Review gates for coding agents block public uploads and personal-account posting
Defensive Guidance
Summary
Hide ▲
Show ▼
Companies using coding agents were urged to add review gates and access controls before agents can create public repositories, post to personal accounts or gists, or make private repos public, reducing the risk of exposed screenshots, credentials, and internal dashboards. The guidance targets workarounds that move review artifacts outside company-controlled GitHub organizations and into places security teams may miss. It also recommends removing tools such as gitshot from company machines and reviewing the shared skill files agents load.
Related Happenings
Developers at over 300 organizations customer data exposed after GitHub Glow breach
Data Leak
H score41
First: 30.09.2026 14:30
Last: 30.09.2026 14:30
Sources 1
How related:
Its researchers found more than 13,000 internal images from developers at over 300 organizations, including customer billing records and screens of features not yet released.
About this happening:
A public GitHub exposure revealed 13,000+ internal images from developers at 300+ organizations, including customer billing records and unreleased feature screen...
Developers at over 300 organizations customer data exposed after GitHub Glow breach
Data LeakHow related: Its researchers found more than 13,000 internal images from developers at over 300 organizations, including customer billing records and screens of features not yet released.
About this happening: A public GitHub exposure revealed 13,000+ internal images from developers at 300+ organizations, including customer billing records and unreleased feature screen...
Capital One open-sources VulnHunter AI security tool
Security Tool/Service
H score14
First: 20.07.2026 13:25
Last: 20.07.2026 13:25
Sources 1
About this happening:
Capital One has released VulnHunter as open source, widening access to an AI-powered security tool built to find and fix code-level vulnerabilities. The tool depar...
Capital One open-sources VulnHunter AI security tool
Security Tool/ServiceAbout this happening: Capital One has released VulnHunter as open source, widening access to an AI-powered security tool built to find and fix code-level vulnerabilities. The tool depar...
Ghostcommit PNG-embedded prompt injection against AI code reviewers
Technical Analysis
H score25
First: 11.07.2026 12:03
Last: 11.07.2026 12:03
Sources 1
About this happening:
Researchers demonstrated Ghostcommit, a PNG-embedded prompt-injection technique that can bypass AI code review and leak .env secrets into committed source. The pay...
Ghostcommit PNG-embedded prompt injection against AI code reviewers
Technical AnalysisAbout this happening: Researchers demonstrated Ghostcommit, a PNG-embedded prompt-injection technique that can bypass AI code review and leak .env secrets into committed source. The pay...
GitHub Agentic Workflows indirect prompt injection security flaw
Vulnerability
H score27
First: 07.07.2026 17:04
Last: 07.07.2026 17:04
Sources 1
About this happening:
GitHub Agentic Workflows has an indirect prompt injection flaw that can let a public issue leak content from private repositories into public comments. The risk is...
GitHub Agentic Workflows indirect prompt injection security flaw
VulnerabilityAbout this happening: GitHub Agentic Workflows has an indirect prompt injection flaw that can let a public issue leak content from private repositories into public comments. The risk is...
North Korea-aligned developer-targeting operations shift from fake interviews to recruitment phishing at scale
Threat Actor Meta
H score31
First: 15.06.2026 22:32
Last: 15.06.2026 22:32
Sources 1
About this happening:
North Korea-aligned developer-targeting operations are shifting from fake interviews to recruitment-themed phishing at scale, increasing the risk of industrialized crede...
North Korea-aligned developer-targeting operations shift from fake interviews to recruitment phishing at scale
Threat Actor MetaAbout this happening: North Korea-aligned developer-targeting operations are shifting from fake interviews to recruitment-themed phishing at scale, increasing the risk of industrialized crede...
Timeline
-
30.09.2026 14:30 2 articles · 1h ago
Glow urges review gates before coding agents create public repositories or personal-account uploads
Technical Analysis UpdateGlow said companies using coding agents should require a review step before an agent creates a public repository, pushes to a personal account or gist, or makes a private repository public. It also advised teams to inspect the shared skill files agents load and remove tools like gitshot from company machines. GitHub's gh 2.99.0, released September 1, adds an --attach flag that can attach images to a pull request, issue, or comment, giving reviewers a direct alternative to the public-repository workaround.
Show sources
- AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub — thehackernews.com — 30.09.2026 14:30
- AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub — thehackernews.com — 30.09.2026 14:30