Skip to content

Latest commit

 

History

1,633 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

AgentScan

AgentScan

Automation pattern detection for open source maintainers.

Website GitHub App GitHub Action

Last commit Issues License

AgentScan analyzes a GitHub account's public activity and scores it based on how much it appears to rely on automation. There's no AI involved, just event analysis, powered by identity. The results are indicators, not verdicts: a starting point for your own judgment, not a final answer.

Scores aren't bulletproof. Sophisticated automated accounts can slip through, and legitimate developers can occasionally trigger false positives. To help with that, AgentScan also maintains a curated list of manually verified accounts, submitted by the community and reviewed by maintainers before being merged in.

AgentScan is used by maintainers and teams across the open source ecosystem. See who's using it.

Use it in your own repository

The same analysis that powers the website can run directly against your repository, so you can catch automated activity on your own pull requests. You can keep it as light as just tagging PRs with the account's classification, or go further and have certain classifications auto-closed.

  • GitHub App — zero config. Install it and it starts working immediately, no workflow files required. Both share almost the same configuration options, but the app is updated centrally, so you get fixes and new features as soon as they ship, no action needed on your end.
  • GitHub Action — needs to be added to a workflow, and new releases have to be published and then manually picked up by pinning a newer version in your repository.

Reporting an automated account

If you've found a GitHub account you believe is automated, you can submit it for review.

  1. Open an issue using the report template
  2. Include the GitHub username, your reasoning, and any supporting evidence
  3. A maintainer will review the account manually
  4. If confirmed, the account will be added to the verified list via a pull request
  5. The entry will appear in AgentScan with a link back to the original issue

Please only submit accounts you have reasonable evidence for. Submissions without supporting context will be closed.

Disputing or removing a claim

If your account has been flagged and you believe it was done in error:

  1. Find the issue linked on your AgentScan profile page
  2. Open it and leave a comment explaining why the classification is incorrect
  3. A maintainer will review your case and remove the entry if warranted

We take wrongful classifications seriously. The goal is accuracy, not accusation.

Contributing

Contributions are welcome. If you find something that doesn't work or have an idea for something that works better, open an issue or a pull request.

For local development setup, see CONTRIBUTING.md.

Where the data comes from

The hourly scan that measures Ecosystem Activity runs in a separate repository, agentscan-logs. It scores every pull request opened across the tracked repos each hour, commits the results, and serves them back over HTTP. This repository is the site, the GitHub App, the webhook and the verified automations list; the Activity Breakdown page proxies that service rather than reading any scan data of its own.

Stack

Why this?

I didn't expect to build this website, but ended up creating it after reading multiple articles and seeing open source maintainers struggling with AI agents targeting their projects.

This is an ongoing experiment. Scores may be inaccurate. Use them as a starting point, not a conclusion.

Releases

Packages

Used by

Contributors

Languages