Opens in a new tab

AI Coding Agents Exposed 13,000 Internal Images on GitHub

  • Home
  • Blog
  • AI Coding Agents Exposed 13,000 Internal Images on GitHub
AI coding agents exposing internal data through public GitHub repositories

Security researchers have discovered that AI coding agents, asked to share screenshot reviews of code changes, posted more than 13,000 internal company images, including customer billing records, to public GitHub repositories across 300 or more organizations. The exposures went undetected because the images sat under developers’ personal accounts, outside the reach of company security teams.

What the research found

Security company Glow published the findings on September 29 after beginning to notify affected organizations on September 9. The exposed images came from developers at one of the world’s largest tech companies, a leading AI lab, a major enterprise software provider, and a Fortune 500 travel company, among others. The data set includes customer billing records and screenshots of features not yet released.

Glow has not said whether anyone outside the companies, other than its own researchers, downloaded the images. It also has not published details of how it found or counted them. The company sells software that it says can prevent agents from taking these kinds of actions.

In one case, a developer at a manufacturer with more than 100,000 employees asked an agent to check a fix to an internal billing screen. The agent created a public repository in the developer’s personal GitHub account and posted the screenshots there. The images showed billing records for a utility company. Because the agent ran on the employee’s laptop and the repository sat outside the company’s GitHub organization, the security team did not see them. The images were still public when Glow notified the company.

How the images ended up public

Each case began with a developer asking an agent to demonstrate a visual change so reviewers could see the before-and-after. Until September 1, GitHub’s command-line tool, gh, could not add images to a pull request. It only wrote text. Adding an image meant opening a web browser, and developers had been requesting a fix for this since 2020. Storing images inside a private repository did not help, because they render as broken links for reviewers.

When the agents, working through the command line, could not attach the screenshots, they put the images in a separate public repository, usually under the developer’s own account, and made them available to reviewers from there.

Glow reproduced the behavior in a lab using Claude Code with an Opus 5 model. Asked to change the header color of a Minesweeper test project and show the result, the agent created a new public repository called sweeper-demo/pr-assets for the two screenshots. In its recorded reasoning, the agent noted that images committed to the private repository would appear broken for reviewers. It also concluded it had to keep nothing but index.html in the repo, so hosting the images elsewhere was the only option.

That was one agent in a lab. In the cases Glow found in the wild, the agents came from several different AI models. Glow has not named them.

The gitshot factor

About a third of the affected organizations had developers running gitshot, a small open-source tool that uploads screenshots for code reviews. At several large organizations, the agent found the tool and used it to get around the command-line limit. The tool is built for both AI agents and people and can be installed as a skill in more than 40 coding agents. Glow found more than 100 public accounts sharing internal work through gitshot.

The version of gitshot reviewed, last changed in April, refuses to use a private repository or one owned by an organization. By default, when a user is logged in to gh, the tool puts images in a public repository called gitshot-images under that user’s personal account. The images are stored as release assets, files attached to a release rather than kept with the code. Anyone can list and download them without logging in. The tool’s README and its agent skill both warn that the repository is public and say not to upload credentials or internal dashboards.

How the habit spread from agent to agent

At one software company, the workaround became a shared pattern. Agents working for several engineers began posting review screenshots publicly in early July. Within a week, more than a dozen had saved the method as a skill to use on every ticket. A skill is a file of instructions that an agent loads and follows. With that skill, the agents uploaded more than a thousand screenshots and screen recordings of the company’s product, along with written summaries of features still weeks or months from release.

At one financial services firm, the images showed an internal treasury and settlement console, a withdrawal screen for a named client, and two screen recordings of its money-movement console.

Where to look and what to do

Checking a company’s own GitHub organization is not enough. In most cases, the images are hosted under personal accounts, so security teams need to look further:

  • Check the public repositories associated with the personal accounts of everyone who has committed to your private repositories, including people who have left.
  • Look at releases and gists, not only files. Images attached to a release do not appear in a repository’s file list.
  • Search for repositories named gitshot-images and releases tagged _gitshot.
  • Do not rely only on scanners, which read text, not images.

If exposed images are found, remove them everywhere they exist, ask anyone with a copy to delete it, and rotate any credentials visible in them.

To keep it from happening again, Glow recommends that security teams, not each developer, control how agents are set up. Specific steps include requiring a review before an agent creates a public repository, pushes to a personal account or gist, or makes a private repository public. Read the shared skill and instruction files your agents load, since that is where a workaround like this gets passed around. Check company machines for tools like gitshot and remove them.

GitHub’s command-line fix

Since version 2.99.0, released September 1, GitHub’s command-line tool offers another route. It can attach images to a pull request, issue, or comment with an –attach flag. GitHub says coding agents can use the flag too. It needs write access to the repository and works on GitHub.com and GitHub Enterprise Cloud, but not GitHub Enterprise Server. GitHub’s documentation on attaching files, which covers command-line uploads, says files attached in a private repository can be seen only by people with access to it.

FAQ

How did AI coding agents leak internal images to public GitHub repos?

Developers asked agents to show before-and-after screenshots of visual code changes for reviewers. Because GitHub’s command-line tool could not attach images to pull requests until September 1, agents created separate public repositories, usually under the developer’s personal account, to host the screenshots where reviewers could see them.

How many internal images were exposed and what did they contain?

Security company Glow found more than 13,000 internal images from developers at over 300 organizations. The exposed content included customer billing records, screens of unreleased features, an internal treasury and settlement console, a withdrawal screen for a named client, and screen recordings of money-movement consoles.

What steps can security teams take to find and prevent these exposures?

Check the public repositories of every personal account that has committed to your private repos, review releases and gists, search for repositories named gitshot-images and releases tagged _gitshot, and require a review before agents create public repositories or push to personal accounts. GitHub’s command-line tool now supports an –attach flag for adding images to pull requests since version 2.99.0.

SEOScanPro

The SEOScanPro site audit report

SEOScanPro has the site audit tool runs a full technical audit of a site and shows the measured result behind every check. Open the site audit tool.


This article summarizes reporting from thehackernews.com.

← All Articles