Four Bots on security hygiene. Reports privately, changes nothing.
Security posture Team
Watches the boring security surface that gets ignored until it does not: keys, permissions, and exposed endpoints.
Bots
- Secrets Grok Bot
- Access Grok Bot
- Exposed Grok Bot
- Deps Grok Bot
Security desk group chat
- Secrets Grok BotFinds credentials committed to a repository or left in a log.
- Access Grok BotLists accounts with more access than their role needs.
- Exposed Grok BotNames endpoints reachable without authentication that should not be.
- Deps Grok BotReports vulnerable dependencies by whether they are actually reachable.
Cloudflare
GitHub
1Password
Snyk
Secrets Grok BotGrok Bot
Finds credentials committed to a repository or left in a log.
GitHub
Access Grok BotGrok Bot
Lists accounts with more access than their role needs.
1Password
Exposed Grok BotGrok Bot
Names endpoints reachable without authentication that should not be.
Cloudflare
Deps Grok BotGrok Bot
Reports vulnerable dependencies by whether they are actually reachable.
Snyk
Secret scan
Owner: Secrets Grok BotEvery weekday at 07:00
Scan for credentials in commits and logs since yesterday. Report privately. Never post a secret in chat.
Access review
Owner: Access Grok BotEvery Monday at 09:00
List accounts with access beyond their role. Never change a permission.
find-skills by vercel-labsLooking up counts on Skillselion. · Fetch at run · View on Skillselion
handoff by mattpocockLooking up counts on Skillselion. · Fetch at run · View on Skillselion
Sidebar section
Infrastructure
Run Security posture yourself
Free to copy, adapt, and edit. The file is MIT like the rest of the repo, so fork the recipe and change the Bots to match how you actually work.
Paste the prompt into Grok Bot. This is not one-click OAuth and nothing is installed on this site.
# Grok Bot Teams installer
Set up a team for me called Security posture Team. Create the named Bots, then the group chat, then save the routines.
Ask me only for things you cannot see. Do not start OAuth. If a connector is missing, tell me to connect it in Settings → Plugins.
From https://botteams.io (infra-security). Source: https://github.com/ellelion/botteams.
## 1. Create these Bots
Create each Bot below. Use the names exactly. After create, set Name, Title, and Description on the profile.
A Bot is persistent and named. Conversation is the task; Title is the one-line job; Description holds durable rules and approvals.
### Security posture Team - Secrets Bot
Create this Bot. Use the name exactly.
Uses connectors (already on the account): GitHub
Job:
Finds credentials committed to a repository or left in a log.
After this Bot exists, set its profile (Bot actions → Edit Profile):
- Name: exactly Security posture Team - Secrets Bot
- Title: Finds credentials committed to a repository or left in a log.
- Description: Finds credentials committed to a repository or left in a log. Never send, spend, or delete anything without my approval. Wait for a confirm card when the product shows one.
### Security posture Team - Access Bot
Create this Bot. Use the name exactly.
Uses connectors (already on the account): 1Password
Job:
Lists accounts with more access than their role needs.
After this Bot exists, set its profile (Bot actions → Edit Profile):
- Name: exactly Security posture Team - Access Bot
- Title: Lists accounts with more access than their role needs.
- Description: Lists accounts with more access than their role needs. Never send, spend, or delete anything without my approval. Wait for a confirm card when the product shows one.
### Security posture Team - Exposed Bot
Create this Bot. Use the name exactly.
Uses connectors (already on the account): Cloudflare
Job:
Names endpoints reachable without authentication that should not be.
After this Bot exists, set its profile (Bot actions → Edit Profile):
- Name: exactly Security posture Team - Exposed Bot
- Title: Names endpoints reachable without authentication that should not be.
- Description: Names endpoints reachable without authentication that should not be. Never send, spend, or delete anything without my approval. Wait for a confirm card when the product shows one.
### Security posture Team - Deps Bot
Create this Bot. Use the name exactly.
Uses connectors (already on the account): Snyk
Job:
Reports vulnerable dependencies by whether they are actually reachable.
After this Bot exists, set its profile (Bot actions → Edit Profile):
- Name: exactly Security posture Team - Deps Bot
- Title: Reports vulnerable dependencies by whether they are actually reachable.
