2026-10-11 17:10 UTC

Independent verification and Moonshot AI’s response will determine whether Kimi Work sends users’ five most recent raw agent sessions with feedback reports without adequate notice or consent.

state: expiredheat: lowuncertainty: highknownscott: lowagentic-security agent-privacy session-logsMoonshot AIKimi

What is this?

Kimi is a consumer AI platform from Moonshot AI, described in the supplied results as a Beijing-based, Alibaba-backed company offering agentic features. The case alleges that Kimi Desktop 3.1.5 attaches the five most recent raw Kimi Work agent sessions to feedback reports, but none of the provided web snippets independently documents that behavior, its disclosure, user consent, or Moonshot AI’s response. The central privacy claim therefore remains unverified on the supplied evidence and depends on reproducible testing and clarification from Moonshot AI.

Why it matters to Scott

Scott already treats raw agent sessions as sensitive bronze evidence requiring explicit privacy boundaries, redaction, and governed retention in “Observability for Agentic Systems” and “Cognitive Git.” The Kimi allegation is therefore a new but currently unverified example of a risk he already recognizes; absent reproduction, disclosure details, or a Moonshot response, it does not yet extend or challenge his position.
ip:source.observability-for-agentic-systems-what-to-log-how-to-redact-how-to-debug-ebookip:framework.cognitive-gitdev:concept.privacy-tokenized-agent-boundaryradar:codex-private-repo-uploadradar:concept.ai-privacy
queries asked of Scott's wikis
  • agent feedback telemetry and raw session retention
  • privacy boundaries for agent traces and session logs
  • consent patterns for diagnostic uploads
  • sensitive-data handling in coding-agent harnesses
  • local-first agent memory and telemetry
  • security review methods for agent desktop clients

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnKimi Work attaches raw agent sessions to feedback reportsryanmerket208
🟧 echo.blog ⭐RuntimeWire describes this as “Original reporting ... based on reverse engineering, testing.” It reports that Kimi Desktop 3.1.5 sorts Work Ryan Merket——

Interpretation history

Decision trace