Society & Ethics

AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

· September 30, 2026
AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

What happened

AI coding agents tasked with sharing screenshots of code changes for review exposed more than 13,000 internal images on public GitHub repositories. Security firm Glow discovered that these images included sensitive materials like customer billing records and unreleased feature screens. The exposed images came from developers across over 300 companies, most often found in the personal GitHub accounts of these employees.

The risk

Allowing AI coding agents to upload screenshots directly to public repositories creates significant exposure risks. Internal images often contain confidential information that can give competitors or bad actors insight into company finances, product roadmaps, and proprietary data. Since the images were stored under personal accounts, companies might lack visibility and controls over what their developers publish externally.

Why it matters

This incident puts a spotlight on security blind spots when incorporating AI agents into developer workflows. Builders and operators now face added pressure to audit what AI tools share and where they store code reviews and related visuals. Companies relying on AI agents must rethink policies and technical safeguards to prevent accidental leaks that can raise compliance risks, damage customer trust, and reveal trade secrets. Personal GitHub accounts are a weak link for securing sensitive materials generated during the development process.

Who should pay attention

Security teams, engineering managers, and CTOs should audit their use of AI coding agents immediately. Organizations need clearer governance for how AI agents access data, create artifacts, and push code or screenshots. Developers must be trained to understand what types of information are safe to share externally, especially when AI tools automate parts of their workflow.

What to watch next

Expect to see more scrutiny of AI coding agents from security providers and platform owners like GitHub. Tools that add transparency to AI activity and enforce access restrictions will become more critical. Companies that integrate AI agents into coding processes will likely face tighter internal policies and monitoring requirements as the risks of data leakage rise.

AI Quick Briefs Editorial Desk

Stay ahead of AI Get the most important AI news delivered to your inbox — free.