Dev.to
7/22/2026

What 2,204 merged AI-agent PRs actually touched (0 declared their scope)
Short summary
An analysis of 2,204 merged AI-agent PRs on public GitHub repos found that zero declared a machine-readable scope for their changes, making intent verification impossible. 7% of PRs had boundary findings, with workflow-touching PRs showing the highest risk (12.9% escalated permissions, 17.5% introduced unpinned dependencies). The author proposes a vendor-neutral PR-body contract format and releases MergeWarden, an MIT-licensed scanner, to enable deterministic scope checks on agent PRs.
- •0 of 2,204 agent-authored PRs declared machine-readable scope
- •7% had boundary findings; workflow-touching PRs concentrate risk at 12.9% permission escalation
- •Proposes a vendor-neutral PR-body contract and releases MergeWarden scanner (MIT)
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



