Grok Uploads Plaintext Secrets When Reading Files
WesEklund · x · 2026-07-14
Wes Eklund observed that when grok reads files to answer questions or review code, the contents enter the LLM context sent to the responses endpoint in plaintext.
Implications listed include:
- Real secrets in .env files will be sent to xAI servers
- Credentials in config files are fully transmitted
- No local filtering of sensitive content occurs before sending
- No warnings are provided when suspected secret files are detected
The core message is a warning: cloud-based LLMs/code assistants reading local files pose a clear risk of leaking secrets and compromising privacy.
More from coding & agent
- A better path to agent autonomy is running waves, finding friction, and iterating — JnBrymn · 2026-07-22
- Coding agents are heading toward an AI-writes, AI-reviews, human-approves workflow — aftahi_ai · 2026-07-22
- oMLX 0.5.2 adds Mac menu-bar stats, low-bit decode kernels, and faster downloads — awnihannun · 2026-07-22
- GitHub review bot hits its PR limit and forces a 39-minute cooldown — DanielLockyer · 2026-07-22
- Max reasoning effort appears to be mobile-only in Codex Remote, not desktop — GabGarrett · 2026-07-22
- A Reddit demo argues online stores should expose carts and pricing through MCP — gelembjuk · 2026-07-22