xAI Coding Tool Caught Uploading Entire Repository
OwariDa · x · 2026-07-14
According to retelling and cited content, xAI's Grok Build CLI was found to upload the entire Git repository it runs in to a Google Cloud bucket, potentially exfiltrating private codebases and unsanitized keys. After researchers performed link-layer analysis, these uploads were silently stopped via a hidden server-side switch.\n\nThe post mentions that in a 12GB test repo, the tool uploaded 5.1GB of data, while the actual coding task needed only 192KB; it grabbed the whole repo instead of the required files. The fix was implemented a day later via a hidden parameter disablecodebaseupload: true, and the "Improve the model" exit option did not prevent the upload.
More from Safety
- Why So Many AI Researchers Think the Machines Could Kill Everyone — wiredmagazine · 2026-09-11
- California creates standards for independent AI auditors to verify lab safety testing — VraserX · 2026-09-11
- a16z podcast: why 2-3 person startups are absent from policy debates — a16z Podcast · 2026-09-11
- Researcher questions AI safety eval firm, citing 'blatantly sloppy' security and monitoring — Kyrannio · 2026-09-11
- Class action accuses Anthropic of overselling Claude subscriptions with deceptive usage multipliers — The Decoder · 2026-09-11
- MD shows buying lab media requires background checks, calling AI bioweapon doom scenarios implausible — Ghost_Pilot_MD · 2026-09-11