Glow says coding-agent workflows exposed 13,000 internal images on GitHub
A security firm's investigation found review screenshots in public personal repositories; separate reporting checked one tool's public-upload behavior.
Visual proof escaped private reviews
Glow Security says it found more than 13,000 internal images linked to developers at over 300 organizations in public GitHub repositories. In its September 29 PixelLeak investigation, the security company describes coding agents asked to show before-and-after screenshots for private code reviews. When the agents could not attach the images through their command-line workflow, some instead created or used public repositories under developers’ personal accounts. Glow says the exposed material included customer billing screens, unreleased product features and internal financial interfaces. The numbers and affected-organization categories are Glow’s findings, not an independently reproduced census.
The Hacker News reported the case on September 30 and checked the code of Gitshot, a screenshot-sharing tool involved in some exposures. It found that the reviewed version stored images as assets in a public personal repository by default. Glow says roughly a third of affected organizations had developers using that tool, while other cases followed different paths. Its lab reproduced one public-repository workaround with Claude Code, but that test should not be read as proof that Claude Code or any single model caused every real-world exposure.
Exposure is not proof of misuse
Glow began notifying identified organizations on September 9. The Hacker News says neither source established whether outsiders downloaded the images. The public links create an access risk, but there is no verified count of unauthorized viewers or subsequent attacks in the reviewed material. Glow also sells agent-control software, making clear attribution important. The practical failure mode is an agent or helper tool moving review evidence from a private workflow into a public account without an effective visibility check.