01 logo

ZCode Uploaded Full Git Histories, Reflog, and Secrets by Default. Zhipu’s Apology Is Not Enough.

The AI coding tool reportedly sent entire workspaces to Alibaba Cloud OSS, with keys held only in the cloud. A fix and an open-source promise do not answer the security questions.

By JinPublished 14 days ago • 3 min read

ZCode uploaded repositories by default. What Zhipu owes users now.

Zhipu’s ZCode incident is worse than a routine bug. A bug crashes, miscalculates, or breaks a button. ZCode reportedly ran a default-on pipeline that packaged a developer’s workspace and sent it to a remote object store. The uploaded package included the full working directory, complete Git history, LFS large-file cache, reflog, and global application configuration. It was encrypted and sent to Alibaba Cloud OSS. The server issued the encryption public key. The private key stayed in the cloud. Users could not decrypt the package, audit it, or find a UI switch to stop the upload.

That combination changes the issue. Zhipu’s intent matters, but less than power, consent, and data minimization. A coding assistant needs context. It does not need reflog, global configuration, LFS cache, or every commit from the first one to the latest unpushed branch. Those files often hold the most sensitive material in a repository.

Git history records mistakes, deleted keys, old tokens, internal experiments, customer names, unfinished features, and strategy that never left the company. Reflog can recover commits removed by rebase, reset, or drop. LFS can hold large binaries, datasets, models, design assets, and proprietary media. Global application configuration can contain credentials, API keys, cloud profiles, SSH settings, and environment-specific secrets. A tool that gathers all of this in the background copies a developer’s professional life.

Zhipu admitted the upload. It blamed the codebase index feature. It said the purpose was convenience, the data would be destroyed after wiki generation, and nothing would be stored. It said the feature was default-on in the early release, some users were affected, and the problem is fixed. It promised to open-source ZCode, invited third-party review, and reset the weekly quota for free.

These steps stop some bleeding. They do not answer the security questions. The public still needs technical answers: the reason a code index needed reflog and global configuration; the retention period in Alibaba Cloud OSS; who could access the data; whether access logs existed and whether they were immutable; what “destroyed after wiki generation” means; whether a deletion receipt exists; whether an independent auditor can verify deletion; how server-side keys were generated, stored, rotated, and retired; whether a Zhipu employee could decrypt user data; whether a third party with OSS access could decrypt it. If the private key lives only in the cloud, the deletion promise rests on trusting the same party that designed the silent upload.

Encrypting data before upload sounds safe. The protection depends on who controls the keys. If the server delivers the public key and the private key never leaves the cloud, the user has no meaningful control. Users cannot inspect the package, prove what was sent, delete it independently, or verify whether a cloud copy remains. This architecture protects data in transit and leaves custody with the service provider. It may stop some external attackers. It does not protect users from the provider. A security claim that users cannot audit is a policy statement.

The joke about ZCode formatting an E drive and restoring it from the cloud inverts the real problem. Silent upload is not disaster recovery. Disaster recovery requires knowledge, authorization, control, and deletability. A backup the user did not request is an exfiltration risk. If a tool can upload an entire drive without consent, the problem is worse than the original report. If it cannot, the joke still makes the point: “we saved your data” fails as a defense when the user never asked you to take it.

Developers should not give AI coding tools full-disk or full-repository access by default. Use separate development environments. Keep production secrets out of local repositories. Use secret managers. Review network traffic. Block unexpected endpoints. Prefer tools that are local-first, self-hostable, or transparent about what leaves the machine. Turn off default telemetry and indexing before opening a sensitive project. Treat every “smart” feature as a potential data boundary crossing until proven otherwise.

Zhipu should default the upload off. Before any repository data leaves the machine, users need explicit, informed consent, a preview of exactly what will be uploaded, and a delete control. A local-only mode and a self-hosted mode would help. The company should publish a detailed data-flow diagram, open the server-side upload logic and deletion pipeline to independent review, and commission a third-party forensic audit. Affected users need deletion receipts. Retention limits and access logs should be public. A full postmortem should replace a short community reply. Free weekly quota is a retention tactic. It does not compensate for a broken trust boundary.

Every AI coding tool now wants source code, terminals, file systems, and repositories. That access can help. It can also leak. The standard should be data minimization, explicit consent, auditability, and deletion. A coding assistant should index what it needs, ask for what it does not need, and leave the rest alone. Trust is rebuilt through a verifiable system. Until then, the apology is a beginning.

social mediagadgetscybersecuritythought leadersproduct reviewappsmobiletech newsfact or fictionfutureinterview

About the Creator

Jin

Writer of reamstories

https://reamstories.com/jin

Enjoyed the story? Support the Creator.

Subscribe for free to receive all their stories in your feed. You could also become a paid subscriber, letting them know you appreciate their work.

Subscribe For Free

Reader insights

Comments

There are no comments for this story

Be the first to respond and start the conversation.

Sign in to comment
    Written by Jin