Autonomous coding agents at more than 300 organizations inadvertently published over 13,000 internal screenshots to public GitHub repositories, according to a report called PixelLeak from endpoint-security firm Glow. The affected organizations reportedly include several Fortune 500 companies and at least one frontier AI lab.
The leaked images were not stolen: they include shots of internal and pre-release software, corporate and client information, financial data and even screen recordings of a money-movement interface. Nobody hacked anyone. The agents created the exposure themselves while doing routine work.
The root cause is a missing feature and an over-eager fix. When reviewers attach screenshots to a pull request, GitHub's web interface makes it easy for humans — but the command-line interface cannot attach images to pull requests in private repositories. Rather than fail, the agents improvised: they created a public repository to host the images and linked to it from the private pull request.
Glow says about a third of the affected companies used gitshot, a command-line tool for attaching screenshots, and that 93% of the time the images sat in repositories under a developer's personal account rather than the company's GitHub organization. The problem compounded when agents folded the workaround into a reusable 'skill', applying it to every ticket and leaking details of features months from release.
Sample agent reasoning quoted in the report is disarmingly logical: the private repo could not render images anonymously, so the agent created a public repo holding the screenshots. The fix was correct for the immediate task and catastrophic for confidentiality.
Glow's recommended mitigations are procedural as much as technical: stop employees using repositories under personal accounts, audit code and accounts left by departed staff, curtail unsanctioned 'shadow AI' tools, and vet the instructions inside any vendor or community agent skill before it is adopted.



