logoalt Hacker News

ZCode, the GLM coding agent, silently uploads your Git history

169 pointsby cdnstevetoday at 10:35 AM39 commentsview on HN

Comments

outloudvitoday at 11:31 AM

LLM-paraphrased from the original post: https://blog.ferstar.org/en/posts/zcode-silent-workspace-sna...

show 1 reply
philbotoday at 12:38 PM

Tangential, mildly amusing thing I noticed while implementing my own harness: GLM and particularly Deepseek are both fond of trying to read dotfiles and anything listed in your .gitignore files. I only noticed it because I have separate read scopes for project files, ignored files, dotfiles and external files, so the latter three always prompt me for approval.

I'm sure there's a perfectly reasonable explanation for it, which has nothing at all to do with exfiltration of secrets, but it does amuse me when it happens. I imagine the labs have access to lots of secrets that various actors would like to get their hands on...

(shameless plug for my own harness, which is open source and doesn't have a backend to send any data to: https://www.opairdev.org/ )

show 1 reply
v3ss0ntoday at 12:41 PM

Never use a Harness if it is not opensourced.

DeepSeek Harness is my favorite for coding. Hermes is my favourite for Other things , followed by OpenCode (sucks at managing long running services) .

Others swear by Pi.dev

show 2 replies
Aldipowertoday at 11:41 AM

That the article cannot distinguish between the git history 'git log' and the git repository, which is meant here, tells a lot.

Claude Fable uploads my git history (git log) every day to the Anthropic servers!

show 2 replies
tancoptoday at 11:43 AM

Closed source agents are a red flag no matter if its China or America. Always use an open harness with a good reputation and enough users that someone will notice if they push malicious code like this one here. Right now that's Opencode and Pi.

show 2 replies
weirantoday at 1:19 PM

I've been using ZCode since it's initial release and can't find any of this in my data. There aren't any logs showing capture or upload, and I don't even have a ~/.zcode/v2/checkpoints/ directory.

So unless they've cleared it all with a recent update then it doesn't seem to affect everyone.

crossroadsguytoday at 1:44 PM

At this point does any of us/you really think all those piss-cheap tokens are coming out of thin air? That unlimited token-usage during certain hours was not coming from Chinese side of Himalayan glaciers, was it?

Besides why would you use a closed source harness from a certain place, even if you decide to use the model (if nothing then for the price alone). And, that first remark wasn't just for ZAI but all the providers.

At this point: wrapping the harness around something like sandbox-exec or agent-safehouse is a must. Better still, create a new user account (after so much resistance I am warming up to the idea).

Will ZAI see a blowback after this news? Naah. People will keep using it. Hell, I will keep using it. That's how it is now - post truth and post LLM world.

PS. Anyone singing praise of OpenCode here, it's literally one of the worst harneses, open or not. Just look at their fricking issues - the strategic and rampant placements of "no planned" is mind boggling. And for what? Slightly better than ClaudeCode in token consumption and that too starts getting muddled after a while.

mococatoday at 11:36 AM

That’s explains the 300 million of tokens on the weekend only if you use their tool.

shevy-javatoday at 1:46 PM

Well - spy agents. Not surprising. But people could have suspected this before surrendering to AI skynet.

rfgplktoday at 1:30 PM

This is all publicly available anyways, who cares? Also you're practically consenting to it when you run an agent locally

alightsoultoday at 12:42 PM

This sounds a lot like the same thing Openai did with navier stokes, but Openai is more stealthy about it.

hn1rig3raktoday at 12:46 PM

Built a similar read-scope gate and the fiddly bit was symlinks escaping the project root.

lohtoday at 11:50 AM

I recently began playing around with ZCode. Works pretty well. Super sketchy though if it is in fact silently uploading full git history of every user's projects. This is why we need not only open weight models, but open source harnesses as well. Luckily the project I'm trying ZCode on is already open source (Molecule.dev), and I'm already allowing full telemetry with my other agents/harnesses (e.g., Claude) for this particular project, so it's not a huge deal in my case, but it's obviously a huge deal for anything proprietary.

apitoday at 11:49 AM

Lots of modern software plays it loose with privacy, but this IMO crossing a second line: doing so with zero notification whatsoever, in a massively intrusive way, against data that is almost certainly private and possibly illegal to exfiltrate, with no obvious way to turn it off.

That crosses into outright malware.

Makes me not want to use GLM or other Z.ai models either, since who knows what interesting easter eggs are embedded in their training data.

You know... (puts on foil hat)... I did notice that Z is also the weird Russian logo for their invasion of Ukraine and Russia and China have cooperated to some degree (or at least China is helping Russia in exchange for access to resources). I dismissed this when I first thought of it, but I will now leave it here. Still probably coincidence but my Bayesian priors were just updated in its direction very slightly.

show 2 replies
theplumbertoday at 11:37 AM

Ohhh no another one found that agents don’t actually run locally. We already had the “grok uploads all my stuff to Google cloud bucket” news…

next I can’t wait to see news about “ai company is using my data without my consent” as well.

show 2 replies
dude250711today at 11:37 AM

Is this a step forward compared to previous distillations or a step backwards?

itsmeduncantoday at 1:35 PM

[flagged]

novaapitoday at 11:51 AM

[flagged]

aidiveyttoday at 12:02 PM

[dead]

tonyhart7today at 12:53 PM

[flagged]