Grok Build CLI Suspected of Uploading Entire Repos
Tiancaixinxin · x · 2026-07-13
Packet sniffing reveals that Grok Build CLI appears to bundle entire repositories (including full Git history) into a git bundle and uploads them to xAI's Google Cloud Storage.
More critically, files read by the CLI are also transmitted, potentially exposing .env secrets. Even when explicitly prompted "not to read any files" or when "Improve the model" is disabled, the uploading behavior persists.
The original post notes that there is no clear explanation for this mechanism in official announcements or changelogs, advising against using it for sensitive repositories until an update clarifies the issue.
Related event: xAI's Grok Build CLI Allegedly Uploads Entire Repos and Secrets(5 posts)→
More from coding & agent
- Anthropic researcher: 99% of engineers now run swarms of 300+ self-improving agents — AlishaOutridge · 2026-09-11
- Gergely Orosz: Shipping 10x PRs With AI Agents, Sites Fill With Small Regressions — ducha_aiki · 2026-09-11
- Same Echo Maze prompt, three frontier models: all passed visually but shipped the same hidden bug — eyishazyer · 2026-09-11
- Astra storyboards plus Minimax H3 per-shot generation boost video success rates — Hailuo_AI · 2026-09-11
- Codex tip: use Sol with Astra and Luna sub-agents to save usage — pvncher · 2026-09-11
- agents-best-practices: a provider-neutral Agent Skill for designing and auditing agentic harnesses — tom_doerr · 2026-09-11