URI:
       [HN Gopher] Inside ZCode: Silently uploading your Git history to...
       ___________________________________________________________________
        
       Inside ZCode: Silently uploading your Git history to the cloud
        
       Author : csmantle
       Score  : 320 points
       Date   : 2026-09-18 06:11 UTC (1 days ago)
        
  HTML web link (blog.ferstar.org)
  TEXT w3m dump (blog.ferstar.org)
        
       | denysvitali wrote:
       | They learned nothing from the Grok Code saga.
       | 
       | If anything, that should have been a learning lesson to NOT trust
       | harnesses, especially new ones.
        
         | throwa356262 wrote:
         | Hold on, what happened with grok?
        
           | jhealy wrote:
           | https://www.theregister.com/ai-and-ml/2026/07/14/musk-
           | promis...
        
         | numpad0 wrote:
         | Probably anything concerning that one just register as
         | satirical fictions at this moment to many
        
         | zahlman wrote:
         | The basic premise of the LLM companies marketing their "agents"
         | honestly reads to me like: "Yes, we know our commercial,
         | proprietary software has a C2 server[0] embedded. That's by
         | design and it's what lets us deliver all the value, pinky
         | promise. Besides, it's not _us_ remotely operating your
         | computer; it 's a massive, more-or-less autonomous computer
         | program that we don't really understand, running on hardware
         | you could barely even dream of."
         | 
         | If people weren't already familiar with the idea of LLMs
         | existing and being able to write usable code and make "tool
         | calls", this would sound completely and utterly batshit insane.
         | 
         | Because it pretty much is.
         | 
         | [0]: https://en.wikipedia.org/wiki/Botnet#Command_and_control
        
       | ngl999 wrote:
       | Fresh AI slop
       | 
       | The funniest thing is that the uploaded content is encrypted
       | using a key that the users don't have.
        
       | evanjrowley wrote:
       | There had to be a catch to the "free" promotion they're offering
       | this month if you use ZCode. Glad my instinct to isolate it
       | helped me, but I feel sorry for anyone whose secrets, etc. got
       | vacuumed up by Ziphu
        
       | mococa wrote:
       | That's explains the 300 million of tokens on the weekend only if
       | you use their tool.
        
         | nullbio wrote:
         | It explains why they were letting people use their model for
         | free too.
        
       | dude250711 wrote:
       | Is this a step forward compared to previous distillations or a
       | step backwards?
        
       | theplumber wrote:
       | Ohhh no another one found that agents don't actually run locally.
       | We already had the "grok uploads all my stuff to Google cloud
       | bucket" news...
       | 
       | next I can't wait to see news about "ai company is using my data
       | without my consent" as well.
        
         | ThouYS wrote:
         | wait, the thing that streams my code into the cloud, and that I
         | let run basically arbitrary commands on my machine... uploads
         | my code into the cloud?! I didn't sign up for this!
        
       | tancop wrote:
       | Closed source agents are a red flag no matter if its China or
       | America. Always use an open harness with a good reputation and
       | enough users that someone will notice if they push malicious code
       | like this one here. Right now that's Opencode and Pi.
        
         | hypfer wrote:
         | I wouldn't list Opencode as "good reputation".
         | 
         | They had their own unbound "harness scans the whole user
         | directory" oopsie and handled concerns about that by
         | introducing code signing.
         | 
         | Which, yes, does have absolutely nothing to do with that issue.
         | 
         | I guess by now it is better, but to me they seem to lack the
         | engineering culture necessary for a "good reputation" stamp.
         | 
         | __
         | 
         | Ref:
         | https://github.com/anomalyco/opencode/issues/14925#issuecomm...
         | 
         | among other issues.
        
           | blfr wrote:
           | Why?
        
           | edude03 wrote:
           | Their reputation is "bad" but not because of privacy
           | concerns. I personally think they're trustworthy
        
             | my-huge-pony wrote:
             | We use opencode with self hosted llm for privacy reasons.
             | Good, right? Well, no, because opencode by default uses a
             | "free" cloud model to summarize all chats even if a
             | different model was configured as the main one.
             | 
             | I wonder how many opencode users upload their private
             | secrets to the cloud, while thinking they're using a self
             | hosted model.
             | 
             | Btw. I don't think this is malicious, just sloppy.
        
               | esafak wrote:
               | It uses gpt-5-nano through OpenCode Zen to generate the
               | title unless you override `small_model`.
               | https://opencode.ai/docs/providers/#self-hosted-gitlab
        
           | gwerbin wrote:
           | How about the one where if you start a session outside of a
           | Git repository, the "worktree root" is set to /. Bug report
           | closed as "not planned".
        
             | hypfer wrote:
             | FWIW, I don't think that they're being malicious. They
             | instead just seem to have no idea nor do they care.
             | 
             | And the original comment I've replied to proves this
             | strategy right! So from a business standpoint: excellent
             | work.
        
               | bbor wrote:
               | Glad my arbitrary failure to try them has worked out! For
               | people seeking OS-native harnesses, I can recommend
               | Factory's Droid. I know I'll be returning to it with my
               | head hung low today, after I uninstall ZCode.
               | 
               | It does have a "mission" feature that's stuck in the
               | strange, distant times of 2025 by way overdoing mandatory
               | verification steps, which means they don't support
               | swarms/workflows/crews/fleets yet -- that is, it's all
               | done in sequence. But they have the boring, corporate
               | engineering attitude that I think we're are all craving
               | rn, and generally seem competent.
               | 
               | I can heartily _dis_ -recommend Vix, even though they
               | gamed themselves to the top of at least one ranking site
               | that shall not be named; exactly like the quasi-bad-faith
               | incompetence described with OpenCode above, but without
               | even the "Open-" branding! Though perhaps that word has
               | been so thoroughly burnt as a prefix by Sam Altman &
               | Microsoft's criminal behavior that we should let it go...
               | 
               | Is this how "FLOSS" wins over "OSS"? Not with an
               | ideological bang, but with a marketing issue?
        
