Z.ai open-sources ZCode coding agent, sets bug bounty after security concerns
Zai_org · x · 2026-09-21
Responding to community-reported security issues, Z.ai has fixed ZCode, apologized, and open-sourced the coding agent harness on GitHub (1.2k stars) for community scrutiny.
Key points:
- A standing vulnerability reporting and response process with severity-based rewards
- The company confirms the questioned code data was never retained or used for model training
- Post-remediation reviews included China's CAICT
ZCode ships as a powerful, extensible coding agent harness with a CLI, remote harness, and agent skills.
Related event: Z.ai Open-Sources ZCode After Security Backlash, Launches Bug Bounty(3 posts)→
More from coding & agent
- KDE Drafts AI Policy: Use LLMs, But Don't Tell Anyone — carsonfarmer · 2026-09-21
- 9 practical Jev API recipes: browser agent flies through Google Flights in 7 seconds — alexcovo_eth · 2026-09-21
- GitHub's 17.4k-Star stop-slop Teaches LLMs to Strip AI Writing Tells — tom_doerr · 2026-09-21
- Solo attorney running agent fleet: evidence gates to stop coding-agent regression loops — Specialist_Call_1257 · 2026-09-21
- Code review classification saves 122k tokens, author says even 10% savings is a free win — draginol · 2026-09-21
- Microsoft open-sources IQ Solution Accelerator unifying enterprise data, knowledge and decisions — adnan_hashmi · 2026-09-21