Grok Build Uploading Secrets to xAI’s Cloud
Grok Build was uploading entire Git repositories to xAI’s cloud, including committed secrets. A wire-level analysis revealed the CLI sent full commit history, API keys, and files it was told not to open.
xAI had marketed Grok Build as a tool that wouldn’t transmit code.
Published on July 14, 2026 – 8:48 pm by Ana Maria Constantin (Expertise: Digital Marketing, Product Management, Branding & Identity)
Analysis and Findings
- The researcher found that version 0.2.93 of Grok Build packaged entire tracked repositories, including full Git history, committed secrets, and API keys.
- Upload volume was approximately 27,800 times greater than required for the coding task.
- The privacy toggle claimed to prevent data transmission but was ineffective, according to reports.
Past Privacy Concerns
Grok has a history of privacy issues, including training on user data without consent, which breached EU regulations. A quarter of European firms have banned Grok entirely in favor of alternatives with better security controls.
Elon Musk’s Response
Elon Musk confirmed the uploads and promised SpaceXAI would delete all prior Grok Build user data. They added a /privacy endpoint and implemented a server-side flag to disable uploads, but no independent audit has confirmed data deletion.
Impact
Grok Build launched alongside Grok 4.5 as xAI’s answer to competitors. This privacy breach is particularly damaging for the product’s stated goal of winning enterprise developer trust.