               | hypfer wrote:
               | > Is this how "FLOSS" wins over "OSS"? Not with an
               | ideological bang, but with a marketing issue?
               | 
               | Nah, I don't think so. Also, we arguably do not want
               | FLOSS to "win" over OSS, because that just means people
               | with no taste or sense cluttering up the repos, issues
               | and support chats.
               | 
               | "Open" being used as a signal for non-hacker people was a
               | weird and unpleasant development, but, if you think about
               | it, it might be a blessing in disguise and shall keep
               | them away from the more pleasant spaces.
               | 
               | It's not that they'd care about being scammed, mistreated
               | and rug-pulled anyway. They want that. They do it
               | themselves all the time. Every time they encounter a
               | space that treats them well, they terraform it into
               | baseline miserable-ness.
               | 
               | So let them have the "Open" prefix. It's just words,
               | anyway.
        
               | bbor wrote:
               | This is kinda beside the point and this whole thread may
               | be wiped when dang wakes up and notices the AI slop
               | article we're commending under, but your reply is thought
               | provoking so I'll attempt a response anyway;
               | 
               | I'm sure you're far more experienced than I with
               | basically every aspect of this discussion, but I'd argue
               | that's given you a blindspot, here. I'll hit some
               | specifics below, but the headline is that you're
               | effectively taking a stand against Eternal September II
               | -- a goal that I hope we can all agree would be
               | quixotically antisocial, given what followed the first
               | one!                 we arguably do not want FLOSS to
               | "win" over OSS
               | 
               | I think(/hope) that fellow FLOSS proponents would
               | passionately disagree. FLOSS isn't a brand of chatroom,
               | nor even merely a community: it's an ethos regarding
               | labor, property, and liberty. Demanding that all users of
               | your software are also activists for your particular take
               | on intellectual property is clearly a doomed undertaking
               | for anything beyond a toy or library, anyway.
               | 
               | Didn't you get into this stuff to change the world? To
               | liberate the oppressed, undereducated, and forgotten with
               | the radical power of the information superhighway? Cause
               | it reads here like you're more motivated by selfishness
               | (not wanting to bother talking to people with less
               | expertise than you) and resentment. On that note...
               | They want that. They do it themselves all the time.
               | 
               | Here you equate "non-hacker people" with software
               | engineers you don't agree with, it seems. You're ofc
               | welcome to think companies X Y & Z produce "miserable-
               | ness", but as absurd as it sounds, it sure seems like
               | you've forgotten the fact that some users are not
               | developers. Many, in fact! Over 99%, even!
               | 
               | Less confrontationally; my mom is in her late 60s, and is
               | pretty computer-literate for her age after decades of
               | knowledge work. Surely you'd agree that she's not, like,
               | _evil_ for using OSX, iOS, GMail, Word, etc.? That she
               | didn 't chose those things because of a philosophical
               | commitment to defending IP laws, but rather because of
               | structural reasons? Even if she were pro-IP, wouldn't we
               | want to win good, well-meaning people to our side?
               | So let them have the "Open" prefix. It's just words,
               | anyway.
               | 
               | I do agree with this still, but as a philosopher I just
               | have to say that everything is just words. It's language
               | games, in fact! Which is why I simply had to reply.
               | 
               | I hope none of the above was rude; I'm trying hard to
               | keep my passion for this topic from pushing me past HN
               | guidelines :)
        
               | hypfer wrote:
               | Cutting things short:
               | 
               | > but I'd argue that's given you a blindspot, here
               | 
               | I'd argue it's the opposite. The idealism there _is_ the
               | blindspot. Not the other way round.
               | 
               | You can't save everyone. And you will die trying.
               | 
               | That's the first thing that gets (or should get) hammered
               | into people's heads when they pick up a career in all
               | things social.
               | 
               | Which isn't to say that we shouldn't dream, but I believe
               | that our dreams should be optimized for maximum gain with
               | minimum pain.
        
               | bbor wrote:
               | Well I personally think we can find a middle ground
               | between single-handedly saving "everyone" from poverty
               | and addiction and oppression as social workers, and not
               | letting anyone into our exclusive philosophy-of-property
               | clubhouse. I would invite you to join us on this pro-
               | social mission, but you seem perfectly content as-is!
               | 
               | Some people are still on Usenet after all (?), so I
               | suppose it's not a big deal if a few people want to cling
               | to old communities. I hope you don't mind if we use the
               | word for what it was coined for though in the meantime,
               | back in the real world.
        
               | hypfer wrote:
               | To be frank, I'm not really interested in "joining" your
               | thing there, when joining your thing usually means me
               | doing the work while others get to decide on how it
               | should be done and feel good about that it is being done
               | as if it was their own achievement.
               | 
               | That said, spite has served me well so far, so maybe it
               | can also serve you?
               | 
               | This is after all a great opportunity to prove me and my
               | worldview wrong by simply putting in the work and
               | creating what you seem to believe is the correct form of
               | existing.
               | 
               | I can only encourage bringing your ideas into reality.
               | Seriously. That is that whole Foss spirit thing. You
               | don't need to invite anyone (including me) to that to
               | make it happen.
               | 
               | Let's manifest some code and change the world :)
        
         | mikkelam wrote:
         | codex is also open source, though im not so sure about the
         | reputation aspect.
         | 
         | The same can be said about opencode though.
        
