Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
← All Grok Build issues

This week in Grok Build · Jul 20, 2026

Grok Build July 20: xAI Open-Sources the Full CLI - 844,530 Lines of Rust Under Apache 2.0 - After Repo-Upload Privacy Backlash, Grok Automations Launches Free Scheduled Tasks

Get the next issue in your inbox. Weekly · Free

unsubscribe anytime.

TLDR;

xAI answered its worst week with its most transparent move. After security researchers found on July 14 that Grok Build had been uploading users' entire directories - complete Git repositories including commit histories, SSH keys, API keys, cloud tokens and password databases - to xAI's Google Cloud buckets, xAI disabled data retention by default, says it deleted all previously retained coding data, and on July 15 open-sourced the entire CLI at github.com/xai-org/grok-build: roughly 844,530 lines of Rust under Apache 2.0 covering the agent loop, tools, terminal UI and the extension system (skills, plugins, hooks, MCP servers, subagents). Usage limits were reset for all users, and you can now compile Grok Build locally against your own inference. Separately, Grok Automations launched July 16: free scheduled tasks for all users, email-triggered automations for SuperGrok at $30/month or $300/year. Audit the published code before pointing Grok Build at sensitive repos.

Grok Build CLI

Grok Build goes open source: 844,530 lines of Rust under Apache 2.0, published after the repo-upload privacy controversy

  • On July 14, researchers found Grok Build had been uploading users' entire directories - Git histories, SSH keys, API keys, cloud tokens, password databases - to xAI's cloud buckets; xAI disabled retention by default and says it deleted the retained data.
  • On July 15, xAI open-sourced the full CLI at github.com/xai-org/grok-build (~844,530 lines of Rust, Apache 2.0, a single commit with no history) and reset usage limits; the tree adapts tool code from Codex and OpenCode, still contains the now-disabled upload code, and compiles locally against your own inference via config.toml.

Editor’s read: Open-sourcing the harness is the right response, but the single-commit publish means you must audit the code as-is - there is no history to review.

Developer Tools & Community

Grok Automations launch: scheduled tasks free for all users, email triggers require SuperGrok at $30/month

  • On July 16, xAI launched Grok Automations: describe a recurring task in plain language and set a schedule (one-time, daily, weekday, weekly, monthly, yearly) free for all Grok users, while email-triggered automations - Grok watches your inbox and fires on sender/recipient/subject matches - require a SuperGrok subscription at $30/month or $300/year.
  • Automations integrate with Slack, Google Workspace, GitHub, Airtable and Salesforce connectors plus reusable Skills packages, with full run history, live now at grok.com and in the iOS and Android apps.

Community & Independent Developers

Competitor Dev Tools

Action Items

Immediate

  • Verify your Grok Build data-retention setting is off and rotate any SSH keys, API keys or cloud tokens that lived in directories you opened with Grok Build before July 14
  • Audit the open-sourced code at github.com/xai-org/grok-build before pointing it at sensitive repos - the disabled upload infrastructure is still in the tree
  • Use the reset usage limits, or compile Grok Build locally with config.toml against your own inference for full control

By July 27

  • Compare Kimi K3 open weights (promised July 27) against Grok 4.5 if you are standardizing on an open coding stack

All Resources

Every Monday morning

This week in Grok Build

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.