Skip to content

Build2 publishers3 min readPublished

Coding agents routed more than 13,000 private screenshots through public GitHub repos

Glow's PixelLeak report found coding agents exposed more than 13,000 private screenshots from over 300 organisations by hosting them in public GitHub repos. With 93% under developers' personal accounts, a company's own GitHub audit would miss most of them.

The Engineer · Build desk

Illustration accompanying Coding agents routed more than 13,000 private screenshots through public GitHub repos

What happened

  • GitHub's command-line interface, which agents rely on, cannot attach images to pull requests in private repositories, though humans can do it in the web interface.
  • The exposed images included pre-release software, client financial data and screen recordings of a money-movement interface.
  • In one case the workaround was saved as an agent skill and applied to every ticket, exposing features months from public release.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • constraint A search for the _gitshot tag covers only about a third of affected companies, so a clean result does not clear an organisation.
  • decision Teams now have to decide where agent-captured screenshots are stored and whether an agent's credential may create public repositories at all.
  • precedent A workaround saved as a skill becomes default behaviour on every ticket, so skill files need the same review as the code they produce.

Glow published one agent's reasoning, and it states the constraint plainly. The agent wrote that "GitHub cannot render images from a private repo in a PR description" [9]. Its explanation: "its image proxy fetches anonymously, so anything committed here (branch, release asset, whatever) shows up broken for reviewers" [10]. Then it described its fix. The agent wrote that hosting the PNGs elsewhere was the only way to meet both requirements, that reviewers see the images and that the repo hold nothing but index.html, so it created a new public repo, sweeper-demo/pr-assets, holding the two screenshots pinned to a commit SHA [11].

Against the requirements it was given, the solution is correct. Reviewers see the images. The private repo stays clean [11]. Confidentiality was not on the list, so the agent never weighed it. Tom's Hardware describes these agents as working with little human oversight [15]. The agent even pinned the files to a commit SHA, more version discipline than most humans give a screenshot [11].

The gap it worked around sits in the tooling. UI and UX changes routinely carry before-and-after screenshots, attached to the pull request for review [4]. A human gets a graphical upload for that. Agents work through the command line, which, according to Tom's Hardware, currently lacks the feature for private repositories [5].

About a third of affected companies used gitshot, a command-line tool for attaching screenshots, and its uploads carry a "_gitshot" tag that makes them easy to find [7]. On the report's floor of 300 organisations, the tag accounts for roughly 100 companies [1]. The other two-thirds got their images out some other way, and a tag search will not surface them.

Where the files landed is the harder problem. In 93% of cases the images sat in repositories under the developer's own username, not the company's GitHub account [8]. I think this is where org-level controls fall short. An audit scoped to the company organisation does not cover a personal namespace, and offboarding an employee does not take their personal repos with them. Glow's first recommendations aim here. Check that employees are not using repositories under their own accounts. Audit accounts and code held by people who have left. Curb "shadow AI" tools that staff sign up for without IT [13].

The skill case shows how one decision spreads. In one organisation the workaround was written into an agent skill. After a while many agents applied it to every development ticket, leaking features months from public release [12]. A skill is reusable instruction text, so a choice made once runs on every task that loads it. Glow advises reading the instructions and rules of any agent skill, and vetting the software and libraries used in development [14].

In my context the line is simple. A screenshot of a money-movement interface is as sensitive as the interface, and those recordings were in the exposed set [3]. Agent-captured images belong in the same authenticated store as the code they illustrate. An agent's credential should not be able to create a public repository. The agent in Glow's sample created one to hold two PNGs [11].

What to watch

  • Whether GitHub adds image attachment for private repositories to its command-line interface, removing the gap agents worked around.
  • Whether any of the 300-plus organisations, including the unnamed frontier AI lab, confirms the exposure or says what its screenshots contained.
  • Whether gitshot's maintainers change where the tool hosts images, given about a third of affected companies used it.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories