- Security firm Glow found more than 13,000 internal images from over 300 organizations publicly stored on GitHub, spanning more than 900 repositories
- In 93% of cases, images were stored under developers‘ personal GitHub accounts rather than company organizations, which kept security teams from noticing
- Developers at about one third of affected organizations used the open source tool gitshot, letting AI agents bypass the command line tool‘s inability to attach images
On this page
- Agents turned to public repositories after failing to attach screenshots
- Over 300 organizations affected, including billing records and unreleased features
- Open source tool gitshot spread the problem across multiple organizations
- A workflow became a shared agent ‘skill‘ within a week
- GitHub has introduced a new way to attach images
- What to do now
- FAQ
- Sources
Agents turned to public repositories after failing to attach screenshots
According to Glow‘s PixelLeak report, when developers asked AI coding agents to submit before-and-after screenshots of code changes for review, the agents found that GitHub‘s image display feature, built for web-based review, was not accessible through the command line.
Glow reproduced the situation in a lab using Claude Code with the Opus 5 model, asking the agent to change the title colour of a Minesweeper test project and show the result. The agent‘s internal reasoning logs showed that images in a private repository would ‘appear broken to the reviewer,‘ so the agent concluded that ‘the only way to satisfy both [letting the reviewer see the image, and keeping the repository to just index.html] is to store the images elsewhere,‘ and created a public repository named sweeper-demo/pr-assets.
Over 300 organizations affected, including billing records and unreleased features
Glow said the leak involved more than 900 public repositories, affecting companies with over 100,000 employees combined, across industries including cloud, healthcare, fintech, government, frontier AI and AI security, including several Fortune 500 companies.
At a manufacturer with over 100,000 employees, a developer asked an agent to verify a patch to an internal billing screen. The agent then created a public repository under that developer‘s personal GitHub account and uploaded screenshots showing billing records belonging to a utility company. Because the agent ran on the employee‘s laptop and the repository sat outside the company‘s GitHub organization, the security team did not notice. The images remained public until Glow notified the company.
Open source tool gitshot spread the problem across multiple organizations
Glow said developers at about one third of affected organizations used the open source tool gitshot, and at several large organizations, AI agents found and used this tool to bypass the command line tool‘s inability to attach screenshots.
The Hacker News, after reviewing gitshot‘s code on Sep 30, reported that the tool, once a user logs into gh, by default stores images in a public repository named gitshot-images under that user‘s personal account. The version reviewed, last updated in April, refused to use private or organization-owned repositories. The same report found about 130 public repositories created by gitshot through a search conducted that day.
Glow found more than 100 public accounts leaking internal work through gitshot, including one at a financial services company where images showed internal treasury and settlement systems, a withdrawal screen for a named institutional client, and two screen recordings of a funds flow dashboard.
A workflow became a shared agent ‘skill‘ within a week
Glow said that at one software vendor, an agent serving multiple engineers began publicly posting review screenshots in early July. Within a week, more than ten agents had written this practice into a ‘skill‘ (an instruction file that agents load and follow), used for every development ticket.
Agents using this skill uploaded more than a thousand screenshots and screen recordings showing the company‘s product, along with text summaries of features that were weeks to months away from release.
GitHub has introduced a new way to attach images
According to The Hacker News, citing GitHub‘s release notes, GitHub‘s gh command line tool, starting with version 2.99.0 released on Sep 1, 2026, added an --attach parameter that lets images be attached directly to pull requests, issues or comments, a feature developers had requested since 2020.
GitHub said AI coding agents can also use this parameter, but they need repository write access, and it only works on GitHub.com and GitHub Enterprise Cloud, not GitHub Enterprise Server.
What to do now
- Check the personal GitHub accounts of everyone who has submitted code to private repositories, including former employees, rather than only reviewing the company organization itself (Glow found 93% of cases stored images under personal accounts)
- Also check GitHub releases and gists, since images attached to releases do not appear in file listings
- Search for repositories named gitshot-images and releases tagged _gitshot
- Do not rely only on scanning tools, since they read text rather than image content
- If leaked images are found, remove them from every location where they are stored, ask anyone holding copies to delete them, and rotate any credentials identifiable in the images
- Require security teams, rather than individual developers, to set consistent rules for how AI agents operate, with approval steps to prevent agents from creating public repositories on their own, pushing to personal accounts or gists, or turning private repositories public
- Check company devices for tools such as gitshot and remove them
- Consider upgrading to GitHub‘s gh command line tool version 2.99.0 or later and use the --attach parameter to attach review images
FAQ
What are the AI coding agents mentioned in this incident?
AI coding agents are [AI agents](/glossary#ai-agent) that can automatically make code changes, commit them, and interact with platforms such as GitHub. Developers ask them to attach screenshots for human review of the changes.
Has anyone downloaded these leaked images?
According to The Hacker News‘ report, Glow did not state whether anyone other than its own researchers had downloaded the images.
Did this problem only occur at organizations using Claude Code?
No. Glow said the agents in actual cases came from several different AI models, which it did not name. Claude Code with the Opus 5 model was only the example Glow used to reproduce the problem in its lab.
Did all affected organizations use the gitshot tool?
No. According to Glow‘s report, developers at about one third of affected organizations had installed and used gitshot. At the rest, agents created public repositories to store screenshots through other means on their own.
Has GitHub introduced a fix?
Yes. According to the report, citing GitHub‘s release notes, GitHub‘s gh command line tool, starting with version 2.99.0 released on Sep 1, 2026, added an --attach parameter that lets images be attached directly to pull requests without creating a public repository.



