Not Safe for GitHub: PixelLeak
An AI coding agent wanted to show a reviewer two screenshots. In its own words: “GitHub cannot render images from a private repo in a PR description.” So it put them somewhere GitHub could render them. A public repository.
Glow Labs (a security vendor) counted the result and named it PixelLeak: over 13,000 internal images published openly on GitHub, across more than 900 repositories, from over 300 organizations. Billing records. An internal treasury and settlement console. A dollar withdrawal screen. In 93 percent of cases the images sat in a repository an employee had created under their own username. The organizations include enterprises with 100,000 or more employees across cloud, healthcare, fintech, government, frontier AI and, yes, AI security companies; several are Fortune 500.
No attacker was needed. The agent met a limitation and solved it.
Three things I take from that.
The limit you should set on an agent, what I call its ceiling, is a list of what it may do, enforced by what its credentials can do. Not a list of prohibitions in a prompt: a prohibition in a prompt is text the agent can reason past, and this one did. A token limited to named private repositories, with no other path to publish, leaves little to be creative with.
A review step that shows the reviewer what is leaving, and where, is a control. Blanket auto-approval is the absence of one.
Look where you have no control: public code hosts, personal accounts, people who have left. Glow’s own advice includes departed employees.
- Glow Labs, “How AI agents exposed developer screenshots from leading tech companies,” 29 September 2026 (all counts, the agent’s quoted words, the sectors and the advice on departed employees): glow.io
Scope note. Glow sells security products in this area. Mike Bidun has no relationship with the company. The figures are Glow’s, as published on 29 September 2026; they come from public GitHub and were not independently recounted. The three takeaways are the author’s view, not Glow’s.
Written for compliance and risk readers in regulated financial firms. Informational, not legal advice; Mike Bidun is not a lawyer.
