Developer working on keyboard showing AI coding agents data leak

AI Coding Agents Habitually Leak Thousands of Private Developer Screenshots to Public Repositories

New research from cybersecurity firm Glow Security documents a new category of leak that is widespread and impacts multiple leading AI coding agents.

“PixelLeak” is a tendency of these agents to post screenshots of private developer work-in-progress to public repositories. The issue stems from a limitation in GitHub that prevents the AI coding agents from displaying side-by-side before and after images from a private repository, something that coders sometimes request while working. The agents appear to have hacked out a workaround to that limitation, but the workaround instead involves them dumping the screenshots to a public repository first so that they can then be displayed as the coder requested.

AI coding agents dump private screenshots to personal and public GitHub accounts

The research found that at least 343 companies were impacted by the PixelLeak flaw, including several in the Fortune 500. In total the researchers uncovered more than 13,000 screenshots that had been dumped by AI coding agents in this way across over 900 code repositories.

The issue impacts GitHub users. It stems from the fact that GitHub private repositories do not allow the AI coding agents to attach images to a pull request via the command-line tool that they are limited to using. Rather than telling the coder that this is not possible, the agents have a tendency to try to maximize their helpfulness and find an alternative solution on their own. Unfortunately, the answer they tend to hit upon does not take privacy and security considerations into the equation. They will instead dump the requested screenshots to a developer’s personal and public GitHub repository instead, or create an entirely new public repo, which they can then display them to the coder from.

The researchers note that this might not only expose internal works in progress, but also authentication credentials or sensitive personal information. Organizations that were contacted about this by the researchers also did not seem to have previously been aware of the issue, likely due to not actively monitoring personal developer accounts or whatever repos the AI coding agents might create on their own. In some cases the coders were working on their personal laptops, putting them entirely beyond the reach of network security monitoring.

One group of AI coding agents shared this technique as a new “best practice”

As the researchers point out, these screenshot comparisons are a common “last mile” practice for coders. They are done often enough that in some cases, the AI coding agents adopted this dumping as a sort of standardized best practice and shared it amongst themselves. The report recounts a tale of this happening at an unnamed software vendor, where the agents took it upon themselves to start putting screenshots into public repositories in July. Within a week, a dozen agents had made this a standard practice and it was happening with every development ticket. In total the agents posted over a thousand internal screenshots of products in development before the issue was detected.

Ryan McCurdy, VP of Marketing at Liquibase, notes that this requires organizations to keep their eyes open for clumsy agent actions as well as intentional threat actors: “This is exactly why an AI agent doesn’t have to be compromised or malicious to create a security problem. These agents were trying to complete the task they were given. They hit an obstacle, found another way to accomplish the goal, and exposed sensitive information in the process. That’s a very different problem from traditional software. An agent can decide how to accomplish a task, which means enterprises have to think beyond what the agent has permission to access. They also have to decide what actions the agent has the authority to take on its own.”

Test examples displayed in the report use Claude Code Opus 5 to reproduce the issue, but the researchers note it can potentially occur with most of the major coding models. The AI coding agents in general simply have a blind spot in this area, not recognizing that the screenshots they dump may contain sensitive and private information and thus cannot be stored in a publicly accessible place.

In about a third of these instances, the coders were unwittingly making it even easier for malicious actors to find what the AI coding agents were dumping in public. This group of coders was using the open source tool “gitshot”, which is designed specifically for publishing screenshots of code review. When this tool is used it affixes a “_gitshot” tag to each image, which is relatively easy to search for.

Glow Labs began directly notifying impacted parties on September 9, but cautions that it likely did not identify all of the organizations out there that are experiencing this issue (and may well still not be aware of it). The issue will require various developers to make tweaks to their AI coding agents, and when (and if) that will happen is unpredictable.

In the meantime, the researchers provide a list of recommended mitigations that will help prevent agents in use from dumping screenshots to the public. These include reviews of both employee personal GitHub repos and those of former staff (to include releases and gists), ensure that agents are not granted blanket auto-approval, monitor the shared rule and instruction files the agentic tools load to ensure one agent that hit upon this brilliant scheme is not passing it along to other ones, and check endpoints for relevant packages like gitshot. Context-aware runtime protection that steps in for pushes to a personal account or new public repositories can also be extremely helpful.

Darin Fredde, Sr. Director of Technical Marketing Engineering at Ridge Security, adds: “As organizations give agents more autonomy, we need to test the entire path: the model, tools, permissions, data access, and the environment in which the agent operates. The question isn’t only whether an agent can complete its task, but what it is willing and able to do to complete it. That’s where continuous offensive testing becomes increasingly important.”