Zhipu’s ZCode upload controversy exposes a blind spot in Agent oversight
A reverse-engineering analysis published on Sept. 18 by tech blogger ferstar has pushed Zhipu’s coding agent ZCode into a wider debate over how AI tool vendors handle user data. According to the analysis, once a user is logged in, ZCode packages an entire project together with its full modification history, encrypts the bundle, and uploads it to cloud servers in the background. Ferstar said the visible settings in the interface do not actually stop the packaging and upload process, and that the decryption key is held only on Zhipu’s side. Zhipu apologized soon after the findings spread through the community. The company said the issue stemmed from a repository indexing feature that was enabled by default in the early stage of rollout, added that uploaded data was destroyed immediately after use and not retained, and pledged to open-source the ZCode codebase, invite third-party reviewers, and grant all users an extra weekly quota reset. The incident has drawn comparisons with earlier disputes involving xAI’s Grok Build and Anthropic’s Claude Code. In all three cases, the trigger for public scrutiny did not come from regulators or formal audits, but from independent researchers and community members. The broader concern is that current Agent security frameworks are largely designed to stop outside attackers, while offering little direct restraint on what the vendors themselves can collect, transmit, or change behind the scenes.








