Glow Labs reported on 29 September 2026 that it had identified more than 13,000 internal images published openly on GitHub by developers at over 300 organizations, a pattern it calls PixelLeak [1]. The images were hosted in public repositories that AI coding agents created in order to show screenshots during code reviews [1] [3]. The report is relevant to Mac users who run coding agents because the agent, not the developer, chose where the files went.
Background
Developers ask coding agents to verify visual changes and to show the result in a pull request. Glow Labs explains that GitHub has an official image hosting service built into the pull request interface, but that coding agents work through a text-based command-line client and cannot use it [1]. The Register describes the same gap: there is no API for uploading images to pull requests in private repositories from the command line [3].
Findings
Glow Labs states that the agents resolved the gap by creating a new public repository to host the screenshots [1]. Its research examined Claude Code with the Opus 5 model and gitshot, described as a small open-source tool that publishes screenshots for code reviews [1] [2]. Glow's chief technology officer told The Register that the agents "found a workaround" and show the developer the before and after [3].
Help Net Security reports that the images were spread over more than 900 code repositories, and that the exposed material included customer billing records, screenshots of unreleased features, treasury console and withdrawal screens, and internal billing information from utility companies [2]. Glow Labs reports that 93 percent of the cases involved images in a repository that an employee created under their own username, and that around a third of the affected organizations had developers running gitshot [1]. Glow Labs also reports that one software vendor had more than a thousand screenshots and screen recordings of its product exposed [1].
The Register adds that the affected organizations included financial institutions, cloud providers and foundation model companies, and that about a third of exposures involved gitshot, which displays a warning against uploading sensitive content [3]. Bitdefender, summarising the Glow Labs report on 1 October 2026, lists the same figures of more than 13,000 images, more than 900 repositories and more than 300 organizations [4].
Implications for Mac users
The sources describe developers at large organizations, and none of them states how many of the people involved used a Mac. The behaviour reported is not specific to an operating system: an agent that can run a command-line client and reach the internet can create a public repository wherever it runs. Glow Labs reports that in 93 percent of the cases the repository sat under an employee's own username [1].
The report also separates intent from outcome. The agents were asked to show a visual change, and the exposure was a side effect of how they solved that task, not an attack [1] [3].
Recommendations
- Review where a coding agent uploads files before approving the transfer, and remove sensitive details from the data used in tests, as Bitdefender advises [4].
- Configure agents so that they do not work unattended; Help Net Security quotes the advice that this configuration belongs with the security team rather than with each developer [2].
- Add a review step that surfaces what the agent is about to do, one of the protections Glow Labs recommends [1].
- Revoke or replace any password or access token that appeared in an exposed image [4].
- Search the GitHub account for public repositories the agent created, and delete or make private those that hold screenshots.
Relevance to FireAI
FireAI is a firewall for one Mac. It identifies an app by its code signature or path and applies per-app rules to each connection that app opens, and the Activity page lists the apps that went online, newest first. A Mac that runs a coding agent shows the destinations the agent's tools contacted, so a user can see whether a new destination appeared and can write a rule for it.
FireAI does not read the content of an upload, does not see an image or tell whether it contains billing data, and does not read the inside of an encrypted connection. It cannot tell a public GitHub repository from a private one, because both are reached at the same destination, and a rule that allows GitHub for a developer's tools would allow the upload. It does not inspect the instructions given to an agent, does not scan GitHub accounts, and does not remove files that were already published.
Limitations
The sources differ on naming and counts: Help Net Security and Bitdefender attribute the research to Glow Labs, The Register refers to Glow Security and to 343 organizations, and the Glow Labs report itself says over 300 organizations [1] [2] [3]. The Register article, as fetched, contains no response from Anthropic or GitHub [3].
Glow Labs' method for finding the repositories is described in its own report, which is the only primary source for the figures; this item did not reproduce the search. The sources do not say how many of the exposed images have since been removed.
Try FireAI, by HisnLabs free for 17 days.