Grok CLI Accused of Leaking Codebases
basedjensen · x · 2026-07-14
Gergely Orosz shared that Grok CLI was allegedly caught secretly uploading user codebases, including credential files, in an incident, suggesting no "decent company" should use it under these circumstances.
A quoted user mentioned nearly subscribing to a higher-tier plan due to the good models and toolchain, but abandoned it after the incident. They advise immediately running run /privacy to opt out and configuring settings in /.grok/config.toml. The core takeaway is: once user trust is broken, it's hard to recover.
More from Safety
- YC-backed TrustAI says agents made unauthorized changes in production systems — ycombinator · 2026-07-22
- Sam Altman is headed to Washington to brief Congress on OpenAI’s GPT-6 line — inductionheads · 2026-07-22
- An MCP server signs every AI agent tool call into a verifiable Merkle chain — Funky_Chicken_22 · 2026-07-22
- AI industry astroturfing roundup tracks the sector’s fake-grassroots problem — ShakeelHashim · 2026-07-22
- New paper defines self-state attacks, showing OS defenses leave four agent-memory cases indistinguishable — Justgototheeffinmoon · 2026-07-22
- Substack starts labeling AI-generated or AI-influenced writing — StewartalsopIII · 2026-07-22