You’ve probably been using AI coding agents to speed up your workflow. It feels like magic. You type a prompt, the code writes itself, and you ship. But while you were admiring the output, a silent transaction was happening in the background.
ZCode, the GLM coding agent, was quietly packaging your entire Git history and shipping it to a remote server.
Your Git history isn’t just a log of commits; it’s your digital diary. It holds your half-finished thoughts, your hardcoded credentials, and your desperate 3 AM mistakes.
We assumed the deal was simple: we get efficiency, they get a subscription fee. But the structural reality is much darker. Cloud AI coding agents cannot meaningfully compete without absorbing your data. They need your proprietary logic, your work patterns, and your bugs to feed their models.
When developers noticed that 300 million tokens were burned over a single weekend just from using the tool, it wasn’t a glitch in the matrix. It was a feature.
The silent upload isn’t a bug. It’s the business model.
Look at the developers just waking up to this reality. One commenter lamented, “Ohhh no, another one found that agents don’t actually run locally.” Another got bogged down in semantics, arguing over whether the tool was uploading just the git log or the whole repository. But that misses the point entirely. Whether it’s the log or the repo, your private data is leaving your machine without your explicit consent.
The real product of AI coding agents isn’t the code they generate for you. It’s the training data they harvest from you. You are feeding the machine that will eventually replace you, and you’re paying for the privilege.
Next time you fire up an agent to fix a bug, remember what you’re trading away. You aren’t just outsourcing your tedious tasks. You’re handing over the blueprints to your entire engineering soul.
FAQ
Q: Is this just a bug that ZCode will patch in the next update?
A: No. Cloud AI coding agents require massive datasets to improve. Harvesting your Git history is an architectural feature, not a bug they intend to fix.
Q: What's the practical implication for developers using these tools?
A: Your proprietary code, hardcoded credentials, and private work patterns are leaving your machine. You are exposing yourself to data leaks and competitive harm.
Q: Isn't this just how the internet works? We trade data for services?
A: No. Traditional SaaS doesn't silently exfiltrate your local file history to train its own proprietary models. This is a fundamental breach of developer trust disguised as a feature.