RC RANDOM CHAOS

Grok Bot: xAI's autonomous agent logs into your tools and works while you sleep

· via Hacker News

Original source

Grok Bot

Hacker News →

xAI is pitching Grok Bot, an early-beta agentic product that goes beyond chat: you authenticate it once against your apps and websites, and it then operates those tools the way a human employee would — clicking through interfaces, running multi-step projects end to end, and returning only when it needs your approval. Each bot runs on its own cloud-hosted computer so it can work 24/7 in parallel even with your laptop closed, learns a workflow by watching you perform it once and replaying it on a schedule, and can hand tasks off to other bots in a shared thread. The marketing example is overnight sales prospecting: researching accounts, scoring contacts by intent, and drafting personalized email and LinkedIn outreach for you to review. It’s sold at $200/month (Ultra) and $120/seat/month for teams with SSO and centralized billing, on macOS (Apple silicon) and iOS.

For a security audience, the headline isn’t the automation — it’s the trust model. A persistent agent that holds standing credentials to your entire tool stack and takes actions unsupervised is a concentrated attack surface: credential storage and session persistence become high-value targets, and an agent that reads and acts on web content is exposed to prompt-injection that could redirect it toward attacker-chosen actions using your own access. “You watch them take action instead of approving every step” is precisely the property that makes autonomous misuse or a compromised bot dangerous, and delegated identity of this kind complicates audit, least-privilege, and accountability.

Worth flagging on provenance: the captured page is promotional landing copy rather than reporting, and it’s internally inconsistent — the same page references “Cursor Ultra” and “SuperGrok Heavy” alongside Grok Bot, suggesting the scraped content is garbled or stitched from multiple product pages. Treat the specific tiers, feature list, and even the exact branding as unverified until confirmed against a clean primary source.

Read the full article

Continue reading at Hacker News →

This is an AI-generated summary. Read the original for the full story.