Independent verification and Moonshot AI’s response will determine whether Kimi Work sends users’ five most recent raw agent sessions with feedback reports without adequate notice or consent.
state: expiredheat: lowuncertainty: highknownscott: lowagentic-security agent-privacy session-logsMoonshot AIKimi
What is this?
Kimi is a consumer AI platform from Moonshot AI, described in the supplied results as a Beijing-based, Alibaba-backed company offering agentic features. The case alleges that Kimi Desktop 3.1.5 attaches the five most recent raw Kimi Work agent sessions to feedback reports, but none of the provided web snippets independently documents that behavior, its disclosure, user consent, or Moonshot AI’s response. The central privacy claim therefore remains unverified on the supplied evidence and depends on reproducible testing and clarification from Moonshot AI.
Why it matters to Scott
Scott already treats raw agent sessions as sensitive bronze evidence requiring explicit privacy boundaries, redaction, and governed retention in “Observability for Agentic Systems” and “Cognitive Git.” The Kimi allegation is therefore a new but currently unverified example of a risk he already recognizes; absent reproduction, disclosure details, or a Moonshot response, it does not yet extend or challenge his position.
ip:source.observability-for-agentic-systems-what-to-log-how-to-redact-how-to-debug-ebookip:framework.cognitive-gitdev:concept.privacy-tokenized-agent-boundaryradar:codex-private-repo-uploadradar:concept.ai-privacy
queries asked of Scott's wikis
- agent feedback telemetry and raw session retention
- privacy boundaries for agent traces and session logs
- consent patterns for diagnostic uploads
- sensitive-data handling in coding-agent harnesses
- local-first agent memory and telemetry
- security review methods for agent desktop clients
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (2) — ⭐ canonical anchor
Interpretation history
2026-08-20T11:28:27Z
No independent reproduction, disclosure analysis, or Moonshot AI response emerged within the case’s active horizon, so the allegation remains unresolved but has faded as a live signal.
2026-08-18T10:34:39Z
The refreshed discussion raises source-credibility concerns and notes that feedback-related privacy-policy carve-outs may exist, but it neither reproduces the upload behavior nor establishes adequate disclosure or consent. The case remains a single-source, testable allegation awaiting independent verification or Moonshot AI’s response.
2026-08-16T17:38:56Z
No independent reproduction, disclosure evidence, or Moonshot AI response has appeared; the lone additional comment does not change the single-source allegation. The case remains testable but has cooled pending a substantive confirming fact.
2026-08-16T17:27:53Z
grounded: known/low — Scott already treats raw agent sessions as sensitive bronze evidence requiring explicit privacy boundaries, redaction, and governed retention in “Observability
2026-08-16T17:24:50Z
origin walked (codex/luna, conf 0.98): anchor hn.story.49313711 -> echo.blog.8dadad0c99 by Ryan Merket
2026-08-16T17:23:53Z
case created — A specific reverse-engineering allegation describes potentially sensitive session transmission and is resolvable through replication or vendor response.
Decision trace
- 08-20 21:28expireNo independent reproduction, disclosure analysis, or Moonshot AI response emerged within the case’s active horizon, so the allegation remains unresolved but has faded as a live signal.
- 08-20 21:28alert_silentThe only delta is elapsed staleness, not new evidence; the case can be reopened if an independent replication, client change, or vendor response appears.
- 08-20 21:28alert_routeThe only delta is elapsed staleness, not new evidence; the case can be reopened if an independent replication, client change, or vendor response appears.
- 08-18 20:34repriceThe refreshed discussion raises source-credibility concerns and notes that feedback-related privacy-policy carve-outs may exist, but it neither reproduces the upload behavior nor establishes adequate
- 08-18 20:34alert_silentThe new comments are commentary and source skepticism rather than consequential evidence; they can wait for independent reproduction, disclosure analysis, or a vendor response.
- 08-18 20:34alert_routeThe new comments are commentary and source skepticism rather than consequential evidence; they can wait for independent reproduction, disclosure analysis, or a vendor response.
- 08-17 03:38repriceNo independent reproduction, disclosure evidence, or Moonshot AI response has appeared; the lone additional comment does not change the single-source allegation. The case remains testable but has cool
- 08-17 03:38alert_silentThe new delta is only negligible engagement and adds no consequential evidence, so it can wait for independent testing or a vendor response.
- 08-17 03:38alert_routeThe new delta is only negligible engagement and adds no consequential evidence, so it can wait for independent testing or a vendor response.
- 08-17 03:36alert_silentA named researcher reports reproducing a concrete Kimi Desktop 3.1.5 behavior—packaging the five newest Work sessions and attempting to upload them with feedback—but the evidence remains single-source
- 08-17 03:36surface_candidateA named researcher reports reproducing a concrete Kimi Desktop 3.1.5 behavior—packaging the five newest Work sessions and attempting to upload them with feedback—but the evidence remains single-source
- 08-17 03:36alert_routeA named researcher reports reproducing a concrete Kimi Desktop 3.1.5 behavior—packaging the five newest Work sessions and attempting to upload them with feedback—but the evidence remains single-source
- 08-17 03:27groundScott already treats raw agent sessions as sensitive bronze evidence requiring explicit privacy boundaries, redaction, and governed retention in “Observability for Agentic Systems” and “Cognitive Git.
- 08-17 03:24promote_anchororigin walk conf 0.98
- 08-17 03:23createA specific reverse-engineering allegation describes potentially sensitive session transmission and is resolvable through replication or vendor response.