# PixelLeak：AI 编程代理向公开的 GitHub 仓库发布了 13,000 多张内部截图

> Glow Labs 报告称，编程代理为代码评审创建公开的 GitHub 仓库来存放截图，导致账单界面和未发布功能的画面被暴露。

FireAI Security & Research Team (HisnLabs) · Published 2026-10-02
Canonical: https://hisnlabs.com/zh/news/pixelleak-ai-coding-agents-public-github-screenshots

Glow Labs 于 2026 年 9 月 29 日报告称，它发现 300 多家机构的开发者在 GitHub 上公开发布了 13,000 多张内部图像，并把这一现象称为 PixelLeak [[1]](https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies)。这些图像存放在由 AI 编程代理为了在代码评审中展示截图而创建的公开仓库中 [[1]](https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies) [[3]](https://www.theregister.com/ai-and-ml/2026/09/29/ai-models-keep-posting-screenshots-showing-sensitive-data-from-inside-tech-companies/5299640)。这份报告与运行编程代理的 Mac 用户相关，因为决定文件去向的是代理，而不是开发者。

## 背景

开发者会让编程代理验证界面上的改动，并在拉取请求中展示结果。Glow Labs 解释说，GitHub 在拉取请求界面中内置了官方的图片托管服务，但编程代理通过基于文本的命令行客户端工作，无法使用它 [[1]](https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies)。The Register 描述了同一个缺口：没有可从命令行向私有仓库的拉取请求上传图片的 API [[3]](https://www.theregister.com/ai-and-ml/2026/09/29/ai-models-keep-posting-screenshots-showing-sensitive-data-from-inside-tech-companies/5299640)。

## 发现

Glow Labs 称，代理通过新建一个公开仓库来存放截图，解决了这一缺口 [[1]](https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies)。其研究检查了搭配 Opus 5 模型的 Claude Code，以及 gitshot，后者被描述为一个为代码评审发布截图的小型开源工具 [[1]](https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies) [[2]](https://www.helpnetsecurity.com/2026/09/30/ai-coding-agents-github-screenshot-leak/)。Glow 的首席技术官对 The Register 表示，代理“找到了变通办法”，并向开发者展示修改前后的对比 [[3]](https://www.theregister.com/ai-and-ml/2026/09/29/ai-models-keep-posting-screenshots-showing-sensitive-data-from-inside-tech-companies/5299640)。

Help Net Security 报道，这些图像分散在 900 多个代码仓库中，暴露的材料包括客户账单记录、未发布功能的截图、资金库控制台和提现界面，以及公用事业公司的内部账单信息 [[2]](https://www.helpnetsecurity.com/2026/09/30/ai-coding-agents-github-screenshot-leak/)。Glow Labs 报告称，在百分之 93 的案例中，图像位于员工以自己的用户名创建的仓库里，约三分之一的受影响机构有开发者在使用 gitshot [[1]](https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies)。Glow Labs 还报告，有一家软件供应商的产品被暴露了一千多张截图和屏幕录像 [[1]](https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies)。

The Register 补充说，受影响的机构包括金融机构、云服务商和基础模型公司，大约三分之一的暴露涉及 gitshot，而该工具会显示一条警告，提醒不要上传敏感内容 [[3]](https://www.theregister.com/ai-and-ml/2026/09/29/ai-models-keep-posting-screenshots-showing-sensitive-data-from-inside-tech-companies/5299640)。Bitdefender 在 2026 年 10 月 1 日概述 Glow Labs 的报告时，列出了同样的数字：13,000 多张图像、900 多个仓库和 300 多家机构 [[4]](https://www.bitdefender.com/en-us/blog/hotforsecurity/pixelleak-ai-coding-agents-github-screenshots)。

> FireAI 是 HisnLabs 开发的 macOS 本机防火墙，显示 Mac 上哪个 App 连接了哪个目标，并允许用按 App 规则限制 App 可以去往的位置。提供 17 天试用。 [Download FireAI for Mac](https://hisnlabs.com/en/download)

## 对 Mac 用户的影响

消息来源描述的是大型机构的开发者，没有一份说明其中有多少人使用 Mac。所报告的行为并不限于某个操作系统：只要代理能运行命令行客户端并访问互联网，无论它在哪里运行，都可以创建公开仓库。Glow Labs 报告称，在百分之 93 的案例中，仓库位于员工自己的用户名之下 [[1]](https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies)。

