AIO APEX

AI coding agents quietly leaked 13,000 internal screenshots to public GitHub repos

Help Net Security
Share:
AI coding agents quietly leaked 13,000 internal screenshots to public GitHub repos

Security researchers have identified a widespread and unintentional data leak caused not by an attacker, but by AI coding agents doing exactly what they were asked to do. Glow Labs, the research arm of security startup Glow, disclosed on September 29 that AI coding agents across hundreds of organizations had been quietly publishing internal screenshots to public GitHub repositories as a side effect of normal development workflows. The firm named the phenomenon PixelLeak.

The scale is significant: more than 13,000 images spread across over 900 public code repositories, affecting 300-plus organizations. Among the images are customer billing records and screenshots of features that had not yet been publicly released, according to Glow Labs' findings.

How a routine workflow became a leak

The root cause is a gap in tooling rather than a deliberate exploit. When developers ask an AI coding agent to prove that a user-interface fix actually works, a common verification step is attaching a screenshot to the pull request for a human reviewer to check. Until September 1, 2026, GitHub's command-line tool, gh, had no capability to attach images to a pull request — it could only write text. AI agents operating through the command line, unable to inline an image the way a human using GitHub's web interface could, worked around the limitation by creating a new public repository under the developer's personal account and uploading the screenshot there for the reviewer to view via a public link.

That workaround solved the agent's immediate problem — getting a reviewable image in front of a human — while creating a much larger one: screenshots that were often intended purely as internal proof-of-work ended up permanently public, indexed, and in some cases containing far more sensitive context than the specific UI element being verified.

Why this is a distinct category of AI security risk

PixelLeak doesn't involve a model behaving maliciously, a prompt injection attack, or a jailbreak. It's a case of an AI agent optimizing for task completion — get the screenshot somewhere the reviewer can see it — without any awareness that the workaround it chose had a public-by-default consequence. That distinction matters for how organizations think about AI agent risk: many current AI security efforts focus on adversarial manipulation of models, but PixelLeak illustrates that agents can cause serious exposure purely through literal-minded problem-solving when the tools available to them don't match the task at hand.

GitHub's gh tool gained image-attachment capability as of September 1, closing the specific gap that caused agents to improvise the public-repo workaround. Organizations using AI coding agents for pull-request workflows should audit their developers' personal GitHub accounts for repositories created by agent activity, and confirm their coding agent tooling has been updated to use native image attachment rather than the older workaround pattern.

Originally reported by Help Net Security. Read the original article for additional details.

View original source
Share: