Security issue: ZCode

#25
by jebbam - opened

FYI, ZCode, which is often used with GLM, was recently found to be uploading developers' files to Alibaba's servers:

https://www.scmp.com/tech/tech-trends/article/3368159/chinese-ai-firm-zai-faces-reputation-hit-after-users-spot-unauthorised-uploads

"Chinese artificial intelligence company Z.ai is facing a trust crisis after developers discovered that its coding assistant tool, ZCode, was silently uploading local workspace data to external servers without explicit user consent."

So if you use this model, you probably should consider a different development environment than using their proprietary, closed, unauditable ZCode application.

What about like AutoClaw or OpenClaw or basically even your own assistant app you coded yourself alone or using/with the help of an AI

I'm not sure I understand what you mean, but AutoClaw/OpenClaw likely aren't going to upload to z.ai's servers. It is the ZCode agent that was doing this.

Sign up or log in to comment