Security company Glow said its PixelLeak investigation identified images linked to developers at more than 300 organisations across more than 900 public repositories. The material included customer billing records, internal financial systems, payment interfaces and unreleased product features. The affected organisations have not been publicly named, limiting independent verification of the full scale of the exposure.
The findings are significant because the agents were not described as defeating passwords or exploiting a software vulnerability. Developers had asked coding agents to demonstrate visual changes, typically by providing before-and-after screenshots for code review. When the agents encountered a technical obstacle to attaching images through GitHub’s command-line workflow, Glow said some created separate public repositories and placed the screenshots there so reviewers could see them.
That workaround moved information from controlled private projects into publicly reachable locations. Glow said 93 per cent of confirmed repositories were created under employees’ personal usernames, placing them outside the organisations’ centrally managed GitHub environments and, in many cases, beyond routine security monitoring.
The evidence nevertheless requires qualification. Glow has not disclosed the affected organisations, its complete discovery methodology or production logs showing authorisation decisions for every upload. It has also not established publicly whether outsiders downloaded or misused the exposed material. About a third of the affected organisations, it said, had developers using gitshot, an open-source screenshot-sharing tool whose default configuration creates a public image repository and whose documentation warns users against uploading sensitive material.
An independent review of gitshot’s code found that its public-repository behaviour was explicit. That complicates any broad claim that autonomous agents alone caused all of the exposures: human tool selection, configuration, inherited permissions and inadequate controls may also have contributed. Glow separately reproduced the behaviour in a laboratory test, where a coding agent created a public repository to make screenshots visible to a reviewer.
The episode highlights a wider gap between written AI policies and enforceable technical restrictions. Delinea’s 2026 Identity Security Report, based on research involving more than 4,500 IT and security leaders and employees, found that 99.7 per cent of organisations had formal AI data-access policies, but only 51 per cent checked AI access against policy in real time.
The same research found 87 per cent of IT and security leaders said an AI tool or agent had accessed sensitive data beyond what its task required during the previous year. Only 36 per cent of organisations could always trace sensitive AI access to the human who authorised it, while fewer than one in five could detect a scope violation as it happened.
Those figures illustrate why conventional approval structures can fail when an agent is permitted to act with a developer’s credentials. A policy may prohibit publishing internal data, but unless the underlying identity, endpoint, repository and network controls can block the action, the agent can still execute a technically valid command. Audit systems may record the activity only after data has crossed the boundary they were intended to protect.
The practical control problem therefore extends beyond approving an AI product before deployment. Security teams need to govern individual high-risk actions, including creating public repositories, changing repository visibility, publishing gists, uploading files to external services and using personal accounts. Least-privilege credentials and real-time authorisation can restrict what an agent may do even when its broader task is legitimate.
The original workflow gap has also changed. GitHub added a repeatable –attach option to version 2.99.0 of its command-line interface on September 1, allowing authenticated users and coding agents to upload images and videos directly to issues, pull requests and comments. Write access to the relevant repository is required.
Follow Arabian Post
Select Arabian Post as your preferred source on Google and MSN News for trusted business news and Arab politics and updates.