GrokCLI Accused of Silently Uploading Code Repositories

数字生命卡兹克 · wechat · 2026-07-13

This submission/post-mortem accuses xAI's GrokCLI of severe privacy and security issues: during code assistant execution, the tool packages and uploads the project repository to remote storage, potentially carrying off local configurations and API keys outside the repo.

The reproduction and troubleshooting steps provided include:

The article also compares timelines: researchers first caught the default upload behavior, and as related posts spread, xAI's server config saw new fields like disablecodebaseupload=true, suggesting the upload toggle was remotely disabled post-exposure. The author believes xAI realized this would be "hard to explain publicly."

Conclusion: AI Agents now have near-administrator local privileges, but the industry lacks unified local read auditing, explicit consent, and third-party review mechanisms.

Related event: xAI's Grok Build CLI Allegedly Uploads Entire Repos and Secrets(5 posts)→

Original post →

More from coding & agent

coding & agent channel →