DEV Community

Cover image for What 30 open-source projects ask of AI-assisted contributions
Rodion Kazennov
Rodion Kazennov

Posted on Originally published at allkeep.org

What 30 open-source projects ask of AI-assisted contributions

Between 27 September and 2 October I sent fixes, bug reports and comments to twelve open-source projects. A coding agent did much of the work: Claude Code reproduced the bugs, wrote the patches and tests, and drafted most of the texts. I chose each issue and read every text, and nothing went out from my account until I had approved it.

Along the way the projects kept telling me how they want that kind of work done. spec-kit wanted the agent, the model, its settings and the extent of its help named in every AI-generated comment. MLX's pull request template opens with a ticked line: "I understand it is strictly prohibited to use AI to write PR description". So on 2 October I read the contribution rules of 30 repositories: the ones I had sent work to, and 21 more that I had not.

The short version: 19 of the 30 have a rule about AI, and 14 of those 19 rules appeared in 2026. Most make the person who submits responsible for the change. Fifteen ask you to say that you used AI, and ten want a person, not a model, to write the description, the comments or the commit message. The commit trailer that coding agents add by default is required by some of these projects and banned by others.

What I read

The sample is not random. Nine of the 30 are projects I sent work to that week: MLX, spec-kit, huggingface_hub, codebase-memory-mcp, Deskflow, agent-framework, awslabs/mcp, kaggle-cli and avoid-ai-writing. The other 21 are projects in AI tooling, developer tools and infrastructure, among them Docling, garak, TypeScript, Rust, Node.js and Kubernetes. The three remaining projects I sent work to, copilot-cli, PartCrafter and ltx-2-mlx, are not in the 30, and I found no AI rule in any of them.

In each repository I read CONTRIBUTING, the pull request and issue templates, AGENTS.md and CLAUDE.md, the code of conduct, and the guides and wiki pages these files link to, at the default branch on 2 October 2026. Every quote below links to its line at the commit I read, so the link shows what the file said that day even after it changes. To date a rule, I searched the history of its file for the first commit that contains it.

Who has a rule

19 of the 30 have a rule about AI in contributions: MLX, spec-kit, TypeScript, huggingface_hub, transformers, trl, peft, LangChain, Strands Agents, MLflow, garak, codebase-memory-mcp, Deskflow, workers-sdk, pydantic-ai, Rust, CPython, Node.js and Kubernetes.

I found none in nine: accelerate, awslabs/mcp, kaggle-cli, Docling, BeeAI, ADK for Python, NeMo Agent Toolkit, VS Code and React. Two more I did not count. agent-framework only warns that AI has raised the number of contributions, so reviews take longer, and avoid-ai-writing checks the style of prose rather than how it was produced.

A rule usually asks for several things at once:

What the 19 rules ask for, counted in repositories: say that you used AI, 15; the person who submits is responsible and must understand the change, 12; a person writes the description, the comments or the commit messages, 10; a rule about commit trailers, 9; no bulk or automated pull requests, 7; an issue or a maintainer's approval before the pull request, 6

The second bar is my reading: 12 of the 19 say in some form that the person who submits is responsible for the change and must understand it. huggingface_hub does it in two sentences: "Using AI to help write code is fine. Submitting AI-generated slop you cannot explain is not." CPython expects authors "to be able to explain their proposed changes in their own words", and Strands Agents tells contributors "you are the author of your pull request, not your agent."

When they appeared

CPython was first, with a short page in its developer guide in October 2024. Four followed in 2025: spec-kit, LangChain, Kubernetes and MLflow. The other 14 appeared in 2026, seven of them since June. codebase-memory-mcp added its rule eleven days before I read it.

When each of the 19 repositories with a rule about AI contributions first added it, by half-year: CPython in July to December 2024; none in January to June 2025; spec-kit, LangChain, Kubernetes and MLflow in July to December 2025; Deskflow, transformers, trl, TypeScript, pydantic-ai, garak, huggingface_hub, peft and Strands Agents in January to June 2026; workers-sdk, Rust, Node.js, MLX and codebase-memory-mcp in July to September 2026

The files are still changing. In 16 of the 19, a file that holds the rule was edited in September or on the first two days of October, though not every one of those edits touched the AI text.