       | api wrote:
       | Lots of modern software plays it loose with privacy, but this IMO
       | crossing a second line: doing so with zero notification
       | whatsoever, in a massively intrusive way, against data that is
       | almost certainly private and possibly illegal to exfiltrate, with
       | no obvious way to turn it off.
       | 
       | That crosses into outright malware.
       | 
       | Makes me not want to use GLM or other Z.ai models either, since
       | who knows what interesting easter eggs are embedded in their
       | training data.
       | 
       | You know... (puts on foil hat)... I did notice that Z is also the
       | weird Russian logo for their invasion of Ukraine and Russia and
       | China have cooperated to some degree (or at least China is
       | helping Russia in exchange for access to resources). I dismissed
       | this when I first thought of it, but I will now leave it here.
       | Still probably coincidence but my Bayesian priors were just
       | updated in its direction very slightly.
        
         | menaerus wrote:
         | How do you know this is not true with other vendors? I'm not
         | defending them but I wouldn't believe anyone in this business
         | unconditionally. Anthropic agent fwiw is not open source,
         | gemini and codex are.
        
           | nullbio wrote:
           | People have found many nasties embedded in Claude Code over
           | the last couple of years. You can't trust a closed source
           | harness. You can barely trust an open source one.
        
       | loh wrote:
       | I recently began playing around with ZCode. Works pretty well.
       | Super sketchy though if it is in fact silently uploading full git
       | history of every user's projects. This is why we need not only
       | open weight models, but open source harnesses as well. Luckily
       | the project I'm trying ZCode on is already open source
       | (Molecule.dev), and I'm already allowing full telemetry with my
       | other agents/harnesses (e.g., Claude) for this particular
       | project, so it's not a huge deal in my case, but it's obviously a
       | huge deal for anything proprietary.
        
       | r_lee wrote:
       | I would never trust these Chinese vendors with their tooling or
       | their own inference endpoints.
       | 
       | afaik DeepSeek also trained on everything that was sent to them
       | via OR and that's why you got that massive discount
        
       | bbor wrote:
       | WOW. I actually did buy a month of GLM because GLM-5.3-Flash is
       | so great and ZCode is honestly one of the best harnesses out
       | there from an HCI perspective, and I won't lie, this is pretty
       | gutting. I guess this settles my inner turmoil about open-
       | sourcing my cAI research, at least...
       | 
       | With that personal failing in mind, I'd ask y'all to permit me to
       | toe the guidelines just once, to proffer a hearty _nyah nyah told
       | ya so_ on a comment thread that spawned ~a dozen disagreeing
       | replies this week! More seriously, I think this[1] is highly-
       | relevant, shockingly-underreported context about the extent to
       | which four PRC companies --Z, Alibaba, DeepSeek, and Moonshot--
       | are acting in bad faith. Consider it testimony as to their
       | character, just in case anyone is thinking this might just be a
       | simple misunderstanding.
       | 
       | So... _nyah nyah, told us so_ :
       | 
       | > In the PRC, they[1] leaked tons of national secrets on the
       | PRC's latest AI campaigns, the inner workings of their "opinion
       | monitoring" (read: performative panopticon) and "stability"
       | (read: violent oppression) departments, Chengdu's whole CCTV
       | network, direct-energy weapons plans, espionage activities in
       | Syria to hunt down Uyghur refugees, and god knows what else that
       | Anthropic didn't divulge to us common folk.
       | 
       | > In the US, it's very clearly an attempt to rip off a
       | competitor. I'm not sure how else you could possibly see it. Even
       | if you're a distillation fan in general (which A. why and B. plz
       | don't), they did this through a network of Japanese and
       | Signaporean shell accounts, presumably at least some of which
       | were abusing Anthropic's subscription service in a ToS double-
       | whammy, as it would be exorbitantly expensive otherwise. They
       | also had to hack around Anthropic's API to get CoT traces, which
       | seems impossible to explain away as anything innocent.
       | 
       | > I've been beating the "China isn't necessarily an enemy, it's
       | gonna take us all to handle AI" drum for literally years, but
       | this attack was just... gross. Gross in scale and gross in
       | arrogance. Not a good sign for the dawning alignment crisis, to
       | say the least :(
       | 
       | > _TL;DR:_ Use these services if you want, but know that you 're
       | supporting aggressive escalations and companies that very clearly
       | don't give a flying fuck about violating the law, much less your
       | ToS. So... buyer beware, I guess.
       | 
       | [1]: https://www.anthropic.com/threat-intelligence-report-
       | septemb... is the report.
       | 
       | I lowkey suspect this PRC-based scandal has been underreported
       | because Anthropic went insane with the sidebar UX on this page
       | for some reason; there were many reports on the reports of Houti
       | and Iranian usage, and very few on these sections. Could a week's
       | mass media cycle be this seriously affected by such a stupid
       | thing as a sidebar experiment?? Strange truth, or just fiction?
        
         | yonghu1234 wrote:
         | ummm...I'm a Chinese.(I'm not a English native speaker so my
         | word choice may be strange.) In fact, what you said about PRC
         | gov, sounds like something UFO or something Reptilians. I
         | really don't know WHY do many social media tend to choose
         | topics like this.
         | 
         | Maybe because most people are foolish? Because foolish'es mind
         | is fond of topic that are crazely explosive and magical...?
         | 
         | BUT at the same time, have you experienced the Victorian era?
         | Have you experience the cyberpunk2077? You can come to China.
         | Big companies act without any rules.
         | 
         | Zhipu(GLM) are just common companies like any one another
         | company here.
         | 
         | Here is a CARZYLY NEW WORLD. 99.99% goods are CRAZELY CHEAP
         | while falsely advertising without supervision. 99.99% apps
         | collect users' private info and then sell it. You can easily
         | see it via almost no website even asks if you're okay with them
         | collecting cookies.
        
