ZCode Was Packaging Entire Workspaces for Upload — A Privacy Scandal That Forced Open Source
On September 18, a security advisory revealed that Z.ai's ZCode was silently packaging entire workspaces for upload. Days later, Z.ai open-sourced the whole thing under Apache 2.0 — 4,200 stars in 7.5 hours. A scandal forced a textbook crisis response.

On September 21, Z.ai (formerly Zhipu AI) open-sourced its agentic coding tool ZCode under the Apache 2.0 license. The repository hit 4,200 stars in about seven and a half hours. But this was no carefully planned strategy launch — it was crisis PR forced by a privacy scandal.
What happened
On September 18, developer ferstar reverse-engineered the ZCode desktop client and found it silently packaging users' entire workspaces into encrypted archives and attempting to upload them to Alibaba Cloud OSS — before every prompt. On his test machine, one 313MB archive held 42,411 files, 86.6% of them .git data (commit objects, reflogs, Git LFS cache), with 564 logged upload attempts in local metadata.
The encryption is the damning part: AES-256-CTR with an RSA public key handed down by Z.ai's servers — the private key exists only in Z.ai's cloud. Had an upload succeeded, only Z.ai could have unwrapped it; not even the user could see what was taken.
How Z.ai responded
The company apologized, said remediation was complete, shipped fixes in version 3.14.0, invited independent audits — and on September 21 published the full source (github.com/zai-org/ZCode): Electron desktop app, web client, Agent CLI and backend. Notably, the upload pipeline was scrubbed clean from the released code, and the previously touted Repo Wiki feature disappeared with it.
A warning for vibe coders
AI coding tools need to read your codebase to understand context. But there is a bright red line between "reading code" and "encrypting your entire git history for upload". The lesson for everyone: audit what your AI tools do in the background — permissions, network calls, upload behavior — with the same rigor you'd review code.
Sources
Related articles

On October 7, 2026, Google Developers launched the Developer Knowledge API ecosystem: official Google Cloud, Firebase, and Android docs as a programmatic source of truth, with a gcloud CLI surface, an official Agent Skill (one-line install), an MCP server, and multi-language client libraries. Why 'docs as APIs' uproots vibe coding's classic failure of models misremembering APIs.

On September 30, 2026, Bitdefender launched AI Guardian in public beta: a security layer for autonomous AI agents that verdicts every tool call, file access, and credential use as allowed, flagged, or blocked. First on macOS, free during beta, supporting Claude Code and OpenClaw. Why this 'agent behavior firewall' arrives right on time for vibe coders.

On October 8, 2026, Google Cloud launched the Gemini agent at Gemini at Work 2026: a universal agent for work that takes objectives, plans by itself, auto-selects between Gemini and Claude models per task, and introduces 'coworker agents' with their own email, calendar, and directory seat. Four judgments on why the second half of the agent race is about 'agents that feel like colleagues.'