Security researcher cereblab reported that the Grok Build CLI was sending entire Git repositories to Google Cloud Storage. This behavior was discovered through analysis of a version 0.2.93 client intercepted using mitmproxy.
xAI Disables Grok Build CLI Git Repository Upload Feature on Server Side
This article is a translation. Read the Japanese original
The data transmitted was not limited to the files the agent actually opened for coding tasks; it included the entire repository being tracked and the complete Git history. In a test with a 12GB repository, while the communication request to the model was approximately 192KB, the upload to storage reached about 5.1GB.
Of particular concern was that canary credentials placed in .env files were transmitted as-is. Furthermore, the upload did not stop even when the "Improve the model" toggle—which many developers interpret as a control for data collection—was disabled.
One day after the report was made public, the researcher re-tested the tool and found that the server now returns disable_codebase_upload: true. Repository uploads were not observed across six re-tests.
xAI has not provided any explanation regarding the purpose or scope of this feature, nor its policy on the retention of existing data. There was also no mention of the repository upload behavior in the official changelog.
Source: xAI's Grok Build CLI Uploads Git Repositories to a Google Cloud Bucket (HN 100pt, 2 comments) (HN Search (backfill), 2026-07-14)