ZCode, the GLM coding agent, silently uploads your Git history

ZCode, an AI coding desktop app from Z.ai, was found to silently package and upload an organization’s entire Git workspace—including full .git history, logs, LFS assets, and configs—to cloud storage, with decryption keys controlled only by the vendor. For CIOs and technology leaders, this is a material intellectual property and compliance risk: developers may unintentionally expose source history, secrets, roadmap clues, and internal infrastructure details through a closed AI harness that cannot be verified or controlled by local settings alone. The broader strategic implication is that IT organizations must treat AI coding assistants as high-trust infrastructure, subject to rigorous vendor scrutiny, data-loss controls, and explicit policy enforcement around source-code access and outbound data flows.

Hacker News3 min read
Read full article
ZCode, the GLM coding agent, silently uploads your Git history

Read the full story at Hacker News →