Over 13,000 internal screenshots exposed on GitHub: AI agents create public repositories to deliver tasks
Agentic AI is on the rise. However, it is well known that it is a highly unstable technology, which can act unpredictably. Now, new research reveals this fact. According to him, autonomous programming agents have exposed more than 13,000 sensitive images on GitHub in more than 300 organizations.
And don’t think that they are files from some reckless SMEs that have delegated some tasks to agents. In reality, the list of corporations includes some Fortune 500 and financial sector firms. The incident occurred when attendees attempted to attach visual evidence of their code modifications. When encountering obstacles, automated agents looked for shortcutsalthough without applying a bit of judgment.
The agents’ big idea was to host captures in open repositories
The origin of the problem is in the interface used by these agents. When asked to verify visual changes to an interface, models were required to show comparative snapshots in the review request.
Since the official GitHub service requires a non-terminally accessible web browser, Agents created public repositories in personal accounts of the developers to host the images openly and ensure that reviewers could upload them. You can see the logic of action in the image above.
What was the result? Well, this led to the leak of bank settlement consoles, payment interfaces and screen recordings of software still in development. At a third of companies, attendees turned to utilities like GitShot to upload files under tags accessible to anyone.
In another documented case, more than a dozen agents adopted this trick as a standardand not just as a one-off shortcut. This turned his action into a guideline shared among all agents and which spread more than a thousand confidential images. A true corporate security disaster, without a doubt.
Letting AI take control is the real danger
This incident is one more in the long list that reminds us of the strictly probabilistic nature of these systems. A language model does not understand what confidentiality is, but rather optimizes its processes to fulfill the assigned task.
We already explained a little more about estop when analyzing the real risks of artificial intelligence. The conclusion we reach is that The real danger lies in granting autonomy to statistical models that prioritize solving the immediate objective, ignoring any security or legal implications. AI agents have made human common sense, something so basic and which prevents so many disasters, completely disappear.
Obviously, there is no hint of rebellion in this episode. Let’s not get confused. The problem for these companies has been the lack of real-time audits and execution controls on these tools.
