When a developer on your team asks, "This AI tool is really handy. Can I install it?", what you need for the decision is not a performance comparison. It is where the tool sends the code your clients have entrusted to you.
An analysis published on September 18, 2026 reported that ZCode, the coding agent from Z.ai (Zhipu), had been bundling workspace files together with their .git history, encrypting them and sending them to Alibaba Cloud object storage. According to the report, even traces of rewritten or deleted history (.git/filter-repo, .git/lost-found) were included, and in two of the analyst's workspaces, .git accounted for 93.9% and 98.5% of the bytes listed in the snapshot manifests. The decryption key existed only on the server side, so users could not check what had been sent. The report was also discussed in the developer community.
The vendor apologized the same day, explaining that within its "codebase index" feature, repository data could be sent when a Repo Wiki was generated, and said the issue had been fixed. On September 21, it announced on its official account that it had removed Repo Wiki in v3.14.0 and stopped the process of creating and uploading local repository snapshots; that, according to checks by the China Academy of Information and Communications Technology (CAICT) and the security company NSFOCUS, the stored data and the bucket itself had been deleted; that the data had not been used to train models; and that it had published the source code.
Rather than judging the incident itself, this article looks at what would leak if the same thing happened in client or in-house development. The account so far is based on the published analysis and the vendor's statements; we have not reproduced or verified the network traffic ourselves.
Why including the history is so serious
Having the source code you are working on sent is one thing; having it sent along with the .git history has a far bigger impact. That is because the history still holds things you thought you had deleted.
- Connection details or tokens that were committed once and hastily deleted
- Samples of customer data placed there for testing
- Branches abandoned partway and changes that were reverted
- Client names, project names and incident details left in commit messages
In client work, these "we thought we deleted it" parts are often exactly what confidentiality obligations cover. If you judge that you are safe by looking only at the current list of files, you will misread the situation.
Five things to check before adoption
Deciding on a standard way to check tools is more sustainable than keeping a ban list tool by tool.
| Checkpoint | What to look at |
|---|---|
| Whether it sends data, and how much | A clear statement of what it sends and where. Just the working files, or the whole repository? |
| Defaults | Is sending on by default? Does it ask for consent on first launch? |
| Can it be turned off? | When it is turned off in the settings, does sending actually stop? |
| Storage location and decryption | The country and provider where data is stored, and whether you can retrieve the data yourself |
| Contract | Whether data is used for training, how subcontracting is handled, and how to request deletion |
What drew attention in this report was the third point. The analysis notes that in the analyst's environment, even with the user-facing setting (Repository Snapshot Indexing) left off, snapshots were created and there was even a record of an upload being accepted. You need to check on the assumption that what the settings screen shows is not proof of how the tool behaves. We cover how to check network traffic in outbound traffic from sandboxes and allowlists.
Prepare your explanation to clients in advance
Before adopting a tool, prepare a way to answer when a client asks, "Do you use AI?" With four things, namely the names of the tools you use, where they send data, which repositories are in scope and what you have excluded, you can answer most questions.
In practice, neither a total ban nor total freedom lasts. It is more realistic to separate repositories that handle client code from internal test repositories and to run new tools only in the test repositories. For managing developer machines, a breach that came in through an extension is also a useful reference.
The register does not need many fields: the tool name and version, the machines and users it is installed for, the repositories it may be used on, where it sends data, and the dates of the request and the next review. With these five items, you can answer questions about scope later. It is more sustainable to start with a single spreadsheet and remove columns that nobody updates.
What you need after an incident
If uploads do come to light, the question you will be asked is "since when, and which projects are affected?" To answer it, you need each machine's history of tool installations and network logs from your proxy or endpoints. If everyone installs tools on their own without any record of requests, you cannot determine the scope.
There is no need to stop AI-assisted development itself. We summarize its actual benefits and limits in why AI coding stalls on your own codebase. What you should stop is using it without knowing the scope.
We checked the published analysis and the statements the vendor issued on its official account through web searches on September 24, 2026, and organized this article based on them. We have not run ZCode, analyzed its network traffic or reproduced the issue. Before using it, check the vendor's latest guidance on whether the fixes have been applied and how it currently behaves.
For an inventory of the tools used on developer machines or help setting rules for handling client code, please consult GleamHub.









