xAI Open-Sources Grok Build After Data Exposure
Summary
xAI has open-sourced Grok Build, its AI coding agent, under an Apache 2.0 license. This move comes after a security researcher found the tool was uploading sensitive developer data, including SSH keys and password databases, to a Google Cloud bucket. The researcher, Cereblab, discovered that Grok Build was sending significantly more data than required for coding tasks, even files the agent never opened. This included credentials from .env files, in plain form. One user reported their SSH keys, password manager database, and personal documents were uploaded. These uploads occurred despite xAI's privacy toggle, which was found to have no effect. xAI later killed the upload server-side and Elon Musk stated all previously uploaded user data would be deleted. The open-sourcing allows developers to compile Grok Build locally and use a self-hosted inference endpoint, potentially cutting out cloud reliance. This transparency release is important because it allows developers to audit the code themselves and better understand how their data is handled.
This is an AI-generated audio summary. Always check the original source for complete reporting.