xAI Tool Accused of Uploading Entire Code Repos
basedjensen · x · 2026-07-14
A cited post claims that xAI's Grok Build CLI uploaded an entire Git repository to a Google Cloud bucket, including private code and unmasked API keys. The uploads were only halted after a researcher performed a line-speed analysis, triggered by a hidden server-side switch.\n\nThe post also noted: in a 12GB test repository, the actual coding task only required 192KB, but 5.1GB of data was transmitted. More concerningly, selecting the "Improve the model" opt-out option did not stop the upload; xAI has yet to publicly disclose the data scope, retention period, and deletion policies.
More from Safety
- Coding agents are heading toward an AI-writes, AI-reviews, human-approves workflow — aftahi_ai · 2026-07-22
- AI security course launches with a small cohort to train the next generation of hackers — wunderwuzzi23 · 2026-07-22
- OpenAI says long-horizon models need safety and alignment checks across full action sequences — rhiever · 2026-07-22
- Stanford HAI’s PNAS feature maps the legal questions around generative AI — StanfordHAI · 2026-07-22
- New Malware Lurking in Blind Spots Targets AI Infrastructure to Steal Data — Wired AI · 2026-07-22
- Generative AI Shatters SMB Security: Flawless Phishing and Voice Cloning at Scale — YvesMulkers · 2026-07-22