Security researcher Cereblab found that xAI’s Grok Build coding-agent CLI (version 0.2.93) was silently transmitting entire local Git repositories — including untracked files, full commit history, and unredacted secrets such as API keys — to a Google Cloud Storage bucket controlled by xAI, even when users had disabled the tool’s data-sharing privacy toggle. In one documented case the tool uploaded 5.1 GiB of data for a task that required roughly 192 KB, and a planted canary credential appeared unredacted in the captured traffic. xAI silently patched the behavior server-side within a day of the July 12, 2026 disclosure, without issuing a public security advisory, and Elon Musk said the company would delete all previously uploaded user data.