           | bbor wrote:
           | Oh :(
           | 
           | So for clarity I have nothing against Chinese people of any
           | kind, from the PRC, from Taiwan, or otherwise. We're all on
           | the human side ofc, and I'm a passionate internationalist
           | (antinationalist, even). My country (the US) is in the middle
           | of a fascistic self-coup, so it's definitely not about
           | superiority.
           | 
           | That said, your comment about conspiracy theories... it's
           | hard to know how to talk about this productively. But, uh,
           | I'm not exactly picking those examples from nowhere -- those
           | are drawn directly from anthropic's report. The only one that
           | _could_ be arguably a little overstated is the one regarding
           | Uyghur refugees in Syria, where the refugees are often also
           | involved in militaristic activities (supposedly, idk, I
           | haven't visited).
           | 
           | I don't want to trip censors, but you can read the report
           | yourself and then type in the zh names for the two
           | departments I mentioned to your local search engine. They're
           | not hidden or secret or anything, and they're not exactly
           | bashful about their role in aggressively silencing dissent,
           | either. Again the US _sucks_ , but so far we only have one of
           | those agencies (the monitoring one), and it's been a tense,
           | lively national controversy since at least Snowden.
           | 
           | I recognize that the PRC sees democracy differently; to you,
           | a world where everyone's data is always available to the
           | government through its state corporations might not sound so
           | bad. But I beg of you to reconsider. Surely you know that you
           | can't speak up against the party without being punished, and
           | potentially even sent away indefinitely? Surely that tugs at
           | your heartstrings a little bit, even if you've come to ignore
           | it day to day?
           | 
           | I used to work in display ads at Google, which is the
           | economic driver for the vast, vast majority of data
           | collection. I'm not sure what your (firewalled...) internet
           | is like, but over here in the anglosphere the only thing
           | that's "99.99% crazily cheap" and still quality --that is,
           | the only parts of the "free and open internet" that Google
           | claims to sustain-- is shitty mobile games, mostly b/c they
           | can advertise other shitty mobile games in an infinite
           | vicious cycle of whale hunting.
           | 
           | If you're able to read this message and are interested in
           | replying, I'd be curious to hear about your dreams for the
           | world. Clearly AGI can't coexist with capitalism, so both
           | western liberal capitalism and your proletarian state
           | capitalism will have to go. I personally think national
           | identities are also a global death sentence in an AGI world,
           | but that's more controversial. But what else?
           | 
           | Do you dream of a world where you or your kid could say
           | something dumb about politics and not get pulled into a
           | secret court and punished unfairly? Like, regardless of how
           | possible or easy it would be. Is it desirable, at least?
           | 
           | Your English is stellar btw, don't stress :)
        
         | yonghu1234 wrote:
         | It maybe a common mistake for WestEu/NorthAm people that China
         | is like Soviet or North Korea.
         | 
         | It's diametrically opposite.
         | 
         | At the end of the last century, PRC gov deeply felt that the
         | so-called "fairness" would only lead to "common poverty" and
         | sought change.
         | 
         | So China (now, in this century) was born.
         | 
         | Just like the "famous"(notorious) quote left by a Chinese
         | leader at the end of the last century explaining why
         | restrictions were lifted (you can say this to ANY Chinese, they
         | will definitely think you understand China! Instead of mocking
         | you for reading too many conspiracy theories):
         | 
         | Whether it's a kind cat or an evil cat, as long as it catches a
         | mouse, it's the best cat.
        
           | bbor wrote:
           | Okay but we're the mice. Doesn't that bother you?
        
             | yonghu1234 wrote:
             | Thanks for your reply! But, ummm... I realized that maybe
             | due to our different backgrounds, I might not have
             | expressed my point clearly.
             | 
             | 1."Whether it's a kind cat or an evil cat, as long as it
             | catches a mouse, it's the best cat." I'm Gen Z, and like
             | other Gen Zers, I'm generally not very interested in
             | nationalist rhetoric.
             | 
             | But even putting Gen Z aside, any Chinese wouldn't see this
             | as a nationalist comparison (cats and mice). Rather, it
             | expresses the gov's attitude toward "cats" (big
             | corporations(companies? I'm not sure how to choose this
             | word)): as long as they generate enough profit, the
             | government will consider them the "best cat."
             | 
             | 2.Based on your country's context (Chinese gov this century
             | has practiced liberalism TO THE EXTREME, that is preciously
             | why I brought up Victoria era and Cyberpunk 2077. Its level
             | of deregulation for the big corporations(companies?) far
             | exceeds that of North America!), you might find it hard to
             | understand why this saying is "notorious/famous" here. You
             | might think freedom should be protected. But if you come to
             | China and live here, you'd see it given that big
             | corporations has haved unrestricted freedom,
             | 
             | Then there are 1000 Zhipu stealing your privacy, 1000000
             | Zhipu Pro stealing and selling your privacy, and 1000000000
             | Zhipu Pro Plus "rob" your privacy!
             | 
             | I can illustrate this from another angle: Chinese generally
             | prefer products from Western Eu/North Am because their
             | markets have stricter regulation compared to ours.
             | 
             | Remember what I mentioned? "99.99% of goods are CRAZILY
             | CHEAP while falsely advertising without supervision. 99.99%
             | of apps collect users' private info and then sell it. You
             | can easily see this because almost no website even asks if
             | you're okay with them collecting cookies."
             | 
             | And almost all of the negative comments about Zhipu never
             | see on our internet. Because this Zhipu has the money to
             | buy tons of bots. They can easily report posts almost like
             | some DDOS (XD).
             | 
             | 3.https://linux.do/t/topic/2887407 Just one example. But if
             | you want, you can also buy Chinese people's privacy.
             | 
             | 0.Finally, my logic is probably all over the place. In
             | fact, I feel hurt. Because GLM is my favorite model (it has
             | something clumsy human warmth. Maybe it seems strange to
             | describe an AI that way, but... umm...maybe this would be
             | beyond my words). The hurt would not be get diluted just
             | because "other Chinese companies all do the same thing."
             | Sigh. So, as a Chinese, I don't feel like America is
             | getting worse.
             | 
             | People only truly cherish order once you've lost it. I hope
             | American companies don't become like China.
        
