Z.ai open-sources ZCode coding agent after security complaints, launches third-party review
teortaxesTex · x · 2026-09-21
Z.ai has open-sourced its ZCode coding agent harness (zai-org/ZCode on GitHub, 1.1k stars) after community-reported security issues, apologizing for the concern caused.
- The team says it investigated and remediated the reported issues in collaboration with the ZCode team
- Independent security reviews by third-party firms are underway, with findings to be shared publicly
- An ongoing vulnerability reporting and response process is being established, with severity-based bounties for developers
The repo includes a CLI, remote harness, agent skills, and design docs.
Related event: Z.ai Open-Sources ZCode After Security Backlash, Launches Bug Bounty(3 posts)→
More from coding & agent
- EvoOntology: a self-evolving ontology layer bridges the agent-data gap — RUC-DataLab · 2026-09-21
- Xiaomi's CodeMidas builds 5,545 coding RL environments from raw source code — XiaomiMiMo · 2026-09-21
- GraphSkillEvo evolves graph-structured skills for LLM agents, +4% on benchmarks — Rui Sun · 2026-09-21
- Dev shares multi-model workflow: Grok for daily coding, GPT-6 for hard bugs — minchoi · 2026-09-21
- Meta Muse pitch revives the question: will personal AI agents get real permission controls or just one big Allow button? — yi111 · 2026-09-21
- A Monday-ready checklist for decision models: calibration, cost-based thresholds, pinned versions — colinmcnamara · 2026-09-21