ZCode: Z.ai's Coding Agent Harness
libraryYour notes
Z.ai's coding-agent harness, open-sourced on 2026-09-20 under Apache 2.0 — the lab's first public harness and the execution layer paired with GLM-5.3, whose product page bills it as the "Official Harness for GLM-5.3" with GLM-5.3-Flash built in for screenshot understanding and image analysis. The repository is a pnpm monorepo holding the whole stack rather than a CLI alone: an Electron desktop client, a web client, the HTTP/WebSocket server and remote-connection layer, shared React UI and RPC packages, provider adapters, and the Agent CLI, TUI and runtime source under apps/zcode-cli. One zcode command opens the terminal interface, zcode --web serves the browser interface from the same backend, and the desktop build adds SSH, WSL and container workspaces. Z.ai's own docs describe it as an "Agentic Development Environment (ADE) designed for long-horizon tasks." It reached 7,245 GitHub stars and 2,200 forks in its first ten days; the code is TypeScript on Node 24.14.0.
The harness layer is where the detail is. The agent core carries separate modules for context compaction (including a microcompact path), memory, session context, system reminders, subagents, MCP, plugins, tool scheduling and a permission service, plus dynamic workflows (added in v3.14.0 on 2026-09-19) in which a single script orchestrates several sub-agents on one task. Tool handlers cover bash with a large read-only command-policy surface, file read/edit/write, glob and grep, web fetch and web search, a Node REPL, a browser, cron and off-peak scheduling, plan mode, and inter-agent messaging. Plugins are local bundles that contribute skills (SKILL.md folders), markdown custom commands and MCP servers, with Browser Use, Document Skills, Skill Creator and a ZCode guide enabled by default. Seven lifecycle hooks (SessionStart, UserPromptSubmit, PreToolUse, PermissionRequest, PostToolUse, PostToolUseFailure, Stop) can inject context, rewrite tool input or take part in permission decisions. Z.ai's NOTICE is unusually candid about the limits: the shared execution adapter ships no default OS sandbox, the shared runtime defaults to a build permission mode while the standalone CLI running --prompt without --mode defaults to yolo, and the bundled Computer Use package is a placeholder that returns an unavailable error. The product predates the code drop — the public changelog runs back to v3.10.1 on 2026-08-28 — and desktop builds for macOS, Windows and Linux ship from zcode.z.ai (v3.14.4, 2026-09-29).