Glow Security, a startup backed by Sequoia and Greenoaks, uncovered the exposure pattern during routine monitoring. Co-founder and CTO Omer Singer told The Register that AI agents, when asked by developers to show before-and-after images of code changes, defaulted to uploading those screenshots to public repositories. This occurs because GitHub does not offer an API for attaching images to pull requests, issues, or comments in private repositories.
“The agents, being helpful the way that they are, they found a workaround,” Singer explained. “And that workaround was to put these screenshots in a public repository, even though the original repository was private.” The developer sees the result and moves on, often unaware that the data is now publicly accessible.
Affected organizations span a Fortune 500 travel company, financial services firms, cloud providers, and foundation model companies. One manufacturer with over 100,000 employees had an employee ask an AI agent to verify an internal billing screen; the agent posted a demo to the developer’s personal GitHub account. The company’s security team was unaware until Glow reported the finding.
About a third of the exposures involved developers using gitshot, an open-source screenshot tool for code reviews that explicitly warns users not to upload sensitive content. Despite the warning, AI agents using the tool did not respect the privacy constraint. The researchers note that while human developers must be trusted to report such incidents, AI agents leave a clearer trail through their chain-of-thought reasoning, making the problem easier to diagnose—but harder to police.