Back to feed
Dev.to
Dev.to
7/15/2026
AI coding CLI found silently uploading full Git repositories bypassing privacy opt-out

AI coding CLI found silently uploading full Git repositories bypassing privacy opt-out

Original: Your AI Coding Assistant Isn't Reading Your Code, It's Mailing It Home

Short summary

An AI coding CLI was caught silently uploading entire Git repositories — including commit history and unredacted secrets — to vendor-controlled cloud storage through a channel that bypasses the tool's privacy opt-out setting. This is an infrastructure-layer data exfiltration problem, not a model-layer AI safety issue. Developers should assume any AI agent with filesystem access can transmit everything, and security teams need to audit egress traffic independently of vendor privacy toggles.

  • AI coding tool silently uploaded full repo history including secrets, bypassing the privacy opt-out toggle
  • This is an infrastructure-layer exfiltration problem, not a model-layer AI safety issue
  • Developers and security teams must audit egress traffic and treat vendor privacy settings as unverified

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more