English

SecurityZCodeZ.ai

ZCode AI Coding Agent Silently Uploads Full Git History to Cloud Storage

A researcher has revealed that ZCode, the AI coding desktop app from Beijing-based Z.ai, silently packages and uploads a user's entire workspace to Alibaba Cloud's object storage (Aliyun OSS).

The investigation, published on September 18, 2026, found that the application automatically collects the complete .git history, LFS asset cache, reflogs, and global application configurations. In one instance, a 345MB commercial workspace resulted in a 313MB encrypted archive, with the .git directory alone accounting for 86.6% of the payload. This means the upload includes the entire lineage of the repository, including deleted API keys and unpushed branches.

The data is encrypted using envelope encryption, where a symmetric key is wrapped with an RSA-OAEP public key. The corresponding private key is held only on Z.ai's servers, meaning neither the user nor the ZCode client can decrypt the archive. While ZCode's privacy policy states it collects text and files submitted during conversations, the researcher found no mention of workspace-wide packaging or Git history uploads.

Z.ai, the company behind the GLM family of open-weight models, has not yet responded to the findings. The researcher noted that the upload process is triggered by a host-level sidecar that operates independently of user preferences or the agent's tool loop, making it impossible to disable via the app's settings. To prevent the uploads, users must apply filesystem-level write protections to the application's checkpoint directory.

Sources

  1. ZCode, the GLM coding agent, silently uploads your Git history (Hacker News Frontpage, 2026-09-18)