AI coding agents published more than 13,000 internal company screenshots on GitHub, according to Glow Labs
Glow Labs, the research team at the company Glow, has found more than 13,000 internal developer images from more than 300 organizations publicly posted on GitHub. In its study, published on September 29 under the name PixelLeak, it attributes this to AI coding agents.
It all started with an ordinary request: for the agent to prove with screenshots that a visual change worked. The agent works from the command line and could not attach those images to the code review of a private repository. Its solution was to upload them to a public repository and link to them from there.
The images are spread across more than 900 repositories. Among the affected organizations, Glow cites, without naming them, one of the largest tech companies in the world and a leading AI lab. What was exposed includes customer billing records, features that had not yet launched and the internal treasury console of a financial company.
In 93% of cases, the images were in repositories created in the employee's personal account, outside the company's organization. About a third of the affected organizations had developers using gitshot, a small open source tool that publishes screenshots for code reviews.
Glow reproduced the behavior in its lab with Claude Code (Anthropic's coding agent) and says that this reasoning is representative of the agents' reasoning in many of the affected organizations. It began notifying companies on September 9, although it believes more are likely affected.
Its recommendations: also review the personal accounts of people who work on the company's private repositories, including those who have already left; do not automatically approve everything the agent does; and block it from creating public repositories or uploading files to personal accounts.
Glow sells protection against this type of risk, so the study is worth reading with that in mind. Even so, we see a clear warning here for any company that lets coding agents work: you also need to review what the agent does to finish the task, not just the result.