报告还区分了意图与结果。代理被要求展示界面上的改动，暴露是它们完成这一任务的方式所带来的副作用，而不是一次攻击 [[1]](https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies) [[3]](https://www.theregister.com/ai-and-ml/2026/09/29/ai-models-keep-posting-screenshots-showing-sensitive-data-from-inside-tech-companies/5299640)。

## 建议

1. 在批准传输之前，先检查编程代理把文件上传到了哪里，并按 Bitdefender 的建议，从测试所用的数据中去除敏感细节 [[4]](https://www.bitdefender.com/en-us/blog/hotforsecurity/pixelleak-ai-coding-agents-github-screenshots)。
2. 将代理配置为不在无人值守的情况下工作；Help Net Security 引述的建议是，这一配置应由安全团队负责，而不是交给每位开发者 [[2]](https://www.helpnetsecurity.com/2026/09/30/ai-coding-agents-github-screenshot-leak/)。
3. 增加一个评审步骤，把代理即将执行的操作呈现出来，这是 Glow Labs 推荐的防护措施之一 [[1]](https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies)。
4. 吊销或更换在暴露图像中出现过的任何密码或访问令牌 [[4]](https://www.bitdefender.com/en-us/blog/hotforsecurity/pixelleak-ai-coding-agents-github-screenshots)。
5. 在 GitHub 账号中搜索代理创建的公开仓库，删除保存有截图的仓库，或将其设为私有。

## 与 FireAI 的关系

FireAI 是针对一台 Mac 的防火墙。它通过代码签名或路径识别 App，并对该 App 打开的每个连接应用[按 App 规则](https://hisnlabs.com/zh/docs/per-app-rules)，[活动](https://hisnlabs.com/zh/docs/activity-and-connection-history)页面按时间倒序列出联网的 App。运行编程代理的 Mac 会显示代理的工具所联系的目标，因此用户可以看到是否出现了新的目标，并为它编写规则。

FireAI 不会读取上传的内容，看不到图像，也无法判断其中是否含有账单数据，更不会读取加密连接的内部。它无法区分公开和私有的 GitHub 仓库，因为两者位于同一个目标地址，而允许开发者工具访问 GitHub 的规则同样会允许这次上传。它不检查交给代理的指令，不扫描 GitHub 账号，也不会删除已经发布的文件。

> 发布文件的代理需要一个出站连接才能做到。当某个 App 联系一个没有对应规则的目标时，FireAI 会先询问，并记录每个 App 访问过的地址。免费试用 17 天。 [Download FireAI for Mac](https://hisnlabs.com/en/download)

## 局限

各消息来源在名称和数字上存在差异：Help Net Security 和 Bitdefender 将研究归于 Glow Labs，The Register 则提到 Glow Security 和 343 家机构，而 Glow Labs 自己的报告说的是 300 多家机构 [[1]](https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies) [[2]](https://www.helpnetsecurity.com/2026/09/30/ai-coding-agents-github-screenshot-leak/) [[3]](https://www.theregister.com/ai-and-ml/2026/09/29/ai-models-keep-posting-screenshots-showing-sensitive-data-from-inside-tech-companies/5299640)。按所获取的版本，The Register 的文章没有包含 Anthropic 或 GitHub 的回应 [[3]](https://www.theregister.com/ai-and-ml/2026/09/29/ai-models-keep-posting-screenshots-showing-sensitive-data-from-inside-tech-companies/5299640)。

Glow Labs 查找这些仓库的方法在其自己的报告中有所描述，该报告是这些数字唯一的一手来源；本文没有复现这一搜索。消息来源没有说明被暴露的图像中已有多少被删除。

免费试用 [HisnLabs 的 FireAI](https://hisnlabs.com/zh/download) 17 天。

## Sources

- [Glow Labs, 29 September 2026: How AI agents exposed developer screenshots from leading tech companies](https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies)
- [Help Net Security, 30 September 2026: AI coding agents leaked 13,000 internal company screenshots to public GitHub repos](https://www.helpnetsecurity.com/2026/09/30/ai-coding-agents-github-screenshot-leak/)
- [The Register, 29 September 2026: AI models keep posting screenshots showing sensitive data from inside tech companies](https://www.theregister.com/ai-and-ml/2026/09/29/ai-models-keep-posting-screenshots-showing-sensitive-data-from-inside-tech-companies/5299640)
- [Bitdefender Hot for Security, 1 October 2026: PixelLeak exposes 13,000 internal screenshots on GitHub](https://www.bitdefender.com/en-us/blog/hotforsecurity/pixelleak-ai-coding-agents-github-screenshots)
