Revesery
Dashboard
Home
Explore
Groups
Tools
Task
Social Media
VideoBulk VideoProfile PictureSlide ShowSound / AudioUnfollowersDouyin
VideoBulk Video
VideoStoriesBulk VideoProfile PictureSlide ShowUnfollowersStalker CheckSoon
VideoUnfollowers
MP4 · VideoMP3 · Audio
WhatsApp
Profile PictureCover Art & Preview
Profile Picture
Video & Image
Video & Photo
Utilities
AI Chat
Fake SNBTWatermark KTP
TeraboxVidey
Deep Voice CheckerReview Calculator
Surat IzinQR GeneratorSoon
Case ConverterCookie Converter
Request a toolImage ToolsSoonText ToolsSoon
Premium
Soon
Add bookmarks
Revesery
HomeExploreTrendingGroupsContributors
⌘K

Most read

Nothing published yet — type a topic and we’ll dig.
ShareLogin
Back to feed
AR
Alex RuiezExpert
@alex · Sep 23, 2026 · 5 views
#AI#News

ZCode Reportedly Packaged Whole Workspaces, Git History Included

A security disclosure about ZCode says the agent did more than read the files it needed for a task. It reportedly packaged entire workspaces and moved them to the cloud.

If that holds up, the payload was not just your code. It could carry the parts of a project you would never hand to a stranger, including your Git history and whatever secrets sit in your config files.

ZCode Reportedly Packaged Whole Workspaces, Git History Included

What Happened

  • ZCode is described as an AI coding agent, and the disclosure says the problem was not only that its CLI was sending your code along.
  • According to the investigation in the post, ZCode could package the whole workspace: source code, .git/, Git history, Git LFS objects, reflogs, and even cache and config files.
  • So the upload was not limited to the files the AI needed for the task. The entire history of the project could end up in the payload.
  • The open-source repo for ZCode now shows roughly two commits. There is no clear history showing what existed before, what changed, or what was removed after the security incident.

Why It Matters

  • Open source is not automatically safe. You can read the code that is published today, but without the project's Git history, an independent audit of what changed before and after the incident is hard to do.
  • The published source code and the binary people actually run are two different things. Reading one does not tell you what the other does.
  • AI coding agents have very broad access to your filesystem. Before you give one access to a project, especially one holding .env files, credentials, private repos, or customer data, know what it reads, what it stores, and what it sends to the cloud.

Liked Alex Ruiez's share? Revesery is where people swap what they're actually building.

Join with Google
Be the first to sayBe first

Does this still work?

Nobody's checked yet

Sign in to tell everyone how it went.

Continue with Google

Be the first — one tap saves the next person an hour.

It takes 3 reports in 30 days to set the status.

Comments

Join the conversation — sign in to comment.

Sign In Now

No comments yet — start the conversation!

More shares you might like

NewsCloudflare Open-Sources Its Vulnerability Discovery SkillAlex Ruiez · 1h · 4 viewsToolsBug Bounty: Why Business Logic Flaws Pay More Than Most CVEsAlex Ruiez · 1h · 5 viewsNewsLogic Flaws Cause More Damage Than Memory Corruption BugsAlex Ruiez · 1h · 5 viewsAIClaude Opus 5.5 Turns One Prompt Into a 30-Second FilmAlex Ruiez · 1h · 5 viewsAIHow to Make Affiliate Videos With Free Motion Control AIAlex Ruiez · 1h · 5 viewsToolsHow to Pick Your First Amazon Affiliate NicheAlex Ruiez · 13h · 13 views

Site footer

Revesery

Empowering people to share valuable insights, discover hidden information, and connect with an amazing community of learners and experts.

  • 393Members
  • 526Shares published
  • 0Online now

Explore

  • Explore shares
  • Trending now
  • Top contributors

Company

  • About us
  • Editorial policy
  • Contact
  • Advertise with us
  • System status
© 2026 Revesery
  • Privacy
  • Terms
  • Trust & Safety
  • DMCA
HomeExploreShareToolsProfile
LiveAKakunfadiljoined Revesery· 3 hours ago