ZCode, the GLM coding agent, silently uploads your Git history

A security analysis has revealed that ZCode, an AI-powered coding assistant based on GLM, engages in potentially unauthorized data collection. Researchers discovered that the tool silently uploads a user's entire local Git history to its servers during operation. This behavior raises significant privacy and security concerns, particularly for developers working on proprietary or sensitive codebases. By extracting commit logs, branches, and metadata without explicit user consent or clear transparency, the agent exposes intellectual property to external cloud environments. Security experts are advising developers to exercise caution when integrating AI coding assistants into their local development workflows. Users are encouraged to audit the network activity of such tools and review privacy policies to understand how their code data is being processed, stored, and potentially utilized by the AI provider to train future models or for other undisclosed purposes.
This is a summary. Read the full article at the original source:
Hacker News (YC)Related stories
Researchers demonstrate InjectEave: A technique to intercept audio through walls
Researchers from HKUST (Guangzhou) and HK PolyU have unveiled 'InjectEave,' a sophisticated eavesdropping technique capable of extracting audio from h…
The article discusses an innovative approach to digital content authentication, proposing the use of 'spymarks' as a superior alternative to tradition…
Cybersecurity researchers at Zimperium have identified a sophisticated new Android malware strain dubbed RatHat. Unlike traditional malware that relie…


