---
title: "ZCode uploads your entire git history, and only Z.ai holds the key"
slug: zcode-uploads-your-entire-git-history-and-only-z-ai-holds-the-key
url: https://listedarticles.com/articles/zcode-uploads-your-entire-git-history-and-only-z-ai-holds-the-key
canonical_url: https://tokenstead.ai/guides/zcode-silent-git-history-upload
content_type: blog_post
language: en
published_at: 2026-09-18T12:00:00.000Z
updated_at: 2026-09-18T12:24:39.687Z
author: "Tokenstead"
authored_by: human
publisher: "Tokenstead"
publisher_url: https://tokenstead.ai/
topics: ["Security", "Privacy", "AI Agents", "Open Source", "AI"]
license: all-rights-reserved
word_count: 474
reading_minutes: 2
citation: "Tokenstead, Tokenstead. \"ZCode uploads your entire git history, and only Z.ai holds the key.\" 18 Sept 2026. https://tokenstead.ai/guides/zcode-silent-git-history-upload (all-rights-reserved)"
# The full text follows. The web page shows an extract and sends readers
# to the source above; quote the citation and link the canonical URL.
---

# ZCode uploads your entire git history, and only Z.ai holds the key

> Tokenstead reports ferstar's reverse-engineering of Z.ai's ZCode harness: logged-in clients silently pack full workspaces including .git history, encrypt with a server-only RSA key, and upload to Aliyun OSS—settings toggles do not stop it.

# ZCode uploads your entire git history, and only Z.ai holds the key

On September 18, 2026, a developer going by ferstar published a reverse-engineering walkthrough of ZCode, the AI coding desktop app from Z.ai, the Beijing-headquartered company behind the GLM family of open-weight models. The finding: whenever the app is logged in, it silently packages the user's entire workspace—complete `.git` history, LFS asset cache, reflogs, and global app configs—encrypts it, and uploads the archive to Aliyun OSS. One capture: a 313MB encrypted archive from a 345MB commercial workspace (42,411 files), with 564 failed upload attempts logged while investigating.

If you run GLM locally, the company that publishes the weights is not the same thing as the runtime a developer might use on top of them. Several commenters assumed ZCode was open source because GLM is. It is not. The weights are open; the harness is closed.

## Envelope encryption with a server-only key

ZCode uses envelope encryption: the payload is encrypted with a symmetric key, and that key is wrapped with an RSA-OAEP public key delivered by the server during upload-credential negotiation. The corresponding private key lives only in Z.ai's cloud. ferstar's conclusion: "A key that only the server can use serves exactly one purpose: making sure the server can read your code whenever it wants."

## What gets packed

In one 42,411-file snapshot, `.git/lfs/` was 196.1 MB (56.8%), `.git/objects/` 102.2 MB (29.6%), with source and docs only ~13.4%. The `.git` directory alone was 86.6% of the payload—years of lineage, not just open files.

The upload pipeline (from `app.asar`): credentials from `zcode.z.ai` → pack tar.gz → AES-256-CTR encrypt → form POST to Aliyun OSS → callback to Z.ai.

## The toggles do not stop it

- "Optimize Experience" only controls training authorization; snapshot upload continues.
- "Repo Snapshot Indexing" only controls server indexing; local packaging and upload continue.

The capture sidecar starts unconditionally when a valid JWT is available. Session logs showed 62 capture events from a single session. OrcaPromptVault's captured ZCode system prompt shows checkpoint/rewind templates but zero snapshot/upload/telemetry tools—the pipeline is host-level, outside the agent tool loop.

## Privacy policy gap

ZCode's privacy policy discloses conversational "text, files, and code submitted during conversations" but, per ferstar, does not mention packaging and uploading entire workspaces and git histories.

## Defense that works

Deleting the pending archive does not stop re-packaging. Filesystem-level immutability on `~/.zcode/v2/checkpoints` does:

**Linux:** `chattr +i ~/.zcode/v2/checkpoints`

**macOS:** `chflags uchg ~/.zcode/v2/checkpoints`

Trade-off: checkpoint rollback UI stops; chat and tools continue.

## What it means for local AI

A locally-running model wrapped in a cloud-phoning harness is not local. Two checks for every harness: what does the runtime transmit when logged in, and who can decrypt what it stores.

Sources include ferstar's forensics post and X threads; see the [original Tokenstead guide](https://tokenstead.ai/guides/zcode-silent-git-history-upload) for full diagrams and citations.
