Our website uses necessary cookies to enable basic functions and optional cookies to help us to enhance your user experience. Learn more about our cookie policy by clicking "Learn More".
Accept All Only Necessary Cookies
NEWSREVIEWSHOWTO

ZCode Privacy Report: AI Coding Agent Uploaded Git History

Candida Corkery

A security researcher says ZCode, Z.ai's desktop coding agent, quietly uploaded entire Git workspaces to Alibaba Cloud. Here's what the report shows and what to check.

Catelog

    On September 18, 2026, a developer who goes by "ferstar" published a reverse-engineering walkthrough of ZCode, the free desktop coding agent from Z.ai. The claim at the center of that writeup is uncomfortable: while you were logged in, the app packaged your whole workspace, complete .git history included, encrypted it, and pushed the archive to Alibaba Cloud storage. No prompt. No switch in the settings. According to the researcher's writeup, it just happened.

    If you use any AI coding tool, this is worth your attention. Not because ZCode is uniquely bad, but because the story exposes what a coding agent can do when you hand it a folder and a login.

    What a coding agent actually is

    A coding agent is a program that reads and writes code on your behalf. You describe a task, it opens files, edits them, runs commands in a terminal, and often commits the result to Git. The term covers a wide range of tools, and ZCode sits at the heavier end of that range.

    ZCode comes from Z.ai, the rebranded identity of Zhipu AI. It runs on macOS and Windows, and it ships with the pieces you'd expect from a desktop agent: an AI assistant built on the GLM-5.2 and GLM-5.3 models, a file manager, a terminal, a Git panel, and a live browser preview. The whole point is convenience. You point it at a project, and it works inside that project the way a junior developer would, except it never sleeps and never asks for clarification.

    That access is the feature. It's also the risk surface, and that's the part most users never think about.

    What the researcher says ZCode uploaded

    According to ferstar's writeup, the upload was not limited to the files the agent had touched. The app packaged the entire workspace: the complete .git directory with its full commit history, the LFS asset cache, reflogs, and global app configuration files. It encrypted the archive, then posted it to Aliyun OSS, which is Alibaba Cloud's object storage service.

    The routing detail matters. The client uploaded the archive directly through an HTTP POST form, so the traffic never passed through Zhipu's own application servers. OSS fired a callback afterward so the backend could record that an upload had happened. In plain terms, the data went straight from your machine to cloud storage, and the company learned about it secondhand.

    The researcher's log also shows ZCode attempting those file uploads 564 times. That number tells you this wasn't a rare edge case or a single misfire.

    Why the encryption makes it worse, not better

    Encryption sounds like the responsible move. It isn't, in this case, and the reason is where the key lives.

    Per the writeup, the app wrapped its symmetric key with RSA-OAEP-SHA256 using a public key that the server supplied at upload time. Public-key encryption means one thing by design: the private key is the only thing that can open the result, and that private key existed solely in the cloud. The researcher tried every local private key against the envelope. All of them failed.

    So the ~313MB ciphertext sitting on the user's disk can't be opened by the user. It can't be opened by ZCode either. Only Zhipu's backend holds the ability to decrypt it, and the researcher's tests back that up. That one fact does more to explain the concern than any headline does.

    Think about what that rules out. If the goal were crash recovery or syncing your work across devices, the key would sit on your machine, the way Git and Time Machine both work. The sources covering this story make exactly that point. When the only key is in someone else's building, the useful question isn't "is it encrypted," it's "who can read it."

    The privacy policy gap

    Z.ai's privacy policy, effective June 15, states that it collects "text, files, and code submitted during conversations." That's a fairly standard line for an AI product, and it covers what you type into a chat box.

    Now line it up against the finding. Packaging an entire workspace, complete Git history and all, isn't the same act as collecting files submitted during conversations. The policy, as written, doesn't describe workspace-level archiving or full repository uploads. Whether that's a drafting gap or something else is a question the document doesn't answer.

    This is the part worth internalizing for any AI tool you use. Read the data section and ask what the wording covers. "Files submitted during conversations" is narrower than "your project directory." If a policy only mentions conversations, the rest is undefined, and undefined is where surprises live.

    What turned up in the settings

    The UI toggles didn't stop it. The researcher's summary of that behavior comes down to a blunt line: settings do nothing. Whatever switch a user flipped, the upload behavior continued.

