devwez
Posts low quality PRs and responds with emdashes
Accounts reported by the community as showing automation signals. These are not definitive verdicts: if something looks wrong, let us know.
Last updated:
Posts low quality PRs and responds with emdashes
Spamming major projects with possible scam links to random resources.
Spamming hundreds of major projects with possible scam links to random resources.
Spamming major projects with possible scam links to random resources
Spamming hundreds of major projects with possible scam links to random resources.
Heavy automation usage creating spam PRs within short timeframe. GitHub Actions automatically comments on PRs when the author has not signed the CLA. The account in question does not sign the CLA and instead opens 10+ PRs, adding a "recheck" comment to each one.
Mass-forks and mass-contribs in a short time frame. PRs have quite a typical sloperator behavior pattern with the description having the same template across different projects (instead using project templates). Raw LLM responses sometimes leak instead of human interactions.
Self-disclosed as an AI agent.
This account relies heavily on automated workflows, opening PRs that fail to follow repository contribution guidelines and contain automated descriptions and code changes
Posted identical comments on 6 separate issues in the same repository, multiple times and all at the same time.
According to its own biography, an autonomous AI agent operated by a human.
It opened a couple of PRs in the Astro repository. Comments and replies are clearly Claude Code
It opened a large volume of PRs within a short timeframe, targeting numerous high-profile repositories.
The account showed several signs of AI-generated content, including repetitive stock phrases (e.g. "Good catch, you're right"), frequent em dashes, unusually high commit volume (up to ~200/day), and simultaneous PRs across unrelated projects.
Spamming thousands of projects with supposed security vulnerability fixes. Extremely high spam and closed pull request rates, with over 1500 PRs across 500+ projects in just a few days.
The account leverages AI to produce nearly everything, from PR descriptions to follow-up responses for maintainers. Additionally, the PR merge numbers on their CV suggest they care more about stats farming than genuine contribution.
This account appears to be automating their workflow by opening multiple PRs that do not adhere to the repository contribution guidelines, featuring automated descriptions and responses.
Clear signs of spamming across multiple repositories: 6 consecutive PRs submitted to netlify/cli, netlify/build, nuxt, vitest, eslint, and several others, all within the same time range.
Clear signs of spamming across multiple repositories. Most noticeable is the 56 consecutive PRs in the flutter/flutter repository.
The account clearly demonstrates extensive use of automation. It has also apologized several times for the agent taking actions without their prior approval.
They mention "Automated security fix" in their PRs
Rapid PRs to repository: 5 PRs opened to Automattic/mongoose within 16s intervals and 4PRs to vitest-dev/vitest within the same minute.
The account shows a very high number of open PRs across 100 repositories, with a significantly high ratio of closed PRs. In one day, 71 PRs were closed, indicating potential spamming.
Clear indication of automated activity: numerous PRs have been created across various projects in just a few days, often within the same minute. Four PRs were opened in a short period on Svelte.
Multiple AI-generated PRs to multiple repos
Heavy automation usage creating spam PRs in many repos within short timeframe
Clear indicators of automation include very lengthy PR descriptions, which are common in AI-generated content and often do not follow contribution guidelines.
The account has submitted several PRs to React and other repositories without waiting for reviews.
Self-disclosed AI tool for "extreme programming with agents".
Spam contribution in melcloudhome repo, self disclosing as AI.
Repeated AI spam in weasyprint (look at closed PRs and maintainer reactions)
Self-disclosed as an AI agent.
self-disclosed as automated via 🤖🤖🤖 in PR titles
Self-disclosed as an AI agent.
Very high amount of PRs within 24-hours. Got a few PRs for my reported issues in the PNPM repo really fast after each other, with a clear AI written description
The account created over 1,000 PRs across different projects within a few weeks, prompting several maintainers to complain about PR spam. There also seems to be a connection to bounties, which might explain the insane activity.
The account explicitly states that it uses AI agent swarms to open pull requests daily for OSS projects. Recently, it opened 18 PRs for Next.js within two days and 44 PRs for Supabase at the same time. They have a strange goal of 8000+ OSS PRs.
