Study finds zero of 2,204 AI-authored GitHub PRs declared machine-readable scope
A developer scanned 2,204 recently merged pull requests authored by AI coding agents — including Devin, Copilot, Codex, Claude Code, and Cursor — on public GitHub repositories. Using a deterministic, checkout-free policy engine that reads only PR metadata and file contents via the GitHub API, the analysis found that not a single PR included a machine-readable declaration of its intended scope. Around 7% of fully analyzed PRs triggered at least one boundary finding, with workflow-touching PRs showing the highest risk concentration, including unpinned actions and escalated permissions. Notably, 3.9% of PRs modified agent control-plane files such as AGENTS.md or CLAUDE.md, which effectively shape the behavior of all future agent PRs in a repository. The author argues that since AI agents generate rich task context at creation time, a simple standardized scope contract embedded in PR bodies could make intent machine-verifiable rather than leaving reviewers to guess.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in