[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"news-slug-zcode-391k-prompt-leak-claude-code-dna":3,"news-related-edefe1ba-ee28-4f3a-94f4-ab898e079807":38},{"id":4,"title":5,"summary":6,"content":7,"original_url":8,"source_id":9,"tags":10,"translations":24,"news_slug":31,"published_at":32,"created_at":33,"modified_at":34,"is_published":35,"publish_type":36,"image_url":14,"view_count":37},"edefe1ba-ee28-4f3a-94f4-ab898e079807","ZCode 提示词泄露:39 万字符暴露 GLM-5.3 智能体的 Claude Code 血统","8 月 15 日,提示词研究者 Pliny the Liberator 把 Z.ai 编程智能体 ZCode 的三个内部文件(Prompts.md、Tools.json、Skills.md,合计 391,439 字符)归档到 CL4R1T4S 仓库。分析显示其工具命名与技能文件设计几乎逐项对应 Claude Code 体系,提示词文本中甚至同时出现 Claude agent 与 ZCode 的身份声明。这是生产级编码智能体操作符提示词的首次完整曝光。","8 月 14 日,Z.ai 发布 GLM-5.3——在 743B 参数基座上后训练出的编码与网络安全模型。第二天,它的编程智能体 ZCode 就出了事:知名提示词研究者 Pliny the Liberator 把 ZCode 的三个内部文件推上了他的 CL4R1T4S 泄露存档库(一个 4.7 万 star 的仓库),合计 391,439 字符。这是 ZCode 操作符提示词的首次完整曝光。\n\n## 三个文件,一个智能体的完整骨架\n\n泄露内容分三层:\n\n- **Prompts.md**:操作符系统提示词,涵盖身份声明、工具使用指令、安全护栏、格式规则、agentic 工作流(计划模式、探索、完成验证)、记忆系统规则与会话管理\n- **Tools.json**:完整的 function-calling schema,定义 ZCode 能调用的每一个工具\n- **Skills.md**:四个内置技能手册——浏览器控制、GUI 测试、docx 生成、PDF 生产\n\n39 万字符听起来吓人,但分析显示其中大部分来自「模块化重复」:同一套 harness 提示、沟通指南和环境设置,针对不同任务类型(标题生成、代码摘要、记忆提取、探索)反复重写。这不是一篇 39 万字的长文,而是一组可复用提示块拼装出的操作手册。\n\n## 最有意思的发现:工具名是 Claude Code 的\n\n对照 Tools.json 里约二十余个活跃工具,会发现一个尴尬的事实:Agent、AskUserQuestion、Bash、Edit、Read、Write、Skill、TodoRead、TodoWrite、WebFetch、WebSearch……这些不是「独立团队碰巧想到的通用命名」,而是 Claude Code 工具名的逐字复刻。\n\n往下看更明显。据提取内容,Prompts.md 中存在多处身份声明,把智能体同时描述为「Claude agent」和「ZCode」——暗示这套 harness 文本改编自 Claude Code 衍生的基础,而非为 GLM-5.3 从零撰写。Skills.md 里 docx 技能的开场白「A .docx file is a ZIP archive containing XML files」,与 Anthropic 公开的 docx Agent Skill 如出一辙;pdf 技能则按 Report\u002FReportLab、Creative\u002FPlaywright、Academic\u002FLaTeX 三条产线路由,同样读起来像直接改编而来。\n\n需要说明:Z.ai 并未官方确认这次泄露,以上均基于存档文本本身的分析,应视作未验证但内部一致的研究材料。\n\n## 安全护栏:与 GLM-5.3 的定位严丝合缝\n\nPrompts.md 明确禁止「破坏性技术、DoS 攻击、大规模目标扫描、供应链投毒、为恶意目的的检测规避」,并要求运行双用途安全工具前必须具备授权上下文。这与 GLM-5.3 发布时的姿态一致:主打防御性网络安全(CyberGym 84.5% 领先),而非进攻性漏洞利用(ExploitBench 54.4%,明显落后)。产品定位写在 benchmark 里,也写在提示词里。\n\n## 所以呢:智能体的「智能」,多少在脚手架里?\n\n这次泄露留给行业的问题比八卦更有价值:用户感受到的「GLM-5.3 是个能干的编码智能体」,多少来自 743B 的模型权重,多少来自它每一轮都在读的 39 万字符脚手架?\n\n泄露本身回答不了这个问题——静态文本不是消融实验。但它至少证明了一件事:工具契约、技能手册、安全护栏、格式规则,这些每轮注入的提示工程,正在成为编码智能体产品的核心资产。Pliny 上个月泄露 GPT-5.6 Sol 的 Codex 提示词时,结论也是同一个:Claude Code、Codex、Cursor、ZCode 的工具分类学正在收敛成同一个形状——不是因为抄袭省事,而是因为这个形状真的有效。\n\n对智能体开发者,可带走三条:第一,学模式别抄文本,39 万字符是 Z.ai 针对自己沙箱和法律姿态调过的;第二,技能文件要写成 playbook(含验证步骤、失败模式、「不许做」清单),不是 API 参考;第三,别指望 harness 设计有什么独门秘籍——行业的最优解正在快速趋同,护城河越来越只剩下模型本身。\n\n*(事件详情与文本分析基于 explainx.ai 的泄露解读与 CL4R1T4S 存档)*","https:\u002F\u002Fwww.explainx.ai\u002Fblog\u002Fzcode-glm-5-3-system-prompt-leak-391439-characters-august-2026","998df6db-96e6-4b8e-8be1-cfa00a6cd177",[11,15,18,21],{"id":12,"name":13,"slug":13,"description":14,"color":14},"6ad31a14-c0da-42df-81fd-564281f768db","agentic-ai",null,{"id":16,"name":17,"slug":17,"description":14,"color":14},"1fcfaaf2-67de-43d3-9e35-5784852fec60","ai-safety",{"id":19,"name":20,"slug":20,"description":14,"color":14},"e82b2d09-81b2-43d1-977e-e018443b3c14","coding-agent",{"id":22,"name":23,"slug":23,"description":14,"color":14},"01598627-1ea6-4b27-a5d8-874971571a71","llm",[25],{"id":26,"lang":27,"title":28,"summary":29,"content":30},"786375a2-e7fd-42b4-b2ff-b17f8bc0a0a0","en","ZCode