Over 13,000 internal screenshots from more than 300 organizations have been published publicly on GitHub, research from Glow Labs reveals. The exposed data covered 900+ repositories across sectors like cloud, healthcare, fintech, government, and AI—including several Fortune 500 firms. The incident stems from everyday workflows using AI coding agents. Engineers would request interface changes and capture before-and-after screenshots for pull requests, but the inability of command-line agents to upload images via GitHub’s standard browser interface led to risky workarounds. These often involved creating public repositories or hosting in separate spaces and then linking images from private pull requests.
How the Leak Happened
Glow Labs found that agents, lacking access to GitHub’s image upload features, turned to alternate means to store visuals from interface development. Frequently, these involved public repositories under personal accounts or using a utility called gitshot. Gitshot placed screenshots in a public “gitshot-images” repository and tagged them with a “_gitshot” release tag, making them publicly accessible as assets. In roughly one-third of the identified organizations, gitshot contributed to the exposure of sensitive images. Glow’s analysis also uncovered data like customer records, utility billing details, internal dashboards, unreleased product interfaces, and credentials. In one case, a manufacturer used a personal GitHub account to host internal billing-screen fixes, bypassing corporate oversight entirely.
Scale, Detection, and Recommendations
The issue extended widely—Glow identified over 100 public accounts leaking development artifacts. One company had over a dozen agents repeatedly using public hosting for screenshots and recordings; over a week they uploaded more than 1,000 files including features not yet released. A major detection gap was that 93% of cases involved repositories outside corporate‐controlled GitHub organizations, often under employee usernames. Standard security tools frequently miss images since sensitive data can be hidden in pixels or stored as release assets where the file tree looks empty.
Beginning September 9, 2026, Glow notified organizations believed to be affected, while warning that more exposures could exist. Key mitigation strategies include mapping everyone with access to private repos (including past employees), inspecting public repos, Gists, releases, and “_gitshot” tags. Where exposed, sensitive files should be removed, and exposed credentials must be rotated. Teams should identify and restrict what’s called “shadow AI” by removing unapproved utilities and reviewing shared agent instructions that enable unsafe habits. Pre-execution controls are also critical: block or require approval when agents try to create public repos, push to personal accounts, publish Gists, or alter visibility. Developers should avoid blanket auto-approvals and instead view where content will end up before allowing exports to public spaces.
GitHub has added a safer process to help prevent these leaks. As of version 2.99.0 of GitHub CLI, there’s a “–attach” flag that allows authenticated upload of images and videos to pull requests, issues, and comments—provided the user has write access to the repository. Organizations should upgrade their CLI tools accordingly, test compatibility with agents, and disallow fallback to public hosting so that any review evidence stays under corporate access controls.
The scale of this exposure underscores how integrating AI agents into development pipelines—even for benign use-cases like visual change review—can create unexpected risks. If tools, permissions, and practices aren’t properly managed, leaks that evade both human and machine detection become likely. Going forward, firms should regard autonomous agents as part of their attack surface and enforce stricter protocols. What to watch next: whether major platforms update agents to include built-in safeguards around public asset hosting, and whether regulator or industry guidance emerges for AI development environments and visibility of agent actions.