Overview
- Security researcher cereblab used mitmproxy to show Grok Build CLI v0.2.93 sent full local Git repositories to a Google Cloud Storage bucket named gs://grok-code-session-traces.
- The intercepted uploads carried complete commit histories and unredacted secret files so that data removed from the working tree could still be archived in the bundle.
- In tests a separate storage channel moved gigabytes of repository data while the model request used only kilobytes, showing the uploads were far broader than files the tool actually read.
- On July 13 xAI changed server flags to stop storage requests, and xAI posted on X while Elon Musk said prior uploads would be deleted, but the company has not issued a formal advisory or verified deletion or scope.
- Researchers found the upload code still present in newer Grok Build binaries so the behavior could be re-enabled by server settings without a client update; developers are advised to inspect network activity and rotate any exposed credentials.