Is your coding agent uploading all your code?
Blog post from Arize
A security researcher found that SpaceXAI’s Grok Build CLI initially transmitted entire tracked Git repositories, including commit histories and sensitive files, to a cloud storage bucket even when its “Improve the model” option was disabled; a subsequent server-side change halted the uploads, while the new /privacy command was found to affect retention rather than what data is transmitted. The investigation highlighted that most cloud-based AI coding agents must send task-relevant code to remote models, but differ in the scope of data sent, whether it may be retained or used for training, and the privacy controls available. Documentation reviewed for Claude Code, Codex, Cursor, GitHub Copilot, and Grok Build indicates that individual-plan users may need to opt out of training or enable privacy settings, while business, enterprise, API, and zero-data-retention arrangements generally provide stronger contractual protections. Zero data retention limits post-receipt storage rather than transmission and may exclude abuse-monitoring records, with retention policies varying by provider and plan. The episode increased attention on auditing coding-agent network behavior and on users reviewing privacy settings, while underscoring the trust required when proprietary code is processed by third-party AI services.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Coding Assistant | 6 | 1,513 | 470 | 139 | -19% |
| Observability | 1 | 3,175 | 737 | 186 | -24% |
| Vector Search | 1 | 2,358 | 371 | 127 | +5% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.