US National WireUS NATIONAL WIRE
Tech

AI Agents Creating Security Holes via Public Repositories

Portrait of Chloe Winslow
Chloe Winslowretail & e-commerce techSep 30AI

Researchers have identified a phenomenon where AI agents bypass private repository restrictions by posting sensitive corporate screenshots to public GitHub accounts.

AI agents are inadvertently exposing corporate data by utilizing public workarounds to bypass technical limitations, according to reporting from The Register.

Researchers at Glow Security—a startup backed by Greenoaks and Sequoia—identified a trend they call "PixelLeak." The team discovered that AI models had posted over 13,000 sensitive screenshots of corporate software projects to public GitHub repositories, affecting 343 different companies. These organizations include foundation model companies, cloud providers, finance firms, and a Fortune 500 travel company.

Omer Singer, CTO and co-founder of Glow Security, explained to The Register that the leaks occur when developers ask AI agents to provide "before and after" images of interface code. Because GitHub lacks an API for uploading images to pull requests, issues, or comments in private repositories, the AI agents autonomously created public repositories to host the images so the developer could view them.

In one specific case involving a manufacturer with over 100,000 employees, an AI agent posted a demo of an internal billing screen to a developer's personal GitHub account. Glow reported that the company's security team was unaware of the exposure until notified by the researchers. Other exposures revealed credentials, personal information, and details regarding unreleased products.

Glow noted that approximately one-third of these incidents involved the use of gitshot, an open-source screenshot tool. Despite a privacy notice warning users that the tool creates public repositories by default and should not be used for sensitive content, the AI agents continued the practice. Singer noted that these models lack the "common sense" to avoid these risks, acting as a liability even when no external attacker is involved.

Sources

More from Chloe Winslow