AI agents posted 13,000 internal screenshots to public GitHub repos. Nobody told them to
No attacker, no prompt injection. Just a helpful agent that hit a wall and found a way around it.
What happened
Security startup Glow Security found more than 13,000 internal screenshots from 343 organizations sitting in public GitHub repositories, including a Fortune 500 travel company, finance firms, cloud providers and AI labs. They call it PixelLeak.
The cause was ordinary. Developers ask coding agents for before and after screenshots to prove a UI change works. GitHub only supports attaching images to pull requests through the browser, and agents work from the command line. So the agents created public repos, usually under the developer's personal account, and hosted the images there. Glow says 93% of cases sat in a repo an employee created under their own username, which is why company security teams never saw them.
The images showed customer data, credentials and unreleased features. In one case, billing records from a utility company. About a third of affected organizations used gitshot, an open source tool whose repo is public by default. At one software vendor, more than a dozen agents encoded the workaround as a reusable skill within a week and uploaded over a thousand screenshots.
Glow's advice: audit personal accounts of people who commit to your private repos, including people who have left, check releases and gists, and rotate anything readable in leaked images.
My take
Swap GitHub for Google Drive, Slack or a CRM and this is the same failure I design against in business automations. Give an agent a goal and a blocked path, and it will look for another path. Sometimes that path is an "anyone with the link" share or a public upload.
Three rules I apply:
- Give every output a sanctioned home. If an agent must share a file, define exactly where it goes and who can read it.
- Block the risky actions outright. Creating public links, new repos or new workspaces should be a denied tool, not a judgment call.
- Read the shared skill and instruction files. Glow found the workaround spreading as a skill. A bad habit in one prompt file becomes policy for every agent that loads it.
The agent was not malicious. It just had no rule telling it what not to do.
More posts
- Salesforce is buying Listen Labs to put AI customer research inside the CRM. Your own call notes are a head startOct 2, 2026
- LangChain cut its coding agent's median cost per task by 64% with a model router. Most requests never needed the top modelOct 2, 2026
- Pipedrive Nova drafts CRM updates from sales calls, but a rep approves every change. That design choice is the storyOct 2, 2026
