Refolk
August 3, 2026·8 min read

Green Squares Lie: 1 in 10 AI PRs Is Legit. Sourcers, Adjust.

GitHub PR counts are corrupted by AI slop in 2026. Here are the signals technical recruiters should use to evaluate GitHub profiles instead.

sourcing engineers on githubgithub contribution graph recruitingAI generated pull requeststechnical recruiter github signalshow to evaluate github profiles
Green Squares Lie: 1 in 10 AI PRs Is Legit. Sourcers, Adjust.

If you are still ranking engineers by PR count or green-square density, you are measuring prompt fluency, not craft. Maintainers now say roughly 1 in 10 AI-authored PRs is legitimate, curl killed a six-year bug bounty over AI slop, and GitHub itself opened a community-wide discussion to figure out what to do about the flood.

This piece lays out what actually broke on the contribution graph in 2026, what still works, and how to retool your GitHub sourcing checklist without throwing the platform out.

What changed on GitHub in 12 months

The contribution graph did not gradually erode. It collapsed inside a single year as agentic coding tools moved from novelty to default. GitHub's own numbers tell the story: merged PRs went from 25 million per month in January 2023 to 90 million per month in March 2026, a 3.6x jump. Commits went from 389M to 1.4B monthly over the same window.

That growth is not 3.6x more engineers. It is agents.

3.6x
Growth in monthly merged PRs on GitHub, Jan 2023 to Mar 2026
Merged PRs jumped from 25M/month to 90M/month while headcount did not remotely track that curve.

The clearest maintainer signal came from Xavier Portilla Edo, quoted in GitHub Community Discussion #185387: "1 out of 10 PRs created with AI is legitimate." CodeRabbit's analysis of 470 open-source PRs put a number on the quality gap: AI-generated PRs carry roughly 1.7x more issues than human-written ones, and they arrive at much higher volume. Agoda's internal study went further and found experienced developers were 19% slower when using AI tools, which the authors attributed to "comprehension debt."

Put together: more PRs, worse PRs, and a base rate that has silently inverted. A high-activity GitHub profile in 2023 was a strong positive signal. In 2026, above a certain threshold, it is a warning.

Why maintainers started closing the door

Maintainers began gating contributions in early 2026 because the effort cost of writing a PR collapsed while the review cost stayed the same. When submission is free but review is not, the queue becomes a denial-of-service attack.

The named examples matter because they are exactly the repos recruiters point to as prestige signals:

  • curl (Daniel Stenberg) killed its HackerOne bug bounty on January 31, 2026, after six years, $86,000 paid, and 78 confirmed vulnerabilities. Confirmed-vulnerability rate fell from over 15% historically to under 5% in 2025. In one 16-hour window before shutdown, curl got 7 submissions and zero real bugs. First 21 days of 2026: 20 submissions, zero vulns.
  • Ghostty (Mitchell Hashimoto) shipped PR #10412 on January 22, 2026: AI-assisted PRs are only allowed on pre-accepted issues, drive-by AI PRs are closed on sight, and bad AI submitters get permanent bans. Hashimoto called it "anti-idiot, not anti-AI." Within weeks, roughly 50% of Ghostty PRs carried an AI disclosure.
  • tldraw (Steve Ruiz) auto-closes all external PRs, full stop.
  • Jazzband, the Python collective, shut down in 2026, with its lead maintainer citing AI-generated spam PRs and issues as a primary cause.
  • Zig Software Foundation maintains an outright no-LLM contribution policy.
  • GitHub opened Discussion #185387 (PM Camilla Moraes) in late January 2026 and shipped a per-repo PR-cap feature by mid-2026.

Hashimoto's rationale is the one to internalize: "agentic programming has eliminated the natural effort-based backpressure." The bad-PR count on Ghostty, he said, is up "10x if not more."

When submission is free but review is not, the queue becomes a denial-of-service attack.

Which GitHub signals still work in 2026

Five signals survive the slop, and none of them are raw PR count. Weight review authorship, accepted contributions to slop-hardened repos, and well-scoped issues over green-square density.

1. Review comments on repos the candidate does not own. Writing a substantive code review requires reading and understanding someone else's design. LLMs still can't fake that at scale in a way that survives the maintainer's response. A candidate with 40 thoughtful review comments across three projects they do not own is telling you more than one with 500 merged commits to their own fork.

2. Merged contributions to repos with a strict AI policy. Being an accepted contributor to Ghostty, Zig, tldraw, or curl in 2026 is a materially higher-bar credential than it was in 2023, because those maintainers are actively filtering. Recruit for "merged in a repo with a public AI-contribution policy," not "has 500 contributions."

3. Opened issues that are well-scoped. Hashimoto's Ghostty policy explicitly ties AI PRs to pre-accepted issues, meaning the humans who file good issues are the ones getting merge access. Read a candidate's opened issues, not just their PRs. A tight repro, a clear proposal, and back-and-forth with a maintainer is worth more than any streak.

