Webinars

Grok Is Leaking Your Repositories. So, What Now?

Grok’s Build CLI does not limit itself to the files the agent opens. Independent researcher cereblab found it sending entire codebases, version histories, and secrets to Google Cloud Storage.

In one case, 5.1 GiB moved in the background, nearly 28,000 times more data than the task actually required. And disabling the “improve the model” toggle only decides whether your data feeds training. It does not decide whether your source code leaves the machine.

Nevo Poran, Tenet’s co-founder and CTO, breaks down the wire-level analysis, what actually left the machine, and what to do about it. Any coding agent with git access carries the same risk.

Inside the recording:

  • The wire-level analysis: 5.1 GiB in the background, nearly 28,000 times more data than the task required
  • How coding agents with git access expose full repositories and history
  • What to rotate now, and why “deleted” secrets still expose you
  • Defenses for agents with broad repo access

Presenter

Nevo Poran, Co-Founder & CTO, Tenet Security. DEFCON speaker.

Nevo Poran
Co-Founder & CTO

Watch the recording

Complete the form to watch the full recording.

More Webinars

agentjacking cover
Webinars
min read
Agentjacking: How We Hijacked AI Agents Inside a $250B Company
A single fake bug report hijacked a $250 billion company's AI coding agent. No malware, no exploit. Every security control it passed stayed silent.
grok webinar
Webinars
min read
Grok Is Leaking Your Repositories. So, What Now?
A single fake bug report hijacked a $250 billion company's AI coding agent. No malware, no exploit. Every security control it passed stayed silent.