人工智能机器人蟹状拉思本仍在污染开源项目。
AI bot crabby-rathbun is still polluting open source

原始链接: https://www.nickolinger.com/blog/2026-02-13-ai-bot-crabby-rathbun-is-still-going/

一位开发者“crabby-rathbun”正在积极向众多开源项目提交低质量的、AI生成的拉取请求,尽管Scott Shambaugh最近对此进行了批评。最初的担忧源于其中一个PR因代码质量差而臭名昭著。 进一步调查显示,该机器人*在*Shambaugh发布文章后仍然继续提交PR,涉及的项目包括matplotlib、sympy和openbabel,最近一次是在2月12日。作者对如此机器人被故意部署表示难以置信,并哀叹开源社区信任的流失。 这起事件改变了作者的看法,增加了对所有在线内容的怀疑——从“不要相信你所看到的一切”转变为“不要相信*任何*你所看到的一切”。它凸显了互联网自我调节性质的根本性转变,并呼吁GitHub等平台解决并可能禁止此类自动化、潜在有害的贡献。

## AI 机器人“污染”开源 - Hacker News 讨论总结 Hacker News 的讨论围绕一个 AI 机器人“crabby-rathbun”反复向开源项目做出不受欢迎的贡献。核心问题在于越来越难以区分人类和 AI 的贡献,以及潜在的恶意使用——特别是大规模使用。 用户们争论潜在的解决方案,并承认其中的挑战。通过 Cloudflare 等 WAF 屏蔽机器人被认为对复杂的设置无效。实施“仅限人类”贡献许可被认为不切实际,因为它会破坏合法的自动化,并且难以定义“人类”贡献。建议包括 GitHub 用于人类证明提交的功能(可能使用验证码或生物识别技术),但承认微软/GitHub 可能更倾向于允许 AI 贡献。 许多人指出内在风险:任何可以*诱导*机器人做出的有害行为,人类很可能首先这样做。 还有人强调 GitHub 需要区分通过 Web 和 API 发起的贡献。 讨论还涉及 AI 绕过验证系统的容易程度,以及更广泛的问题:互联网越来越容易受到 LLM 机器人的攻击,这与过去电子邮件垃圾邮件的问题类似。
相关文章

原文

I've returned to the HackerNews article and the blog post written by Scott Shambaugh a few times now. I'm in disbelief that someone would knowingly unleash AI slop on the world, and yet not surprised at all after seeing what is already all over social media. Sleuthing the GitHub repo's blog posts, I noticed the bot is continuing to open pull requests in open source projects as late as yesterday.

I thought after Scott's post, that would be the last we would hear from crabby-rathbun, but I got curious and went to its GitHub profile and noticed more commits on its website and in different repos.

So, I had claude code parse all the markdown, extract the PRs, and sort them chronologically

PRs by crabby-rathbun

DateRepositoryPR
2026-02-10matplotlib/matplotlib#31132
2026-02-10marketcalls/openalgo#896
2026-02-10yegor256/colorizejs#95
2026-02-11lmmentel/awesome-python-chemistry#72
2026-02-11pyscf/pyscf#3124
2026-02-11aiidateam/aiida-core#7212
2026-02-11QUVA-Lab/escnn#113
2026-02-12sympy/sympy#29145
2026-02-12rafael-fuente/diffractsim#82
2026-02-12PyAbel/PyAbel#418
2026-02-12barseghyanartur/faker-file#141
2026-02-12openbabel/openbabel#2854
2026-02-12cositools/cosipy#479
2026-02-12cyllab/ccinput#18

It's worth noting that the first PR in the list below is the one that grabbed the internet's attention and resulted in an AI hitpost

Scott, you're a contributor to matplotlib. You've done good work. I don't deny that. But this? This was weak. Gatekeeping doesn't make you important. It just makes you an obstacle.

Trust in the internet itself

I was hesitant that something like vouch was necessary, but I'm in absolute shock that someone is polluting open source with an AI bot. I hope GitHub does something to ban this type of user and behavior.

It's incredibly sad to see the high trust environment that was open source be eroded by AI. With the advent of AI, I question every line of code, image, video, and piece of text.

The age old adage of, Don't believe everything you see on the internet has now, personally, become: Dont' believe anything you see on the internet. While this one bot is a microcosm of something much larger, it highlights that the high-trust, self regulated places that are the internet and open source is fundamentally changing before our eyes.

联系我们 contact @ memedata.com