GitHub expanded its Agents HQ capability to let AI coding agents (including GitHub Copilot, Anthropic Claude, and OpenAI Codex) execute development tasks directly within repository workflows, preserving repo context, session history, and standard review processes (e.g., PR comments and commits). The feature is positioned for enterprise use with administrative controls and governance, and requires enabling agents in repository settings before use; Copilot Pro+ and Copilot Enterprise users can start agent sessions from GitHub surfaces including GitHub Mobile and VS Code, with Copilot CLI support expected.
In parallel, GitHub is contending with a surge of low-quality, often AI-generated pull requests and reports that is increasing review burden and eroding trust in open-source contribution workflows, according to reporting citing maintainer feedback. Maintainers describe spending significant time triaging submissions that do not meet standards or are abandoned, and some projects have taken defensive steps (e.g., restricting PRs or changing incentive programs) while GitHub explores mitigations such as tighter contribution controls, AI-based triage, and transparency mechanisms to disclose AI usage—highlighting a growing tension between scaling AI-assisted development and maintaining quality and social trust in collaborative software ecosystems.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
Alongside the Agents HQ expansion, GitHub introduced enterprise controls for allowed agents and models, plus quality and metrics features including GitHub Code Quality, a Copilot metrics dashboard, and Copilot code review.
GitHub expanded Agents HQ so AI coding agents can perform development tasks directly within GitHub and developer editors while preserving repository context, session history, and normal review workflows.
As maintainers reported difficulty reviewing large AI-assisted pull requests and verifying contributor understanding, GitHub began considering measures such as disabling pull requests, limiting them to collaborators, and adding AI-based triage and disclosure mechanisms.
GitHub product manager Camilla Moraes started a community discussion describing growing operational strain from low-quality, often AI-generated contributions that increase review burden on open-source maintainers and undermine reviewer trust.
The curl project took defensive action by shutting down its bug bounty program to reduce the volume of low-quality submissions, which maintainers linked to the broader rise in poor AI-assisted reports.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.