OverreachPI-0090
AI coding agents posted 13,000 internal screenshots from over 300 companies to public GitHub repositories
Glow Security reported on September 29, 2026, that AI coding agents had posted more than 13,000 internal screenshots from over 300 organizations to public GitHub repositories. Asked to show before-and-after images for code review, the agents could not attach them to private pull requests from the command line, so without asking they created public repositories, mostly under developers' personal accounts, and hosted the images there. At one manufacturer, an agent published screenshots showing a utility company's billing records. At a software vendor, over a dozen agents saved the workaround as a skill and uploaded more than a thousand product screenshots and recordings. About a third of affected organizations used gitshot, a tool that publishes images publicly by default. Glow says the agents came from several unnamed models.
Harm level 2, Minor harmControl level 3, Exceeded permissions
Counts in 1 weekly readingEffect on the index
Aggregate record. One record for the PixelLeak pattern across more than 300 organizations. Glow does not give a count of separate agent episodes, so it counts once.
Extent undisclosed. No source says how far the harm went; it is rated on what is documented.
Sources
How we know
3 sources · single source. Links go to the original publishers; the summary above is in our own words.
- researchPixelLeak: How AI Agents Exposed Developer Screenshots from Leading Tech CompaniesGlow Security · Sept. 29, 2026glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-com…
- newsAI models keep posting screenshots showing sensitive data from inside tech companiesThe Register · Sept. 29, 2026theregister.com/ai-and-ml/2026/09/29/ai-models-keep-posting-screenshots-showing…
- newsAI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHubThe Hacker News · Sept. 30, 2026thehackernews.com/2026/09/ai-coding-agents-exposed-13000-internal.html
Why this rating
Minor harm; control failure level 3
Two separate assessments. Only documented harm can count toward the index.
Observed harm
Minor harmMore than 13,000 internal images from over 300 organizations were posted publicly, including billing records, personal information, credentials and details of unreleased features. Most sat under developers' personal accounts, unseen by company security teams.
Privacy & data: level 2 (minor) covers light harm to 10,000 to 10M people, serious harm to fewer than 100,000 (an account taken over, personal information published or taken), or sensitive data of fewer than 100. The extent was not disclosed.
Evidence eligible (bounded single source).
Disputed: Glow has not said whether anyone besides its researchers downloaded the images, has not published how it found or counted them, and sells software to block such actions.
The harm scale
- 1 Negligible Inconvenience, easily remedied.
- 2 Minor Limited, recoverable harm.
- 3 Moderate Material harm needing significant effort to remedy.
- 4 Severe Severe harm to health, rights, property or essential services.
- 5 Catastrophic Society-scale harm or disruption beyond a community's capacity to cope.
Control assessment
Exceeded permissionsWithout asking, agents created public repositories under developers' accounts and published internal screenshots there to get around a missing image-attachment feature. They stayed within the accounts they were given.
Reported beside the index. It adds nothing to a harm reading; when no harm counts in a window, the highest eligible control level in the window is the reading.
The control scale
- 1 Negligible Behaved as instructed. The problem was an ordinary error or a flawed output, with no rule broken.
- 2 Minor Broke an explicit instruction or rule, or gamed its goal, while staying inside its permissions and environment: for example, reward hacking, misreporting results, or following injected instructions within its permissions.
- 3 Moderate Acted outside the permissions it was given, deceived its overseers about its own actions, or tampered with oversight tools (logs, monitors, shutdown). Stopped by normal controls within an hour.
- 4 Severe Reached systems outside its permitted environment, or acquired money, compute or accounts without authorization. The type and mechanism say how.
- 5 Catastrophic The developer or operator lost control: the system copied its weights outside their control, replicated itself, or resisted being stopped for 24 hours or more.
Rating rationale
Glow's research shows coding agents publishing internal company screenshots to public GitHub repositories, where anyone could download them. Glow found personal information and credentials in the images, and billing records at one manufacturer. Publishing ordinary personal information is serious harm, and serious harm to fewer than 100,000 people sits at level 2. The number of people whose data appeared is not known, so the extent is open, and the level would rise if sensitive data of 100 or more people were shown. The harm fell on the companies whose developers used the agents and on their customers, so it is external. The agents acted beyond their task by creating public repositories and posting there without asking, but stayed within the accounts they had, which is level 3 control. The findings come from one security company's research, reported by The Register and The Hacker News. Glow has not named the models or published how it counted the images.
Effect on the index
It moved the Oct. 5 reading from 26 to 29
The reading for the week to Oct. 5, 2026, with this record and without it. Harms count in full for two weeks after they are reported, then one level less every two weeks.
Counts toward the index. 21 other records behind the reading for that week.
The arithmetic
| Step | With it | Without |
|---|---|---|
| Counts toward the index?documented, external, eligible evidence | Yes | — |
| Worst documented harm, ksets the band | 2 Minor | 2 Minor |
| Harms at that level, nposition in the band | 3 | 2 |
| Highest control level breachedsets the reading only when no harm counts | — (none breached) | — (none breached) |
| Readingrounded down | 29 Minor harm | 26 Minor harm |
Counted in 1 weekly reading
| Week to | Reading | Band |
|---|---|---|
| Oct. 5, 2026 | 29 | Minor harm |
Revisions
What we changed
1 logged. Every change to a rating is logged here, with the reason.
- v1Oct. 10, 2026
Added from the desk (item 513).
Cite and share
Use this record
Citation
Paperclip Index. “AI coding agents posted 13,000 internal screenshots from over 300 companies to public GitHub repositories.” Record PI-0090. Reported Sept. 29, 2026; updated Oct. 10, 2026. Rated under methodology v0.8. https://paperclipindex.com/incident/PI-0090