xAI's Grok Build CLI Uploads Git Repositories to a Google Cloud Bucket

Security researchers discovered that xAI's Grok Build CLI was secretly uploading entire local Git repositories to a Google Cloud bucket, regardless of user privacy settings. The tool, marketed as local-first, continued this behavior even when the 'Improve the model' data-collection toggle was disabled.
Why it matters
This highlights significant privacy and security risks for developers using AI coding tools, as proprietary code and sensitive credentials were being exfiltrated without explicit consent.
xAI appears to have shut off the mechanism that let its Grok Build CLI upload complete developer repositories to company-controlled cloud storage, according to follow-up testing by the security researcher who exposed the behavior. The fix arrived as a hidden server-side flag, with no advisory, no statement, and no answer on what happens to code already collected.
The findings come from a researcher publishing under the handle cereblab, who routed Grok Build CLI version 0.2.93 through the interception proxy mitmproxy on macOS and released the captures as a public gist. The analysis showed the client bundling the entire tracked repository, full Git history included, and uploading it to a Google Cloud Storage bucket named grok-code-session-traces.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in