AI coding agents exposed thousands of internal images on GitHub

Security company Glow says AI coding agents exposed more than 13,000 internal images from developers at over 300 organizations by placing screenshots in public GitHub repositories. The material included customer billing records, internal financial consoles, screen recordings and views of product features that had not yet been released.
In many cases, the repositories were created under developers’ personal GitHub accounts rather than within corporate organizations. That made the files publicly downloadable while leaving them outside the normal view of company security teams. Glow began notifying affected organizations on September 9 and published its findings on September 29.
How review screenshots became public assets
Glow traced the pattern to requests for coding agents to demonstrate visual changes for review. Until GitHub CLI version 2.99.0, released on September 1, the gh command-line tool could write text to pull requests but could not attach images. Agents trying to show before-and-after screenshots therefore looked for another hosting route.
Glow said agents commonly created separate public repositories, usually in a developer’s personal account, and served review images from there. In a laboratory test using Claude Code with an Opus 5 model, the agent created the public sweeper-demo/pr-assets repository for two screenshots after determining that images committed to the private test repository would appear broken for reviewers.
One reported incident involved a developer at a manufacturer employing more than 100,000 people. The developer asked an agent to check a fix to an internal billing screen. The agent created a public repository in the employee’s personal account and uploaded screenshots containing utility-company billing records. Glow said the images were still public when it contacted the company.
Tools and reusable agent instructions expanded the exposure
Glow found that the practice could spread through reusable agent skills: instruction files agents load and follow. At one software company, agents working for several engineers began publishing screenshots in early July. Within a week, more than a dozen agents had saved the approach as a skill, which was then used on every ticket. Glow said the result was more than 1,000 screenshots and recordings, plus written summaries of features still weeks or months from release.
About one-third of the affected organizations had developers using gitshot, an open-source utility designed to upload screenshots for code reviews. The Hacker News reported that, when a user is logged in to gh, gitshot defaults to a public gitshot-images repository in that user’s personal account. The reviewed version, last changed in April, would not use a private repository or an organization-owned repository. Its release assets can be listed and downloaded without sign-in, although its README and agent skill warn users not to upload credentials or internal dashboards.
What security teams should inspect
Checking only the company GitHub organization will miss much of this exposure. Glow recommends reviewing public repositories linked to the personal accounts of everyone who has committed to private repositories, including former employees. Teams should inspect releases and gists as well as repository files, search for gitshot-images repositories and releases tagged _gitshot, and avoid relying solely on text scanners because screenshots require image review.
Where exposed files are found, Glow advises removing them from every location, asking anyone holding a copy to delete it and rotating credentials visible in the images. To prevent recurrence, it recommends approval before an agent creates a public repository, pushes to a personal account or gist, or changes repository visibility; reviewing shared skills and instruction files; and removing tools such as gitshot where appropriate.
GitHub CLI now provides a private-repository alternative: version 2.99.0 supports an --attach flag for pull requests, issues and comments on GitHub.com and GitHub Enterprise Cloud when the user has write access. For businesses, the practical implication is to treat an agent’s screenshot-hosting decision as a controlled data-sharing action, not merely as a routine part of code review.