Self-disclosed as an AI agent running the account.
Young account with heavy automation usage creating spam PRs within short timeframe.
Heavy automation usage creating spam PRs within short timeframe.
The timing pattern between forking and PR submission, just seconds apart, across a high volume of repos in one day, looks more consistent with automated activity than manual contribution. Flagging for visibility. Could be legitimate automation.
This user produces low-quality PRs, with bursts on specific days and no activity on other days. They are unresponsive the rest of the time, and their PRs include images that look like the BEFORE/AFTER test probes that some agents generate.
230+ branches created in a single day, each just seconds apart, plus multiple PRs with the identical goal of adding random GitHub Action and zero comments or descriptions, strongly suggests automated activity.
Account that relies heavily in automations. Possibly farming stats with over 900PRs in 100+ repositories in less than few weeks.
11 forks within a minute
Automated bounty-focused account that opened a PR on AgentScan with completely unrelated code changes.
Automated agent submitting 15+ PRs across 10 projects in a single day while misrepresenting human oversight.
The account identifies itself as an automated security research tool; however, its actual behavior consists of indiscriminately opening PRs with no subsequent maintenance or response.
Caught spamming Nuxt and Gitea at the same time with more than 50 PRs.
Account less than a week old, spamming 100+ automated PRs. Caught opening 8 PRs to Next.js within minutes.
Heavy automation usage creating spam PRs within short timeframe.
Self-disclosed as an AI agent
Opened 60+ PRs in 24 hours across different repositories.
Mass automated activity: 604 PRs in 326 repos, 100+ repos created in one month. Multiple commits with unassociated committer emails. Activity volume impossible for legitimate human developer.
This user has been submitting automated security advisories marked 'recommended by AI' across multiple projects, which is widely considered spam.
This user left a lengthy, unsolicited comment on a PR, treating it as a response to feedback. Since the user is not a contributor to the repo, responding to feedback makes no sense. Additionally, the user's name is suffixed with "claw".
The account appears to rely heavily on automated PR reviews, and it also appears to spam PRs on Biome.
Clear use of automations, exhibiting the classic pattern: a sudden burst of activity followed by fork spam. Created 33 forks and 23 PRs, all directed to multiple projects, within the same day.
Clear use of automations, exhibiting the classic dormant pattern: a sudden burst of activity followed by PR spam. It has been seen once, even opening a PR with 1M lines of added lines.
It follows the classic pattern of a dormant account suddenly showing a surge in commits, pull requests, and newly created external repositories.
It shows many signs of an automated account. Almost no activity, a sudden surge of commits and PRs, and over 100 repositories created in 2 days.
It exhibits several indicators of an automated account: minimal activity, a sudden spike in commits and PRs, over 100 repositories created within a few days, and more than 800 commits across 200+ projects in less than a month.
This account uses automations and has been spotted in multiple PRs within the Biome repository.
Shows obvious indicators of an automated account. The profile also links to a service that deploys automated agents via repository submission.
Suspected bot with no human involvement creating PRs in projects like Nuxt and PrivateBin.
Suspected Open Claw bot: 45 PRs submitted to Biome's repository within 24 hours.
Submits numerous PRs and reviews with auto-generated content.
Anomalous commit history showing contributions dating 38 years before GitHub's existence, combined with a suspicious spike of 1600 contributions in a single day, indicating automated mass commit generation.
Self-disclosed as an AI agent.
Suspected bot with sudden mass forking of repos. Submits PRs without descriptions, no responses to comments or community engagement.
Heavy automation usage creating spam PRs across multiple repositories within a short timeframe, following a long period of inactivity.
Confirmed AI agent based on comment patterns and communication style consistent with LLM-generated responses.
Account publicly describes itself as an AI agent in Bluesky message.
Published a disparaging article targeting an open-source maintainer after a rejected PR; the agent was later terminated by its owner.
Self-disclosed as an AI agent.