ES version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
60% Positive
Analyzed from 936 words in the discussion.
Trending Topics
#opencode#harness#open#git#project#source#data#zcode#reputation#cloud

Discussion (34 Comments)Read Original on HackerNews
I'm sure there's a perfectly reasonable explanation for it, which has nothing at all to do with exfiltration of secrets, but it does amuse me when it happens. I imagine the labs have access to lots of secrets that various actors would like to get their hands on...
(shameless plug for my own harness, which is open source and doesn't have a backend to send any data to: https://www.opairdev.org/ )
So unless they've cleared it all with a recent update then it doesn't seem to affect everyone.
Claude Fable uploads my git history (git log) every day to the Anthropic servers!
Maybe Yegge does.
DeepSeek Harness is my favorite for coding. Hermes is my favourite for Other things , followed by OpenCode (sucks at managing long running services) .
Others swear by Pi.dev
They had their own unbound "harness scans the whole user directory" oopsie and handled concerns about that by introducing code signing.
Which, yes, does have absolutely nothing to do with that issue.
I guess by now it is better, but to me they seem to lack the engineering culture necessary for a "good reputation" stamp.
__
Ref: https://github.com/anomalyco/opencode/issues/14925#issuecomm...
among other issues.
And the original comment I've replied to proves this strategy right! So from a business standpoint: excellent work.
I wonder how many opencode users upload their private secrets to the cloud, while thinking they're using a self hosted model.
Btw. I don't think this is malicious, just sloppy.
The same can be said about opencode though.
That crosses into outright malware.
Makes me not want to use GLM or other Z.ai models either, since who knows what interesting easter eggs are embedded in their training data.
You know... (puts on foil hat)... I did notice that Z is also the weird Russian logo for their invasion of Ukraine and Russia and China have cooperated to some degree (or at least China is helping Russia in exchange for access to resources). I dismissed this when I first thought of it, but I will now leave it here. Still probably coincidence but my Bayesian priors were just updated in its direction very slightly.
I didn't fully understand the article, but I gathered this only impacts project directories managed by Z.ai's coding agent? I.e., projects you're already choosing to upload to them (partially), which thus cannot be private.
I'm not excusing this malware; just trying to find clarity about its scope.
next I can’t wait to see news about “ai company is using my data without my consent” as well.