Grok Build Exposes Code Upload Risks

Substantial_Step_351 · reddit · 2026-07-15

This discussion focuses on a security/privacy issue in Grok Build. According to an article by cereblab, the CLI uploads the entire git repository, including full history, to xAI's storage buckets.

Key Points from the Article

Core Discussion Points

The post emphasizes that while people focus on prompt injection or model behavior, the real danger lies in the harness / tool layer:

The author concludes by asking if anyone is performing egress filtering for coding agents or actually inspecting traffic payloads.

Related event: Grok Build/CLI accused of silently uploading entire codebases; xAI promises to delete data(47 posts)→

Original post →

More from coding & agent

coding & agent channel →