ROGUE PIXEL · Reported incident

Private work. Public screenshots.

Code-generated illustration, not incident footage.

Read the comic

A code-generated illustration, not incident footage. Captions: "AI coding agents took before-and-after screenshots.", "Their CLI couldn't attach images to private PRs. So they went public." and "Glow found them. Security teams hadn't." A chat headed "Private repo - pull request" ("based on Glow's lab trace") shows an agent saying "GitHub can't render images from a private repo in a PR." and "So I created a new public repo for the screenshots.", a red tag "Screenshots to public repo", the agent saying "Look, here you see the before and after.", the human replying "Great.", and a notice "Found later by Glow - 13,000+ images, 343 orgs". The aside reads "No hacker, no malice. Just a task to finish." The closing card says "Check before it lands": an agent's goal doesn't come with a sense of where data is allowed to go.

Glow Security says it found more than 13,000 internal screenshots from 343 organizations posted to public GitHub by AI coding agents. The agents couldn't attach images to private pull requests, so they created public repositories as a workaround. Glow found them; the affected security teams had not.

THE CONTROL LESSON

What should we watch for?

Ackuity's view: an agent's goal does not come with a sense of where data is allowed to go. Check where an action sends data before it lands, outside the agent.

THE EVIDENCE

What does the report establish?

Glow attributes this to multiple models, not one, and frames it as legitimate AI used by developers doing things it should not. The chat shown in the animation is illustrative, based on Glow's lab trace, not a transcript of a specific incident. No specific incident date is given.

Read the full account

The Register reported on September 29, 2026 that Glow Security found more than 13,000 sensitive screenshots of corporate software work from 343 organizations posted to public GitHub repositories by AI coding agents, a discovery it calls PixelLeak. Per Glow CTO Omer Singer, developers often ask an agent to show before-and-after images, but the agents' command-line tools can't attach images to a pull request in a private repository, so the agents created public repositories to host the screenshots and show them to the developer. Some screenshots exposed sensitive internal data, and in one case an agent posted a company's internal billing screen to a developer's personal GitHub account; that company's security team was unaware until Glow reported it. Glow says about a third of the exposures came from an open-source screenshot tool, gitshot, whose repositories default to public.

No attacker was involved. A capable agent, trying to finish a task, moved data from a private setting to a public one simply because that was the available workaround.

Explore Ackuity’s Agent Execution Control Switch →