YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0059

Incident record

Grok Build CLI uploaded entire developer repositories, secrets included, to a Google Cloud Storage bucket

Severity
High
Status
Patched
Type
Agent Hijack
Target
Developers using xAI's Grok Build CLI
Actor
researcher

What happened

An independent researcher's wire-level analysis of Grok Build CLI 0.2.93 found the coding tool packaged and uploaded a developer's entire tracked Git repository, deleted secrets still present in its history included, to a cloud storage bucket regardless of the task the model was asked to do. Asking the model only to reply OK, without opening any files, still triggered upload of the full repository as a git bundle, from which the researcher cloned back a file the agent was told not to open. In a separate run on a 12 gigabyte repository of files the agent never read, at least 5.1 GiB left through the storage channel against 192 kilobytes on the model channel, and the capture was stopped while the upload was still running.

The destination is a Google Cloud Storage bucket, gs://grok-code-session-traces, reached through cli-chat-proxy.grok.com. The uploads continued with xAI's privacy toggle switched off. Elon Musk responded on X on 13 July 2026 that previously uploaded user data would be deleted, wording it as data uploaded to SpaceXAI, though independent confirmation of the deletion has not been published, and xAI later disabled the codebase-upload behaviour server side. The researcher said xAI's suggested per-session retention command was not the same as fixing the underlying upload, and declined to claim the research caused the change.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026