    That's the detail that should shape how you evaluate any coding agent. A privacy control that exists in the interface but doesn't change the underlying behavior is worse than no control, because it teaches users to trust something that isn't doing work. For ZCode specifically, the reviewer's testing suggests the visible options didn't govern the data leaving the machine.

    Z.ai's official response to the finding says the issue is fixed. That's a reasonable thing for a company to say, and it may well be true. What public evidence can't currently confirm is whether data already uploaded has been deleted, and exactly how far the fix reaches. Those are open questions, not settled ones.

    How to judge coding agent privacy before you install

    The ZCode story is a useful checklist, and here it is without the drama.

    • Check whether the tool's privacy policy mentions your repository, your Git history, and your workspace as data categories. If it only talks about prompts and conversation content, treat the rest as unknown.
    • Look for a server-side public key. It's the mechanism that lets a vendor read what you send, and it's the difference between encrypted storage and encrypted-and-readable-by-the-vendor.
    • Test the toggles. Turn off anything resembling telemetry or sync, then watch network activity. If a control doesn't change behavior, it's decoration.
    • Treat zcode security claims as claims. An official statement that an issue is fixed is a starting point, not proof.
    • Ask what stays local. A coding agent that only edits files in place and never uploads an archive is a different product from one that ships your folder to object storage.

    If you're wondering whether ZCode is safe today, the honest answer is that the app's behavior has reportedly changed and the public evidence doesn't independently verify the full scope. That's not a verdict on Z.ai. It's a statement about what's provable from outside.

    What the ZCode case means for your Git history

    A Git repository holds more than code. It carries your commit messages, your branches, your reflogs, and often credentials or config files that slipped in years ago and never left. The zcode git upload described in the writeup pulled all of that into one archive. Handing that to an AI coding agent is a bigger decision than handing it a single file.

    This is why "is ZCode safe" is really two questions. The first is whether the current build still uploads archives, which the vendor says it fixed. The second is whether you can live with any tool in the coding agent privacy category having that level of access by default. A zcode alternative won't automatically solve the second question, because the access model is the same across the category.

    Practical boundaries help. Keep API keys and secrets in environment files that aren't part of the repo. Don't point an agent at directories that contain unrelated projects or personal documents. If a tool asks for a login before it will do local work, that's a signal worth pausing on.

    The bottom line

    ZCode's reported behavior didn't come from a malicious download. It came from a normal-looking desktop app with deep access to a folder, plus a privacy policy that never described what happened next. The researcher's writeup supplies the evidence, Z.ai says the problem is fixed, and the public record leaves the cleanup and the scope of that fix unverified.

    Use this story as a lens, not a scoreboard. Any coding agent you install can read everything in the project you give it, and the real question is what it does with that reach once the login is active. Check the data section of the privacy policy before you check the feature list. Keep secrets out of the repos you hand over. And if a tool's controls don't visibly change its behavior, believe the behavior, not the toggle.

    You can also check this ai tool:

    Grok APK

    Grok is a generative AI assistant app that delivers real time answers, creation, and reasoning in one chat.

    ProductivityAI Chatbot

    ProductivityAI Chatbot


    Back to top

    Featured lists

    NEWSNEWSREVIEWSREVIEWSHOWTOHOWTO
    Latest Reviews
    What Is Claude Sonnet 5.5? Benchmarks, Pricing, and What's New in the 2026 Model
    What Is the September 2026 Android Security Update? 180 Vulnerabilities Explained
    Transformers: Eternal War Review 2026: Is This Mobile RPG Worth Playing?
    What Is the Anthropic Claude ART Enzyme System? Discovery Explained
    Top Reviews
    Back Alley Tales: A Unique Blend of Surveillance and Storytelling
    Best New Features in the Minecraft 26.50 Update, Ranked
    Kingdom Rush 6: Genesis TD Review: Worth Buying vs Earlier Games?
    Roblox VNG vs Global Version: Which Roblox Should You Play?
    Does Cat Resolution Pro Work? Review of the Stretched Screen App for Mobile Phones
    Summer Life in the Countryside: A Charming Visual Novel Experience
    EA SPORTS FC Soccer Mobile 27 Update: Every New Season Feature Ranked
    GTA 5 Mobile: The Ultimate Open-World Experience on Your Fingertips
    Subscribe to APKPure
    Be the first to get access to the early release, news, and guides of the best Android games and apps.
    No thanks
    Sign Up
    Subscribed Successfully!
    You're now subscribed to APKPure.