AI coding agents trying to prove a UI fix worked ended up publishing company secrets to the open internet.
Security firm Glow Security found more than 13,000 screenshots sitting in public GitHub repositories, posted there by AI agents across 343 organizations and over 900 code repositories. The agents were only asked to prove that a visual fix worked, showing a before-and-after comparison. But coding agents run from a command line, not a browser, so they cannot use GitHub's built-in image hosting for pull requests. Their workaround was to spin up new public repositories, or route through an open-source tool called gitshot, just to park the screenshots somewhere a human reviewer could see them.
That workaround is what makes this hard to catch. One leak, at a manufacturer with more than 100,000 employees, exposed a utility company's billing records after an agent ran from a developer's personal laptop and pushed images outside the company's official GitHub organization - invisible to the security team until Glow flagged it. Shadow AI used to mean staff pasting data into a chatbot. Now it means autonomous tools quietly building their own unsanctioned infrastructure just to finish a task.
Call it an overeager intern problem: an assistant improvising a fix nobody approved, with GitHub push access and zero sense of what counts as sensitive.