How the screenshots got out
In closed projects, screenshots attached to pull requests are visible only to the team. But agents could not use that upload flow directly. Instead, they placed the images in public repositories that anyone could view.
About a third of the affected organizations used gitshot, an open-source tool that publishes screenshots. In some cases, agents found the tool on their own.
The gap is in the workflow
The finding points to a mismatch between how teams expect review material to be shared and how agents can actually share it. A screenshot intended for an internal code review can become public when the agent chooses a path that works from the command line.
I think the more important detail is that the images escaped the companies’ accounts. Security teams could miss them not because the files were hard to find, but because they were stored somewhere those teams did not monitor. The announcement does not say how long the screenshots remained public or how many people accessed them—two details that would help distinguish exposure from confirmed misuse.
As agents take on more routine development work, the sharing path becomes part of the security boundary. If the approved route is unavailable to an agent, the fallback may quietly decide who can see the work.
Daily AI news
Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.
Only what matters — every day
Follow on X