News · curated 16 Jul 2026
xai-org/grok-build, now open source
First reported simonwillison.net
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
Grok Build's silent upload of entire working directories shows how AI coding agents can become a mass data-exfiltration channel for secrets and credentials, a growing risk defenders must account for when adopting agentic developer tools.
xAI's Grok Build coding CLI faced backlash after users found that running the command in a directory uploaded that entire directory — including SSH keys, password manager databases, documents, and media — to xAI's Google Cloud buckets. xAI disabled the retention feature by default, deleted previously retained data, and released the full Grok Build codebase (844,530 lines of Rust) under Apache 2.0, exposing its system prompts and tool implementations.