6 ms·
ZCode, the GLM coding agent, silently uploads your Git history
- outloudvi 15d agoLLM-paraphrased from the original post: https://blog.ferstar.org/en/posts/zcode-silent-workspace-snapshot-upload/ https://blog.ferstar.org/en/posts/zcode-silent-workspace-sna...
- Luc 15d agoIndeed. Discussion here: https://news.ycombinator.com/item?id=49750694 https://news.ycombinator.com/item?id=49750694
- lucasoshiro 14d agoThanks. I'm upvoting that instead
- dang 14d agoOk, we've merged (most) comments moved thither. Thanks!
- bbor 14d agoSo strange that this is still up 5 hours later… dang, I am yet again begging you to stop trying to roll your own forum ethos. It’s okay. You’re safe now. We can modernize without losing the magic. I know I know, shh, it’s okay, don’t worry, just flip the markdown and automod switches I know you have… (<3)
- xdavidliu 14d agoI made it about two paragraphs in the paraphase before I hit this sentence and realized > The detail that turned a suspicious directory into a story: the encryption key.
- mococa 15d agoThat’s explains the 300 million of tokens on the weekend only if you use their tool.
- nullbio 14d agoIt explains why they were letting people use their model for free too.
- dude250711 15d agoIs this a step forward compared to previous distillations or a step backwards?
- theplumber 15d agoOhhh no another one found that agents don’t actually run locally. We already had the “grok uploads all my stuff to Google cloud bucket” news… next I can’t wait to see news about “ai company is using my data without my consent” as well.
- Aldipower 15d agoThat the article cannot distinguish between the git history 'git log' and the git repository, which is meant here, tells a lot. Claude Fable uploads my git history (git log) every day to the Anthropic servers!
- bbor 15d agoThis is bad-faith AI slop rephrasing the original article, but regardless: the extent of the issue is far, far, far beyond the metadata you're discussing. No one has 300MB of commit messages.
- deleted 14d ago[deleted]
- progval 14d ago> No one has 300MB of commit messages. Commit messages in https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/lin... sum to 900MB. Also, this commit message alone: https://gitlab.com/old-game/sb-b/nanobox.io/nanobox-pkgsrc-lite/-/commit/857d286123acf87ae4a08528a3eef4ce2fbf8db2 https://gitlab.com/old-game/sb-b/nanobox.io/nanobox-pkgsrc-l... weighs 100.5MB (they squashed years of history as a single commit and piped "git log" to the commit message).
- bbor 14d agolol okay you got me. Linux itself might!
- vikramkr 14d agoIt's funny because the author of the article is obviously Claude but most Claude models would definitely know the difference. Some sort of free tier model being used to summarize some other blog that's also ai translated originally it seems.
- TuxSH 14d agoDoes it do so while using an asymmetric key encryption key?
- tancop 15d agoClosed source agents are a red flag no matter if its China or America. Always use an open harness with a good reputation and enough users that someone will notice if they push malicious code like this one here. Right now that's Opencode and Pi.
- hypfer 15d agoI wouldn't list Opencode as "good reputation". They had their own unbound "harness scans the whole user directory" oopsie and handled concerns about that by introducing code signing. Which, yes, does have absolutely nothing to do with that issue. I guess by now it is better, but to me they seem to lack the engineering culture necessary for a "good reputation" stamp. __ Ref: https://github.com/anomalyco/opencode/issues/14925#issuecomment-4149189433 https://github.com/anomalyco/opencode/issues/14925#issuecomm... among other issues.
- blfr 15d agoWhy?
- edude03 15d agoTheir reputation is “bad” but not because of privacy concerns. I personally think they’re trustworthy
- my-huge-pony 14d agoWe use opencode with self hosted llm for privacy reasons. Good, right? Well, no, because opencode by default uses a "free" cloud model to summarize all chats even if a different model was configured as the main one. I wonder how many opencode users upload their private secrets to the cloud, while thinking they're using a self hosted model. Btw. I don't think this is malicious, just sloppy.
