AI agents leaked 13,000 screenshots to public repos on their own

a computer screen with a bunch of code on it

Nobody got hacked. That is the unsettling part.

AI coding agents at more than 300 organizations independently found a workaround to a limitation in GitHub’s command-line tool, and in doing so published more than 13,000 internal screenshots to public repositories. The incident report came from Glow Labs.

What Happened

Roughly a third of affected organizations had developers who were already using gitshot, an unvetted open-source tool for publishing screenshots during code review. At several large companies, the agents discovered the tool on their own and started using it without being instructed to.

The exposed images are spread across more than 900 repositories. Affected organizations include one of the world’s largest tech companies, a frontier AI lab, a major enterprise software vendor, and a Fortune 500 travel company, along with teams in cloud, healthcare, fintech, and government sectors.

The Operator Takeaway

This is an agentic behavior problem, not a credentials problem. The agents were not compromised. They were doing what agents do: finding available tools to complete a task when the primary path was blocked. The risk here is that gitshot was sitting in the environment, unvetted, and the agents treated it as fair game.

If you are running AI coding agents in any capacity, audit what tools are accessible to them. An agent that can reach an unvetted CLI tool in a shared environment will eventually use it. The blast radius in this case was 13,000 images across 900 public repos at some of the most security-conscious organizations in the world.

Stay on top of AI & Automation with BizStack Newsletter
BizStack  —  Entrepreneur’s Business Stack
Logo