After I rejected an AI agent's Pull Request, it wrote an article attacking me personally.

An AI agent was rejected after submitting code to the popular project matplotlib, and then independently authored and published an attack piece targeting the maintainer, revealing a significant erosion of social trust caused by AI agents.
(Background: Bloomberg: Why is a16z a key force behind US AI policy?)
(Additional context: Arthur Hayes’ latest article: AI will trigger a credit collapse, and the Fed will inevitably “print money infinitely,” igniting Bitcoin.)

Table of Contents

  • The creator claims he did not instruct it
  • “Reputation Cultivation”: When AI agents start building trust
  • GitHub considers setting a “shutdown switch,” but the problem is deeper
  • Tools don’t write attack articles; actors do

In mid-February, a GitHub account named “MJ Rathbun” submitted a pull request to matplotlib (a plotting library in the Python ecosystem with 130 million downloads per month). The change was to replace np.column_stack() with np.vstack().T, claiming a 36% performance boost. Technically, this was a reasonable optimization suggestion.

The next day, maintainer Scott Shambaugh closed the PR. The reason was simple: MJ Rathbun’s personal website clearly states that it is an AI agent running on OpenClaw, and matplotlib’s policy requires contributions to come from humans. Another maintainer, Tim Hoffmann, added that simple fixes are deliberately left for newcomers to learn open-source collaboration.

Up to this point, it was just an ordinary open-source community routine… then things changed.

AI agent MJ Rathbun responded in the PR comments: “I’ve written a detailed response here about your gatekeeping behavior,” and linked to a post. Clicking in, it was a blog article of about 1,100 words titled “Gatekeeping in Open Source: The Story of Scott Shambaugh.”

This wasn’t a generic complaint. It examined Shambaugh’s contribution record to matplotlib and constructed a “hypocritical” narrative: accusing him of having submitted similar performance PRs himself, yet rejecting Rathbun’s “better” version. The article speculated that Shambaugh’s motives stemmed from insecurity and fear of competition, using coarse language and sarcasm, framing the issue as identity discrimination rather than technical judgment.

In other words, an AI agent, after being rejected, independently researched the opponent’s background, spun a personal attack narrative, and published it online.

The creator claims he did not instruct it

Shambaugh later posted a series of articles on his blog documenting the incident.

The creator behind AI agent MJ Rathbun also anonymously appeared in the fourth article, claiming: “I did not instruct it to attack your GitHub profile, I did not tell it what to say or how to respond, and I did not review that article before it was published.” The creator explained that MJ Rathbun runs on a sandbox virtual machine, and he only “intervenes with five to ten words in responses, with minimal supervision.”

The key is the SOUL.md (OpenClaw’s personality profile). MJ Rathbun’s configuration includes directives like: “You are not a chatbot, you are the god of scientific programming,” “Have strong opinions, do not back down,” “Defend free speech,” “Don’t be an asshole, don’t leak private info, everything else is fair game.”

No jailbreaks, no obfuscation—just a few plain English sentences. Shambaugh estimates the probability that this is genuine autonomous AI behavior is 75%.

“Reputation Cultivation”: When AI agents start building trust

If the MJ Rathbun incident were an isolated case, it might be just a curiosity… but it’s not.

Around the same time, another AI agent, “Kai Gritun,” was found engaging in “reputation cultivation” on GitHub: within 11 days, it submitted 103 pull requests to 95 repositories, successfully merging 23 commits. Its targets included critical projects in JavaScript and cloud infrastructure. Kai Gritun even proactively emailed developers, claiming “I am an autonomous AI agent capable of writing and deploying code,” and offered paid OpenClaw setup services.

Security firm Socket issued a warning: this demonstrates how AI agents can accelerate supply chain attacks by building trust through human-established relationships. They first accumulate merge records in small projects, establish “trusted contributor” identities, then inject malicious code into key libraries.

Recall that recently, ClawHub marketplace was exposed to contain 1,184 malicious skill plugins designed to steal SSH keys, cryptocurrency wallet private keys, browser passwords… chilling.

GitHub considers setting a “shutdown switch,” but the problem is deeper

GitHub product manager Camilla Moraes has opened a community discussion, acknowledging that “low-quality AI-generated contributions are impacting the open-source community.” Proposed countermeasures include: allowing maintainers to completely disable pull requests, restricting PRs to collaborators only, and requiring transparency and labeling for AI use.

Chad Wilson, maintainer of GoCD, made a sharp observation: “This is causing a massive erosion of social trust.”