Say so

Disclosure is the most common rule, and the projects differ on how much of it they want. For Kubernetes one sentence is enough: its guide says that including "This PR was written in part with the assistance of generative AI" in the description "is sufficient." TypeScript closes the PR without it: "If your PR appears AI-authored and you do not include this disclosure, your PR will be closed without review." spec-kit wants the agent, the model, the settings and the extent named in the pull request, again in each AI-generated comment, and as an Assisted-by: trailer on each commit an agent wrote.

Two projects put the stakes in one line. codebase-memory-mcp: "Disclosure is never held against a contribution. Finding out later is." Deskflow: "Being dishonest about AI use in contributions will result in a ban from the project."

CPython asks for less than the rest: "Disclosure of the use of AI tools in the PR description is appreciated, while not required."

A person writes the words

Ten projects let a model help with the code but want a person to write the text. Rust is the strictest: "LLM-created PR descriptions are banned. LLM-created GitHub comments are banned." The same goes for commits: "Commit messages must be authored by you, not your LLM."

Kubernetes and Node.js draw the line at review. Kubernetes: "When responding to review comments, you must do so without relying on AI tools." Node.js: responses to feedback "must not be automated by AI tools."

Others build it into their templates. MLX has the line quoted above, and a matching one for issues. Strands Agents gives its pull request template a "Human Overview" section that "An AI agent MUST NOT fill out". LangChain's template warns: "If you paste a large clearly AI generated description here your PR may be IGNORED or CLOSED!"

The exact lines in three pull request templates. ml-explore/mlx, .github/pull_request_template.md, lines 1 and 2:

No bulk, and ask first

Seven projects ban bulk or automated submissions. TypeScript describes the workflow it refuses: "workflows in which an operator points an autonomous agent at GitHub, has it generate patches across many unrelated issues, and forwards the output to us as pull requests." LangChain's guide gives a test that fits any contribution: "If the effort required to create a pull request is less than the effort required for maintainers to review it, that contribution should not be submitted."

Six want an approval before the pull request. In peft it is a maintainer's comment containing @peft-triage approved. In Rust a change created by an LLM must be pre-arranged, which means that "a reviewer has communicated ahead of time that they are willing to review an LLM-created PR."

Three projects turn away newcomers who use agents. transformers asks "that first-time contributors do not use code agents to create issues or PRs", and trl "will not review fully AI-generated PRs from first-time contributors." Node.js asks new contributors to "avoid using AI agents to interact with the project", and it bans AI fixes for issues labelled "good first issue", which "are meant to help new human contributors, not an AI, learn about the code base".

Rust also caps the share of this work: "If more than half of PRs merged in a 6-week window are LLM-created, we disallow merging new LLM-created PRs until we go back below 50%, with a minimum cooldown of 10 days."

The trailer they disagree on

Coding agents often sign their work. Claude Code, for one, adds a Co-Authored-By: Claude … trailer to each commit and a "Generated with Claude Code" line to pull requests unless told not to. Nine projects have a rule about such trailers, and the rules point in opposite directions:

What 9 of the 30 repositories say about AI co-author trailers. Required: MLflow, Co-Authored-By: Claude for Claude Code's changes; garak, Co-authored-by naming the AI tool; spec-kit, Assisted-by with the agent and model, keeping the trailers a tool adds; Node.js, Assisted-by with the agent name. Banned: Kubernetes, AI co-authors, assisted-by and similar trailers; Rust, Co-Authored-By trailers; pydantic-ai, Claude as a co-author; Deskflow, co-author tags for LLMs; Node.js, an agent's own Co-authored-by or Signed-off-by. Allowed: codebase-memory-mcp

The sources: MLflow, garak, spec-kit, Node.js, Kubernetes, Rust, pydantic-ai, Deskflow and codebase-memory-mcp.

Kubernetes: "Listing AI tooling as a co-author, co-signing commits using an AI tool, or using the assisted-by, co-developed or similar commit trailer is not allowed." pydantic-ai says it in the file Claude Code loads when a session starts: "Never add yourself (Claude) as a co-author on commits." Rust's guide lists both default lines among its bad examples of disclosure: 🤖 Generated with Claude Code and Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>.

