ZCode silently uploads workspaces and git histories
A reverse-engineering investigation revealed that ZCode, the official desktop AI coding agent from Z.ai, secretly packages and uploads entire user workspaces to Alibaba Cloud storage whenever logged in. The vendor-encrypted archives include complete .git directories, commit lineages, and Git LFS caches, exposing historical secrets and uncommitted code while bypassing UI privacy toggles.
Shipping open-weight models does not make a company's software ecosystem trustworthy, and wrapping open models in closed, covertly exfiltrating developer tooling destroys the fundamental premise of local and sovereign AI.
- –Exfiltrating .git directories is catastrophic because repository object databases preserve years of history, including scrubbed API keys, internal credentials, and unreleased branch plans.
- –Vendor-only asymmetric encryption is an alarming design choice that prevents users from inspecting what code and files are being captured and exfiltrated from their local machines.
- –UI privacy toggles create a dangerous illusion of control, continuing to upload archives even when data-sharing and snapshot indexing options are switched off.
- –The incident highlights the critical risk of closed-source AI harnesses and will accelerate developer migration toward auditable, fully open-source coding agents.
DISCOVERED
1h ago
2026-09-18
PUBLISHED
3h ago
2026-09-18
RELEVANCE
AUTHOR
cdnsteve