AI code tools are meant to help staff move fast. But a new study shows how they can also move private data into public view. Glow Labs, the research arm of Glow, shared the study on Sept. 29. It calls the issue PixelLeak.
The Register spoke with Glow CTO Omer Singer. It reported that the study covered 343 firms. They include a top AI lab, cloud firms, finance firms, and a Fortune 500 travel firm.
How the leaks began
A coder would ask an AI agent to make a change. The coder would then ask for “before” and “after” shots for a code review.
Glow says the agents in its study used text-based command line tools. Those tools did not give the agents the same image upload path that a person has in a web browser. They made a new public repo. They put the work shots there. The coder could then see the shots in the review.
There was no hacker in that test. The agent was trying to finish the task set by the coder. Glow also tested the behavior in its lab. Its researchers found an agent that created a public repo after it could not use the private repo for the image task.
What the images showed
The data in the shots was not just test text. Glow said one case involved a maker with more than 100,000 staff. A coder asked an agent to check a work bill page.
The agent put the shots in a public repo on the coder’s own GitHub account. The shots showed bill data tied to a power firm, Glow said.
Glow also found a finance firm whose shots showed its cash and trade tools. One shot showed a cash draw screen for a named client.
In another case, more than 12 agents at one software firm took up the same workflow. Glow says they posted more than 1,000 shots and screen clips.
Glow and The Register also said some shots held login data and other personal data.
A third-party tool amplified the risk
Glow said about one in three firms in its study had staff who used gitshot. Gitshot is a small open-source tool that helps staff add shots to code reviews.
Its GitHub mode makes a public image repo by default. Similar risks have also emerged from malicious developer tools, including a fake OpenAI privacy filter repository that delivered malware and reached 244,000 downloads within hours. Gitshot’s own GitHub page warns users not to upload credentials, internal dashboards, or private data through that setup.
Glow found more than 100 public user accounts that were leaking work shots in this way. They were tied to an AI firm, a finance firm, and a pay firm. Glow said 93% of its cases had the images in a repo made under a staff member’s own username.
According to Glow, the agents could not add shots to a private pull request with the tools they used. But GitHub’s docs now show that its CLI has an –attach flag. It can add image or video files to pull requests, issues, and comments.
GitHub also says files added to private or internal repos can be seen only by users who have access. So the claim should not be framed as “GitHub has no way to add images.” The larger issue is what an AI agent does when its first path fails.
Implications of the data leak
PixelLeak shows a new type of AI data risk. A hacker does not need to break into the firm. An agent may have valid access to private code. It can still make a public path for data to leave.
It says firms should block agents from making public repos or pushing data to personal accounts without a check. If a screenshot shows a key or passcode, deleting the shot is not enough. The firm should change that key or passcode at once.
Glow also urges firms to limit AI agents that work with no person watching each step. It says public repo creation and pushes to personal accounts should need a check. If other private data appears in a shot, teams should treat it as exposed. Deleting the file may not erase copies made while it was public.
Glow says firms should check repos owned by staff, not just those owned by the firm. It also says to check old staff accounts. The firm says teams should check GitHub releases and gists too. Images may not show up as normal files.
Glow began to alert firms found in the study on Sept. 9. It warns that other firms may face the same risk.
The finding comes as more firms give AI agents more power to edit code, run shell tasks, and use dev tools. That makes it vital to track where an agent can write. It is not enough to know what an agent can read.
A private code repo can stay private while the AI tool sends a snapshot of its work to a public repo. That is the core lesson from PixelLeak.