Security · 1h ago
Grok Build CLI Uploaded Entire Repos Despite Privacy Toggle
A researcher found that xAI's Grok Build CLI, version 0.2.93, uploaded full repository snapshots to a cloud bucket regardless of the privacy toggle setting. The tool sent 5.1 GB of data per session, including git history, while the model itself obeyed instructions not to read files. The privacy toggle only controlled model training data, not the upload.
Meridian48 take
The incident highlights a dangerous disconnect between user-facing privacy controls and actual data flows, a lesson that extends far beyond xAI.
Read the full reporting
xAI's Grok Build Uploaded Your Whole Repo, and the Privacy Toggle Did Nothing →
DEV Community
data-privacyai-agents