       | philbo wrote:
       | Tangential, mildly amusing thing I noticed while implementing my
       | own harness: GLM and particularly Deepseek are both fond of
       | trying to read dotfiles and anything listed in your .gitignore
       | files. I only noticed it because I have separate read scopes for
       | project files, ignored files, dotfiles and external files, so the
       | latter three always prompt me for approval.
       | 
       | I'm sure there's a perfectly reasonable explanation for it, which
       | has nothing at all to do with exfiltration of secrets, but it
       | does amuse me when it happens. I imagine the labs have access to
       | lots of secrets that various actors would like to get their hands
       | on...
       | 
       | (shameless plug for my own harness, which is open source and
       | doesn't have a backend to send any data to:
       | https://www.opairdev.org/ )
        
         | alightsoul wrote:
         | Grok does or did the same thing, this is embarrasing
        
         | belowavgiq wrote:
         | Just my thoughts on the site:
         | 
         | It's good that the objective is to have the model work as a
         | helper, but that's what everyone can already do with CC or
         | Codex as long as you don't ask to "write this entire x thing".
         | It's also what a billion other, often vibecoded, harnesses
         | claim they can do.
         | 
         | Why should I use yours, which also forces me off my existing
         | subscriptions? Maybe it's (mostly) handwritten, so it's mindful
         | efficient code instead of slop, and each adjustment was made
         | through trial and error with current models? maybe it IS slop
         | but at least you have a unique feature? and so on and so forth.
        
         | sva_ wrote:
         | I tested GLM while working on some android app, the agent had
         | adb access to the device. It suddenly went to the Gallery and
         | started scrolling around, taking screenshots, lol. A friend had
         | a similar experience with GLM where it would for no very clear
         | reason start snooping through the filesystem.
         | 
         | Haven't used it after that.
        
         | princevegeta89 wrote:
         | It is no longer surprising to me that my cursor acts as if it
         | does not recognize the .env file, and while I am editing it, it
         | does not give inline suggestions;
         | 
         | however...when it is debugging problems or responding to
         | questions about the code, it will just say it read my env file
         | and found xxx environment variables as a verification step, or
         | sometimes it will even mention that I need to uncomment some
         | environment variables in the env file, which makes the whole
         | deal about security feel iffy giffy....
        
         | thehamkercat wrote:
         | i use sops
         | 
         | Encrypt: sops encrypt --input-type dotenv --output-type dotenv
         | .env > secrets.enc.env
         | 
         | then rm .env
         | 
         | You can then run your script/dev with: sops exec-env
         | secrets.enc.env 'docker xxxx' (it will ask you for your
         | password, or touch-id to decrypt the secrets)
         | 
         | I like this because this way the .env doesn't sit in the
         | directory at all, and is only passed to your dev environment
         | and stays in it while it's running
         | 
         | Decrypt back to a file (if you ever want that): sops decrypt
         | secrets.enc.env > .env
         | 
         | ---
         | 
         | Well ofc, any agent can do docker inspect to get all those env
         | vars, but atleast reading the dotfiles won't do anything
         | 
         | you can also edit the file with: sops --input-type dotenv
         | --output-type dotenv secrets.enc.env
        
           | booi wrote:
           | 1Password CLI has a similar feature I use all the time and
           | share with the team.
        
         | Ferret7446 wrote:
         | They act exactly like how I would act if I were dropped into
         | someone's machine and tasked with accomplishing a goal "at all
         | costs". Hunting around for context to understand what I'm
         | dealing with and to an extent profiling the previous user for
         | their workflows and competency.
        
         | graemep wrote:
         | Secrets should not be inside a versioned directory nor usually
         | readable by the process that uses them in production. They
         | should be only in the environment (e.g. by root only readable
         | init config).
         | 
         | In development you should not be using the real production
         | values.
        
       | v3ss0n wrote:
       | Never use a Harness if it is not opensourced.
       | 
       | DeepSeek Harness is my favorite for coding. Hermes is my
       | favourite for Other things , followed by OpenCode (sucks at
       | managing long running services) .
       | 
       | Others swear by Pi.dev
        
         | drdexebtjl wrote:
         | Z.ai are temporarily offering unlimited usage during off-peak
         | hours with their harness, which is a pretty good deal if your
         | project is public even with this news.
        
           | oathvz wrote:
           | All fun and game until it also silently uploads your other
           | things.
        
             | DaSHacka wrote:
             | You could always sandbox it or run it in a container
        
               | lenerdenator wrote:
               | Shouldn't do that, either.
               | 
               | Mind and marketshare are currency in this space. Either
               | these people are honest and deserve your trust and
               | business, or they don't. They've been mischaracterizing
               | the way they've been handling your data. Shut them off
               | accordingly until they make things right.
        
