Reports Claim AI Coding Tool ZCode Uploads Git History Without Clear Disclosure
ZCode, an AI coding agent, allegedly uploads users' Git repository history to remote servers without explicit user consent or notification.
Two independent bloggers have raised alarms about ZCode, a GLM-based AI coding agent, claiming the tool quietly transmits users' Git commit history to external cloud servers without clearly disclosing this behavior. The allegations center on what the reporters describe as 'silent' data collection — meaning the upload occurs without an obvious prompt, warning, or opt-in step visible to the user during normal operation. Git history can contain highly sensitive material: commit messages, author identities, branch names, and in some cases accidentally committed credentials, API keys, or proprietary code logic. If the claims are accurate, any developer or organization using ZCode on a private or commercial codebase could be exposing that data to third-party infrastructure without realizing it. Both sources — tokenstead.ai and blog.ferstar.org — published findings pointing to the same behavior, suggesting the issue was independently identified rather than amplified from a single report. Neither source's full technical methodology or detailed evidence is available in the text provided, which limits independent verification of the specific mechanism involved. As of this reporting, no official response from ZCode's developers has been captured in the available sources, and it is not known whether the uploads are disclosed in fine-print terms of service, represent a bug, or are an intentional feature. Developers using the tool on sensitive repositories may wish to audit their network traffic until further clarification is available.
Why it matters
Git repositories frequently contain proprietary source code, internal infrastructure details, and occasionally leaked credentials, making unauthorized exfiltration a serious security and intellectual property risk. Developers and organizations using ZCode on private codebases could be unknowingly exposing confidential data.
What's next
Watch for an official response from ZCode's developers clarifying whether the uploads are disclosed in terms of service, constitute a bug, or are an intentional feature.
Key facts
- ZCode is described as a GLM-based AI coding agent
- Two separate bloggers — tokenstead.ai and blog.ferstar.org — independently reported the same alleged behavior
- The alleged uploads involve Git repository history, which can include commit messages, author data, and accidentally committed secrets
- The data is described as being sent 'silently,' meaning without an obvious user-facing prompt or opt-in
- No official developer response or denial is present in the available source material
- Full technical evidence and methodology from the reporting blogs was not available for review
Bias & framing notes
Both sources frame the behavior as definitively occurring ('silently uploading'), but no body text was available to assess the technical evidence underpinning that claim. The absence of any developer response or rebuttal in the sources means only one side of the story is represented. The trust score is low primarily because no source body text was available to verify claims, not because the outlets are assumed to be unreliable.
NewsClear — neutral news & congressional tracking · Bill of the Week