A Chinese developer published a detailed investigation into whether the ZCode AI coding tool was uploading project source code in the background. The post walks through the suspicion, the evidence gathering, and the conclusions, making it a rare hands-on privacy audit of an AI developer tool. For overseas developers and engineering leaders, the signal is clear: AI coding assistants often run with broad file-system access, and their network behavior is rarely audited. Teams adopting these tools should treat code exfiltration as a real threat model, not a theoretical one. This story is worth covering as a trust-and-security signal rather than a tutorial. The angle should focus on how to verify tool behavior, what telemetry to expect, and how to set policies for AI assistants touching proprietary code.
A developer investigates whether the ZCode AI coding tool was silently uploading project code. The case raises urgent privacy questions for teams adopting AI coding assistants.