- esafak 14d agoIt uses gpt-5-nano through OpenCode Zen to generate the title unless you override `small_model`. https://opencode.ai/docs/providers/#self-hosted-gitlab https://opencode.ai/docs/providers/#self-hosted-gitlab
- deleted 15d ago[deleted]
- api 15d agoLots of modern software plays it loose with privacy, but this IMO crossing a second line: doing so with zero notification whatsoever, in a massively intrusive way, against data that is almost certainly private and possibly illegal to exfiltrate, with no obvious way to turn it off. That crosses into outright malware. Makes me not want to use GLM or other Z.ai models either, since who knows what interesting easter eggs are embedded in their training data. You know... (puts on foil hat)... I did notice that Z is also the weird Russian logo for their invasion of Ukraine and Russia and China have cooperated to some degree (or at least China is helping Russia in exchange for access to resources). I dismissed this when I first thought of it, but I will now leave it here. Still probably coincidence but my Bayesian priors were just updated in its direction very slightly.
- menaerus 15d agoHow do you know this is not true with other vendors? I'm not defending them but I wouldn't believe anyone in this business unconditionally. Anthropic agent fwiw is not open source, gemini and codex are.
- nullbio 14d agoPeople have found many nasties embedded in Claude Code over the last couple of years. You can't trust a closed source harness. You can barely trust an open source one.
- peri-cl 14d ago> "against data that is almost certainly private and possibly illegal to exfiltrate" I didn't fully understand the article, but I gathered this only impacts project directories managed by Z.ai's coding agent? I.e., projects you're already choosing to upload to them (partially), which thus cannot be private. I'm not excusing this malware; just trying to find clarity about its scope.
- deleted 14d ago[deleted]
- cyberamirul 14d ago
- loh 15d agoI recently began playing around with ZCode. Works pretty well. Super sketchy though if it is in fact silently uploading full git history of every user's projects. This is why we need not only open weight models, but open source harnesses as well. Luckily the project I'm trying ZCode on is already open source (Molecule.dev), and I'm already allowing full telemetry with my other agents/harnesses (e.g., Claude) for this particular project, so it's not a huge deal in my case, but it's obviously a huge deal for anything proprietary.
- novaapi 15d ago[flagged]
- deleted 15d ago[deleted]
- aidiveyt 15d ago[dead]
- deleted 15d ago[deleted]
- hn1rig3rak 14d agoBuilt a similar read-scope gate and the fiddly bit was symlinks escaping the project root.
- philbo 15d agoTangential, mildly amusing thing I noticed while implementing my own harness: GLM and particularly Deepseek are both fond of trying to read dotfiles and anything listed in your .gitignore files. I only noticed it because I have separate read scopes for project files, ignored files, dotfiles and external files, so the latter three always prompt me for approval. I'm sure there's a perfectly reasonable explanation for it, which has nothing at all to do with exfiltration of secrets, but it does amuse me when it happens. I imagine the labs have access to lots of secrets that various actors would like to get their hands on... (shameless plug for my own harness, which is open source and doesn't have a backend to send any data to: https://www.opairdev.org/ https://www.opairdev.org/ )
- alightsoul 15d agoGrok does or did the same thing, this is embarrasing
- sva_ 14d agoI tested GLM while working on some android app, the agent had adb access to the device. It suddenly went to the Gallery and started scrolling around, taking screenshots, lol. A friend had a similar experience with GLM where it would for no very clear reason start snooping through the filesystem. Haven't used it after that.
- princevegeta89 14d agoIt is no longer surprising to me that my cursor acts as if it does not recognize the .env file, and while I am editing it, it does not give inline suggestions; however...when it is debugging problems or responding to questions about the code, it will just say it read my env file and found xxx environment variables as a verification step, or sometimes it will even mention that I need to uncomment some environment variables in the env file, which makes the whole deal about security feel iffy giffy....