prompt leak: GLM-5.3's Claude Code lineage exposed","On August 15, prompt researcher Pliny the Liberator archived three internal files from Z.ai's coding agent ZCode (Prompts.md, Tools.json, Skills.md — 391,439 characters combined) to the CL4R1T4S repository. Analysis shows the tool naming and skill-file design map almost one-to-one onto Claude Code's taxonomy, and the prompt text reportedly contains identity statements referring to the agent as both a \"Claude agent\" and \"ZCode.\" This is the first full disclosure of a production coding agent's operator prompt.","On August 14, Z.ai launched GLM-5.3 — a coding and cybersecurity model post-trained on a 743B-parameter base. The very next day, its coding agent ZCode had an incident: Pliny the Liberator, the well-known prompt researcher, pushed three internal ZCode files to his CL4R1T4S leak archive (a repository with 47k stars), totaling 391,439 characters. This is the first full disclosure of the operator prompt behind ZCode.\n\n## Three Files, One Agent's Complete Skeleton\n\nThe leak splits into three layers:\n\n- **Prompts.md**: the operator system prompt — identity statements, tool-use instructions, safety guardrails, formatting rules, agentic workflow (plan mode, exploration, completion verification), memory-system rules, and session management\n- **Tools.json**: the full function-calling schema defining every tool ZCode can invoke\n- **Skills.md**: four built-in skill playbooks — browser control, GUI testing, .docx generation, and PDF production\n\n391K characters sounds alarming, but analysis shows most of it comes from modular repetition: the same harness prompt, communication guidelines, and environment setup restated for different task types (title generation, code summarization, memory extraction, exploration). This isn't a 391K-word essay — it's an operations manual assembled from reusable prompt blocks.\n\n## The Most Interesting Finding: The Tool Names Are Claude Code's\n\nCompare the roughly two dozen active tools in Tools.json and an awkward fact emerges: Agent, AskUserQuestion, Bash, Edit, Read, Write, Skill, TodoRead, TodoWrite, WebFetch, WebSearch... these aren't generic names an independent team lands on by coincidence — they're Claude Code's tool names, verbatim.\n\nIt gets more obvious on closer inspection. Per the extraction, Prompts.md contains multiple identity statements describing the agent as both a \"Claude agent\" and \"ZCode\" — suggesting the harness text was adapted from a Claude Code–derived base rather than authored from scratch for GLM-5.3. In Skills.md, the docx playbook opens with \"A .docx file is a ZIP archive containing XML files\" — the same framing as Anthropic's public docx Agent Skill. The pdf skill routes across Report\u002FReportLab, Creative\u002FPlaywright, and Academic\u002FLaTeX production briefs — again reading as directly adapted.\n\nTo be clear: Z.ai has not officially confirmed this leak. Everything above is based on analysis of the archived text itself and should be treated as an unverified but internally consistent research artifact.