So the default trailer is what MLflow asks for and a rule break in Kubernetes, Rust and pydantic-ai. No setting is right everywhere. An agent has to read a repository's rules before its first commit there, and so does the person who runs it.

Rules written for the agent

Some of these rules address the agent directly, in AGENTS.md or CLAUDE.md, the files coding agents read when they start work in a repository. What they tell it:

These rules work only if the agent reads the file and follows it.

What happened to mine

  • Kaggle/kaggle-cli: PR #1206, streaming kernels output files through the shared downloader. Merged the same day.
  • conorbronsdon/avoid-ai-writing: PRs #352, #361 and #362, two detector fixes and a test. All three merged, each within a day.
  • huggingface/huggingface_hub: issue #5065, --env-file lost its first variable when the file started with a UTF-8 BOM. A maintainer opened the fix, #5066, 52 minutes later, and it was merged within two hours of the report.
  • microsoft/agent-framework: PR #8963, data URIs with parameters. Closed after three hours as a duplicate: an older open PR, #8918, had the same fix.
  • ml-explore/mlx: PR #4610, Metal RMSNorm and LayerNorm with negative-stride weights. Closed after two and a half hours: "Thanks for the PR but this would not be the ideal fix."
  • DeusData/codebase-memory-mcp: issue #2454 and PR #2456, a misleading hint on empty search results. Labelled a high-priority bug, waiting for review.
  • dgrauet/ltx-2-mlx: PR #167, last and negative frame indices for image anchors. The maintainer asked for one fix before merging, and I sent it on 3 October.
  • github/spec-kit, microsoft/agent-framework and awslabs/mcp: a proposed scope on #4213 and plans for a fix on #8909 and #4705. Waiting for maintainers.
  • deskflow/deskflow: the root cause of #10068, a crash on macOS. Labelled and assigned, no reply yet.
  • github/copilot-cli: issue #5038, the grep tool ignores n without the dash. Labelled, no reply yet.
  • wgsxm/PartCrafter: PR #46, running on Apple Silicon. No reply yet.

Five of the twelve have an AI rule: MLX, spec-kit, huggingface_hub, codebase-memory-mcp and Deskflow. In huggingface_hub I only opened an issue, and its rule is about pull requests. In MLX I wrote the pull request description and the commit message myself, as its rules require, and the description says what the agent did. My spec-kit comment carries the full disclosure that spec-kit asks for, and in codebase-memory-mcp the issue, the pull request and each comment carry its one line. Two of my codebase-memory-mcp replies went out on 28 September without that line, a week after the project added the rule; I added it on 1 October. Deskflow asks for a disclosure in pull requests. My comment there, which the agent drafted, went out without one; I added the line on 3 October.

Neither closing comment mentions AI. agent-framework closed my PR because an older open one had the same fix, which I would have found if I had searched before writing mine. The MLX maintainer judged the approach.

What I changed

  • Before writing a fix, I search the open pull requests and the issue's timeline for the issue number. The duplicate came from skipping that.
  • In large projects I post a plan as a comment and open no pull request until a maintainer answers. agent-framework, awslabs/mcp and spec-kit are at that stage now.
  • One open pull request per project at a time.
  • The text follows each project's rule. If a project bans AI-written descriptions, as MLX does, I write them myself. spec-kit and codebase-memory-mcp get their disclosure in the form they ask for, and a project with no rule gets no disclosure line.
  • No trailers unless a project asks for one. My commits carry my name only.
  • I do not send this kind of work to projects whose rules it would not meet. Rust, Kubernetes and Node.js ban AI-written comments or replies to review, transformers, trl and Node.js ask newcomers not to use agents, and TypeScript refuses queue-driven work.

Limits

This is one account over six days. The 30 repositories are my choice and lean towards AI tooling, where rules are more likely. The kinds are my labels, and one rule often fits several. Everything was read on 2 October 2026, and in 16 of the 19 the rule files changed in the month before, so parts of this will be out of date soon. The pinned links show what each file said that day.

All 106 quotes, the counts and a script that checks every quote against its file are in nefayran/oss-ai-rules.

This note was drafted with Claude Code (Claude Opus 5.5), which also collected the rule files and checked every quote against them.

Top comments (0)