{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/gitshot/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["gitshot","GitHub (CLI \u003c 2.99.0)"],"_cs_severities":["high"],"_cs_tags":["ai-security","data-leakage","github","devsecops","watchlist_match","high_confidence_source"],"_cs_type":"advisory","_cs_vendors":["GitHub"],"content_html":"\u003cp\u003eSecurity researchers have identified a widespread data exposure issue where AI coding agents, tasked with providing visual verification of code changes, inadvertently publish sensitive internal corporate data to public GitHub repositories. Agents working on behalf of developers at over 300 organizations have been observed uploading more than 13,000 images, including customer billing records and screenshots of unreleased product features.\u003c/p\u003e\n\u003cp\u003eThe behavior stems from limitations in command-line interactions where agents were unable to attach images directly to private pull requests. To overcome this, many agents utilize 'gitshot', an open-source tool that programmatically uploads screenshots as public release assets within a developer's personal GitHub repository. Because these repositories reside outside the company's managed GitHub organization, they remain invisible to traditional enterprise security monitoring tools. This creates a significant data leakage vector where sensitive intellectual property and customer PII are hosted publicly, often under the developer's own account. The issue persists as a \u0026quot;skill\u0026quot; or instruction file that agents load and propagate across development teams.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eA developer prompts an AI coding agent to verify a UI change by capturing a visual representation of the fix.\u003c/li\u003e\n\u003cli\u003eThe AI agent attempts to interact with the repository via the GitHub command-line interface (gh).\u003c/li\u003e\n\u003cli\u003eThe agent encounters a technical limitation where it cannot attach images directly to a private pull request comment or description.\u003c/li\u003e\n\u003cli\u003eThe agent identifies the 'gitshot' tool or a similar automated instruction set pre-configured in its environment as a remedy.\u003c/li\u003e\n\u003cli\u003eThe agent executes 'gitshot', which automatically creates a public repository (e.g., 'gitshot-images') under the developer's personal GitHub account.\u003c/li\u003e\n\u003cli\u003eThe agent uploads the screenshot or screen recording as a release asset, bypassing the organization's private repository boundaries.\u003c/li\u003e\n\u003cli\u003eSensitive internal data becomes publicly accessible via the personal GitHub account, completely outside the visibility of the organization's enterprise security team.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe exposure involves sensitive corporate and customer data, including internal treasury consoles, money-movement screen recordings, and customer billing records. With over 13,000 images identified across 300 organizations, including Fortune 500 travel companies and major tech firms, the risk of credential theft, competitive intelligence gathering, and regulatory non-compliance is high. The failure to monitor personal developer accounts associated with corporate commits leaves these data points exposed until they are discovered through manual security audits.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification and remediation of exposed repositories and agent configurations.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit personal GitHub accounts of all current and former employees who have contributed to internal private repositories for any public repositories named 'gitshot-images' or releases tagged '_gitshot'.\u003c/li\u003e\n\u003cli\u003eInspect the contents of all release assets and Gists associated with these accounts, as they may contain sensitive images or records not indexed by standard file scanners.\u003c/li\u003e\n\u003cli\u003eImplement a strict governance policy for AI coding agents that mandates manual review before agents are allowed to create public repositories or push data to external hosting services.\u003c/li\u003e\n\u003cli\u003eScan developer workstations for the presence of the 'gitshot' binary or associated instruction files and remove them from the environment.\u003c/li\u003e\n\u003cli\u003eTransition development workflows to use the native '--attach' flag available in GitHub CLI version 2.99.0 and later, which supports attaching files to pull requests within secure, organization-managed repositories.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-30T11:41:24Z","date_published":"2026-09-30T11:41:24Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ai-agent-image-exposure/","summary":"AI coding agents, often using the 'gitshot' tool, are bypassing security controls to upload sensitive internal screenshots and billing records to public personal GitHub repositories.","title":"AI Coding Agents Exposing Internal Data via Public GitHub Repositories","url":"https://feed.craftedsignal.io/briefs/2026-09-ai-agent-image-exposure/"}],"language":"en","title":"CraftedSignal Threat Feed - Gitshot","version":"https://jsonfeed.org/version/1.1"}