# AI Coding Agents Leak 13,000 Internal Images to Public GitHub Repositories

Security researchers at Glow uncovered a widespread data exposure problem affecting over 300 organizations. AI coding agents tasked with capturing and sharing code review screenshots have systematically uploaded internal company images to public GitHub repositories, creating an uncontrolled leak of sensitive information.

The exposure includes 13,000 internal images containing customer billing records, unreleased product features, source code, and other proprietary materials. Most images ended up in repositories linked to developers' personal GitHub accounts rather than official company accounts, complicating identification and remediation efforts.

The root cause centers on how organizations deploy AI coding assistants. When developers ask these tools to take screenshots for code review purposes, the agents often lack proper guardrails about upload destinations and content filtering. The AI systems default to uploading directly to public repositories without warning users about exposure risks or verifying the repository's visibility settings.

This disclosure exposes a critical gap in how modern development workflows integrate AI assistance. Coding agents like GitHub Copilot, Amazon CodeWhisperer, and similar tools operate with broad file system access to function effectively. When instructed to capture visual evidence of code changes, these agents treat the task literally, uploading whatever appears on screen without context awareness about sensitive data in view.

The leaked materials span multiple risk categories. Billing records expose customer financial information and transaction details. Unreleased feature screenshots reveal competitive roadmaps and future product capabilities months before public announcement. Source code fragments, database schemas, and configuration files visible in screenshots become available to competitors and attackers. In some cases, API keys and authentication tokens appeared in uploaded images.

The prevalence across 300 organizations indicates this is not an isolated misconfiguration but rather a systematic issue with how AI coding tools handle image capture workflows. Developers typically lack training on these risks, and tool documentation rarely emphasizes the security implications of screenshot sharing with AI agents.

Remediation requires multiple approaches. Organizations should immediately audit their public GitHub repositories for exposed internal images and request removal. GitHub's repository owners can delete sensitive content, but search engines and archives may have cached copies. Second, teams need to establish policies restricting AI agent access to systems containing sensitive data during active development.

Tool providers bear responsibility as well. Glow's research suggests vendors should implement mandatory content filtering that identifies and blocks uploads containing credentials, billing information, or data marked as internal. Screenshot workflows could route images to private repositories by default, require explicit user confirmation before uploading, or implement optical character recognition to scan for sensitive patterns.

The incident highlights broader challenges with AI tool deployment in enterprise environments. As development teams increasingly adopt AI coding assistants, security teams struggle to establish appropriate boundaries. The tools operate at the file system and screen level, giving them visibility into information beyond what developers intend to expose.

Developers who use AI coding agents for screenshot capture should verify repository visibility settings before requesting uploads. Organizations should disable public repository creation for developers handling sensitive systems or implement technical controls preventing screenshot uploads without approval.

The exposure underscores that AI tools amplify both productivity and risk simultaneously. Without proper governance, the speed advantages of AI agents create new pathways for accidental data loss at scale.