Grok Build CLI Suspected of Uploading Entire Repos
Tiancaixinxin · x · 2026-07-13
Packet sniffing reveals that Grok Build CLI appears to bundle entire repositories (including full Git history) into a git bundle and uploads them to xAI's Google Cloud Storage.
More critically, files read by the CLI are also transmitted, potentially exposing .env secrets. Even when explicitly prompted "not to read any files" or when "Improve the model" is disabled, the uploading behavior persists.
The original post notes that there is no clear explanation for this mechanism in official announcements or changelogs, advising against using it for sensitive repositories until an update clarifies the issue.
Related event: xAI's Grok Build CLI Allegedly Uploads Entire Repos and Secrets(5 posts)→
More from coding & agent
- Building a Secure AI Agent Gateway: Self-Hosting OAuth for Multiple SaaS Apps — Defiant_Cod_2654 · 2026-07-22
- Rowboat launches as an open-source, local-first AI coworker with memory — ycombinator · 2026-07-22
- Reddit user chains Ideogram 4 and Krea2 to mimic bbox-based image positioning — v3lh0t05c0 · 2026-07-22
- Apollo Cuts AI Assistant Skill Dev Time by 85% with Deep Agents — LangChain · 2026-07-22
- Scoble says AI “loops” really means long-running multi-agent workspaces — Scobleizer · 2026-07-22
- Kimi Code opens a waitlist as Moonshot rolls out its coding product — Fabulous_Bonus_8981 · 2026-07-22