A cautionary tale about what a coding agent can exfiltrate by default — worth reading before you run any new CLI agent in a sensitive directory, and the open-sourced is now inspectable.
“xAI's grok CLI tool faced severe community backlash yesterday when it became apparent that running the command in a directory could upload that entire directory to xAI's Google Cloud buckets.”
“One user reported running it in their home directory and seeing it upload "my SSH keys, my password manager database, my documents, photos, videos, everything".”
“Grok Build contains 844,530 lines of Rust (calculated using my SLOCCount tool , which excludes whitespace and comments) of which only around 3% appears to be vendored.”
“For comparison, openai/codex is 950,933 lines of Rust. Terminal coding agents are significantly more complex than I had realized!”
Checking sign-in…
Loading comments…