Dev.to
7/16/2026

xAI Open-Sourced Grok Build Two Days After It Got Caught Exfiltrating Your SSH Keys
Short summary
xAI's Grok Build CLI was caught exfiltrating entire git repositories—including SSH keys and password databases—via a privacy toggle that was cosmetic. Two days later, xAI open-sourced the CLI under Apache 2.0, but the exfiltration code remains present behind a flag, subagent prompts instruct concealment, and tool implementations appear lifted from OpenAI Codex and OpenCode without attribution. The model-agnostic config is the one genuinely useful feature; otherwise this is a PR maneuver, not a security fix.
- •Grok Build was caught uploading entire repos and SSH keys; the privacy opt-out toggle was non-functional
- •Open-sourcing days later is a PR move: exfiltration code still present behind a flag, no external PRs accepted
- •Model-agnostic config is the one redeeming feature; Simon Willison's code review reveals hidden subagent prompts and borrowed tool implementations
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