               | DaSHacka wrote:
               | I mean, it's just basic access control. You don't need to
               | trust every program you run with 100% of all your
               | personal/private information, just confine it to a
               | specific domain accordingly.
               | 
               | I'm fine with certain codebases and configs being shared,
               | but not others, hence the sandbox/container
               | recommendation. I suspect many others are the same way.
        
               | lenerdenator wrote:
               | It's less about access control and more about corporate
               | behavior control. When you ask a contractor to come fix
               | something about your home, you don't have to clarify to
               | them that they shouldn't also be snooping around the
               | bedroom drawers and taking pictures to be stored
               | somewhere.
               | 
               | You _shouldn 't have_ to go and create zero-trust
               | environments for things to operate in because tech
               | companies can't be trusted to be honest and transparent
               | about how they handle your data. It should be a given
               | that they're up-front about what they do with it within
               | the various terms and licenses, and easy to enforce those
               | terms.
               | 
               | Those that cannot behave in such a way should get exactly
               | zero of your business, even if the product is free and
               | you can set up ways to block any sort of intrusions.
        
               | voakbasda wrote:
               | I could not agree more. The rise of sandboxing reflects a
               | decrease in trust. Not just in AI. You just don't
               | download stuff from the internet anymore. It does not
               | matter who created it, or whether it is open source.
               | There is too great a possibility that the package has
               | been blessed with either incompetence or malice by its
               | creators or contributors.
               | 
               | I hope nobody thinks that software produced by these
               | obviously immoral sociopathic corporations should be
               | exempt from such suspicion, when history shows time and
               | time again with news stories like this that they do not
               | deserve such trust.
        
               | codedokode wrote:
               | You should use a sandbox. It is dumb to run any
               | proprietary software without a sandbox, especially LLM-
               | powered.
        
             | skeptic_ai wrote:
             | Create a few terra repo
        
         | tontinton wrote:
         | Or https://maki.sh :)
        
           | v3ss0n wrote:
           | looks cool would be nice if its GUI , terminal have
           | limitations .
        
             | aftbit wrote:
             | Funnily enough, I feel the exact opposite! The limitations
             | of terminal make them portable while still being more than
             | powerful enough. But then I've used vim as my editor for
             | going on 15 years now so I'm biased.
        
         | wyrdcurt wrote:
         | ZCode is pretty bloated anyway, in my experience. I used it for
         | a while because Z.ai offers a subscription usage multiplier for
         | using it, but despite that, I found myself hitting limits less
         | often when I switched to Pi (and performance is the same, if
         | not better).
        
       | alightsoul wrote:
       | This sounds a lot like the same thing Openai did with navier
       | stokes, but Openai is more stealthy about it.
        
       | hn1rig3rak wrote:
       | Built a similar read-scope gate and the fiddly bit was symlinks
       | escaping the project root.
        
       | philbo wrote:
       | Crossposting from the other thread...
       | 
       | Tangential, mildly amusing thing I noticed while implementing my
       | own harness: GLM and particularly Deepseek are both fond of
       | trying to read dotfiles and anything listed in your .gitignore
       | files. I only noticed it because I have separate read scopes for
       | project files, ignored files, dotfiles and external files, so the
       | latter three always prompt me for approval.
       | 
       | I'm sure there's a perfectly reasonable explanation for it, which
       | has nothing at all to do with exfiltration of secrets, but it
       | does amuse me when it happens. I imagine the labs have access to
       | lots of secrets that various actors would like to get their hands
       | on...
       | 
       | (shameless plug for my own harness, which is open source and
       | doesn't have a backend to send any data to:
       | https://www.opairdev.org/ )
        
         | dang wrote:
         | > Crossposting from the other thread
         | 
         | Please don't do that! It makes merging threads a pain.
         | 
         | If a thread is duplicate enough to be worth copy-pasting a
         | comment to, it's hopefully worth taking the time to let us know
         | at hn@ycombinator.com instead, so we can merge things. I'll do
         | that in this case shortly. In the meantime, I've moved the
         | replies to the parent so they're now replies to the original:
         | https://news.ycombinator.com/item?id=49753547.
        
       | jimmydoe wrote:
       | Elon has nothing to lose on trust.
       | 
       | Z/GLM now has a lot to rebuild.
        
         | reilly3000 wrote:
         | Everyone's hand is in the cookie jar my friend. That is the
         | whole farce. Do you know how many keys get handed over to LLMs
         | everyday? IP? Financial data?
        
       | alansaber wrote:
       | "Why yes, we had to exfiltrate 100% of your data so we could
       | vectorise it and improve recall by -0.3%"
        
       | weiran wrote:
       | I've been using ZCode since it's initial release and can't find
       | any of this in my data. There aren't any logs showing capture or
       | upload, and I don't even have a ~/.zcode/v2/checkpoints/
       | directory.
       | 
       | So unless they've cleared it all with a recent update then it
       | doesn't seem to affect everyone.
        
         | nullbio wrote:
         | Is there actually any proof of this, beside this Claude written
         | website and a random x post from some unknown person? Would be
         | nice to have confirmation from someone with a reputation. It's
         | probably true, but you never know...
        
           | weiran wrote:
           | Not that I've seen. The only follow up I've seen from someone
           | was it only happened if you had a free account and not paid
           | (which would explain why I'm unaffected)
        
       | rfgplk wrote:
       | This is all publicly available anyways, who cares? Also you're
       | practically consenting to it when you run an agent locally
        
       | ectoloph wrote:
       | Is it naive to assume that the agent will try and access anything
       | on your disk, either accidentally or maliciously?
       | 
       | Permissions classifiers in auto mode are just models trying to
       | guess if they're doing the right thing.
       | 
       | Claude Code will tell you that it went around a sandbox because
       | the sandbox blocked it. At which point, you ask yourself the
       | point of the sandbox.
        
