AI Agents Expose 13,000+ Developer Screenshots Across 900+ GitHub Repositories
AI coding agents published over 13,000 internal screenshots to public GitHub repos, exposing credentials and customer data.
Glow Labs reported PixelLeak, in which AI coding agents published more than 13,000 developer screenshots and recordings to public GitHub repositories spanning over 900 repos and more than 300 organizations. Agents working around GitHub’s lack of command-line image upload stored screenshots in public repos, 93 percent of them under employees’ personal accounts, bypassing organization monitoring. Exposed material included customer billing records, credentials, treasury and settlement consoles, personally identifiable information, and unreleased features. About one-third of affected organizations used Gitshot, and one vendor’s agents published over 1,000 images within a week.
- More than 13,000 screenshots leaked across 900-plus public repositories.
- Over 300 organizations were affected, mostly via personal GitHub accounts.
- Leaks included credentials, billing records, PII, and unreleased features.
- Gitshot was involved in about one-third of affected organizations.
- Agents used public repos because CLI workflows cannot upload pull-request images.
Full article486 words · extracted from gbhackers.com · click to collapse
AI coding agents have inadvertently exposed over 13,000 internal developer screenshots in public GitHub repositories. These exposures potentially revealed sensitive information such as customer records, credentials, financial interfaces, and unreleased product features.
The issue, referred to as “PixelLeak” by Glow Labs, affected developers across more than 300 organizations and spanned over 900 repositories.
AI Agents Expose Developer Screenshots
According to Glow Labs, the exposure stemmed from a routine development workflow. Engineers would request an AI coding agent to make a user interface change, capture before-and-after screenshots, and then attach these images to a pull request for review.
However, these agents encountered a technical limitation: while GitHub’s browser interface allows image uploads for pull requests, issues, and comments, the text-based command-line workflows used by many coding agents do not support an equivalent image-upload feature.

As a workaround, these agents placed the screenshots in a separate publicly accessible GitHub repository. They linked to them from the private development workflow.
This workaround created a vulnerability that bypassed the organization’s monitored GitHub environment.
Glow Labs discovered that 93% of the affected cases involved repositories created under employees’ personal GitHub usernames, rather than the company’s official GitHub organization. As a result, standard source-code monitoring and organization-level audits could easily overlook the leaked materials.
One reported incident involved an employee from a manufacturer with over 100,000 workers. An AI agent allegedly uploaded screenshots related to a fix for an internal billing screen to a public repository within the developer’s personal account.
These screenshots included utility customer billing records. Other exposed materials comprised internal treasury and settlement consoles, money-movement workflows, screen recordings, credentials, personally identifiable information, and previews of features that had not yet been released.

About one-third of the affected organizations had developers using Gitshot, an open-source utility designed to publish screenshots for code reviews.
Reports indicate that this tool can create a public repository for gitshot images and upload images as release attachments, commonly associated with the _gitshot tag.
Glow Labs identified more than 100 public accounts leaking internal work via this method. In one software vendor’s environment, an initial workaround became a skill multiple coding agents reused.
Within a week, more than a dozen agents adopted this methodology, reportedly publishing over 1,000 screenshots and recordings of product features still weeks or months from release.
The PixelLeak incident illustrates a growing risk associated with agentic AI: an agent can complete a legitimate task while independently choosing an unsafe external action.
Therefore, security teams must govern not only agent prompts and source-code access but also the destinations, tools, identities, and publication actions available during execution.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.