2 items
The Grok Build incident exposes gaps in applying shadow IT controls to coding assistants. These tools access repositories and transmit code as part of their work. Exposure depends on developers’ privileges. Controls designed around unauthorized SaaS subscriptions need additional checks for codebase access and transmission.
An independent wire-level analysis of xAI's Grok Build CLI (version 0.2.93) found. The tool transmitted entire repository contents, including secrets files and git history. To xAI's servers regardless of what the AI agent was instructed to read. xAI has since disabled. The upload server-side and added a privacy opt-out. Though the researcher's testing found the opt-out controls data retention rather than blocking transmission. Elon Musk has publicly committed to deleting previously uploaded data, though that deletion has not yet been confirmed complete.