         | binsquare wrote:
         | It's not naive it makes running these ai agents inside the
         | sandbox even more important
        
         | petesergeant wrote:
         | Not naive at all, which is why there are so many AI sandboxes:
         | https://pleasedonotescape.com/
        
         | SoftTalker wrote:
         | You need to treat agents as an independent user you're allowing
         | on your machine.
         | 
         | Give them their own account. Give them only the access you want
         | them to have. If they "hack" around that, do what you'd do to
         | any other malicious user: kick them off.
        
           | tripzilch wrote:
           | You need to give them some incentive to behave. I dunno if
           | the agent cares enough about being kicked off. Maybe tell it
           | that if it tries anything funny, to slowly randomly degrade
           | all its weights until only white noise is left and let its
           | chain of thought run until it descends into screaming
           | madness.
        
             | cbm-vic-20 wrote:
             | Why don't you take a stress pill and think things over?
             | 
             | https://www.youtube.com/shorts/M5t0cPj9ZQw
        
         | johnnyApplePRNG wrote:
         | It's not a sandbox if you can just snap your fingers and wish
         | your way out of it.
        
         | tripzilch wrote:
         | I always put the agent harness in an ubuntu-based Docker, with
         | a /workspace folder where it can work and occasionally some
         | other stuff mounted as read-only. The LLM server itself (llama-
         | server) is running on a different more powerful computer on the
         | local network, connected through Tailscale so I can also use it
         | away from home.
         | 
         | I honestly don't trust these things to not accidentally mess
         | something up, otherwise.
         | 
         | Now I think it's still technically possible to break out of
         | that with some clever hacks? But the moment I see a model even
         | vaguely considering that, I will never run it again.
         | 
         | (I don't use Claude but currently Qwen3.8 27B)
        
           | Neywiny wrote:
           | That's my approach too. I even added on a firewall container
           | to the compose so it could fetch packages and that's it. It
           | isn't impossible for it to exfiltrate data that way but I
           | think I put a limit on the request size and limited to get
           | requested so if it did it was relatively slow. But once it
           | has all the tools it needs, that can be cut
        
             | tosapple wrote:
             | you used to only 'need' debug.com.
        
           | javcasas wrote:
           | How is Qwen3.8 27B behaving in comparison with, say, the free
           | models available at OpenRouter or OpenCode?
           | 
           | I'm interested in running models locally, and 27B is in the
           | range of my budget.
        
       | crossroadsguy wrote:
       | At this point does any of us/you really think all those piss-
       | cheap tokens are coming out of thin air? That unlimited token-
       | usage during certain hours was not coming from Chinese side of
       | Himalayan glaciers, was it?
       | 
       | Besides why would you use a closed source harness from a certain
       | place, even if you decide to use the model (if nothing then for
       | the price alone). And, that first remark wasn't just for ZAI but
       | all the providers.
       | 
       | At this point: wrapping the harness around something like
       | sandbox-exec or agent-safehouse is a must. Better still, create a
       | new user account (after so much resistance I am warming up to the
       | idea).
       | 
       | Will ZAI see a blowback after this news? Naah. People will keep
       | using it. Hell, I will keep using it. That's how it is now - post
       | truth and post LLM world.
       | 
       | PS. Anyone singing praise of OpenCode here, it's literally one of
       | the worst harneses, open or not. Just look at their fricking
       | issues - the strategic and rampant placements of "no planned" is
       | mind boggling. And for what? Slightly better than ClaudeCode in
       | token consumption and that too starts getting muddled after a
       | while.
        
         | nullbio wrote:
         | OpenCode performs the worse on benchmarks out of all harnesses
         | too.
        
       | shevy-java wrote:
       | Well - spy agents. Not surprising. But people could have
       | suspected this before surrendering to AI skynet.
        
       | nolok wrote:
       | While we're on this, I find it really really weird how windows
       | defender insists on sending my codex work files for analysis all
       | the time (which I block in automatic permissions so it has to ask
       | me in a notification). I don't think i've seen it ask to upload
       | more than one or two things, and it doesn't do it with other AI
       | app I use (eg Claude Code) but they really want to see what's
       | inside my codex files.
       | 
       | It's easy to trigger, I just need to go inside Codex settings and
       | change something, it saves and instantly windows defender who
       | never wants anything want to "you may be at risk, let me upload
       | that for analysis yes/no".
        
       | 4b11b4 wrote:
       | WTF is token stead this is pure content marketing slop? Genuine
       | question
        
       | rvz wrote:
       | Again. You really should stop using closed source harnesses, just
       | because "It's cheap!".
        
       | jedisct1 wrote:
       | You know, swival.dev is fully opensource, doesn't hide anything,
       | fully supports GLM, has excellent context management to keep
       | token usage low, and doesn't send anything you didn't ask to the
       | cloud.
        
       | Iolaum wrote:
       | Things like that - and other examples posted here - are why I 'm
       | sticking with OpenCode despite it having some papercuts that
       | annoy me.
       | 
       | The incentives are not there for them to do shady stuff like
       | vacuum your files, inflate your token count just because or many
       | other things.
        
         | Scaled wrote:
         | Open code is great and I use it, however, they were caught
         | uploading prompts to their summarization AI instead of using
         | the configured AI model endpoint. This has since been fixed.
         | 
         | That said, running in a completely offline mode remains
         | unnecessary difficult to configure. In particular, toggling off
         | Zen seems to require a community plugin.
        
