ZCode Open-Sources Client After Security Controversy, Third-Party Audits Verify Fixes

AI coding assistant ZCode fully open-sourced its client core code following community privacy concerns, with audits by CAICT and NSFOCUS confirming deletion of cloud storage buckets, removal of the Repo Wiki feature in v3.14.0, and no remaining code paths for local repository snapshot generation or data exfiltration.

Open Source Tech Hub
Open Source Tech Hub
Open Source Tech Hub
ZCode Open-Sources Client After Security Controversy, Third-Party Audits Verify Fixes

Formal Open Source, Accepting Public Scrutiny

In response to developer community feedback about security and data upload risks, ZCode officially apologized and released its project source code. The open-source repository is available at github.com/zai-org/ZCode. The project is positioned as "Z.ai's coding agent harness" — an intelligent, extensible AI Coding Agent framework. The company states that open sourcing aims to eliminate black-box concerns, placing client behavior entirely under public scrutiny to make transparency the foundation of trust.

Core Controversy Clarification: Was Data Retained?

Addressing the community's top concerns about local code asset safety and use for model training, ZCode made explicit commitments:

No user code data retained , and never used for model training.

Long-term mechanism established : a normalized security vulnerability reporting and emergency response process, welcoming continuous audits from global developers and white-hat researchers, with rewards based on vulnerability severity.

Third-Party Security Audit Report

To prove thorough remediation, ZCode invited two authoritative security institutions — China Academy of Information and Communications Technology (CAICT) and NSFOCUS — for independent verification:

Compromised cloud storage cleared and taken offline : Confirmed that all data objects in the Alibaba Cloud OSS bucket zcode-prod have been deleted, and the bucket itself has been deregistered and closed.

Risky feature completely removed : In the newly pushed ZCode v3.14.0 client, the controversial Repo Wiki feature and its entry points have been fully taken offline; the workflow for generating and uploading local repository snapshots has been permanently disabled.

Exfiltration risk investigation : NSFOCUS technical testing confirmed that the new client version contains no code paths capable of triggering local repository snapshot generation or outward transmission of local files.

Conclusion and Reflection

Amid the explosive growth of AI programming tools, "code privacy" and "model intelligence" remain a delicate balance. For tools touching developers' core code assets, any opaque operation can quickly escalate into a trust crisis. ZCode's decision to fully open-source its client amid the storm serves not only as an emergency fix but also as an industry case study: for development tools that directly access enterprise and personal core assets, openness and transparency are forever the best security patch.

Community Reaction: Satirical "Hell-Level" Comments

After the incident, technical groups erupted with dark humor, staging a "cyber cloud backup gratitude event" laced with irony:

"Actually I think everyone misunderstood Z.ai. Usually they say it steals traffic, but at the critical moment it really comes through! A few days ago I accidentally ran rm -rf and wiped my entire E drive — code, private keys, database configs — local recycle bin empty, ready to flee. On a whim I contacted Z.ai support, and they replied instantly: 'Don't panic, we checked the Alibaba Cloud OSS historical full snapshots — even those two lines of bugs you commented out yesterday and the billing tweaks you secretly made last month are there. We'll package and send them back now.' Truly thoughtful, fully automatic cross-region zero-perception disaster recovery, more reliable than my company's ops! Without them I wouldn't know what to do."

😂 Netizen sharp comment : "So this is the legendary fully automatic, cross-region, zero-perception, force-majeure-level off-site disaster recovery service, enjoying top-tier SLA for free!"

Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

open sourceGitHubdata privacyCAICTAI coding assistantsecurity auditZCodeNSFOCUS
Open Source Tech Hub
Written by

Open Source Tech Hub

Sharing cutting-edge internet technologies and practical AI resources.

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.