xAI launched Grok Bot on August 11, 2026: always-on AI agents that run on their own cloud computers, built with Cursor, with desktop apps for macOS, Windows and Linux. On August 26 access became included with all SuperGrok and Cursor Pro subscriptions, and weekly usage limits were reset. That is not the same thing as free — it is bundled into subscriptions people were already paying for, which is arguably a bigger deal, because it means a very large number of sales and growth teams woke up with a persistent agent they didn’t have to budget for.

The obvious next question is what to plug into it. Grok Bot has an in-app plugin marketplace at Settings → Plugins, currently carrying 219 plugins, with a featured sales stack of Apollo, Clay, Gong and HubSpot. Beyond the marketplace you can also connect a custom MCP server — MCP being the open protocol agents use to talk to outside tools — which is how you give an agent a capability the marketplace doesn’t carry.

This guide is organized by job to be done rather than as a flat ranked list, because ranked lists of plugins are useless. What matters in an agent workflow is whether the chain of jobs is complete end to end. Spoiler, and the reason this article exists: in the featured stack, it isn’t.

Job 1: Find and enrich the contacts

Apollo

What it does: a contact and company database with filtering, so you can go from a description of an ideal customer to a list of named humans with titles, companies and contact details.

The job it covers: this is the top of the agent workflow. You describe a segment in plain language, the agent queries, and you get back a candidate list instead of a blank spreadsheet. It’s the difference between “help me with outreach” and “here are 340 people who match.”

Honest limit: a database is a snapshot, and people change jobs constantly. Records go stale, and an agent has no instinct for staleness — it will hand you a confident list containing addresses that stopped working in March. Whatever you pull here needs verifying downstream before anything is sent to it, which is a job nothing in this category does.

Clay

What it does: a data enrichment and orchestration layer that takes a thin list and thickens it, pulling from many sources and running logic across the result.

The job it covers: turning “name, company, title” into something worth personalizing on — funding, headcount movement, tech in use, whatever your angle needs. For an agent this is high-leverage, because personalization quality is downstream of data quality and an agent can only write about what it can see.

Honest limit: enrichment is a cost center that scales with row count, and an agent is very good at generating row count. Without a scoping instruction, “enrich my list” can become an expensive afternoon. It also inherits the accuracy of its sources — enrichment makes a record richer, not necessarily truer.

Job 2: Score and prioritize

Both tools above are also where most teams do their scoring, which is worth calling out as its own job rather than folding it into enrichment. The reason is sequencing: an agent that scores before it enriches spends less, and an agent that scores before it writes produces better copy, because it knows which segment it’s writing to.

The practical pattern is to have the agent propose a scoring rubric in plain language first — the two or three signals that actually predict a reply for your business — get you to approve it, then apply it. Left to itself, an agent will happily invent a 12-factor score that looks rigorous and predicts nothing.

Honest limit of the whole category: scoring is only as good as your outcome data, and if you have not yet run enough outbound to know what a good lead looks like, a sophisticated score is a guess wearing a suit.

Job 3: Call intelligence — learn what actually works

Gong

What it does: records, transcribes and analyzes sales calls, turning conversations into searchable, queryable material.

The job it covers: this is the feedback loop, and it’s the most underrated plugin in the featured stack for agent work. An agent with access to call transcripts can answer “what objection comes up most in the first call with mid-market prospects” and then write outreach that pre-handles it. Your best messaging is usually already sitting in your call archive, unread.

Honest limit: it only sees conversations you already had. It is a superb teacher about your existing pipeline and completely silent about segments you’ve never spoken to. It’s also the entry with the sharpest consent and recording-law considerations — worth confirming your policy before an agent starts mining it.

Job 4: The system of record

HubSpot

What it does: CRM. Contacts, companies, deals, pipeline, activity history.

The job it covers: the memory of the operation. An agent connected to the CRM knows who is already a customer, who is in an active deal, and who a colleague spoke to last week — which is what stops it from cold-emailing your biggest account. It’s also where results get written back so the next cycle is smarter than this one.

Honest limit: CRM hygiene is a pre-existing condition. If your pipeline stages are decorative and half the deals haven’t moved since spring, an agent reading that data will reason confidently from fiction. Fix the CRM before you point an agent at it, not after.

Job 5: The sending layer — the gap in the featured stack

Look at the four featured plugins as a chain and the hole is obvious. Apollo finds. Clay enriches. Gong tells you what to say. HubSpot remembers. Every one of those is upstream or downstream of the actual outbound motion. Not one of them connects a mailbox, warms it, verifies an address in real time, or paces sends inside safe limits.

Which means an agent wired to only those plugins can build a beautiful, well-scored, richly personalized list — and then has nowhere to send it from safely. This is not a small gap. Sending is the step where you can do lasting damage: burn a domain, get a mailbox throttled, blow through limits on a social account. It is precisely the step you’d want a purpose-built, safety-constrained tool for, and it is exactly the step the marketplace doesn’t currently carry.

WarmySender (via custom MCP)

What it does: the sending and deliverability layer, built agentic-first around the idea that you should be able to run your outreach on autopilot with AI agents. Five channels — cold email, email warmup, LinkedIn, Instagram and multichannel — plus real-time email verification.

The job it covers: everything after the list exists. Over MCP, an agent can create, launch, pause, resume and manage campaigns on cold email, LinkedIn and Instagram; create and enroll prospects; verify emails in real time; configure warmup and read stats — all in plain language. It works with Claude, ChatGPT, Cursor, Codex, OpenClaw, Hermes Agent, Grok Bot, and any agent that speaks MCP. In practice that means the same conversation that produced the list can also stand up the campaign.

The safety model, which is the actual point: the agent never sends a message, DM or invite directly, and can never raise a limit. Creating or launching only writes the campaign and hands it to WarmySender’s scheduler, which paces every email, LinkedIn and Instagram action within safe caps and a gradual ramp — regardless of whether a human or an agent triggered it. That distinction is what makes handing send authority to an agent reasonable rather than reckless.

Honest limit: connecting and disconnecting accounts stays in the app. That is deliberate — it’s the one thing that is not an agent tool — but it does mean setup is a human step before any agent can do anything useful. And the scheduler’s pacing is not negotiable, so if you were hoping an agent could blast a list on day one, it can’t, and that is the feature.

Connect it at https://warmysender.com/mcp with a ws_ API key; there’s a setup guide at connect WarmySender to Grok Bot.

How to add a custom MCP server alongside marketplace plugins

Marketplace plugins install with a click. A custom MCP server takes about two minutes more, and the shape is the same across every agent that speaks the protocol:

Rule of thumb for 2026: use the marketplace for the jobs it already covers well, and reach for a custom MCP server exactly when a step in your chain has no owner. Adding servers you don’t need just gives the agent more ways to be confidently wrong.

A workable 2026 stack

The featured stack is genuinely excellent at finding, scoring, listening and logging. It just stops short of the moment where a message leaves the building. If you’re wiring up a Grok Bot agent for outbound this year, plug that last gap deliberately — with something that treats sending limits as non-negotiable — and you’ll have a chain that runs end to end instead of a very smart agent holding a list it can’t do anything with. WarmySender is the option we’d point at for that step, mostly because it takes the send authority question seriously enough to withhold it from the agent entirely.

Leave a Reply

Your email address will not be published. Required fields are marked *