Grok Bot is xAI's managed assistant. Its Linux VM has normal internet and shared credentials. That is a capable vendor environment. Fleet does not wrap it.
Fleet's job is different: keep Fleet-launched Linux agents from escaping. Default-deny network. A human allows a host for a bounded window. You prove that with fleet doctor and TestAcceptance_CompromisedAgentHasNoAlternateEgressPath.
OpenCode on Fleet can still run Grok-backed sessions. Those processes are Fleet-jailed. Grok Bot itself is a vendor VM. Cursor Cloud and Codex cloud VMs are the same class of machine.