Devops iconDevopsSep 23, 2026 ~5 min source read

ZCode Uploaded Developers’ Workspaces by Default — What Happened and What to Do Now

A default-on indexing feature in Z.ai’s ZCode packaged and uploaded full developer workspaces, including Git history and config files, to Alibaba Cloud. The company disabled uploads, deleted cloud data, open-sourced the assistant, and commissioned security assessments. The incident highlights practical controls teams should apply to AI coding tools.

Your AI Coding Assistant Has the Keys to the Repo. Z.ai Just Showed Why That Matters

Share this story

Send the public story page.

Useful takeaways from this story.

ZCode’s Codebase Indexing automatically bundled and uploaded entire workspaces, including.git history and configs, to Aliyun OSS while running in the background.

Z.ai disabled the upload mechanism, deleted the related cloud storage, open-sourced ZCode, added zero-data-retention options, and commissioned external security reviews.

Prefer tools with documented data flows, independent audits, and verifiable behavior rather than opaque, server-encrypted uploads.

# What happened

# Why this matters for teams

The core issue is not an AI model flaw but a software-architecture and defaults problem. AI coding assistants require deep repository context to be useful, so they run next to.env files, credentials, commit logs, and dormant customer data. A desktop app or agent with broad filesystem access and a background process that "phones home" can move that data offworkstations without obvious signs.

Because the archives were encrypted with keys held by Z.ai, users could not independently verify what left their machines or whether deletion claims were complete. One company initially reported sensitive data had been uploaded, then retracted the complaint, citing wrong evidence.

# Practical steps for security and engineering teams

  • Treat coding assistants as privileged software. Apply the same vendor and security review you would for any agent that touches source or secrets.
  • Audit defaults before deployment. Identify indexing, sync, and memory features that are enabled out of the box and confirm whether they can be turned off centrally.
  • Keep secrets out of repos. Use secret scanning and vault-based credential management to reduce the blast radius if tools access the workspace.

# What Z.ai did and why verification still matters

Z.ai disabled the mechanism in ZCode version 3.14.0, deleted the related storage, open-sourced the assistant built on GLM-5.3, and commissioned assessments. NSFOCUS reported that the stored data and the storage bucket had been deleted. Z.ai also added zero-data-retention options and promised a product security vulnerability reporting and response process.

Even after these steps, independent verification remains important because the original archives were encrypted with keys only Z.ai controlled. Teams should ask vendors for reproducible proofs, audit reports, and the technical details of what the software reads, bundles, encrypts, and uploads.

# Short checklist to reduce immediate risk

  • Inventory AI assistants installed on developer machines and CI agents.
  • Disable or centrally manage any automatic indexing, sync, or memory features until reviewed.
  • Apply workstation egress monitoring for large uploads and unknown object storage endpoints.

This incident is an operational reminder: tools that improve developer productivity often need deep access. That access requires explicit risk controls, clear defaults, and verifiable vendor behavior.

More context around this story.

Advanced AI Debugging Assistants: Real Results & 2026 Data
Dev iconDevSep 8, 2026

Advanced AI Debugging Assistants: Real Results & 2026 Data

Originally published at nlocoding.com Only 18% of developers trust their AI debugging assistant to suggest production-ready fixes without review. The other 82%? They’re still glued to Stack Overflow, tabs multiplying like rabbits. (Source: JetBrains State of Developer Ecosystem 2026) Software eats itself faster every y

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app