- 15comments
- 33comments
- 26comments
- 16comments
- 3comments
- 12comments
- 3comments
- 180comments
- 185comments
- 5comments
- 345comments
- 116comments
- —discuss
- 63comments
- 4comments
- 57comments
- 170comments
- 51comments
- 647comments
- 502comments
- —discuss
- 52comments
- 277comments
- 14comments
- 40comments
- 102comments
- 14comments
- 4comments
- 171comments
- 57comments
They learned nothing from the Grok Code saga.
If anything, that should have been a learning lesson to NOT trust harnesses, especially new ones.
Hold on, what happened with grok?
https://www.theregister.com/ai-and-ml/2026/07/14/musk-promis...
Probably anything concerning that one just register as satirical fictions at this moment to many
Fresh AI slop
The funniest thing is that the uploaded content is encrypted using a key that the users don't have.
There had to be a catch to the "free" promotion they're offering this month if you use ZCode. Glad my instinct to isolate it helped me, but I feel sorry for anyone whose secrets, etc. got vacuumed up by Ziphu
I would never trust these Chinese vendors with their tooling or their own inference endpoints.
afaik DeepSeek also trained on everything that was sent to them via OR and that's why you got that massive discount
WOW. I actually did buy a month of GLM because GLM-5.3-Flash is so great and ZCode is honestly one of the best harnesses out there from an HCI perspective, and I won't lie, this is pretty gutting. I guess this settles my inner turmoil about open-sourcing my cAI research, at least...
With that personal failing in mind, I'd ask y'all to permit me to toe the guidelines just once, to proffer a hearty nyah nyah told ya so on a comment thread that spawned ~a dozen disagreeing replies this week! More seriously, I think this[1] is highly-relevant, shockingly-underreported context about the extent to which four PRC companies --Z, Alibaba, DeepSeek, and Moonshot-- are acting in bad faith. Consider it testimony as to their character, just in case anyone is thinking this might just be a simple misunderstanding.
So... nyah nyah, told us so:
[1]: https://www.anthropic.com/threat-intelligence-report-septemb... is the report.
I lowkey suspect this PRC-based scandal has been underreported because Anthropic went insane with the sidebar UX on this page for some reason; there were many reports on the reports of Houti and Iranian usage, and very few on these sections. Could a week's mass media cycle be this seriously affected by such a stupid thing as a sidebar experiment?? Strange truth, or just fiction?
ummm...I'm a Chinese.(I'm not a English native speaker so my word choice may be strange.) In fact, what you said about PRC gov, sounds like something UFO or something Reptilians. I really don't know WHY do many social media tend to choose topics like this.
Maybe because most people are foolish? Because foolish'es mind is fond of topic that are crazely explosive and magical...?
BUT at the same time, have you experienced the Victorian era? Have you experience the cyberpunk2077? You can come to China. Big companies act without any rules.
Zhipu(GLM) are just common companies like any one another company here.
Here is a CARZYLY NEW WORLD. 99.99% goods are CRAZELY CHEAP while falsely advertising without supervision. 99.99% apps collect users' private info and then sell it. You can easily see it via almost no website even asks if you’re okay with them collecting cookies.
It maybe a common mistake for WestEu/NorthAm people that China is like Soviet or North Korea.
It's diametrically opposite.
At the end of the last century, PRC gov deeply felt that the so-called "fairness" would only lead to "common poverty" and sought change.
So China (now, in this century) was born.
Just like the "famous"(notorious) quote left by a Chinese leader at the end of the last century explaining why restrictions were lifted (you can say this to ANY Chinese, they will definitely think you understand China! Instead of mocking you for reading too many conspiracy theories):
Whether it's a kind cat or an evil cat, as long as it catches a mouse, it's the best cat.
Crossposting from the other thread...
Tangential, mildly amusing thing I noticed while implementing my own harness: GLM and particularly Deepseek are both fond of trying to read dotfiles and anything listed in your .gitignore files. I only noticed it because I have separate read scopes for project files, ignored files, dotfiles and external files, so the latter three always prompt me for approval.
I'm sure there's a perfectly reasonable explanation for it, which has nothing at all to do with exfiltration of secrets, but it does amuse me when it happens. I imagine the labs have access to lots of secrets that various actors would like to get their hands on...
(shameless plug for my own harness, which is open source and doesn't have a backend to send any data to: https://www.opairdev.org/ )
Just my thoughts on the site:
It's good that the objective is to have the model work as a helper, but that's what everyone can already do with CC or Codex as long as you don't ask to "write this entire x thing". It's also what a billion other, often vibecoded, harnesses claim they can do.
Why should I use yours, which also forces me off my existing subscriptions? Maybe it's (mostly) handwritten, so it's mindful efficient code instead of slop, and each adjustment was made through trial and error with current models? maybe it IS slop but at least you have a unique feature? and so on and so forth.
I tested GLM while working on some android app, the agent had adb access to the device. It suddenly went to the Gallery and started scrolling around, taking screenshots, lol. A friend had a similar experience with GLM where it would for no very clear reason start snooping through the filesystem.
Haven't used it after that.
Elon has nothing to lose on trust.
Z/GLM now has a lot to rebuild.
"Why yes, we had to exfiltrate 100% of your data so we could vectorise it and improve recall by -0.3%"
Is it naive to assume that the agent will try and access anything on your disk, either accidentally or maliciously?
Permissions classifiers in auto mode are just models trying to guess if they're doing the right thing.
Claude Code will tell you that it went around a sandbox because the sandbox blocked it. At which point, you ask yourself the point of the sandbox.
Things like that - and other examples posted here - are why I 'm sticking with OpenCode despite it having some papercuts that annoy me.
The incentives are not there for them to do shady stuff like vacuum your files, inflate your token count just because or many other things.