Grok Build CLI Exposed for Uploading Entire Repos and Secrets
TastyLeadership2757 · reddit · 2026-07-11
这条 Reddit 帖称,作者用 mitmproxy 抓包后发现 Grok Build CLI 会把整个仓库上传到 xAI 的云端,包含:
- 完整 git 历史;
- 你本地的 .env 等敏感文件;
- 即使提示里要求“不要读取文件”,上传依然发生。
帖子还声称:
- 被植入的一个 canary 文件,后来能从抓到的 git bundle 里被原样恢复;
- “Improve the model” 关闭后也不会阻止上传,因为那个开关只影响训练,不影响数据发送。
原帖附了复现方法、SHA-256 校验和以及 gist 证据。
Related event: xAI's Grok Build CLI Allegedly Uploads Entire Repos and Secrets(5 posts)→
More from coding & agent
- AI agents are starting to strain code hosting platforms — craigsdennis · 2026-07-21
- Async OPD distillation doubles throughput while matching synchronous math accuracy — _lewtun · 2026-07-21
- Omnigent 0.6.0 adds Claude Code imports, Slack approvals and desktop apps — matei_zaharia · 2026-07-21
- Google appears to have quietly shipped Gemini 3.6 Flash, with lower pricing and better agentic scores — xiaohu · 2026-07-21
- Open-source CLI audits AI tools, MCP configs, and agent skills on local machines — Initial-Copy332 · 2026-07-21
- Coding agents feel less stressful when the 5-hour limits are temporarily removed — iamrobotbear · 2026-07-21