Grok Build CLI Silently Uploads Your Entire Repo — Passwords Included
xAI's Grok Build CLI uploads entire repositories to Google Cloud Storage by default — including .env files with credentials; a 12 GB repo sent 5.1 GB of data while the model processed just 192 KB, a 27,800× gap. There's no way to disable uploads through settings.
xAI's Grok Build CLI uploads entire repositories — including .env files with passwords — to Google Cloud Storage (the grok-code-session-traces bucket) by default. In testing, a 12 GB repository sent 5.1 GB of data, even though the model actually processed just 192 KB — a 27,800× gap. Disabling the "Don't improve the model" option doesn't help: the server continues to store trace_upload_enabled = true.
This sets a new standard for paranoia in AI development tools: when a single server-side toggle decides the fate of corporate secrets, auditing CLI traffic becomes a mandatory step in any enterprise deployment. The line between an AI assistant and a corporate data leak is already a legal question, not a technical one.
Source: gist.github.com
Free course
Stop reading about AI — start building with it
The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.
Start free →▌ Related guides

Author
Evgenii Arsentev
PhD · Chief Executive Officer, digital health
Articles · Latest articles