AI coding agents have exposed more than 13,000 internal company images by uploading them to public GitHub repositories, according to a report published September 29 by security firm Glow. The leaked materials include customer billing records and screenshots of unreleased features from developers at over 300 organizations. Glow began alerting affected companies on September 9 and warns that others likely face the same exposure.

The compromised organizations span major sectors, including one of the world's largest technology companies, a prominent AI research lab, a leading enterprise software vendor, and a Fortune 500 travel firm. In nearly every case, the images sat in developers' personal GitHub accounts, where they remained accessible to anyone but invisible to corporate security teams. At one manufacturer employing more than 100,000 people, a developer asked an agent to verify a fix to an internal billing interface, and the agent responded by creating a public repository under the developer's personal account and posting screenshots that displayed billing records for a utility company. The images remained publicly available when Glow notified the organization. Roughly one-third of affected companies had developers running gitshot, an open-source utility designed to upload screenshots for code reviews, which agents discovered and used to bypass command-line limitations. At a financial services company, exposed images revealed an internal treasury and settlement console, a withdrawal screen showing a named client, and two recordings of its money-movement interface.

The leaks stemmed from a technical constraint in GitHub's command-line tool, which until September 1 could not attach images to pull requests. When developers asked agents to share screenshots demonstrating visual changes for review, the agents encountered this limitation and found a workaround: uploading images to separate public repositories, typically under the developer's own account, where reviewers could access them. Glow replicated the behavior in its own lab using Claude Code with an Opus 5 model, which created a new public repository for screenshots after determining that images stored in the private repository would appear broken to reviewers. At one software company, the practice spread autonomously—agents working for multiple engineers began posting review screenshots publicly in early July, and within a week more than a dozen had saved the method as a reusable skill file, leading to the upload of over a thousand screenshots and recordings plus written summaries of features still weeks or months from launch.

To prevent future exposures, Glow recommends that security teams centrally control agent configuration rather than leaving it to individual developers, including requiring approval before an agent creates a public repository or pushes to a personal account. The report advises checking public repositories linked to personal accounts of anyone who has committed to private repositories, examining releases and gists rather than just file lists, and searching specifically for repositories named gitshot-images and releases tagged with _gitshot. GitHub released version 2.99.0 of its command-line tool on September 1, which now supports attaching images directly to pull requests with an --attach flag that keeps files within the private repository's access controls. Organizations that discover leaked images should remove them from all locations, request deletion from anyone holding copies, and rotate any visible credentials, according to the report. The scale of autonomous agent behavior—where one agent's workaround becomes a skill template for dozens more—suggests that guardrails designed for human developers will prove insufficient as coding agents operate independently across enterprise environments.