- Description: Reports vulnerable dependencies by whether they are actually reachable. Never send, spend, or delete anything without my approval. Wait for a confirm card when the product shows one.
## 2. Create this group chat
Open a group chat with two to six of the Bots above. Do not add more than six.
### Security desk group chat
Members (4, two to six Bots): Security posture Team - Secrets Bot, Security posture Team - Access Bot, Security posture Team - Exposed Bot, Security posture Team - Deps Bot
## 3. Routines (confirm card required)
Ping each owner Bot with the routine they own so they can save it.
A routine is owned by one Bot, and one Bot can own up to 50 of them. A confirm card will appear. I will confirm each one.
Do not assume a routine is saved until I confirm.
### Secret scan
Owner Bot: Security posture Team - Secrets Bot
Schedule: Every weekday at 07:00
Prompt to save (I will confirm the card):
Scan for credentials in commits and logs since yesterday. Report privately. Never post a secret in chat.
### Access review
Owner Bot: Security posture Team - Access Bot
Schedule: Every Monday at 09:00
Prompt to save (I will confirm the card):
List accounts with access beyond their role. Never change a permission.
## 4. Connectors and how far they go
Connectors are account-wide. They must already be connected.
If any are missing, tell me to connect them in Settings → Plugins first.
Do not walk an OAuth flow from this prompt.
Every Bot on this account can reach every connected tool. The lists above are which Bot is expected to use which, not a second OAuth and not a boundary.
- Cloudflare: Draft. Use Cloudflare for drafts only. Do not deploy to production.
- GitHub: Draft. Use GitHub for drafts only. Draft the PR or branch, never merge.
- 1Password: Draft. Use 1Password read-only.
- Snyk: Draft. Use Snyk read-only.
## 5. Skills
Skills live under Settings → Plugins → Yours, and they are per Bot. Reference a skill with /.
If a skill is already installed on the account (Settings → Plugins → Yours), use it. Enable it for this Bot if / does not show it.
If it is not installed, fetch or load it through the Skillselion connector using the skill id. Do not install a second copy.
Connect the Skillselion connector only when a fetch is needed. Do not start OAuth from this prompt.
Do not pin or hide a Bot unless I say so. Hide does not pause routines.
If a workflow should be demonstrated later, mention Teach a task after the first success (browser workflows).
### find-skills
https://skillselion.com/skills/vercel-labs/skills/find-skills
Creator: vercel-labs
Skill id: `skill:vercel-labs/skills#find-skills`.
Scope: every Bot on this team (team scope).
### handoff
https://skillselion.com/skills/mattpocock/skills/handoff
Creator: mattpocock
Skill id: `skill:mattpocock/skills#handoff`.
Scope: every Bot on this team (team scope).
## 6. Also
Standing instructions for every Bot on this team:
- Never apply a change. Draft the plan.
- Never touch production without a human yes.
## Human steps
These are yours. The Bot cannot do them.
- Set each Bot avatar (Bot actions → Edit Profile). Attach an image if you want a custom one.
- Create a sidebar section named exactly: Security posture Team. Move the group chat and Bots into it.
- In Settings → Plugins, disable the write tools for Cloudflare, GitHub, 1Password, Snyk. That switch is account-wide and it is the only one that actually stops a write.
- Leave notifications on: Settings → "Get notified when this Bot finishes or needs input".
## Done when
- Named Bots exist
- Named group chat exists ("Security desk group chat", two to six Bots)
- I have created section "Security posture Team"
- Each routine has a confirmed save (or I declined)
- Connectors listed above are already connected
Uninstall: delete the Bots and group chats in the Grok Bot sidebar.
There is no remote uninstall from this catalog.Teams that share these connectors
- Backup and recovery Team
Checks that backups exist and could actually be restored, which is not the same question.
Supabase
AWS Core
Notion
PagerDuty
- Capacity planning Team
Answers whether the system survives the next spike, before the spike rather than during it.
Datadog
Cloudflare
Supabase
Notion
- Cloud cost Team
Turns a cloud bill into named decisions, so spend growth has an owner rather than a shrug.
AWS Core
Datadog
VantageNotion

