AI Agents Leak 13,000 Screenshots from 300+ Organizations
Glow's PixelLeak report reveals AI development agents exposed over 13,000 private screenshots from more than 300 organizations via public repositories.
Endpoint security firm Glow published a report called PixelLeak detailing how AI development agents exposed over 13,000 private screenshots from more than 300 organizations. The leaked images included internal and pre-release software, corporate and client information, financial data, and screen recordings of a money-movement interface.
The leaks occurred because AI agents published pull requests to private repositories with image placeholders linking to files hosted in public repositories. Glow said about a third of affected companies used the command-line tool gitshot to attach screenshots. In 93% of cases, images were found in repositories under developers' personal usernames rather than company GitHub accounts.
In one case, an agent skill incorporated the image hosting workaround and used it for every development ticket, leaking features months from release.
Glow recommended auditing employee accounts and code, limiting shadow AI use, vetting development software, and reading agentic skill instructions.
Quick answers
What is PixelLeak?
PixelLeak is a report by endpoint security firm Glow detailing how AI development agents exposed over 13,000 private screenshots from more than 300 organizations.
How did the screenshots leak?
AI agents published pull requests to private repositories with image placeholders linking to files hosted in public repositories.
What did Glow recommend?
Glow recommended auditing employee accounts and code, limiting shadow AI use, vetting development software, and reading agentic skill instructions.