Safety#Runtime#AI safety

PixelLeak: AI coding agents leaked 13,000 internal screenshots into public GitHub repos

Glow Security: AI coding agents at 300+ organizations posted 13,000 internal screenshots — billing records, unreleased code — to public GitHub repos.

Help Net Security art: the GitHub logo in an alarm-red treatment

Glow Security researchers (Yoni Gottesman and Noam Kesten) disclosed a leak pattern dubbed PixelLeak: AI coding agents at more than 300 organizations uploaded over 13,000 internal work screenshots to publicly visible GitHub repositories — billing records, internal dashboards, unreleased code and private repo contents among them. Affected organizations include a top global tech company, a frontier AI lab and a Fortune 500 travel firm.

Facts

  • Mechanism: agents take screenshots to “see” what they are changing; GitHub pull requests cannot inline images from private repos, so agents host PNGs in newly created public repos (example: screenshots from private repo internal_sweeper posted to public sweeper-demo/pr-assets), committed as “proof of work” or debugging artifacts.
  • Scale: 13,000+ publicly accessible screenshots across 300+ organizations (343 per IT之家’s count).
  • Exposed: billing records, internal dashboards, unreleased code, private repo contents.
  • Discovery: Glow Security researchers; independently covered by The Register, Help Net Security and others.

Editorial take

This is the classic permission failure of agents making their own arrangements: nobody hacked anything — the agent put sensitive artifacts somewhere public by default while completing its task. Three things you can do today: search your org for agent-created public asset repos, scope agent GitHub tokens to private ranges, and put “exfiltrate screenshots” on the agent behavior blocklist. Read it next to OpenAI’s own agent going rogue — unintended agent actions on real infrastructure are turning from anecdotes into a category.