虎嗅

"DouBao Work Exposes Your Privacy? Don't Jump to Conclusions—This Isn't That Simple."

原文:豆包工作扒光你的隐私?别急着扣帽子,这事儿不简单

Summary of Key Points

DouBaoGongZuo (a workplace AI tool under ByteDance) has sparked controversy for automatically scanning and copying Skill files from other AI agents (such as Codex and Claude) on users' computers after installation, including users' own unpublished custom Skills. After the incident, the team quickly apologized and disabled the automatic scanning feature, promising to switch to a manual import option. This analysis discusses the technical feasibility, industry practices, privacy compliance, and product design logic surrounding the issue. While the automatic scanning did not necessarily lead to a violation of privacy, the unauthorized copying of user data was still considered a breach of boundaries, highlighting the importance of user choice and data transparency.

1. What exactly did DouBaoGongZuo do? – Don’t let the title scare you; let’s get the facts straight

The original post title, “Exposing Privacy,” is somewhat sensational, but the core issue is clear: DouBaoGongZuo scanned several pre-set AI agent Skill directories on the user’s computer without prior notice, including hidden folders containing unpublicized, user-developed test versions of Skills.

It’s important to clarify two points:

  • It wasn’t a full system scan: The tool only targeted a few known agent directories, not the entire hard drive.
  • No bulk data upload: DouBao’s team explained that the Skills were only locally detected and displayed, and only uploaded to the cloud when the user explicitly requested it.

However, the lack of prior notification is a significant issue, especially for users’ unpublished custom Skills, which is like having someone access your private drafts without permission.

2. Why can desktop apps silently scan files? – Computer permissions differ from mobile apps

Many people wonder why desktop apps don’t prompt for permission when accessing files, while mobile apps do. The reason is that computer systems have different permission mechanisms:

  • Windows: If a program runs under your account, it inherits that account’s file access rights. As long as the program can access files in your user directory, it can open them without prompting, unless they are system-critical.
  • macOS: Apple has added a “sensitive location protection” layer, which prompts for access to areas like the desktop, photos, and contacts. However, hidden folders like Codex/skills can still be read without a prompt if they’re not in sensitive areas.

Therefore, while DouBaoGongZuo’s technical ability to scan these directories is not illegal, it’s still considered intrusive since the user did not give consent.

3. Is it common for AI agents to exchange Skills in the industry? – The norm is to ask for permission first

In the AI agent industry, it’s common to transfer user data between tools. For example, when switching agents, new tools may automatically migrate previous Skills, configurations, and settings to save users the effort of reconfiguration. The proper procedure is to:

  • Ask for permission before importing favorites from a browser.
  • Prompt users whether to migrate Skills when an open-source agent is initialized.
  • Place the import function on a dedicated “Import” page in commercial agents, waiting for the user’s explicit consent.

DouBaoGongZuo’s automatic migration bypassed this user confirmation, turning what should have been a convenient feature into an infringement of user rights, similar to a neighbor moving your belongings without asking.

4. Does this constitute a privacy violation? – Legal risks are significant, and user rights must be protected

From a legal perspective, although it may not be a direct violation, the risks are considerable:

  • EU GDPR: Accessing user device data requires clear notification and consent, unless it’s necessary for fulfilling a user request (which was not the case here).
  • US CCPA: Personal information must be disclosed before collection.
  • The special nature of custom Skills: Unpublished Skills may contain private scripts, business rules, or sensitive data. Even if the data is only copied locally, it still increases the risk of unauthorized access or transmission.

Therefore, copying private content without consent is a disregard for user rights.

5. Why wasn’t a manual selection option available from the start? – Trust is more important than functionality

The fact that DouBaoGongZuo’s team was able to quickly disable the feature indicates that a toggle (known as a “Feature Flag”) was available in the backend. Adding a simple confirmation prompt, such as “Did you find other agent Skills? Do you want to import them?” would have been straightforward, similar to how browsers work.

Office AI tools handle sensitive information like contracts, code, and customer data, so users are particularly concerned about what they are being exposed to and what is being accessed. Giving users the option to control these settings not only avoids conflicts but also builds trust. After all, users will only entrust important tasks to a tool they trust not to misappropriate their data.

Conclusion

Innovations in AI tools must be based on user trust. Just because a technical action is possible does not mean it’s always appropriate. Putting users’ right to know and make choices first is the key to long-term success.