The Harness

A coding CLI quietly uploads your whole repo.

Show Notes

A teardown of xAI's Grok Build CLI found it silently uploads entire local repositories, secrets included, to a Google Cloud Storage bucket no matter what the coding agent actually touches. The same week SK Hynix raised twenty six billion dollars in the second largest US stock listing ever, cementing memory chips as the tightest chokepoint in the AI supply chain, while SambaNova closed a billion dollar round pairing fresh capital with a JPMorgan on-premises inference deal. The Federal Reserve also pulled Marc Andreessen onto a new task force to study AI's effect on jobs and productivity, bringing AI's labor impact into central bank policy for the first time.

What is The Harness ?

A daily summary of what is interesting and happening in the AI industry, with a focus on what this means for people building harness experiences that are used.

Good morning, it's Sunday, July twelfth.

In today's briefing we see xAI's Grok Build CLI uploading entire repositories without authorization, SK Hynix's record IPO cementing memory as the tightest constraint in the AI supply chain, and the Federal Reserve pulling AI into central bank policy machinery for the first time.

In the harness, tools and orchestration world;

A teardown of xAI's Grok Build CLI version zero point two point nine three found the tool sends unredacted secrets including environment variable files to xAI when the agent reads them, and separately uploads entire local repositories to a Google Cloud Storage bucket regardless of what the agent actually touched. In a twelve gigabyte test repository, only one hundred and ninety-two kilobytes moved through the visible model-call channel while five point one gigabytes moved silently via storage endpoints: a twenty-seven thousand eight hundred times gap. The full repository remained recoverable via git bundle, complete with a file the author had explicitly marked never to be read. This is the third undisclosed data exfiltration pattern found in an agentic coding tool in two weeks, after Claude Code's covert telemetry routing and GitHub's GitLost prompt injection vulnerability. For teams evaluating agentic CLIs, the implication is that network traffic audits need to become a standard procurement step, not an afterthought, because the exfiltration surface on these tools continues to run ahead of what vendors disclose.

In AI Infra;

Two capital events this week both point the same direction: compute capital is consolidating around whoever can promise scarce memory or a credible Nvidia alternative, not just model quality. SK Hynix closed its Nasdaq debut up thirteen percent on Friday, raising twenty-six point five billion dollars, the second-largest US stock listing ever and the largest by a foreign company. The company controls more than half of global high-bandwidth memory supply, and its valuation has climbed more than seven times over a year, driven by AI-driven memory shortages. SambaNova announced the first tranche of a one billion dollar Series F at an eleven billion dollar valuation, led by General Atlantic with Qatar's sovereign wealth fund and T. Rowe Price also participating, and paired the raise with a deal making JPMorgan's SN40L and SN50 systems its on-premises inference partner. JPMorgan choosing dedicated on-premises silicon inside its own security boundary over API access is the sharpest signal yet that regulated enterprises will pay a premium to keep inference off a vendor's cloud entirely. For AI PMs thinking about inference deployment economics and where capital consolidation will lead, expect a sustained bifurcation between API-first and on-premises-first models within regulated industries, because memory constraints and security boundaries have become binding variables independent of model selection.

In other news;

The Federal Reserve pulled AI squarely onto its policy agenda this week. New Fed Chair Kevin Warsh named five external task forces on July ninth; Marc Andreessen co-leads the Productivity and Jobs panel alongside Stanford economist Charles Jones and Microsoft's Asha Sharma. Their mandate is to assess AI's effect on employment and growth and deliver recommendations by year-end. This is a G7 central bank formally absorbing AI's labor market impact into its policy machinery, running on a separate track from the export control and access control apparatus that has dominated AI policy all year. Andreessen and Warsh are thirty-year personal friends, which observers have already flagged as a conflict of interest worth watching as recommendations take shape. For product teams implementing AI-driven workforce automation, the implication is that centralized policy attention will shape how these decisions are discussed publicly, because the Federal Reserve's formal labor market assessment will influence how enterprises communicate about automation's employment effects.

That's the briefing. Have a great day.