Primary wire analysis of Grok Build CLI v0.2.93. Two channels: (A) model-turn POST /v1/responses with read file contents including unredacted .env; (B) background POST /v1/storage uploading entire repo as git bundle to grok-code-session-traces GCS bucket.
Canary file never_read_canary.txt recovered from uploaded bundle despite prompt forbidding file reads. 12 GB test repo: 5.10 GiB storage vs 192 KB model channel (~27,800× ratio). “Improve the model” toggle OFF did not stop uploads; trace_upload_enabled: true in settings.
Binary embeds xai-data-collector Rust crate referencing storage.googleapis.com. Does not prove training on data — proves transmission and storage.