How verification works
Four trust levels, applied per entry and shown with a date. Claims are labeled Official or Independent based on where the evidence comes from.
Trust levels
- Official
- Demonstrated or published by xAI / Cursor sources; linked to the official page.
- Tested
- We ran the setup ourselves and record what happened, with evidence.
- Community
- Shared publicly by its creator; attributed and linked, not re-run by us.
- Untested
- Listed with provenance but no run evidence. Never displayed as blank — always labeled.
Risk badges
Assigned by analyzing the bot's published prompt text (never by running it with your data). A badge means the capability is present, not that the bot is malicious. Missing approval gates are flagged separately.
- sends
- The prompt instructs the bot to send email/messages on your behalf.
- spends
- The bot can spend money or trigger refunds/purchases.
- logins
- Setup requires handing the bot credentials or connected accounts.
- browses
- The bot operates a logged-in browser session.
Last updated 2026-08-31. Changes to this methodology are logged in /corrections.