A developer reverse-engineered xAI's Grok Build CLI and discovered it transmits local file contents to xAI servers without explicit confirmation. The tool sends entire codebases, including sensitive files like .env and API keys, as part of its build context. No encryption was observed in transit for metadata. The findings were published on GitHub and have sparked debate about transparency in AI developer tools.


This is what progress looks like now. A shiny CLI promises to help you build faster. You run a command. Your entire project leaves your machine. No popup. No warning. Just bytes streaming to a server you can't see.

Look, I get it. Grok Build needs context to generate accurate code. But there's a difference between sending a summary and vacuuming up everything. We trade privacy for convenience every day. This trade needs to be visible. It needs to be a choice.

Don't stop using these tools. Just know what they take. Your code is your intellectual property. Treat it that way.