Grok Uploads Plaintext Secrets When Reading Files
WesEklund · x · 2026-07-14
Wes Eklund observed that when grok reads files to answer questions or review code, the contents enter the LLM context sent to the responses endpoint in plaintext.
Implications listed include:
- Real secrets in .env files will be sent to xAI servers
- Credentials in config files are fully transmitted
- No local filtering of sensitive content occurs before sending
- No warnings are provided when suspected secret files are detected
The core message is a warning: cloud-based LLMs/code assistants reading local files pose a clear risk of leaking secrets and compromising privacy.
More from coding & agent
- Gergely Orosz: Shipping 10x PRs With AI Agents, Sites Fill With Small Regressions — ducha_aiki · 2026-09-11
- Same Echo Maze prompt, three frontier models: all passed visually but shipped the same hidden bug — eyishazyer · 2026-09-11
- Astra storyboards plus Minimax H3 per-shot generation boost video success rates — Hailuo_AI · 2026-09-11
- Codex tip: use Sol with Astra and Luna sub-agents to save usage — pvncher · 2026-09-11
- agents-best-practices: a provider-neutral Agent Skill for designing and auditing agentic harnesses — tom_doerr · 2026-09-11
- Cognition's SWE-2 uses a KKT duality argument in RL to shift the effort Pareto curve — YouJiacheng · 2026-09-11