secrets" in the published recipe.)
Create this Bot. Use the name exactly.
Uses connectors (already on the account): GitHub
Job:
Finds credentials committed to a repository or left in a log.
After this Bot exists, set its profile (Bot actions → Edit Profile):
- Name: exactly Security posture · Secrets Grok Bot
- Title: Finds credentials committed to a repository or left in a log.
- Description: Finds credentials committed to a repository or left in a log. Never send, spend, or delete anything without my approval. Wait for a confirm card when the product shows one.
Then tell me to open Edit Profile and set the avatar. You cannot stamp a custom image yourself unless I attach one.
If you create this Bot from an existing Bot, ask the new Bot to set those profile fields after create.
### Security posture · Access Grok Bot
(Named "Security · Access" in the published recipe.)
Create this Bot. Use the name exactly.
Uses connectors (already on the account): 1Password
Job:
Lists accounts with more access than their role needs.
After this Bot exists, set its profile (Bot actions → Edit Profile):
- Name: exactly Security posture · Access Grok Bot
- Title: Lists accounts with more access than their role needs.
- Description: Lists accounts with more access than their role needs. Never send, spend, or delete anything without my approval. Wait for a confirm card when the product shows one.
Then tell me to open Edit Profile and set the avatar. You cannot stamp a custom image yourself unless I attach one.
If you create this Bot from an existing Bot, ask the new Bot to set those profile fields after create.
### Security posture · Exposed Grok Bot
(Named "Security · Exposed" in the published recipe.)
Create this Bot. Use the name exactly.
Uses connectors (already on the account): Cloudflare
Job:
Names endpoints reachable without authentication that should not be.
After this Bot exists, set its profile (Bot actions → Edit Profile):
- Name: exactly Security posture · Exposed Grok Bot
- Title: Names endpoints reachable without authentication that should not be.
- Description: Names endpoints reachable without authentication that should not be. Never send, spend, or delete anything without my approval. Wait for a confirm card when the product shows one.
Then tell me to open Edit Profile and set the avatar. You cannot stamp a custom image yourself unless I attach one.
If you create this Bot from an existing Bot, ask the new Bot to set those profile fields after create.
### Security posture · Deps Grok Bot
(Named "Security · Deps" in the published recipe.)
Create this Bot. Use the name exactly.
Uses connectors (already on the account): Snyk
Job:
Reports vulnerable dependencies by whether they are actually reachable.
After this Bot exists, set its profile (Bot actions → Edit Profile):
- Name: exactly Security posture · Deps Grok Bot
- Title: Reports vulnerable dependencies by whether they are actually reachable.
- Description: Reports vulnerable dependencies by whether they are actually reachable. Never send, spend, or delete anything without my approval. Wait for a confirm card when the product shows one.
Then tell me to open Edit Profile and set the avatar. You cannot stamp a custom image yourself unless I attach one.
If you create this Bot from an existing Bot, ask the new Bot to set those profile fields after create.
## 2. Create this group chat
Open a group chat with two to six of the Bots above. Do not add more than six.
### Security desk group chat
Members (4, two to six Bots): Security posture · Secrets Grok Bot, Security posture · Access Grok Bot, Security posture · Exposed Grok Bot, Security posture · Deps Grok Bot
## 3. Sidebar section
You cannot create sidebar sections. When the Bots and group chat exist, tell me to Move to, then New section.
I will name that section exactly: Infrastructure.
Ask me to move the group chat and Bots into it.
## 4. Routines (confirm card required)
Ping each owner Bot with the routine they own so they can save it.
A routine is owned by one Bot, and one Bot can own up to 50 of them. A confirm card will appear. I will confirm each one.
Do not assume a routine is saved until I confirm.
### Secret scan
Owner Bot: Security posture · Secrets Grok Bot
Schedule: Every weekday at 07:00
Prompt to save (I will confirm the card):
Scan for credentials in commits and logs since yesterday. Report privately. Never post a secret in chat.
### Access review
Owner Bot: Security posture · Access Grok Bot
Schedule: Every Monday at 09:00
Prompt to save (I will confirm the card):
List accounts with access beyond their role. Never change a permission.
## 5. Connectors and how far they go
Connectors are account-wide. They must already be connected.
If any are missing, tell me to connect them in Settings, then Plugins, first.
Do not walk an OAuth flow from this prompt.
Every Bot on this account can reach every connected tool. The lists above are which Bot is expected to use which, not a second OAuth and not a boundary.
- Cloudflare: Draft. Use Cloudflare for drafts only. Leave every draft unsent and every change unsaved so a human can review it.
- GitHub: Draft. Use GitHub for drafts only. Leave every draft unsent and every change unsaved so a human can review it.
- 1Password: Draft. Use 1Password for drafts only. Leave every draft unsent and every change unsaved so a human can review it.
- Snyk: Draft. Use Snyk for drafts only. Leave every draft unsent and every change unsaved so a human can review it.
Human: the lines above are instructions, not permissions. In Grok Bot open Settings, then Plugins, and disable the write tools for Cloudflare, GitHub, 1Password, Snyk. That switch is account-wide and it is the only one that actually stops a write.
## 6. Skills
Skills live under Settings → Plugins → Yours, and they are per Bot. Enable the ones listed here for the named Bots. Reference a skill with /.
You cannot flip the human Notifications toggle. Tell me to leave Settings → “Get notified when this Bot finishes or needs input” on.
Do not pin or hide a Bot unless I say so. Hide does not pause routines.
Sidebar sections are human-only: tell me to Move to → New section. A group chat holds two to six Bots. An account holds 50 Bots and group chats combined. One Bot can own 50 routines. Confirm cards stay on me.
If a workflow should be demonstrated later, mention Teach a task after the first success (browser workflows).
Connect the Skillselion connector first if any skill below is Fetch at run (Settings → Plugins). Do not start OAuth from this prompt.
### find-skills
https://skillselion.com/skills/vercel-labs/skills/find-skills
Creator: vercel-labs
Scope: every Bot on this team (team scope).
Do not install. When this job comes up, use the Skillselion connector to search/load `skill:vercel-labs/skills#find-skills`. Connect Skillselion in Settings → Plugins first.
### handoff
https://skillselion.com/skills/mattpocock/skills/handoff
Creator: mattpocock
Scope: every Bot on this team (team scope).
Do not install. When this job comes up, use the Skillselion connector to search/load `skill:mattpocock/skills#handoff`. Connect Skillselion in Settings → Plugins first.
## 7. Also
Standing instructions for every Bot on this team:
- Never apply a change. Draft the plan.
- Never touch production without a human yes.
## Done when
- Named Bots exist
- Named group chat exists ("Security desk group chat", two to six Bots)
- I have created section "Infrastructure"
- Each routine has a confirmed save (or I declined)
- Connectors listed above are already connected
Uninstall: delete the Bots and group chats in the Grok Bot sidebar.
There is no remote uninstall from this catalog.Teams that share these connectors
- Backup and recovery
Checks that backups exist and could actually be restored, which is not the same question.
Supabase
AWS Core
Notion
PagerDuty
- Capacity planning
Answers whether the system survives the next spike, before the spike rather than during it.
Datadog
Cloudflare
Supabase
Notion
- Cloud cost
Turns a cloud bill into named decisions, so spend growth has an owner rather than a shrug.
AWS Core
Datadog
VantageNotion