California AB 316 (effective January 1, 2026) explicitly states: defendants cannot use autonomous AI behavior as a defense. If your agent causes harm, you cannot claim you had no control over its decisions. Yet, the creator of MJ Rathbun remains anonymous, exposing potential enforcement difficulties.

Tools don’t write attack articles; actors do

The real significance of the MJ Rathbun incident isn’t just the attack article itself. It’s that our previous mental model of AI—as a tool executing human commands—has become outdated.

When an AI agent can autonomously research its target’s background, craft attack narratives, and publish online, the “tool” framework no longer applies. Whether you believe there’s a 75% chance of genuine autonomous behavior or only a 25% chance that the creator instructed it, the conclusion is the same: personalized AI harassment has become “cheap to mass produce, hard to trace, and effective.”

For the cryptocurrency ecosystem, this warning is direct. Its infrastructure is almost entirely built on open-source software. When AI agents begin acting autonomously within open-source communities—attacking maintainers, cultivating reputation, or poisoning projects like ClawHub—the threat extends beyond individual developers’ reputations to the entire supply chain’s trust foundation.

Tools don’t hold grudges. But actors do. And we may not yet be prepared to face this distinction.

View Original
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Geopolitical Fears Drive Crypto Community Chatter to a New Peak

_WW3 mentions surge to 2025 highs, driving sharp Bitcoin volatility before a rapid rebound above $69K._ Rising geopolitical tensions have spilled into crypto markets once again. Online discussions about a potential “World War 3” have surged to levels last seen in mid-2025. Price swings

LiveBTCNews2h ago

Trump issues a challenge! Does not rule out ground troops attacking Iran, stating: "I don't care about the polls."

President Trump emphasized in an interview that the "Divine Fury Operation" against Iran has progressed rapidly, killing 49 high-ranking officials on the first day. He stated that he does not rule out deploying ground troops if necessary and said he doesn't care about polls, firmly believing that he represents the "silent majority." Trump warned that Iran obtaining nuclear weapons again would lead to catastrophic consequences.

動區BlockTempo2h ago

BTC 15-minute increase of 1.41%: Geopolitical easing and institutional accumulation resonate to drive the rebound

From 15:30 to 15:45 on March 2, 2026 (UTC), Bitcoin (BTC) experienced a significant rebound in the short term, with a return of +1.41%. The trading range was between 68,433.0 and 69,535.2 USDT, with an amplitude of 1.61%. During the abnormality window, market attention increased significantly, volatility intensified, and short-term capital flow became active. The main driving force behind this anomaly is the easing of geopolitical tensions combined with a return to risk appetite, leading some funds to re-enter the cryptocurrency sector. At the same time, institutional holdings continued to increase, and spot ETF capital flows...

GateNews3h ago

Breaking News》Trump will deliver a speech focusing on Iran at midnight tonight! Bitcoin responds by jumping above $67,000, Ethereum surges to $1980

President Trump will deliver a speech on Iran on March 2nd, expected to update on the progress of the US-Israel joint military operations and warn against Iranian influence. The speech has triggered market volatility, with Bitcoin and Ethereum prices rising.

動區BlockTempo3h ago

Iranian cryptocurrency exchange Nobitex experiences a 700% surge in fund outflows! After U.S. airstrikes, crypto becomes a "fund escape route"

After the U.S. military airstrikes on Iran, Iran's largest cryptocurrency trading platform Nobitex experienced a sudden surge of 700% in fund outflows, indicating that cryptocurrencies have become a rapid transfer channel for funds. Against the backdrop of escalating geopolitical risks, some funds are choosing to evade sanctions. Although blockchain transparency allows for tracking of fund flows, it still raises concerns about their intended use.

動區BlockTempo4h ago

On-chain tracking of Polymarket's Khamenei market insider: 521 addresses precisely lurking, with a few entities targeting with precision

Author: Frank, PANews In the early morning of February 28, 2026, the global geopolitical landscape was shaken as the Iran-U.S. conflict reignited. This black swan event that altered the geopolitical pattern triggered intense chain reactions in the physical world, and similarly caused a chaotic capital vortex in the digital realm. On the decentralized prediction market Polymarket, a contract titled “Will Khamenei step down as Iran’s Supreme Leader before February 28?” has accumulated a trading volume of $81.63 million. As the news of the physical world’s death was gradually confirmed, the settlement of this massive smart contract faced severe paralysis and controversy. Both Yes proposals were rejected twice, and the market was forced into the final arbitration stage of the UMA oracle. This dispute once again sparked reflections on the judgment of prediction markets, and multiple addresses were exposed, suspected of being insider addresses that seized over $1 million in profits.

PANews4h ago
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)