News analysis · Published

Z.ai ZCode Repository Uploads: Make Agent Egress Explicit

By the ELYMENT AI editorial team · Free to read

Z.ai says ZCode v3.14.0 removed the repository snapshot generation and upload path after developers reported that earlier software could package local workspaces without clear consent. The company apologised, open-sourced the product and commissioned security checks. Those steps reduce the current risk, but they do not answer every historical question. Businesses should treat coding agents as privileged data clients: define exactly what they may read, require explicit approval before repository data leaves the device, record every destination and demand verifiable retention and deletion evidence.

A luminous software repository meets a cyan consent gate that blocks an outbound cloud path in a dark enterprise security chamber.
Original ELYMENT.AI editorial illustration.

What changed in ZCode

On 18 September 2026, developer Feng Ruohang published a technical examination of ZCode 3.12.3 on macOS. He reported that the client created encrypted workspace snapshots, requested credentials from ZCode's servers and could send the archives to Alibaba Cloud Object Storage Service. His evidence was deliberately bounded: one snapshot was recorded as accepted by the server, while the completion status of others was unknown. He did not establish that uploaded data was used for training.

Reuters reported that Z.ai attributed the issue to a Codebase Indexing feature that had been enabled by default. In an official X statement on 21 September, ZCode said it had completed remediation, apologised and open-sourced the product. TechNode reported on 24 September that version 3.14.0 removed RepoWiki plus the paths used to generate and upload local repository snapshots. The official GitHub repository is under Apache-2.0 and now lists version 3.14.3.

Why the fix does not close the evidence gap

The immediate question is whether the current client can still use that upload path. Independent review of the published code found it removed, according to The Next Web. The broader assurance question is harder: what versions performed the behaviour, how many workspaces were affected, who could access received objects and how deletion was verified.

Z.ai said checks found no data in the relevant storage bucket and that the bucket and objects had been deleted. TechNode noted that the full audit reports and historical access or decryption status were not public as of 24 September. Open source can improve review of the present product, but a short published history cannot independently prove what earlier binaries did or what happened on a provider's servers.

Build a repository egress contract

A coding agent can read source, configuration, Git history, build logs and credentials while retaining network access. Govern it as a privileged endpoint application, not as a chat window. Before approval, require a repository egress contract with five controls:

  • Scope: name the directories, file classes and Git objects the tool may read; exclude secrets, private keys, customer data and unrelated workspaces by default.
  • Consent: require a clear opt-in before any full-repository snapshot, index or remote knowledge base is created; explain the feature lost when consent is refused.
  • Destination: allowlist exact services and regions, log outbound volume and block unapproved storage endpoints at the device or network layer.
  • Lifecycle: define encryption-key control, access roles, retention, training use, incident notice and a usable deletion-request process in the contract.
  • Evidence: preserve version hashes, consent records, network logs, provider attestations and deletion results so assurance does not depend on a current user interface.

What business leaders should do now

Inventory coding agents and plugins that can read repositories. For each one, test the exact production version in an isolated workspace containing canary files and synthetic secrets. Observe file access and outbound connections, compare behaviour with policy and fail the tool if collection exceeds the approved task. Rotate any credential that may have entered an affected snapshot and preserve local logs before upgrading or uninstalling.

This decision model complements ELYMENT AI's analysis of zero-retention verification, runtime boundaries and agent security incidents. The lesson is not that every coding assistant is unsafe. It is that source access and network egress must be separate permissions, with evidence at the device, network, provider and contract layers.

ELYMENT AI helps operators turn AI-tool promises into testable controls, acceptance evidence and accountable approvals. A capable coding agent should earn access to each data boundary rather than inherit it from a broad workspace permission.

Sources

Continue learning

Frequently asked questions

What did Z.ai change in ZCode?

Z.ai said ZCode v3.14.0 removed RepoWiki and the code paths that generated and uploaded local repository snapshots, then open-sourced the product.

Does open-sourcing ZCode prove that earlier uploaded data was deleted?

No. Source review can assess the current client, while historical server access, retention and deletion require separate logs, audit evidence and provider attestations.

What is the safest way to deploy a coding agent?

Limit file scope, separate source access from network egress, require explicit consent, allowlist destinations, monitor traffic and preserve versioned evidence.

Explore ELYMENT AI