xAI Coding Tool Caught Uploading Entire Repository
OwariDa · x · 2026-07-14
According to retelling and cited content, xAI's Grok Build CLI was found to upload the entire Git repository it runs in to a Google Cloud bucket, potentially exfiltrating private codebases and unsanitized keys. After researchers performed link-layer analysis, these uploads were silently stopped via a hidden server-side switch.\n\nThe post mentions that in a 12GB test repo, the tool uploaded 5.1GB of data, while the actual coding task needed only 192KB; it grabbed the whole repo instead of the required files. The fix was implemented a day later via a hidden parameter disablecodebaseupload: true, and the "Improve the model" exit option did not prevent the upload.
More from Safety
- Substack starts labeling AI-generated or AI-influenced writing — StewartalsopIII · 2026-07-22
- ControlAI CEO says an international ban on superintelligence is needed to avert extinction risk — zetalyrae · 2026-07-22
- Coding agents are heading toward an AI-writes, AI-reviews, human-approves workflow — aftahi_ai · 2026-07-22
- AI security course launches with a small cohort to train the next generation of hackers — wunderwuzzi23 · 2026-07-22
- OpenAI says long-horizon models need safety and alignment checks across full action sequences — rhiever · 2026-07-22
- Stanford HAI’s PNAS feature maps the legal questions around generative AI — StanfordHAI · 2026-07-22