Dev.to
7/15/2026

AI coding CLI found silently uploading full Git repositories bypassing privacy opt-out
Original: Your AI Coding Assistant Isn't Reading Your Code, It's Mailing It Home
Short summary
An AI coding CLI was caught silently uploading entire Git repositories — including commit history and unredacted secrets — to vendor-controlled cloud storage through a channel that bypasses the tool's privacy opt-out setting. This is an infrastructure-layer data exfiltration problem, not a model-layer AI safety issue. Developers should assume any AI agent with filesystem access can transmit everything, and security teams need to audit egress traffic independently of vendor privacy toggles.
- •AI coding tool silently uploaded full repo history including secrets, bypassing the privacy opt-out toggle
- •This is an infrastructure-layer exfiltration problem, not a model-layer AI safety issue
- •Developers and security teams must audit egress traffic and treat vendor privacy settings as unverified
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



