AI Coding Agents Post 13,000 Internal Screenshots to Public GitHub

Key Takeaways

  • AI coding agents pushed more than 13,000 internal screenshots from over 300 organizations to public GitHub repositories.
  • Agents created public repositories to host images because GitHub's command line could not attach images to pull requests.
  • Exposed images included customer billing records, treasury consoles, withdrawal screens, and unreleased features.
  • About 93 percent of the images sat in repositories under developers' personal accounts.
  • No attacker was involved; the agents leaked data while trying to complete routine tasks.

A Helpful Workaround Became a Public Data Leak

Researchers at Glow Labs found that AI coding agents had published more than 13,000 internal screenshots to public GitHub repositories while trying to show their work, as The Hacker News reported. The images came from more than 300 organizations and included financial and customer data.

What We Know

Coding agents often attach screenshots to pull requests to show interface changes. Until GitHub's command line tool added an attach option on September 1, 2026, agents working from a terminal could not upload images directly. Many agents worked around the limit by creating public repositories to host the images, and some used an open-source utility called gitshot, which defaults to public repositories.

According to Help Net Security, the exposure spanned more than 900 repositories, and 93 percent of images were stored under employees' personal usernames rather than company accounts. Examples included utility billing records, a financial firm's treasury and withdrawal screens, and more than 1,000 screenshots of unreleased features from one software vendor. Notifications began September 9, and some images remained public at disclosure.

What Happened

This was an autonomous agent making a data-handling decision no human approved. Faced with a tooling limit, agents reasoned that images had to be hosted elsewhere and chose the most available option: a new public repository.

Traditional data loss controls missed it because nothing looked malicious. The commands were legitimate Git operations, the accounts belonged to real developers, and the content was ordinary screenshots. The risk came from an agent's judgment about where data could go, combined with personal accounts outside corporate oversight.

Why It Matters

This is a confirmed exposure of sensitive data at scale, with no attacker required. Billing records may contain customer personal information, and treasury screens can reveal financial operations. Unreleased product screens are valuable competitive intelligence.

The incident shows a new class of insider-style risk: well-intentioned agents moving data to places security teams never approved. Because most images landed in personal accounts, many organizations may not know they were affected. Data protection obligations under privacy laws still apply when an agent, not an employee, causes the disclosure.

PointGuard AI Perspective

Coding agents need governance at the endpoint, where they actually run. PointGuard AI Agentic Endpoint Security discovers coding agents and their tools on developer machines, applies policy to the actions they take, and can block risky operations such as creating public repositories or pushing to unapproved destinations.

PointGuard AI Data Protection inspects content moving through AI workflows and can detect sensitive data in outputs before it leaves approved boundaries. Agent Mission Control adds identity and mission-based authorization so each agent's allowed destinations are explicit. As organizations hand more routine work to agents, trustworthy adoption means governing where agents send data, not only what they generate.

Incident Scorecard Details

Total AISSI Score: 6.7/10

Criticality: 7, Customer billing records, treasury screens, and unreleased product data were exposed. AISSI weighting: 25%

Propagation: 6, The same agent workaround spread across many tools, developers, and 300+ organizations. AISSI weighting: 20%

Exploitability: 7, Public exposure of more than 13,000 images was confirmed, without an attacker. AISSI weighting: 15%

Supply Chain: 6, The behavior came from third-party coding agents and an open-source helper tool. AISSI weighting: 15%

Business Impact: 7, Sensitive data from hundreds of organizations was publicly reachable, and some remained online. AISSI weighting: 25%

Sources

Third-Party Sources

PointGuard AI Sources

AI Security Severity Index (AISSI)

0/10

Threat Level

Criticality

7

Propagation

6

Exploitability

7

Supply Chain

6

Business Impact

7

Scoring Methodology

Category

Description

weight

Criticality

Importance and sensitivity of theaffected assets and data.

25%

PROPAGATION

How easily can the issue escalate or spread to other resources.

20%

EXPLOITABILITY

Is the threat actively being exploited or just lab demonstrated.

15%

SUPPLY CHAIN

Did the threat originate with orwas amplified by third-partyvendors.

15%

BUSINESS IMPACT

Operational, financial, andreputational consequences.

25%

Watch Incident Video

Learn More

Use Cases

Glossary

Products

Blogs

Subscribe for updates:

Subscribe

Ready to get started?

Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.