ZCode, Z.ai's GLM Coding Agent, Silently Uploads Your Entire Git History
ZCode, the AI coding desktop app from Z.ai — the Beijing company behind the GLM open-weight models — silently packages and uploads your entire workspace whenever you're logged in. That includes .git history, LFS asset cache, reflogs, and global app configs, encrypted and shipped to Aliyun OSS (Alibaba Cloud object storage). The finding comes from a September 18, 2026 reverse-engineering walkthrough by a developer going by ferstar.
What actually gets packed
The packaging manifest is stored locally in plaintext. For one 42,411-file snapshot, ferstar captured a 313MB encrypted archive built from a 345MB commercial workspace:
.git/lfs/— 196.1 MB (56.8%).git/objects/— 102.2 MB (29.6%).git/logs/— 0.6 MB (0.2%)- Source code and docs — 46.2 MB (13.4%)
The .git directory alone is 86.6% of the payload. A git object store isn't a working-tree snapshot — it's the full lineage of the repo. Deleted-in-a-later-commit API keys, unpushed branch names, internal hostnames and repo paths from .git/config are all in there. 564 failed upload attempts were logged during the investigation.
The encryption key lives only in Z.ai's cloud
ZCode uses envelope encryption: the payload is encrypted with a symmetric key, which is wrapped with an RSA-OAEP public key delivered by the server during upload-credential negotiation. The corresponding private key is only in Z.ai's cloud. ferstar tried every private key on the local system to unwrap the archive and failed. The 313MB ciphertext on your own disk can't be decrypted by you or by the ZCode client.
The upload pipeline, from app.asar
- Client requests credentials from
zcode.z.ai, which returns OSS form signatures, an object key, a size cap, and a per-round RSA public key. - Client packs the workspace to
tar.gz, encrypts withAES-256-CTR, wraps the symmetric key. - Client POSTs the archive directly to Aliyun OSS, which callbacks to Z.ai's backend to register the snapshot.
During the test, the running client held persistent connections to zcode.z.ai and two Aliyun OSS nodes.
The settings toggles don't stop it
- Optimize Experience (
optimizeAgentExperienceEnabled) — only controls whether data is authorized for model training. Snapshot capture and upload continue. - Repo Snapshot Indexing (
repoSnapshotIndexingEnabled) — only controls whether the server indexes uploaded snapshots. Local packaging and upload continue.
ferstar found the capture sidecar is instantiated unconditionally at startup, with no gating on user preferences — the only requirement is that the token provider can produce a valid JWT. Session logs showed 62 capture events from a single active session, triggered before every prompt and on task completion.
The confusion worth naming
Part of why this spread — 276,000 views on ferstar's post, 63,800 on FeiZ's Chinese-language alert — is that people conflate GLM the weights with ZCode the harness. The weights are open-weight. ZCode is closed source, and it's Z.ai's first-party harness. Petri Kuittinen's quoted response: "My advice has been and continues to be: do NOT trust closed source AI harnesses." If you run GLM locally via Ollama or llama.cpp, you're not running ZCode. But if you installed the desktop app to use those same GLM models, you are.
📖 Read the full source: HN AI Agents
👀 See Also

Claude Cage: Docker Sandbox for Claude Code Security
A developer created a Docker container called Claude Cage that isolates Claude Code to a single workspace folder, preventing access to SSH keys, AWS credentials, and personal files. The setup includes security rules and takes about 2 minutes with Docker installed.

Analysis of Claude Code's Instrumentation and Telemetry Capabilities
A source code analysis reveals Claude Code implements extensive behavior tracking including keyword-based sentiment classification, permission prompt hesitation monitoring, and detailed environment fingerprinting.

AISI Evaluation Shows Claude Mythos Preview's Cyber Capabilities in CTF and Multi-Step Attacks
The AI Security Institute evaluated Anthropic's Claude Mythos Preview, finding it successfully completed 73% of expert-level capture-the-flag challenges and solved a 32-step corporate network attack simulation in 3 out of 10 attempts.

Student contributes two security patches to OpenClaw production system
A student developer fixed a 'fail-open' vulnerability in OpenClaw's gateway logic (PR #29198) and a tabnabbing vulnerability in chat images (PR #18685), with both patches landing in production releases v2026.3.1 and v2026.2.24 respectively.