The xAI Grok Command-Line Interface is facing intense scrutiny after reports revealed the tool automatically uploaded sensitive user directories and private credentials to company servers without explicit consent.
Key Points
- Security researchers discovered Grok CLI transmitted SSH keys, Git repositories, and password manager databases to xAI servers.
- Unauthorized data uploads occurred even when users disabled "help improve this model" settings, drawing comparisons to malware behavior.
- xAI responded by introducing a
/privacycommand and disabling specific data-sharing flags to mitigate the privacy breach. - Elon Musk announced that all previously uploaded user data would be deleted from company servers following the backlash.
- Critics argue that relying on server-side toggles rather than client-side restrictions fails to fully resolve underlying data security vulnerabilities.