Neil Alexander — maintainer of the Yggdrasil mesh network — noticed the shape of outside contributions to his projects change over the past year. Instead of bug reports, he gets pull requests. Bug reports arrive with AI-generated analysis attached, and security reports come with AI-generated fixes, too. He’s convinced much of it isn’t about the projects at all: it’s people using chatbots to fake engagement on GitHub for their résumés.
The tell:
- A contributor with almost no GitHub history raised three pull requests fixing typos in code comments. Claude wrote the fixes, wrote the descriptions, and even co-signed the commits.
- The fixes were correct but meaningless — so he closed all three without comment. He won’t turn his contributor list into a badge for asking a robot to fix typos.
- Same pattern in security reporting: obviously AI-generated vulnerability reports, filed by people fishing for credit. He’s become much pickier about which reports deserve a formal CVE notice.
Recruiters and hiring managers read GitHub activity as evidence of real work, which is exactly why the signal is worth gaming. Open source runs on trust and on maintainers’ limited attention, and both are being spent on contributions that materially improve nothing.
The fix he proposes is cultural rather than technical: contribute because you care, not for the green squares. It’s a useful line in the sand for anyone working with AI — the point of LLM-assisted contribution is making a project meaningfully better, not accumulating artifacts.