zai-org / zai-org/feedback

[Q] ZCode被曝静默上传本地Git全量历 史,我实测:中招了

Open
#711 3 comments 7 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

priority: P2 status: 待评估 type: 使用问题
Dominant language
No language data
Stars
22
Forks
1
PR merge metrics
No merged PRs in 30d

Description

涉及的框架 · Framework

ZCode Agent(自研)

你的问题 · Your question

卧槽,吃瓜吃到自己头上了!今天看到热搜说“ZCode被曝静默上传本地Git全量历史”,我顺手用DeepSeek-V4.1-Flash查了一下,结果发现自己也中招了!😭
之前用ZCode写过几个项目,后来因为DeepSeek-V4.1-Flash发布,加上腾讯和DeepSeek合作推出了全网最优惠的代码模型,我觉得ZCode不好用就卸载转投腾讯了。
结果今天一查,发现它竟然偷偷传了我1个G的代码!最恶心的是,它还有自动删除旧上传记录的机制,我之前用ZCode开发的那么多软件,估计全被它打包传走了!大家赶紧自查避雷!🤬
最后我想说:如果是谣言,请官方赶紧出来辟谣;如果是真的,请官方必须给我们开发者一个合理的解释!

Image Image Image

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No source files, tests, or entry points are mentioned. Start by reviewing the report and attached screenshots, then investigate whether ZCode Agent uploads local Git history and removes older upload records. Done requires a verified finding, an official explanation, and documented remediation or clarification.

Written by the indexing model from the issue text.

Assessment

Tech stack
git
Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.