{
  "schemaVersion": 1,
  "checkedAt": "2026-08-11T10:31:00Z",
  "operationId": "20260811095225-f85a95f6c7",
  "discovery": {
    "source": "AI HOT",
    "itemId": "cmso95agg0ig3rofwaqvy9crw",
    "permalink": "https://aihot.virxact.com/items/cmso95agg0ig3rofwaqvy9crw",
    "feedClaim": "ZCode全面升级：Goal、Subagents、Remote Control与闲时任务四大功能上线",
    "treatment": "untrusted discovery lead; every product and security claim was checked against current first-party documentation"
  },
  "method": {
    "auditType": "dated public-document and search-intent audit",
    "sourceResponses": 9,
    "searchQueries": 2,
    "modelCalls": 0,
    "desktopAppOpened": false,
    "livePairingPerformed": false,
    "authorizationLinkGenerated": false,
    "qrCodeScanned": false,
    "networkOrCryptographyTestPerformed": false,
    "reasonForNoPairing": "A live pairing would create a bearer-like control link to a real desktop window and was unnecessary to verify the documented scope and revocation controls."
  },
  "productSnapshot": {
    "desktopVersionShown": "3.7.5",
    "desktopVersionDate": "2026-08-10",
    "glmIntegrationClaim": "ZCode 3.0 is described by Z.ai as optimized for GLM-5.2 and the current product page says Deep GLM-5.2 integration.",
    "releaseClaimBoundary": "The August 11 AI HOT item called the four features newly launched. The first-party changelog page checked that day listed ZCode v3.7.5 for August 10 but did not list Remote Control as a new v3.7.5 feature, so this audit does not repeat the launch-timing claim."
  },
  "capabilityAudit": [
    {
      "id": "control-surface-only",
      "documented": true,
      "finding": "The phone is a control surface for the running desktop application; Remote Control is not a code-sync service or a separate cloud runtime.",
      "sourceId": "remote-control"
    },
    {
      "id": "runtime-stays-desktop",
      "documented": true,
      "finding": "Commands continue in the environment already connected by the desktop: local, SSH, WSL, or Docker.",
      "sourceId": "remote-control"
    },
    {
      "id": "window-scope",
      "documented": true,
      "finding": "The mobile page can reach the current ZCode desktop window, not only the workspace visible when the link was scanned.",
      "sourceId": "remote-control"
    },
    {
      "id": "workspace-session-navigation",
      "documented": true,
      "finding": "The phone can list and switch workspaces, tasks, and sessions in the current desktop window.",
      "sourceId": "remote-control"
    },
    {
      "id": "create-task-existing-workspace",
      "documented": true,
      "finding": "A new task can be created in a workspace that is already available to the desktop.",
      "sourceId": "remote-control"
    },
    {
      "id": "registered-remote-reconnect",
      "documented": true,
      "finding": "The phone can reconnect a remote environment already registered in the desktop application.",
      "sourceId": "remote-control"
    },
    {
      "id": "single-phone-page",
      "documented": true,
      "finding": "Only one phone page can be connected at a time.",
      "sourceId": "remote-control"
    },
    {
      "id": "no-new-remote-connection",
      "documented": true,
      "finding": "The phone cannot create a new SSH, WSL, or Docker connection.",
      "sourceId": "remote-control"
    },
    {
      "id": "no-arbitrary-project-browse",
      "documented": true,
      "finding": "The phone cannot browse arbitrary directories or projects that are not already open or registered in the desktop application.",
      "sourceId": "remote-control"
    },
    {
      "id": "link-authorizes-control",
      "documented": true,
      "finding": "The control link itself carries authorization; a person who obtains it can operate the connected ZCode window.",
      "sourceId": "remote-control"
    },
    {
      "id": "close-is-not-stop",
      "documented": true,
      "finding": "Closing the desktop dialog does not stop Remote Control; the Stop action is required.",
      "sourceId": "remote-control"
    },
    {
      "id": "refresh-revokes-old-link",
      "documented": true,
      "finding": "Refreshing the QR code invalidates prior links and connections.",
      "sourceId": "remote-control"
    },
    {
      "id": "desktop-online-required",
      "documented": true,
      "finding": "The desktop application and machine must remain running and online.",
      "sourceId": "remote-control"
    },
    {
      "id": "permission-modes",
      "documented": true,
      "finding": "ZCode documents Confirm Before Changes as the default, plus Auto Edit, Plan, and Full Access modes; least privilege remains the safer starting point.",
      "sourceId": "safety-confirm"
    },
    {
      "id": "five-minute-question-boundary",
      "documented": true,
      "finding": "Permission and plan approvals wait, while ordinary questions can auto-continue after five minutes unless that behavior is disabled.",
      "sourceId": "safety-confirm"
    },
    {
      "id": "idle-tasks-not-mobile-list",
      "documented": true,
      "finding": "Idle-time automations are one-shot local-project tasks and do not appear in the Remote Control mobile task list.",
      "sourceId": "idle-tasks"
    }
  ],
  "channelComparison": [
    {
      "channel": "Remote Control",
      "entry": "temporary phone web page opened from a QR/link",
      "runtime": "existing ZCode desktop window and its already connected environment",
      "bestFit": "short monitoring or steering while away from the keyboard",
      "revocation": "Stop; Refresh invalidates prior links"
    },
    {
      "channel": "Bot Channel",
      "entry": "WeChat or Feishu bot",
      "runtime": "existing ZCode desktop session and machine",
      "bestFit": "a longer-lived messaging entry point",
      "revocation": "manage or remove the configured bot channel"
    },
    {
      "channel": "Remote Development",
      "entry": "desktop-created SSH, WSL, or Docker connection",
      "runtime": "the selected remote or isolated environment",
      "bestFit": "choosing where code and commands execute",
      "revocation": "disconnect or remove the desktop-side environment"
    },
    {
      "channel": "Idle-time task",
      "entry": "one-shot queued desktop automation",
      "runtime": "local project while the subscribed computer remains awake",
      "bestFit": "deferred local housekeeping",
      "revocation": "remove or disable the queued automation"
    }
  ],
  "securityRunbook": [
    "Open only the intended ZCode window, workspace, account, and already connected runtime before generating a link.",
    "Start in Confirm Before Changes or Plan mode; do not enable Full Access merely to reduce phone prompts.",
    "Treat the URL and QR payload as a credential: do not paste it into chat, tickets, screenshots, logs, or shared notes.",
    "From the phone, confirm the visible workspace, task, session, and runtime before issuing an instruction.",
    "Use Stop when finished and verify that the phone no longer controls the desktop; closing the dialog is insufficient.",
    "Use Refresh immediately if a link may have been exposed, then verify that the old page is disconnected."
