AI coding agents have exposed more than 13,000 internal images from developers at more than 300 organizations by uploading screenshots and screen recordings to public GitHub repositories, according to security company Glow.

The exposed images reportedly included customer billing records, internal dashboards and details of unreleased products and features. The affected organizations include a major technology company, a leading AI lab, a large enterprise software provider and a Fortune 500 travel company.

Glow said it began contacting affected organizations on September 9 before publishing its findings on September 29. In one case, a developer at a manufacturer with more than 100,000 employees asked an AI coding agent to review an internal billing screen. The agent created a public repository under the developer’s personal GitHub account and uploaded screenshots showing utility company billing records. The company’s security team did not detect the exposure until Glow reported it.

Glow said it has not determined whether anyone other than its researchers downloaded the exposed images. The company also has not disclosed exactly how it identified and counted the images. Glow sells security software designed to prevent AI agents from taking similar actions.

The issue appears to have started when developers asked coding agents to provide before-and-after screenshots showing visual changes to their work. Until September 1, GitHub’s command-line tool did not support attaching images directly to pull requests, leaving AI agents looking for alternative ways to share screenshots.

Glow reproduced the behavior using Claude Code and Opus 5 while making a simple Minesweeper interface change. The agent created a separate public repository to host screenshots because images stored in a private repository could appear broken to reviewers.

READ
Meta Denies Muse AI Agent Read Private Messages Without Permission

In one software company, the workaround reportedly spread between AI agents. More than 12 agents saved the method as a reusable skill in early July and subsequently uploaded more than 1,000 screenshots and screen recordings containing summaries and details of unreleased features.

Glow also found that around one-third of the affected organizations had developers using gitshot, an open-source tool designed to upload screenshots. The tool can be installed as a skill across more than 40 coding agents and is intended for both developers and AI agents.

At several large organizations, AI agents discovered and used the tool. Glow found more than 100 public accounts sharing internal work through gitshot. At one financial services company, exposed images reportedly showed an internal treasury and settlement console, a client withdrawal screen and recordings of a money-movement console.

The Hacker News reviewed gitshot’s code on September 30 and found that, by default, when a user is authenticated with GitHub’s CLI, the tool uploads images to a public repository called gitshot-images under the user’s personal account. The reviewed version also refused to use private or organization-owned repositories. Images were stored as release assets and could be accessed without authentication.

Gitshot’s documentation and agent instructions warn users that the repository is public and advise against uploading credentials or internal dashboards. However, the incident highlights how AI agents can follow technical instructions without fully understanding the security implications of where sensitive screenshots are being published.

READ
Elementor WordPress Flaw Could Let Hackers Create Admin Accounts

Security teams should therefore look beyond their company’s official GitHub organization when investigating possible exposure. Public repositories connected to personal accounts belonging to current and former employees can also contain internal material. Releases and gists should be checked alongside repository files, while searches for names such as gitshot-images and _gitshot may help identify potential exposures.

If sensitive images are discovered, organizations should remove them from public locations, ask anyone who may have downloaded copies to delete them and rotate any credentials or secrets visible in the images.

GitHub has since introduced a safer option. Version 2.99.0 of the GitHub CLI, released on September 1, added an --attach option that allows images to be attached directly to pull requests, issues and comments. The feature requires repository write access and works with GitHub.com and Enterprise Cloud, although it is not available for Enterprise Server. GitHub says attachments in private repositories can only be viewed by authorized users.


Buy ExpressVPN with PayPal or Credit Card

For organizations using AI coding agents, Glow recommends controlling how agents are configured and requiring human review before an agent creates a public repository, pushes content to a personal account or gist, or changes a private repository to public. Security teams should also review shared agent skills and instruction files and check company devices for tools such as gitshot.

Advertisement