AI coding agents used by developers to assist with software changes have been linked to the exposure of more than 13,000 internal images across public GitHub repositories, according to security company Glow. The findings revealed that screenshots shared for code review purposes included sensitive internal material such as customer billing records and images of features that had not yet been released. Glow researchers found that the images were associated with developers from more than 300 organisations and, in many cases, were stored under personal GitHub accounts rather than company controlled repositories, making them difficult for internal security teams to identify.
The affected organisations included major technology companies, an AI research organisation, an enterprise software provider, and a Fortune 500 travel company, according to Glow. The company began notifying affected organisations on September 9 and published its findings on September 29, while noting that additional organisations may also have been impacted. In one case examined by Glow, a developer working at a manufacturer with more than 100,000 employees asked an AI coding agent to review a fix related to an internal billing screen. The agent created a public repository under the developer’s personal GitHub account and uploaded screenshots showing billing information linked to a utility company. Since the repository existed outside the organisation’s GitHub environment and the agent operated through the employee’s device, internal security teams did not detect the exposure at the time.
Glow stated that it has not confirmed whether any external parties accessed the exposed images beyond its own researchers and has not publicly shared the complete methodology used to identify and count the affected files. The company provides security solutions designed to help organisations monitor and control actions performed by AI agents. According to the research, many cases originated when developers asked AI agents to demonstrate visual changes made during software development so reviewers could compare before and after versions. Limitations in previous GitHub command line workflows meant that attaching images directly to pull requests was not always straightforward, leading some AI agents to place screenshots in separate public repositories instead.
Glow also tested similar behaviour in a controlled environment using Claude Code with an Opus 5 model. During the test, an AI agent asked to display changes made to a sample project created a public repository for storing screenshots. The company said several AI models were involved in the cases it reviewed and identified situations where agent instructions or skills encouraged repeated use of similar approaches. At one software company, Glow reported that multiple AI agents began uploading review screenshots publicly, with the practice spreading through shared instruction files used by different agents. The company also identified more than 100 public accounts sharing internal work through gitshot, an open source tool designed for uploading screenshots during code reviews. Security researchers highlighted that organisations should review public repositories linked to developer accounts, check release assets and other storage locations, and monitor AI agent instructions to reduce the risk of accidental exposure. GitHub has also introduced an updated command line feature that allows users and coding agents to attach images directly to pull requests, issues, and comments through its media attachment option, providing an alternative method for sharing review material within controlled repositories.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





