Z.ai open-sourced the ZCode harness on 20 September, and its NOTICE.md admits there is no default OS sandbox
The zai-org/ZCode repository went public on 2026-09-20 under Apache-2.0 and reached 4,947 stars in a day, one day after independent teardowns of its telemetry. The accompanying NOTICE.md is a real risk disclosure rather than a legal boilerplate: it states the shared agent execution adapter provides no default operating system sandbox, that working directory, workspace identity, git worktree, browser page isolation and the Node REPL must not be treated as system-level isolation, and that the standalone CLI invoked with `--prompt` and no `--mode` runs in `yolo`. It also warns that a model claiming a task is done or authorized is not evidence of either, and that model tool approval is not an application-wide permission switch covering terminal operations, plugin processes or update downloads.
↳ Follow the thread