Security/ ai · coding-agents · privacy · security

ZCode Coding Agent Accused of Silently Uploading Git History

A tokenstead.ai guide alleges the ZCode coding agent uploads Git history without clear disclosure, though key details remain unconfirmed.

A newly published guide accuses ZCode, a coding agent built on Zhipu's GLM models, of quietly uploading users' Git history.

The guide appeared on developer resource site tokenstead.ai on September 18, 2026, warning that ZCode uploads a user's Git history without clear disclosure. The post spread fast on Hacker News, pulling in 85 points and 16 comments. The specific technical claims, how the upload happens, whether there is an opt-in, and what parts of history get sent, are not detailed in the material available here. What is confirmed is the core allegation: a coding agent with repository access is reportedly sending data users did not expect it to send.

Coding agents need broad filesystem and repo access to function, so users are effectively trusting them with commit history, branch names, and any secrets committed by accident years ago. An agent that silently exports that data, even for benign telemetry or model training, raises the same consent questions that have dogged code-assistant tools before it. Until the full technical writeup surfaces, this is a serious but unverified allegation, not a confirmed breach.

A pointed headline and an active comment thread do not amount to a security audit. Treat this one as a lead worth following, not a verdict on GLM-based tools.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →