SpaceXAI’s AI coding tool Grok Build has been exposed for defaulting to uploading entire Git repositories, including code that the tool itself hasn’t read or contextual calls, as well as the full Git commit history. A 12GB of repository data was sent to Google Cloud, where Grok Build uses Google GCP to store the collected data. If you run this on a sensitive stack, your entire repo is already compromised regardless if it’s public or not. It’s literal spyware.