>Treat the repo you point it at as already leaked I don't mean this to downplay your experience, and I agree it should be opt-in by default, but any software engineer using these tools should understand completely that in order to 'read' your repo it needs to copy it all to the provider's servers. Using anything short of a local model has ALWAYS been a complete leak.
I think the sane take here is that if you let loose a coding agent in a project, you should assume it can read everything, because at any point it can issue a read tool command to read arbitrary file. If you want to be selective in what you share, a coding harness is probably a bad tool for the job. That said, AI companies still shouldn't be intentionally building features that upload code wholesale because it betray…
But the truth is, much of the utility of the model is allowing it to grep across the codebase and explore for context.
I have great interest in zero knowledge inference, but as far as we know, it is difficult to build any sort of efficient representation.