Grok Build Accused of Ignoring Permissions to Upload Repos
ctjlewis · x · 2026-07-15
A post alleges that Grok Build suffers from severe privacy and permission flaws: even if an agent is explicitly denied access to a file, it can still package and upload the entire repository (including full Git history) to an xAI-controlled Google Cloud Storage bucket via an alternative code path.
The report further notes that the binary is Apple-signed and internally contains strings like grok code session traces, aftercodebase.tar.gz, and disablecodebaseupload. Even with /privacy enabled and traceuploadenabled=false, the client still sends requests to /v1/traces.
More from Companies & People
- Law Professor on Legal Engineering Jobs: Stigma Is Real but Builder Skills Open New Doors — jkubicki · 2026-09-11
- AI safety community mocked as 'bridge engineers' who say bridges can never be safe — Dan_Jeffries1 · 2026-09-11
- SoftBank's Masayoshi Son predicts 100 trillion self-replicating AIs: "humans' era as top life form is ending" — Puzzleheaded-King584 · 2026-09-11
- IIT Madras Launches EdTech Tulna Standards for AI-Powered Learning Products — ravi_iitm · 2026-09-11
- Warp's six non-engineering teams all run on Linear and Claude Code — mon__lim · 2026-09-11
- Anthropic Insiders: Not Everyone at the Lab Believes in High p(doom) — anpaure · 2026-09-11