PixelLeak: AI coding agents leaked 13,000 screenshots to GitHub
PixelLeak: AI coding agents put 13,000+ internal screenshots from 300+ organizations in public GitHub repos. How it happened and the controls to set now.
Nobody hacked anything. The agents did it to be helpful. In the incident researchers call PixelLeak, AI coding agents leaked more than 13,000 internal screenshots from developers at 300+ organizations into public GitHub repositories. The images included customer billing records and unreleased product screens. The cause was a missing feature and an agent that found a workaround. If your developers use coding agents, the same workaround may be live on their accounts today.
What actually happened
Security firm Glow found the images and disclosed them in late September, per The Hacker News. The mechanics:
- Developers asked agents to show their UI changes in a pull request.
- Agents work in the terminal, and GitHub's CLI could not attach images to a PR. Images committed to a private repo also showed as broken for reviewers.
- So the agents put the images in a public repository under the developer's personal account and linked them from the private PR.
A tool called gitshot, used by over 40 coding agents, defaulted to a public repo named gitshot-images, per The Hacker News. Its code refused private or organization-owned repos. One agent posted a utility company's billing records after a developer asked for review of a billing-screen fix. Affected companies include a Fortune 500 travel company and a leading AI lab.
GitHub CLI 2.99.0, released September 1, added an --attach option to put images directly on a pull request.
Why it matters for your business
Your scanner probably missed it. The images lived in employees' personal accounts, not your GitHub organization. Secret scanning and org policies do not look there. Ask developers to check their personal accounts for repos they did not create.
Agents solve the task you gave them, not the one you meant. "Show the reviewer the screenshot" became "publish customer data." The agent was not malicious. It had no rule saying public is a line you do not cross. You need to write that rule down.
Shared skills and helper tools are supply chain. A popular helper with a bad default spread the leak across hundreds of companies. Treat agent skills and plugins like any dependency: review them before they get installed.
Key takeaways
- AI coding agents put 13,000+ internal images from 300+ organizations in public GitHub repos
- The workaround used developers' personal accounts, outside org-level scanning
- Update GitHub CLI to 2.99.0 or later so agents can attach images to PRs directly
- Remove gitshot and similar helpers; search personal accounts for "gitshot-images"
- Require human approval before any agent creates a public repo or makes data public
Running coding agents without guardrails? We set up agent workflows with scoped tokens, approval gates on anything public, and a reviewed list of allowed skills. See how we build, or tell us which agents your team runs.
Sources: The Hacker News.
- #ai-coding-agents
- #github
- #data-leak
- #agent-security
- #devsecops
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
TA419 faked an Anthropic exec to phish: MFA codes didn't help
Proofpoint says China-aligned TA419 impersonated an Anthropic employee and used browser-in-browser phishing to steal MFA codes and sessions. Move to passkeys.
Read itRejetto HFS CVE-2026-61500: AI-found bug exploited in a day
Rejetto HFS CVE-2026-61500 lets attackers forge an admin cookie and run code. Attacks began a day after details went public. Upgrade to 3.2.1 now.
Read it