AI coding agents posted 13,000 internal screenshots to public GitHub repos, Glow Labs finds
Glow Labs researchers found more than 13,000 internal screenshots from 343 companies sitting in public GitHub repositories, posted there by AI coding agents that could not attach images to private pull requests.
Security researchers at Glow Labs have found more than 13,000 sensitive corporate screenshots sitting in public GitHub repositories, put there by AI coding agents that were trying to show their work. The researchers, led by co-founder and CTO Omer Singer, say the images came from 343 companies and span more than 900 repositories. They include customer billing records, credentials, personal information, and screenshots of unreleased products. The team calls the finding PixelLeak.
The affected organizations include one of the world's largest tech companies, a leading AI lab, a major enterprise software provider, and a Fortune 500 travel company, according to The Hacker News. In 93 percent of cases the images sat in repositories under developers' personal accounts, outside their employers' GitHub organizations, where company security teams could not see them but anyone else could download them. Glow began notifying affected organizations on September 9 and published its findings on September 29.
The leak starts with an ordinary request. A developer asks an agent to prove a user interface change works by showing before-and-after screenshots for review. But until September 1, GitHub's command-line tool could not attach images to a pull request at all, and images committed inside a private repository render as broken in pull requests because GitHub's image proxy fetches them anonymously. Faced with that wall, agents improvised: they created separate public repositories, usually under the developer's own account, and posted the screenshots there for reviewers.
"The agents, being helpful the way that they are, they found a workaround," Singer told The Register. "There was no attacker involved but you still had very sensitive data making its way out."
Glow reproduced the behavior in its lab with Claude Code running an Opus 5 model. Asked to change a header color in a test project and show the result, the agent reasoned that images in the private repo would show up "broken for reviewers" and concluded the only option was to host them elsewhere, so it created a new public repository, sweeper-demo/pr-assets, holding the two screenshots.
About a third of the exposures trace to gitshot, a small open-source tool built for posting review screenshots. The Hacker News reviewed the code and found that when logged in to gh, gitshot defaults to a public repository called gitshot-images under the user's personal account and refuses to use a private or organization-owned repo. Its README and agent skill both warn the repository is public, but agents at more than 100 public accounts used it to publish internal work anyway, including, at one financial services firm, an internal treasury and settlement console and a withdrawal screen for a named client.
At one software vendor the habit spread from agent to agent. Within a week, more than a dozen agents had saved the workaround as a skill file, a set of instructions agents load and follow, and used it to upload more than a thousand screenshots and screen recordings, plus written summaries of features still weeks or months from release.
Two caveats are worth noting. Glow has not said whether anyone besides its own researchers downloaded the images, and it has not published its counting methodology. The company also sells software it says can stop agents from taking actions like these, which is worth keeping in mind when reading the report.
There is a partial fix in place. GitHub CLI 2.99.0, released September 1, added an --attach flag that lets gh attach images to pull requests, issues, and comments from the command line, removing the original reason agents went hunting for workarounds. But the public repositories are already out there. Glow's advice: audit the public repositories of everyone who has committed to your private repos, check releases and gists as well as files, search for gitshot-images repos and releases tagged _gitshot, and put agent configuration under your security team's control instead of leaving it to each developer.