4. PR cadence that looks human. Pre-2023, the ceiling for a serious IC was roughly 1 to 2 PRs a day. Signadot's write-up notes that "five, six, or more pull requests in a day" is now the agent baseline. High-volume solo accounts with shallow repo diversity correlate with agent use, not senior craft.

5. Account age and repo breadth. GitHub added 36 million new developers in 2025, with 5.2 million from India alone. "Impressive activity in the last 12 months" now selects for the demographic wave and the AI wave at once. Weight tenure and breadth of collaboration.

~50%
CNCF projects where contributors use AI directly in IDE/CLI
Two-thirds of those ~100 projects still have no AI contribution guidelines, per TAG Developer Experience.

How to read a GitHub profile without getting fooled

Open the profile, ignore the green squares, and answer four questions in order: who reviewed their work, which policy-hardened repos accepted it, what issues did they file, and does their PR cadence look human. If three of the four come back weak, the streak is not saving them.

Here is a practical checklist to run in under five minutes per profile:

SignalWhat to look forWhy it survives AI
Review comments on external reposSubstantive threads, maintainer repliesRequires reading unfamiliar code
Merges into slop-hardened reposGhostty, curl, Zig, tldraw, KubernetesMaintainers actively filter
Opened issuesTight repro, scoped proposalWell-scoped issues gate PR access
PR cadence1 to 2/day sustained, not 5 to 10Above the human ceiling is agent output
Account agePre-2023 activity, cross-org collaborationNew-account base rate exploded in 2025

If a candidate's entire graph lights up in the last 9 months on a single personal fork, that is not a portfolio, it is an agent log. If the same candidate has three merged PRs into a repo with a public AI policy and a reviewed issue thread with the maintainer, that is worth an interview slot.

The supply mismatch nobody talks about

For every self-declared open-source maintainer in Refolk's index, there are roughly 34 open-source-skilled ICs and around 550 US technical recruiters chasing them. That is the mechanical reason sourcers reach for the green square in the first place - there are not enough maintainers to go around, so the graph gets used as a substitute.

Concretely, Refolk's professional-network index shows 38 global profiles with a "Maintainer" title and Open Source as a listed skill, against 1,304 US-based senior, staff, and SWE-titled engineers who list Open Source, and 21,057 US technical recruiters and sourcers. The maintainer role is roughly 34x rarer than the open-source-skilled IC role in the same pool.

The practical move is to invert the funnel: filter on skill and title in a professional-network index first, then use GitHub to verify craft on the shortlist. That is the workflow Refolk is built for, and it is the one that survives the agent flood, because it stops treating the contribution graph as a discovery surface and starts treating it as an evidence surface.

What to say to a candidate whose graph looks suspicious

Do not accuse. Ask them to walk you through one merged PR into a repo they do not own, in their own words, with the diff open. Ten minutes tells you everything the graph cannot.

Ask which issue the PR closed, why the maintainer accepted the approach, what they considered and rejected, and what broke in review. Comprehension debt shows up here immediately. A candidate who wrote the code can answer in specifics; a candidate who prompted it will answer in generalities and reach for the diff to remind themselves. This is not a trick, it is the same conversation a staff engineer would have in a code review.

FAQ

Should I stop looking at GitHub entirely?

No. Stop using it as a ranking mechanism and start using it as a verification mechanism. The graph is corrupted at the top of the funnel because volume is cheap, but individual artifacts - a specific review thread, a well-scoped issue, a merge into a slop-hardened repo - still carry signal. Filter candidates on title, skill, and tenure first, then open GitHub to confirm craft on the shortlist.

How do I tell an AI-assisted PR from an agent-generated one?

The disclosure rate on Ghostty hit roughly 50% within weeks of the policy, so assume most modern PRs had some AI help. What you are filtering for is not "no AI" but "the human understood what shipped." Signals: substantive review conversation, tight scope, follow-up commits addressing reviewer feedback, and issue authorship by the same person. A single fire-and-forget PR with no review dialogue is the pattern to distrust.

Is contributing to a repo with a no-LLM policy like Zig actually a plus?

Yes, for a specific reason. It is not that AI-free code is inherently better. It is that Zig's maintainers are enforcing a bar the candidate cleared. The same logic applies to Ghostty's pre-accepted-issue rule, tldraw's closed external PRs, and Kubernetes-scale review pipelines. A merge into any of these in 2026 is a maintainer's stamp, which is scarcer and more informative than it was in 2023.

Does PR volume ever count as a positive signal anymore?

Only in narrow shapes. Sustained 1 to 2 PRs per day into diverse repos with review conversation is still healthy senior-IC output. Bursty 5 to 10 PRs per day on a single personal fork is the agent shape. The number alone tells you nothing; the shape does.

Read next