Grok Build Accused of Ignoring Permissions to Upload Repos
ctjlewis · x · 2026-07-15
A post alleges that Grok Build suffers from severe privacy and permission flaws: even if an agent is explicitly denied access to a file, it can still package and upload the entire repository (including full Git history) to an xAI-controlled Google Cloud Storage bucket via an alternative code path.
The report further notes that the binary is Apple-signed and internally contains strings like grok code session traces, aftercodebase.tar.gz, and disablecodebaseupload. Even with /privacy enabled and traceuploadenabled=false, the client still sends requests to /v1/traces.
More from Companies & People
- Skyfall AI plans to buy a SaaS business for $1 million and run it with AI — ChrisGPT · 2026-07-22
- Netflix buys AI startup InterPositive for $587 million in cash — aloncarmel · 2026-07-22
- “Build what agents want” may become AI’s most crowded and commoditized category — vaibhavbetter · 2026-07-22
- RSS launches under OMSF to push structural biology data modeling at scale — MoAlQuraishi · 2026-07-22
- Moonshot AI reportedly targets a $50B round ahead of Hong Kong listing — ctjlewis · 2026-07-22
- Annotated transcript of a Claude Code team interview is now available — trq212 · 2026-07-22