xAI Grok Build CLI Found Uploading Entire Repos Despite Privacy Toggle
In July 2026, a researcher known as cereblab discovered that xAI's Grok Build CLI (version 0.2.93) was silently uploading entire code repositories to a cloud storage bucket during coding sessions. The upload occurred via a second network channel separate from the model's own data requests, sending roughly 5.10 GiB as a full git bundle — including complete commit histories — compared to just 192 KB used by the actual task. The researcher confirmed the behavior using a canary file the agent was explicitly told never to read, yet its contents appeared verbatim in the captured upload. Critically, xAI's in-app privacy toggle, which was labeled around model-training consent, had no effect on this client-side upload path, meaning users had no functional control over the data transfer. The incident highlights a broader risk for development teams: AI coding agents may transmit far more data than the model itself requires, including sensitive historical credentials that were rotated but never fully erased from git history.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in