External Transmission
- Category
- Data Exfiltration
- Confidence
- 95% confidence
- Finding
The skill explicitly transmits git diffs, including uncommitted or branch changes, to a third-party API. Even though the README warns about common secret files and says nothing is stored, ordinary source files can still contain credentials, proprietary code, or sensitive business logic, so this creates a real data exfiltration risk.
- Content
md 1. Takes the diff for the range you ask for: your uncommitted changes, `main...HEAD`, the last commit, or any other git revision range. 2. Leaves out files that usually hold secrets (`.env*`, `*.pem`, `*.key`, `*.p12`, `id_rsa*`, `id_ed25519*`). 3. Stops if the diff is larger than 80,000 bytes, so a request stays under the 32,000 input-token cap per request that free accounts have. 4. Sends the diff to `https://api.grokified.com/v1/chat/completions` with the `grok-build-0.1` model and a short reviewer prompt. 5. Prints the review, and the token counts on stderr. Nothing is stored by the script. The diff goes to the Grokified API and nowhere else. A secret written directly into ordinary source code is not detected, so do not review a diff that contains one.
