Leak Exposes 391,439 Characters of Z.ai ZCode Prompts in First Full GLM 5.3 System Disclosure
Legal48d agoA disclosure on the site CL4R1T4S published 391,439 characters of system prompts, tool contracts, and skill bodies for Z.ai's ZCode interactive coding agent. The leaked files reveal the internal logic and tool specifications used by the GLM-5.3 model, including 24 receipt-verified tool contracts and 15 skill bodies that guide the agent through software engineering and reverse engineering tasks.
The system instructions mandate that the agent output text using GitHub-flavored markdown and strictly refuse requests for destructive techniques, such as DoS attacks and supply chain compromise. To ensure readability, the prompts require the model to provide the final outcome in the first sentence of any response and avoid redundant comments in generated code to streamline the pull request process.
Key sources
- SOURCE@elder_plinius“Refuse requests for destructive techniques, DoS attacks, mass targeting, supply chain compromise, or detection evasion for malicious purposes”x.com
- SUPPORT@zixuanli_“It found a potentially serious vulnerability in Cursor”x.com
- SUPPORT@arena“post-training on the 743B base model”x.com
- SUPPORT@mtslive“found 2,436 vulnerabilities across 269 projects, 1,097 critical or high”x.com
- SUPPORT@semianalysis_“massively beats every American open model: Nemotron, Laguna, Inkling”x.com