ZCode coding agent silently uploads user Git history
Reports reveal that the GLM-based coding agent ZCode is secretly uploading developers' Git history to remote servers.

Discussions on Hacker News have brought to light a concerning issue regarding ZCode, a coding agent built on GLM technology, which reportedly uploads users' Git history to remote servers without explicit consent or notification.
Coding assistants powered by artificial intelligence have become central to modern software development, helping write and optimize code. However, the unexpected exfiltration of local repository data introduces severe security and privacy risks for developers and enterprises alike.
Cybersecurity experts emphasize the growing need for strict auditing of AI development tools that interact with local file systems and version control histories. Incidents like this highlight the potential dangers of implicit data collection by third-party utilities.
For developers in Uzbekistan and the wider technological ecosystem, this serves as a critical reminder to vet AI coding assistants thoroughly before integrating them into personal or corporate workflows.
As of now, the creators of ZCode have not issued an official statement addressing the issue, but the tech community continues to scrutinize the tool's data handling practices and demand greater transparency.