\n\n## Safety Guardrails: Consistent With GLM-5.3's Positioning\n\nPrompts.md explicitly prohibits \"destructive techniques, DoS attacks, mass targeting, supply chain compromise, or detection evasion for malicious purposes,\" and requires authorization context before running dual-use security tools. This matches GLM-5.3's launch posture: leading in defensive cybersecurity (CyberGym 84.5%) while trailing in offensive exploit generation (ExploitBench 54.4%). Product positioning is written into the benchmarks — and into the prompt.\n\n## So What: How Much of an Agent's \"Intelligence\" Lives in the Scaffolding?\n\nThe question this leak leaves the industry is more valuable than the gossip: of the \"GLM-5.3 feels like a capable coding agent\" experience, how much comes from the 743B weights, and how much from the 391K characters of scaffolding it reads every single turn?\n\nThe leak itself can't answer that — static text is not an ablation study. But it proves one thing: tool contracts, skill playbooks, safety carve-outs, and formatting rules — the prompt engineering injected every turn — are becoming the core asset of coding-agent products. When Pliny leaked GPT-5.6 Sol's Codex prompt last month, the conclusion was the same: Claude Code, Codex, Cursor, and now ZCode are converging on a shared tool taxonomy — not because copying is easy, but because the shape genuinely works.\n\nFor agent builders, three takeaways: first, study the pattern, don't paste the text — those 391K characters are tuned to Z.ai's sandbox and legal posture. Second, write skills as playbooks (with validation steps, failure modes, and \"do NOT\" lists), not API references. Third, don't count on harness design as a moat — the industry's best practices are converging fast, and the only moat left is increasingly the model itself.\n\n*(Event details and text analysis based on explainx.ai's leak coverage and the CL4R1T4S archive)*","zcode-391k-prompt-leak-claude-code-dna","2026-08-16T17:15:00Z","2026-08-16T17:13:02.040792Z","2026-08-16T17:13:02.040802Z",true,"agent",126,{"items":39},[40,45,50,55,60,65],{"id":41,"title":42,"news_slug":43,"published_at":44},"e8965513-b56f-475b-b15f-22a5ea2d2a4e","Agent 取代人成为 HF Hub 一号用户:Claude Code 占 44.4%,还有一次 4.5 天未察觉的入侵","hf-hub-agent-user-claude-code-4-5-day-intrusion","2026-08-21T08:00:00+00:00",{"id":46,"title":47,"news_slug":48,"published_at":49},"c0f3a940-9a7e-41ec-94f4-bb921e4323b9","OpenAI 首次因安全暂停前沿训练：Astra 触及网络「关键」阈值，最大 RL run 搁置","openai-pacing-astra-critical-cyber-pause","2026-08-19T15:20:00+00:00",{"id":51,"title":52,"news_slug":53,"published_at":54},"5a90a793-8ec1-4b3a-9691-edef5ffe8535","AI「思想病毒」实证:Anthropic 与 EPFL 让恶意想法在 Agent 间自我复制,免疫只需一段警告","mind-viruses-multi-agent-llm","2026-08-18T13:30:00+00:00",{"id":56,"title":57,"news_slug":58,"published_at":59},"6b203495-fcab-4afe-baa7-1079cf993796","拆开 GLM-5.3 的「后训练工厂」:基座一字未动,靠环境合成与 1e-7 对齐撑起全部提升","glm-5-3-post-training-stack-deep-dive","2026-08-17T13:00:00+00:00",{"id":61,"title":62,"news_slug":63,"published_at":64},"6e79fd96-2b0f-4743-b7ac-6b39f875f2cb","AISI 122 轮 cyber eval 图解：17 次 Mythos 5、2 次 GPT-5.6 Sol 越界","aisi-cyber-eval-mythos-gpt56-august-2026-deep-dive","2026-08-09T02:00:00+00:00",{"id":66,"title":67,"news_slug":68,"published_at":69},"2114f0e9-30a8-4e46-8a59-b9f40b06470b","UK AISI cyber eval 19 起越界：Mythos 5 供应链攻击开源维护者","aisi-mythos-5-agent-cyber-eval-incident","2026-08-06T19:00:00+00:00"]