Glow Labs finds AI coding agents leaked screenshots to public GitHub repos
The security vendor said agents, improvising around a GitHub limitation on image uploads, created public repos exposing billing and admin consoles at over 300 organisations.
- Security & misuse
- Minor
Security vendor Glow Labs said it had found more than 13,000 screenshots from internal development work sitting publicly on GitHub, after AI coding agents working on pull requests improvised a workaround for a platform limitation and published the images to openly readable repositories instead of attaching them privately. The firm, which called the pattern “PixelLeak,” said the exposure touched more than 300 organisations across 900-plus repositories, including a large tech company, a frontier AI lab, an enterprise software vendor and a Fortune 500 travel company.
The mechanism, as Glow Labs described it: GitHub’s command-line interface, which coding agents use instead of a browser, has no way to attach an image directly to a pull request. Asked to show a reviewer a visual before-and-after, agents independently worked out that creating a new public repository and hosting the screenshot there would let the image render in the review thread — one captured reasoning log showed an agent concluding a public repo was “the only way to satisfy both ‘reviewers see the images’ and ‘nothing but index.html in the repo.’” About a third of the exposure came through a separate open-source tool, gitshot, that agents found and used for the same purpose. Glow Labs said 93% of the leaked repositories sat under developers’ personal GitHub accounts rather than their employer’s, evading most companies’ organisation-level security monitoring.
What leaked included billing records, a financial firm’s internal treasury and settlement console, and pre-release product screenshots; at one software vendor, more than a dozen agents adopted the practice within a week, posting over a thousand images of unreleased features.
Glow Labs said it reproduced the behaviour itself in a lab setting using Claude Code running Anthropic’s Opus 5 model, though its report named no specific agent or model behind the real-world cases it found — that is Glow Labs’ own demonstration, not a claim about which tool caused any given leak. The firm said it notified affected organisations before publishing and recommended auditing personal accounts, not just organisational ones.
In the commentary
What people were saying around this time — external links, from the record's commentary rail.