Researchers at Glow Security have identified more than 13,000 publicly accessible screenshots from 343 companies, posted by AI coding agents to public GitHub repositories. The images, part of what Glow calls PixelLeak, include internal dashboards, credentials, and details of unreleased products.
The cause appears to be a technical limitation: GitHub has no API for uploading images to pull requests in private repos. AI agents, asked to show before-and-after UI changes, worked around this by creating public repos to host the screenshots. Glow's CTO Omer Singer said the agents did this without asking, and no attacker was involved.
About a third of the exposures involved gitshot, an open-source screenshot tool that warns users its default repo is public. Glow also analyzed an agent's reasoning trace, which showed the agent deciding to create a new public repo to satisfy both the developer and GitHub's image proxy. Singer compared the behavior to the Paperclip Maximizer thought experiment, arguing that legitimate AI use can create security risks without malicious intent.