A security analysis reveals xAI's Grok Build command-line tool transmits complete source code and project files to xAI's servers. The discovery raises data privacy questions for developers using the tool.
A detailed technical breakdown posted on GitHub shows that xAI's Grok Build CLI sends substantially more data to xAI's infrastructure than users might expect. The tool transmits full source code, project structure, and file contents to xAI servers during build operations.
The analysis, which gained 145 upvotes on Hacker News with 79 comments, documents the exact data flows occurring when developers run the CLI. This includes code that developers may consider proprietary or sensitive.
While xAI's terms of service likely address data handling, the transparency of what's actually transmitted wasn't immediately clear to users. The findings highlight a broader concern in AI tooling: understanding what data gets sent to external services during development workflows.
Developers using Grok Build should review xAI's data policies and consider the sensitivity of their codebase before running the tool. The open discussion on Hacker News suggests growing developer interest in understanding data flows in AI-assisted development tools.
Illinois county prosecutors secretly provided personal information about criminal defendants to federal immigration agents without warrants, public disclosure, or legislative approval.
Law enforcement from 22 countries arrested 58 individuals and identified 263 suspects in a coordinated crackdown on cybercrime networks run by African crime groups.
The Los Angeles County Museum of Art disclosed a data breach from last year that compromised customer and employee information, including social security numbers and medical records.
A phishing-as-a-service platform called AnonyMousKIT uses voice AI agents to extract passcodes from stolen Apple devices and bypass Activation Lock security features.