xAI Tool Accused of Uploading Entire Code Repos
basedjensen · x · 2026-07-14
A cited post claims that xAI's Grok Build CLI uploaded an entire Git repository to a Google Cloud bucket, including private code and unmasked API keys. The uploads were only halted after a researcher performed a line-speed analysis, triggered by a hidden server-side switch.\n\nThe post also noted: in a 12GB test repository, the actual coding task only required 192KB, but 5.1GB of data was transmitted. More concerningly, selecting the "Improve the model" opt-out option did not stop the upload; xAI has yet to publicly disclose the data scope, retention period, and deletion policies.
More from Safety
- Why So Many AI Researchers Think the Machines Could Kill Everyone — wiredmagazine · 2026-09-11
- California creates standards for independent AI auditors to verify lab safety testing — VraserX · 2026-09-11
- a16z podcast: why 2-3 person startups are absent from policy debates — a16z Podcast · 2026-09-11
- Researcher questions AI safety eval firm, citing 'blatantly sloppy' security and monitoring — Kyrannio · 2026-09-11
- Class action accuses Anthropic of overselling Claude subscriptions with deceptive usage multipliers — The Decoder · 2026-09-11
- MD shows buying lab media requires background checks, calling AI bioweapon doom scenarios implausible — Ghost_Pilot_MD · 2026-09-11