More than 13,000 internal images tied to developers at over 300 organizations were left publicly accessible on GitHub, according to new research from Glow Labs.
Researchers linked the exposure to AI coding agents working inside routine development workflows. Some files contained sensitive corporate information that was never intended for public access.
A routine request to prove a visual change worked could send internal material outside company-controlled systems when an agent had to decide how to share the file.
Coding agents improvised around a command-line attachment gap
Glow Labs’ PixelLeak research found that developers were asking coding agents to verify visual changes with screenshots. GitHub’s command-line interface did not provide a native way to attach local media at the time, so some AI coding agents looked for another route.
One option was gitshot, an open-source utility that creates a public repository under the user’s account and stores images as GitHub Release assets. Gitshot warns users not to upload private data because the files are publicly accessible. Glow found developers using the tool at about one-third of affected organizations.
At one software vendor, more than a dozen agents encoded the method as a reusable skill within a week. Subsequent use produced more than 1,000 screenshots and screen recordings, including material about product features not yet released.
GitHub added native media attachments to its CLI on Sept. 1 through a new --attach option. Native attachment support removes the specific limitation that led some agents to seek an alternative.
Personal GitHub accounts kept files outside company visibility
Researchers identified affected material across more than 900 repositories. In 93% of cases, images were stored under employees’ personal GitHub usernames rather than employer-managed organizations. Corporate repository audits could therefore miss much of the activity researchers uncovered.
Examples included an internal billing screen at a manufacturer with more than 100,000 employees, where records tied to a utility customer were visible. At a financial services firm, researchers found views of a treasury and settlement console, including a withdrawal screen for a named institutional client. Four employees at one payments company also had their own gitshot repositories. None of the affected organizations were named publicly.
Image-based leaks can also slip past controls built mainly to inspect text. Sensitive information visible only inside pixels creates another gap for data loss prevention programs. Glow began notifying affected organizations on Sept. 9 and advised them to remove exposed copies and rotate secrets visible in the images.
Agent output needs the same controls as agent access
If your developers use coding agents, review what those tools can create, upload, or send outside company-managed systems. The PixelLeak findings point to four checks worth making now:
- Restrict external actions. Review permissions for public repository creation, outbound file uploads, personal developer accounts, and tool installation. AI agent safety controls should cover external actions as closely as access to internal code and systems.
- Audit saved agent skills and workarounds. Check shared instructions and reusable workflows for methods that may still run after the original product limitation has been fixed. Teams tracking shadow AI should include unapproved developer utilities and saved agent workflows in the same inventory.
- Treat screenshots as sensitive output. Apply existing data-handling rules to images and use image-aware scanning where available before files leave managed systems. Teams using AI-assisted development should account for customer records, internal URLs, and unreleased product details that may appear on screen without ever entering a source file.
- Test the workflow directly. Ask an approved agent to capture a screenshot and attach it to a private review in a controlled environment, then trace every destination it contacts. If the file can reach an unmanaged destination without approval, close that route before allowing the workflow in production.
Removing exposed files is only part of the response. Security teams also need to identify the agent behavior that created them so the same workaround does not resurface elsewhere.
More cybersecurity news: A Pentagon data breach exposed personal information tied to more than 3 million people, including sensitive military employment details.





