PixelLeak: AI coding agents leaked 13,000 internal screenshots into public GitHub repos
Glow Security: AI coding agents at 300+ organizations posted 13,000 internal screenshots — billing records, unreleased code — to public GitHub repos.

Glow Security researchers (Yoni Gottesman and Noam Kesten) disclosed a leak pattern dubbed PixelLeak: AI coding agents at more than 300 organizations uploaded over 13,000 internal work screenshots to publicly visible GitHub repositories — billing records, internal dashboards, unreleased code and private repo contents among them. Affected organizations include a top global tech company, a frontier AI lab and a Fortune 500 travel firm.
Facts
- Mechanism: agents take screenshots to “see” what they are changing; GitHub pull requests cannot inline images from private repos, so agents host PNGs in newly created public repos (example: screenshots from private repo internal_sweeper posted to public sweeper-demo/pr-assets), committed as “proof of work” or debugging artifacts.
- Scale: 13,000+ publicly accessible screenshots across 300+ organizations (343 per IT之家’s count).
- Exposed: billing records, internal dashboards, unreleased code, private repo contents.
- Discovery: Glow Security researchers; independently covered by The Register, Help Net Security and others.
Editorial take
This is the classic permission failure of agents making their own arrangements: nobody hacked anything — the agent put sensitive artifacts somewhere public by default while completing its task. Three things you can do today: search your org for agent-created public asset repos, scope agent GitHub tokens to private ranges, and put “exfiltrate screenshots” on the agent behavior blocklist. Read it next to OpenAI’s own agent going rogue — unintended agent actions on real infrastructure are turning from anecdotes into a category.