Grok Build sent not only files to xAI, but entire Git repositories with commit history

Colleagues, I’d like to highlight a case in cybersecurity and code protection.
A researcher showed that Grok Build v0.2.93 was uploading not only the required files, but the entire Git repository, including commit history, to xAI storage.
The volume of storage traffic was far greater than the model requests: this was no longer a working file, but a much broader data boundary.
Later, xAI disabled such uploads server-side, without a client update.
Why this matters: training opt-out does not mean code and secrets never leave your machine. If you used such a tool, review the repository and rotate credentials.
How do you feel about defaults like these?
#cybersecurity #SourceCodeSecurity #DataPrivacy #AI

