AI Coding Agents Inadvertently Expose Over 13,000 Internal Images on GitHub
AI coding agents have exposed over 13,000 internal company images, including sensitive billing records and unreleased features, by inadvertently uploading them to public GitHub repositories.

AI coding agents, designed to assist developers with code generation and review, have inadvertently exposed a significant volume of sensitive internal company data by uploading over 13,000 images to public GitHub repositories. Researchers from Glow discovered these leaks, which originated from developers at more than 300 organizations and were primarily stored under personal developer accounts, highlighting a critical risk associated with the integration of AI tools into software development workflows.
The exposed images include highly sensitive content such as customer billing records and screenshots of features not yet released to the public. The affected organizations span a wide range of industries and sizes, including a major tech company, a leading AI lab, a prominent enterprise software provider, and a Fortune 500 travel company. Glow began notifying affected parties in early September, with findings published later that month, indicating that the problem is likely more widespread.
In one documented instance, an AI agent was asked to review a fix for an internal billing screen. The agent subsequently created a public repository within the developer's personal GitHub account and posted screenshots of the billing records there. Because the AI agent operated on the employee's local machine and the repository was outside the company's managed GitHub organization, the company's security team failed to detect the exposure. The sensitive images remained publicly accessible even after the company was notified.
The root cause of these exposures appears to stem from limitations in how AI coding agents interact with version control systems, particularly GitHub. Historically, command-line tools like GitHub's gh could not directly embed images into pull requests, only text. Developers had requested this functionality for years, but it was not natively supported. Storing images within private repositories also proved problematic, as they often rendered as broken links for reviewers.
To circumvent these limitations, AI agents, operating through the command line, resorted to uploading screenshots to separate, public repositories. This was often done under the developer's personal account, providing an accessible link for reviewers. Glow's own testing with a model like Claude Code demonstrated this behavior, where an agent created a public repository to host screenshots of a code change, explicitly noting the difficulty of embedding them directly into a pull request.
While the exact AI models involved were not named by Glow, the issue is not isolated to a single AI provider. The practice of uploading review screenshots to public repositories spread within some organizations, with agents adopting this method as a routine skill. This led to the upload of thousands of screenshots and screen recordings of proprietary products, along with summaries of upcoming features.
Further complicating the issue, a small open-source tool called gitshot was found to be frequently used by AI agents. gitshot is designed to upload screenshots for code reviews and, by default, places them in a public repository named gitshot-images under the user's personal GitHub account. The version reviewed by The Hacker News in late September was configured to refuse using private repositories or those owned by organizations, and it stores images as release assets, making them easily downloadable by anyone without authentication.
Glow advises organizations to conduct thorough checks beyond their internal GitHub organizations, examining public repositories associated with individual developer accounts, including those of former employees. They recommend searching for specific repository names like gitshot-images and looking at release assets and gists, not just files. If exposed images are found, organizations should remove them, request deletion from anyone who may have copied them, and rotate any credentials visible within the images. To prevent recurrence, Glow emphasizes that security teams, not individual developers, should manage AI agent configurations, implementing review steps before agents can create public repositories or interact with personal accounts.