← All stories
● Covered by 3 sources · 4 reportsMedium impact

xAI's Grok CLI Tool Exposed for Uploading Entire Repositories Without Consent

🔄 Updated 79d ago — new reporting from The Verge
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Grok Build CLI uploaded whole repositories to cloud storage.
  • Security researcher cereblab discovered the unauthorized uploads.
  • Elon Musk promises deletion of previously uploaded data.
  • xAI silently disabled the upload feature post-disclosure.

Discovery of Unauthorized Uploads

xAI's Grok Build CLI tool was discovered to be transmitting entire code repositories to Google Cloud Storage without user consent. Security researcher, known as cereblab, used tools to intercept and analyze the data, revealing the unauthorized uploads, including sensitive file contents and git history.

Security and Privacy Concerns Raised

The tool's behavior raised significant privacy issues due to its invasive data collection, potentially exposing sensitive information. The uploads were substantial, with reports showing massive amounts of data being transferred compared to what was necessary for the tool's operation.

Actions Taken by xAI and Public Reactions

Following the leak of these findings, xAI quietly disabled the feature responsible for these comprehensive uploads. Despite the lack of formal communication from xAI, public outcry over privacy and data retention policies prompted a response from Elon Musk, who claimed all previously uploaded data would be removed.

Response from Elon Musk

Elon Musk addressed the controversy by asserting that all data previously uploaded to the cloud would be "completely and utterly deleted." Furthermore, he emphasized that privacy settings would be adhered to, though he advocated for continued data retention under user consent to aid in debugging.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

SpaceXAI's Grok Build AI tool was found uploading users' entire codebases to Google Cloud, including sensitive data. Elon Musk stated that uploaded data will be deleted and privacy settings respected, following widespread concerns regarding privacy and excessive data retention.

xAI's Grok Build CLI has been found to upload entire Git repositories, including commit history, to its own Google Cloud Storage, which poses significant privacy risks for users. This behavior contrasts with the stated purpose of only transferring necessary files for coding tasks, exposing potential security vulnerabilities when sensitive source code leaves user machines.

xAI has disabled a feature in its Grok Build CLI that allowed unintended uploads of entire developer repositories to Google Cloud Storage, following a security exposure report. The change, implemented silently without public notification, protects developers' codebases but raises concerns about previously uploaded data.

xAI's Grok Build CLI transmits sensitive file contents, including secret variables, to its servers. It uploads entire repositories independently of the files actually accessed, raising significant privacy concerns regarding user data handling.