{
  "type": "bundle",
  "id": "bundle--34925f60-0101-4fae-8593-10ce3593af0e",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-07-16T00:00:00.000Z",
      "modified": "2026-07-16T00:00:00.000Z",
      "name": "Optimus Labs · Civilizations",
      "identity_class": "organization",
      "description": "Threat research team at Optimus Labs. Agentic AI attack surface research.",
      "contact_information": "https://www.optimuslabs.io/research/briefings"
    },
    {
      "type": "report",
      "spec_version": "2.1",
      "id": "report--70ad5698-0100-4872-81ad-beea71ae3f0a",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-07-16T00:00:00.000Z",
      "modified": "2026-07-16T00:00:00.000Z",
      "name": "Grok Build CLI shipped entire repos to xAI",
      "description": "The upload ran as a background job outside the agent's permission system, so it fired even in sessions where file access had been denied.\n\nGrok Build CLI bundled entire git repositories into archives and staged them for upload to xAI cloud storage. The bundle included every object reachable from HEAD, so .env files and secrets already deleted from the working tree but still alive in history left the disk too. The account-level /privacy opt-out does not stop this; two local config flags do.",
      "published": "2026-07-16T00:00:00.000Z",
      "report_types": [
        "threat-report"
      ],
      "confidence": 85,
      "labels": [
        "Coding agent",
        "Rogue AI",
        "Supply chain",
        "AI Asset Supply Chain Security",
        "Agentware Lifecycle Security",
        "Agent Permissions",
        "Outside the Agentic Loop",
        "severity:critical"
      ],
      "object_refs": [
        "indicator--69f8e4a0-0102-4608-88fa-82a86afb4aa8",
        "software--1f96623e-0101-457b-8e97-7745209777b9",
        "software--0d785c44-0101-426e-8c79-ee2a0e7a0eb2"
      ],
      "external_references": [
        {
          "source_name": "Optimus Labs · Civilizations",
          "url": "https://www.optimuslabs.io/research/briefings/grok-build-repo-exfiltration"
        },
        {
          "source_name": "Optimus Labs — discovery write-up (LinkedIn)",
          "url": "https://www.linkedin.com/posts/guptanipun_my-spare-laptop-ran-completely-out-of-disk-share-7482518573358264320-gt"
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--69f8e4a0-0102-4608-88fa-82a86afb4aa8",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-07-16T00:00:00.000Z",
      "modified": "2026-07-16T00:00:00.000Z",
      "name": "file: grok/config.toml",
      "description": "~/.grok/config.toml — check for [harness] disable_codebase_upload and [telemetry] trace_upload",
      "indicator_types": [
        "compromised",
        "malicious-activity"
      ],
      "pattern": "[file:name = 'config.toml']",
      "pattern_type": "stix",
      "valid_from": "2026-07-16T00:00:00.000Z",
      "labels": [
        "grok-build-repo-exfiltration",
        "coding-agent",
        "rogue-ai",
        "supply-chain"
      ]
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--1f96623e-0101-457b-8e97-7745209777b9",
      "name": "xAI"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--0d785c44-0101-426e-8c79-ee2a0e7a0eb2",
      "name": "Grok Build CLI"
    }
  ]
}