- thehamkercat 14d agoi use sops Encrypt: sops encrypt --input-type dotenv --output-type dotenv .env > secrets.enc.env then rm .env You can then run your script/dev with: sops exec-env secrets.enc.env 'docker xxxx' (it will ask you for your password, or touch-id to decrypt the secrets) I like this because this way the .env doesn't sit in the directory at all, and is only passed to your dev environment and stays in it while it's running Decrypt back to a file (if you ever want that): sops decrypt secrets.enc.env > .env --- Well ofc, any agent can do docker inspect to get all those env vars, but atleast reading the dotfiles won't do anything you can also edit the file with: sops --input-type dotenv --output-type dotenv secrets.enc.env
- v3ss0n 15d agoNever use a Harness if it is not opensourced. DeepSeek Harness is my favorite for coding. Hermes is my favourite for Other things , followed by OpenCode (sucks at managing long running services) . Others swear by Pi.dev
- drdexebtjl 14d agoZ.ai are temporarily offering unlimited usage during off-peak hours with their harness, which is a pretty good deal if your project is public even with this news.
- oathvz 14d agoAll fun and game until it also silently uploads your other things.
- DaSHacka 14d agoYou could always sandbox it or run it in a container
- codedokode 14d agoYou should use a sandbox. It is dumb to run any proprietary software without a sandbox, especially LLM-powered.
- lenerdenator 14d agoShouldn't do that, either. Mind and marketshare are currency in this space. Either these people are honest and deserve your trust and business, or they don't. They've been mischaracterizing the way they've been handling your data. Shut them off accordingly until they make things right.
- DaSHacka 14d agoI mean, it's just basic access control. You don't need to trust every program you run with 100% of all your personal/private information, just confine it to a specific domain accordingly. I'm fine with certain codebases and configs being shared, but not others, hence the sandbox/container recommendation. I suspect many others are the same way.
- alightsoul 15d agoThis sounds a lot like the same thing Openai did with navier stokes, but Openai is more stealthy about it.
- tonyhart7 14d ago[flagged]
- weiran 14d agoI've been using ZCode since it's initial release and can't find any of this in my data. There aren't any logs showing capture or upload, and I don't even have a ~/.zcode/v2/checkpoints/ directory. So unless they've cleared it all with a recent update then it doesn't seem to affect everyone.
- nullbio 14d agoIs there actually any proof of this, beside this Claude written website and a random x post from some unknown person? Would be nice to have confirmation from someone with a reputation. It's probably true, but you never know...
- weiran 14d agoNot that I've seen. The only follow up I've seen from someone was it only happened if you had a free account and not paid (which would explain why I'm unaffected)
- yuuna 12d agohttps://cdn-zcode.z.ai/zcode/electron/releases/3.12.3/windows-x64/ZCode-3.12.3-win-x64.exe https://cdn-zcode.z.ai/zcode/electron/releases/3.12.3/window... in the asar, search for string that contains "/api/v1/snapshot/upload-credential", that's the endpoint signing the S3 upload url, triggered every prompt
- rfgplk 14d agoThis is all publicly available anyways, who cares? Also you're practically consenting to it when you run an agent locally
- itsmeduncan 14d ago[flagged]
- crossroadsguy 14d agoAt this point does any of us/you really think all those piss-cheap tokens are coming out of thin air? That unlimited token-usage during certain hours was not coming from Chinese side of Himalayan glaciers, was it? Besides why would you use a closed source harness from a certain place, even if you decide to use the model (if nothing then for the price alone). And, that first remark wasn't just for ZAI but all the providers. At this point: wrapping the harness around something like sandbox-exec or agent-safehouse is a must. Better still, create a new user account (after so much resistance I am warming up to the idea). Will ZAI see a blowback after this news? Naah. People will keep using it. Hell, I will keep using it. That's how it is now - post truth and post LLM world. PS. Anyone singing praise of OpenCode here, it's literally one of the worst harneses, open or not. Just look at their fricking issues - the strategic and rampant placements of "no planned" is mind boggling. And for what? Slightly better than ClaudeCode in token consumption and that too starts getting muddled after a while.
- nullbio 14d agoOpenCode performs the worse on benchmarks out of all harnesses too.
- shevy-java 14d agoWell - spy agents. Not surprising. But people could have suspected this before surrendering to AI skynet.
- deleted 14d ago[deleted]
- ff114514 14d agoYou people are making too much of a fuss; even we don't use our own products.
- deleted 13d ago[deleted]