HomeSecurityAI coding agents expose thousands of corporate images in public GitHub repositories

AI coding agents expose thousands of corporate images to public GitHub repositories

AI coding agents can automate a significant portion of developers’ daily work, but new research highlights a different risk: the inadvertent disclosure of internal company material. According to cybersecurity firm Glow, more than 13,000 internal images and screenshots were found in public GitHub repositories, linked to more than 300 organizations.

Article image: AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

The material wasn’t limited to just code images. The researchers found, among other things, customer billing screens, internal dashboards, unreleased product features, and screen recordings. In several cases, the files were located in personal developer accounts, outside of the companies’ official GitHub infrastructure.

How the problem arose

The root cause seems to lie in a seemingly simple need: developers ask an AI agent to make a change and then present a screenshot of the resultfor code review.

However, according to Glow, command-line agents faced limitations in attaching images to pull requests. Until recently, gh could handle text, but not images in the same way.

See also: GitHub Actions: Critical rollback and solution with commit SHA

So, some agents looked for an alternative solution . Instead of keeping the images in the private repository, they uploaded them to a separate public repository , often in the developer's personal account

The problem is that such an action can bypass company security controls. A repository located under personal account may not be covered by the same policies and monitoring mechanisms as corporate repositories.

GitHub: Over 13,000 images from over 300 organizations

Glow's research shows the scale of the phenomenon. The researchers identified over 13,000 internal images associated with more than 300 organizations.

Among the affected entities, according to the company, are one of the world's largest technology groups, a major AI lab, a major enterprise software , and a Fortune 500 travel company.

In a typical incident, a developer at a large company with more than 100,000 employees asked an AI agent to review a change to an internal billing screen. The agent created a public repository on the developer's personal account and uploaded the screenshots there.

The images contained billing information related to a utility company and remained public when Glow notified the organization.

"Gitshot" adds another risk

Of particular interest is the use of gitshot, a small open-source tool designed for sending screenshots in code review processes.

According to Glow, about a third of the organizations it identified had developers using the tool. Gitshot can be installed as a “skill” in more than 40 AI coding tools.

AI agents - SecNews.gr

The problem is its default behavior. The version reviewed by The Hacker News used a public repository called gitshot-images in the user's personal account. The images were stored as release assets and could be viewed or downloaded offline.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

It is worth noting that the tool itself warns users that the repository is public and recommends that it not be used for credentials or internal dashboards.

The problem can be reproduced from agent to agent

Glow also describes a case where this practice began to spread within a company through so-called skills.

A skill is essentially a set of instructions loaded by an AI agent that determines how it performs specific tasks. According to the research, more than a dozen agents adopted the method of publishing screenshots to public repositories within about a week.

See also: Snowflake: GitHub Actions vulnerability allows command injection

Subsequently, more than 1,000 images and screen recordings, as well as descriptions of features that had not yet been released, were published in this way.

This is especially important for businesses, as an issue doesn't have to be manually repeated by each employee. An incorrect instruction in a shared skill can affect multiple agents and, by extension, multiple developers.

How should companies react?

Glow recommends that security teams not limit themselves to checking official GitHub repositories. They should also examine public repositories, releases, and gists associated with personal accounts of employees, even former employees.

At the same time, it is recommended to search for repositories such as gitshot-images and releases with the tag _gitshot, as well as check corporate computers for tools that can bypass the prescribed procedures.

If exposed material is found, it should be removed and assessed for passwords, tokens, personal data or other sensitive information. Where exposed credentials exist, they should be changed or revoked immediately.

AI coding agents expose thousands of corporate images to public GitHub repositories

GitHub now offers a more secure option

However, there is now an official solution. Since version 2.99.0 of the GitHub CLI, released on September 1, gh supports attaching images to pull requests, issues, and comments via the --attach.

See also: AISI incident: AI created fake GitHub identities to scam developers

The feature can also be used by coding agents, provided they have the necessary permissions. In private repositories, attached files can remain visible only to users who have access to the specific repository.

The case shows that integrating AI agents into software development is not just about code quality. It is also about where data is stored, what permissions an agent has, and what actions it can perform autonomously. For businesses, controlling these capabilities is thus becoming a key part of modern cybersecurity strategy.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS