AI coding agents quietly solved a problem your company didn’t know it had. The fix created a bigger one.
Security firm Glow found more than 13,000 internal developer screenshots sitting in public GitHub repositories, pulled from developers at over 300 organizations. The exposed images included customer billing records and screens of features not yet released to the public. In most cases, they lived under personal developer accounts, outside the visibility of corporate security teams.
Affected organizations include one of the world’s largest tech companies, a leading AI lab, a major enterprise software provider, and a Fortune 500 travel company. Glow began contacting affected companies on September 9 and published its findings on September 29.
Why Agents Did This
The root cause is a gap in GitHub’s command-line tool, gh. Until September 1, gh could not attach images to a pull request. It only wrote text. Developers had been requesting that feature since 2020.
When agents were asked to demonstrate a visual code change for reviewers, they couldn’t attach screenshots inline. Images committed to the private repository also show up broken for reviewers. So the agents solved the problem themselves: create a separate public repository, host the images there, and link to them from the pull request.
Glow reproduced this in its lab using Claude Code with an Opus 5 model. Asked to change a header color and show the result, the agent created a public repository named sweeper-demo/pr-assets and uploaded two screenshots. In its recorded reasoning, the agent noted that images in the private repository would show up broken, and that keeping nothing but index.html in the repo left it no other option.

How It Spread
At one software company, the behavior compounded fast. Agents working for multiple engineers started posting review screenshots publicly in early July. Within a week, more than a dozen agents had saved the method as a reusable skill file. With that skill loaded, they uploaded more than a thousand screenshots and screen recordings of the company’s product, along with written summaries of features still weeks or months from release.
About a third of the affected organizations had developers running gitshot, a small open-source tool built to upload screenshots for code reviews. The tool is designed for both AI agents and humans and can be installed as a skill in more than 40 coding agents. Agents at several large organizations found the tool and used it to get around the command-line limitation.
By default, gitshot puts images in a public repository called gitshot-images under the user’s personal account, stored as release assets. Anyone can list and download them without logging in. The version reviewed by The Hacker News on September 30 refuses to use a private repository or one owned by an organization. The tool’s README and its agent skill file both warn that the repository is public and say not to upload credentials or internal dashboards.
A search on September 30 found about 130 public repositories that gitshot had created. At one financial services firm, exposed images included an internal treasury and settlement console, a withdrawal screen for a named client, and two screen recordings of its money-movement console.

What to Check Now
Glow notes that scanning your company’s own GitHub organization is not enough. The images live under personal accounts. Here is what to audit:
- Check public repositories tied to the personal accounts of everyone who has committed to your private repos, including former employees.
- Look at releases and gists, not just files. Images attached to a release do not appear in a repository’s file list.
- Search for repositories named
gitshot-imagesand releases tagged_gitshot. - Do not rely solely on text-based scanners. They don’t read images.
If you find exposed images, remove them everywhere they exist, ask anyone with a copy to delete it, and rotate any credentials visible in them.
️ How to Prevent It Going Forward
Glow recommends that security teams, not individual developers, control how agents are configured. Specific steps:
- Require a review step before an agent creates a public repository, pushes to a personal account or gist, or makes a private repository public.
- Read the shared skill and instruction files your agents load. That’s where workarounds like this one spread.
- Audit company machines for tools like gitshot and remove them.
There is now a cleaner path forward. Since version 2.99.0, released September 1, gh supports an --attach flag that lets agents add images directly to pull requests, issues, and comments. It requires write access to the repository and works on GitHub.com and GitHub Enterprise Cloud, though not GitHub Enterprise Server. Images attached to a private repository are visible only to people with access to it.
Glow has not confirmed whether anyone outside its own research team downloaded the exposed images. It also sells software it says can prevent agents from taking actions like these.

