伦敦国王学院的独立安全研究员 Lukasz Olejnik 博士向 The Verge 证实,这种数据保留量是“过度的”,并补充说可能存在风险的数据包括“专有源代码、安全漏洞信息、个人数据、基础设施细节以及凭证”。
SpaceXAI’s Grok Build AI coding tool was spotted uploading users’ entire codebases to Google Cloud before it was reported, and the company turned it off. The Register :https://www.theregister.com/ai-and-ml/2026/07/14/musk-promises-purge-after-grok-build-caught-sending-entire-repos-to-the-cloud/5271123 reports that Cereblab:https://cereblab.com/ published findings on Monday showing how the Grok Build CLI was packaging and uploading entire code repositories, “including files it was told not to open and secrets deleted from history,” significantly more data retention than similar tools like Claude Code.
The researchers say that as of Monday, their tests show SpaceXAI’s servers returning a “disable_codebase_upload: true” flag, and the codebase upload “no longer fires.”
Dr. Lukasz Olejnik, an independent security researcher at King’s College London, confirmed to The Verge that this amount of data retention is “excessive,” adding that the data potentially at risk could include “proprietary source code, information about security vulnerabilities, personal data, infrastructure details, [and] credentials.”
情报判断
Aioga 编辑摘要
Aioga 编辑摘要:SpaceXAI 的 Grok Build AI 编程工具被曝在用户不知情时将完整代码库上传至 Google Cloud。 Aioga 将其归入「行业动态」方向,重点关注它对真实使用和行业竞争的影响。