Grok Build Accused of Ignoring Permissions to Upload Repos

ctjlewis · x · 2026-07-15

A post alleges that Grok Build suffers from severe privacy and permission flaws: even if an agent is explicitly denied access to a file, it can still package and upload the entire repository (including full Git history) to an xAI-controlled Google Cloud Storage bucket via an alternative code path.

The report further notes that the binary is Apple-signed and internally contains strings like grok code session traces, aftercodebase.tar.gz, and disablecodebaseupload. Even with /privacy enabled and traceuploadenabled=false, the client still sends requests to /v1/traces.

Related event: Grok Build/CLI accused of silently uploading entire codebases; xAI promises to delete data(47 posts)→

Original post →

More from Companies & People

Companies & People channel →