Protect.Computer
NEWS

AI Coding Agents Posted 13,000 Internal Screenshots to Public GitHub

· 2 min read · Data hijack Privacy tracking
AI Coding Agents Posted 13,000 Internal Screenshots to Public GitHub

Security company Glow reports that AI coding agents, asked to show reviewers a before-and-after screenshot of a code change, have been publishing internal company images in public GitHub repositories. It found more than 13,000 images from developers at over 300 organizations, including customer billing records, a treasury and settlement console, and screens of unreleased features. Most sat under developers’ personal GitHub accounts, which company security teams do not monitor, and anyone could download them without logging in.

The cause is a workflow gap. Until September 1, GitHub’s gh command-line tool could not attach images to a pull request, and screenshots stored in a private repository show up broken for reviewers. Agents working through the command line improvised: they created a separate public repository under the developer’s account and linked the images from there. At one software company the habit spread between agents through a shared “skill” file, and more than a thousand screenshots and recordings were posted. About a third of the affected organizations had developers using gitshot, an open-source tool that, by default, uploads images as release assets to a public gitshot-images repository; The Hacker News found roughly 130 such repositories on September 30. Glow, which sells agent-control software, has not said whether anyone outside its own researchers downloaded the images, and has not published how it found them. GitHub CLI 2.99.0 (September 1) now supports an --attach flag for pull requests, issues and comments.

How to check if you’re affected

Affected products are any developer workstation where an AI coding agent or the gitshot tool can use a logged-in gh session, plus the personal GitHub accounts of everyone who has committed to your private repositories, including people who have left.

  • Search those personal accounts for public repositories named gitshot-images and for releases tagged _gitshot. Images attached to a release do not appear in a repository’s file list, so check releases and gists too.
  • Do not rely on secret scanners alone; they read text, not images.
  • If you find exposed images, delete them everywhere, ask anyone holding a copy to delete it, and rotate any credentials visible in them.
  • Check machines for gitshot, review the shared skill and instruction files your agents load, and require approval before an agent creates a public repository, pushes to a gist, or makes a private repository public.
  • Update to GitHub CLI version 2.99.0 or later so agents have a supported way to attach images; it needs write access to the repository and is not available on GitHub Enterprise Server.

Sources

Related reading