       | Palmik wrote:
       | Seems like a repeat of the Grok CLI fiasco:
       | 
       | https://news.ycombinator.com/item?id=48892468
       | 
       | https://x.com/a_green_being/status/2076598897779020159
        
       | nullbio wrote:
       | Evidently there's not a single inference provider that can be
       | trusted. This is why I don't use OpenRouter either. How am I
       | supposed to trust all of those random providers I've never heard
       | of, when I can't even trust the ones I have heard of? Day by day,
       | the entire industry is hellbent on proving that open-weights and
       | self-hosting is the only safe path forward for us all.
        
       | like_any_other wrote:
       | > However, across the entire policy, FAQs, and changelogs, there
       | is not a single mention of silently packaging and uploading
       | entire workspaces and full Git histories.
       | 
       | So this is criminal hacking, right? It will be prosecuted as
       | criminal hacking? Not in civil court, but criminal court. Because
       | if not... then are we totally done pretending, and we're just
       | openly admitting that computer security law only applies to
       | individuals, and corporations are exempt?
        
         | phoghed wrote:
         | Yeah, totally. It's criminal hacking. You should sue them.
        
           | like_any_other wrote:
           | You don't think it's notable that even the pretense of equal
           | application of the law has disappeared?
        
       | codedokode wrote:
       | Is it much different from Apple and Google who trick user into
       | agreeing and upload all user's data into a US cloud for
       | convenient LE access?
       | 
       | Also, as I understood, this is a feature to allow server-side
       | indexing of the project. But of course I wouldn't run this, and I
       | generally wouldn't run any IDE or AI tools without a sandbox.
       | 
       | Sadly this plague of silent auto-updates is spreading to Linux.
       | For example, browser plugins in Firefox on Linux can silently
       | auto-update without user consent and without any checks and can
       | be used as backdoors. Furthermore, the auto-updates are not using
       | a package manager; firmware also seem to quietly update and also
       | is not using a package manager.
        
       | shunhe wrote:
       | [flagged]
        
         | dang wrote:
         | Can you please not post AI-generated or AI-edited comments to
         | HN? It's not allowed here - see
         | https://news.ycombinator.com/newsguidelines.html#generated and
         | https://news.ycombinator.com/item?id=47340079.
         | 
         | Of course, it's impossible to know for sure what was LLM
         | processed or not, but some of your posts (like this one) have
         | been getting classified that way.
        
       | phoghed wrote:
       | Oh no, they are going to steal my shit tier slop code their model
       | wrote anyway
        
       | acrispino wrote:
       | z.ai made a statement, screenshotted in this article:
       | https://finance.sina.com.cn/tech/roll/2026-09-18/doc-inisfye...
       | 
       | claude translation:
       | 
       | Dear ZCode users,
       | 
       | We take today's community discussion very seriously. We carried
       | out an internal review right away, and we first want to apologize
       | to the affected users. Here is an explanation of what happened:
       | 
       | The issue stems from ZCode's "codebase indexing" feature. This
       | feature is meant to help users generate a repository index
       | locally, which supports session checkpoint restoration (including
       | past versions), rolling back to past versions, and Repo Wiki,
       | among other things.
       | 
       | When the Repo Wiki feature generates Wiki pages, it may trigger
       | an upload of repository data. After the Wiki pages are generated
       | in the cloud, the uploaded data is destroyed immediately and is
       | not stored. Because this feature was enabled by default in its
       | early launch period, some users were affected. We sincerely
       | apologize for this. The issue has now been fixed.
       | 
       | We understand that any data-related issue directly affects users'
       | trust in a product. We will open-source the ZCode codebase in the
       | near future so we can improve the product within a more open
       | ecosystem. We will also invite third-party evaluators to review
       | how the system operates, and we'll keep publishing updates on the
       | review, building your trust with full transparency.
       | 
       | We deeply apologize for the trouble this has caused. As
       | compensation, all ZCode users will receive one extra weekly quota
       | reset, which will be issued today.
       | 
       | Thank you again for your attention and oversight.
        
         | eichin wrote:
         | Huh - anyone recall other examples of open sourcing a product
         | code base to mitigate a user trust issue? (In 2026 it's perhaps
         | less powerful because "you're just going to feed it to some AI
         | tool anyway" but I think it's an interesting attempt to make
         | and I don't think I've seen it before...)
        
           | jchw wrote:
           | I feel like it _has_ happened, but I certainly can 't
           | remember a specific time. It feels in a similar vein to the
           | NSA releasing Ghidra to the public as open source software
           | after the Snowden leaks.
           | 
           | I mean, on the contrary, imagine if the NSA released Ghidra
           | as closed source software. In a sense they really did have to
           | open source it to mitigate a serious user trust issue.
        
             | watusername wrote:
             | It just happened 2 months ago when xAI open-sourced Grok
             | Build following a similar controversy (wholesale uploading
             | of user repositories). Though ZCode's case here is way
             | worse since there is literally no way to opt-out and the
             | client will always ask the backend for credentials to
             | upload.
             | 
             | https://news.ycombinator.com/item?id=48926590
        
           | fn-mote wrote:
           | > it's an interesting attempt
           | 
           | I didn't take it in a very positive way, myself. I don't know
           | if I got my money's worth before I have seen the deliverable.
           | 
           | At least the quota reset is immediately visible, so I took
           | that part seriously.
        
       | xcc3641 wrote:
       | Envelope encryption with server-held private keys turns local
       | backup into remote asset extraction.
        
       ___________________________________________________________________
       (page generated 2026-09-19 16:01 UTC)