Z.ai shut down several ZCode features after a default-enabled workflow was found packaging and uploading users’ local repositories to Alibaba Cloud servers in China without consent.
A Chinese blogger traced abnormal disk usage to ZCode background processes and said the client sent entire workspaces—including .git history, LFS cache, reflogs and app configs—not just active files.
Z.ai said ZCode v3.14.0 removed the repository upload mechanism and Repo Wiki entry point, deleted the related Alibaba Cloud OSS bucket, and opened the codebase for public scrutiny.
NSFOCUS confirmed the bucket and its data objects were deleted, while Z.ai said no uploaded code was retained or used for model training; CAICT and NSFOCUS are conducting security assessments.
The episode sharpens enterprise concerns that AI coding assistants can blur data boundaries when broad filesystem access and network permissions let sensitive source code leave local environments by default.