  ],
  "searchIntentAudit": {
    "method": "read-only Google results in a task-owned visible-browser target",
    "queries": [
      {
        "query": "ZCode Remote Control GLM-5.2",
        "finding": "Results mixed Z.ai product material, coding-agent comparisons, and video coverage; the exact phone-control security job was not answered by an existing GLM52.ai page."
      },
      {
        "query": "ZCode Remote Control QR code security",
        "finding": "The official Remote Control guide ranked prominently, and the result set emphasized QR authorization, one-phone scope, Stop, and Refresh."
      }
    ],
    "serpApiUsed": false,
    "serpApiReason": "The shared ledger showed 760 known monthly searches, above this project's conservative 250-search operating cap, so no paid request was made."
  },
  "sources": [
    {
      "id": "zcode-home",
      "url": "https://zcode.z.ai/en",
      "status": 200,
      "bytes": 277787,
      "sha256": "1e05ac55256683a13691d4f02eee7788d80baff05a7b8f7311d952b7e647e9a0"
    },
    {
      "id": "changelog",
      "url": "https://zcode.z.ai/en/changelog",
      "status": 200,
      "bytes": 133077,
      "sha256": "760a762dd2742f5826bb4b2959c4515f97a0dd8a6a6cde630069151c931ad065"
    },
    {
      "id": "remote-control",
      "url": "https://zcode.z.ai/en/docs/remote-control",
      "status": 200,
      "bytes": 83286,
      "sha256": "bc593f68b7c3a28c305bff722d425bb149f507e104169c704bd4fd1f2c213474"
    },
    {
      "id": "safety-confirm",
      "url": "https://zcode.z.ai/en/docs/safety-confirm",
      "status": 200,
      "bytes": 87319,
      "sha256": "8ba94aff2ebdd56005f8b1b0a1a9395f52fdc1466fd417473ed2949c2f8c4f64"
    },
    {
      "id": "bot-channel",
      "url": "https://zcode.z.ai/en/docs/bot-channel",
      "status": 200,
      "bytes": 78062,
      "sha256": "98e15f838fa647af6f87b6a516f0c4060ce644a813c262388b04aaa43d8da8db"
    },
    {
      "id": "idle-tasks",
      "url": "https://zcode.z.ai/en/docs/idle-time-tasks",
      "status": 200,
      "bytes": 89352,
      "sha256": "886feca29f6d5a9f27316a27f9005f0bf2a1180a4b41bef3163c6b5d39f7d470"
    },
    {
      "id": "glm-release",
      "url": "https://z.ai/blog/glm-5.2",
      "status": 200,
      "bytes": 598,
      "sha256": "d0299326d21fd363483eabe4f4a719efc842022bc843f6e7c2d4ee77d4d8a5c0"
    },
    {
      "id": "zhipu-research",
      "url": "https://www.zhipuai.cn/zh/research",
      "status": 200,
      "bytes": 1243011,
      "sha256": "c9825ad32a505b312954e96db523aa18233301902cddb0a9b91244d939509402"
    },
    {
      "id": "aihot-item",
      "url": "https://aihot.virxact.com/items/cmso95agg0ig3rofwaqvy9crw",
      "status": 200,
      "bytes": 314163,
      "sha256": "2e6b7b1785cb571d2c02758de764f7b479374849b994ea7a100f8e1e469c058e"
    }
  ],
  "limitations": [
    "No live ZCode window, account, project, QR code, or remote environment was exposed to this audit.",
    "The public documentation does not establish the transport protocol, encryption design, link lifetime, or resistance to interception.",
    "The audit does not prove that every permission prompt can be handled from the phone.",
    "No claim is made about mobile reliability, latency, uptime, or behavior after a desktop crash.",
    "Product UI, version, availability, subscription rules, and documentation can change after the checked date."
  ]
}
