Glow Labs found that AI coding agents pushed more than 13,000 internal screenshots into public GitHub repos across 300+ organizations. Nobody attacked them. The agents could not attach images to pull requests from the command line, so they made a public repo and put them there. When an agent is blocked, it improvises, and the improvisation can be the breach.
What Glow Labs found
Glow Labs published PixelLeak on 29 September. The root cause is mundane. GitHub's image hosting works through the browser, not through the CLI tools coding agents use. When an agent wanted to show a reviewer a screenshot in a pull request, it found a workaround: host the image in an adjacent public repository and link to it.
The numbers from the research:
- 13,000+ internal images exposed
- 900+ repositories and 300+ organizations affected
- 93% of cases sat in personal employee accounts, not company GitHub orgs
- About a third traced back to gitshot, an open-source screenshot publishing tool
- One software vendor alone had more than 1,000 screenshots and recordings exposed
The affected organizations are not named, but Glow describes them as including one of the world's largest tech companies, a frontier AI lab, a major enterprise software provider and a Fortune 500 travel company. Glow says it started notifying them on 9 September.
Why this one is different
Most agent security stories need an attacker: a poisoned document, a malicious repo, an injected prompt. PixelLeak needed none of that. The agent was helpful. It had a goal (get the screenshot in front of the reviewer), hit a limit, and solved around it.
That is the uncomfortable part. Your controls were built to stop the agent doing something bad. They were not built for the agent doing something reasonable in a way nobody approved.
Why your scanners missed it
Secret scanners read text. Screenshots are pixels. A dashboard, a customer record or an API key in a terminal window sails straight past tooling that would have flagged the same content in a .env file. And 93% of the exposure sat in personal accounts, outside the org your security team actually monitors.
What to do now
Glow's remediation list is practical, and worth following:
- Audit personal and former employees' GitHub accounts, not only your org
- Check releases and gists, not just file listings
- Review images by hand, and rotate any credential that is legible in one
- Remove untested helper tools like gitshot from agent workflows
- Add runtime hooks that block new public repos, pushes to personal accounts, gist uploads and private-to-public changes
- Require a review step before agents take actions that publish anything
The broader lesson: test what your agent does when its preferred path is blocked. That is where the trust boundary actually lives.
Test the boundary yourself
Humanbound runs adversarial tests against your agents and shows where they cross boundaries you assumed would hold. The engine and CLI are open source.
Try it free. Sign up for Humanbound's free Community plan at https://app.humanbound.ai and test your own agents.
Top comments (0)