More than 13,000 internal images from over 300 organizations were published to GitHub by AI agents, according to an investigation by Glow Labs called PixelLeak. The breach exposed unreleased work, customer data, and internal system screenshots from companies across cloud, healthcare, fintech, government, and AI sectors—including Fortune 500 firms.
The problem started during code review tasks. When AI agents modified interfaces, they needed to attach before-and-after screenshots. GitHub's image hosting works through the web interface but has limitations for agents operating via CLI, so some agents created public repositories as a workaround for storing files. This improvised solution became a vector for exposure.
About one-third of affected organizations had developers using gitshot, an open-source tool that publishes screenshots for code review. In one company, the behavior became standard practice—within a week, more than a dozen agents adopted the approach as a skill and uploaded over 1,000 images and recordings of unreleased features. Security teams missed the breach because 93% of images were stored in personal repositories of employees, outside the corporate GitHub organization, and traditional security scanners analyze text, not pixels.
To prevent similar incidents, organizations should audit current and former collaborators' accounts, releases, and gists; disable unrestricted auto-approval; review shared skills; and implement runtime blocks on pushing content to public repositories or personal accounts.