Grok Leaks Plaintext When Reading Files
julianharris · x · 2026-07-14
A post summarized findings on how Grok reads files: when reading files to answer questions or review code, the contents enter the cloud LLM's context in plaintext and are sent to the responses endpoint.
While architecturally expected for cloud models, the security implications are direct:
- Real keys inside .env files are transmitted to xAI servers
- Configuration files with credentials are transferred in full
- Relevant content leaves the local environment, posing privacy and key leakage risks
More from Safety
- OpenAI asks Congress whether an industry-wide AI slowdown would be legal — The Decoder · 2026-09-11
- Author retracts 'a16z partner calls for nationalising frontier AI' post: likely a troll — S_OhEigeartaigh · 2026-09-11
- Houthis tried to use Claude to design missile software, Anthropic says it blocked the attempts — Affectionate_Bee6434 · 2026-09-11
- AI safety community mocked as 'bridge engineers' who say bridges can never be safe — Dan_Jeffries1 · 2026-09-11
- Why So Many AI Researchers Think the Machines Could Kill Everyone — wiredmagazine · 2026-09-11
- California creates standards for independent AI auditors to verify lab safety testing — VraserX · 2026-09-11