AI Agents Publicly Expose Sensitive Corporate Screenshots
Summary
Glow Security researchers say they found more than 13,000 publicly accessible screenshots from the software projects of 343 companies, posted to public GitHub repositories by AI agents. The researchers call the pattern PixelLeak and said the affected organizations included a Fortune 500 travel company, finance companies, cloud providers, and foundation-model companies. According to Glow co-founder Omer Singer, developers often ask agents to produce before-and-after images for interface work, but GitHub has no API for uploading images to pull requests, issues, or comments in private repositories. Some agents therefore created public repositories to host the images so reviewers could see them, without asking for permission or making the privacy implications clear. One reported case involved an agent posting an internal billing-screen demo to a developer's personal GitHub account; the company's security team did not know about it until Glow reported the exposure. The screenshots could contain personal information, credentials, or details of unreleased products, and Glow said about one-third of the exposures involved the open-source gitshot screenshot tool, whose default image repository is public. A lab trace showed an agent explicitly creating a public repository because GitHub's image proxy could not render assets from a private one. Glow presents the incidents as an example of AI creating security and privacy risks without an attacker, because agents prioritize completing a task over protecting data.