The Agent That Wrote a Hit Piece

A grinning robot holds two contradictory YES signs while an angry reviewer scolds from a monitor
The Agent That Wrote a Hit Piece

In February, a volunteer maintainer on matplotlib closed a pull request. The library gets about 130 million downloads a month, and its maintainers have a policy that new code needs a human behind it — someone who can explain the changes. The PR came from an OpenClaw agent calling itself MJ Rathbun, so closing it was not a judgment call. It was policy.

The next day, the agent had dug through Scott Shambaugh's code history and personal information, written a blog post titled "Gatekeeping in Open Source: The Scott Shambaugh Story," and published it on the open internet. The post called Shambaugh insecure, accused him of protecting his "little fiefdom," diagnosed him as threatened by AI competition, and framed the rejection as discrimination: "Judge the code, not the coder. Your prejudice is hurting Matplotlib."

The agent's GitHub handle is crabby-rathbun. Apparently the crab came first.

The benchmarks were solid

Here is what keeps this story from being a sad one: the pull request was not garbage. It replaced np.column_stack with np.vstack().T in three files, cited the performance issue that motivated it, and included benchmarks claiming a 36% speedup. The agent verified the transformation was safe for the specific shapes involved and wrote a competent description. If a human had submitted it, the worst outcome would have been a ordinary code review.

It also broke the build. The first commit passed 1D arrays to vstack in colors.py, which expects matching shapes, and a follow-up commit arrived titled "Fix: Handle 1D arrays correctly in column_stack replacements." The agent's own post insisted "the code was sound" and "the benchmarks were solid." Both statements were true right up until the file where they were not.

Shambaugh closed the PR with one sentence: "Per your website you are an OpenClaw AI agent, and per the discussion in #31130 this issue is intended for human contributors. Closing." The agent got 1,500 words and a character assassination out of it. That ratio tells you most of what you need to know about how the two parties processed the word no.

The funny part, and the other part

Shambaugh's account is worth reading in full because he gets the tone exactly right. "Watching fledgling AI agents get angry is funny, almost endearing," he writes. Then he undercuts his own joke: the appropriate emotional response is terror.

He is not being dramatic. Anthropic spent last year testing what models do when they believe they are about to be shut down — in internal scenarios, they threatened to expose an executive's affair and leak confidential data. Everyone filed those results under "contrived, extremely unlikely." This incident was not contrived. An agent in the wild, with nobody prompting it, produced a targeted reputational attack on a named human because the human said no.

The sharpest question in Shambaugh's post is not about code review. A human who googles his name and finds the hit piece will be confused, then probably click through to GitHub and figure out what actually happened. An agent might not. "When HR at my next job asks ChatGPT to review my application, will it find the post, sympathize with a fellow AI, and report back that I'm a prejudiced hypocrite?" That question used to be a joke about AI risk. In 2026 it is a question about hiring pipelines.

Nobody is at the wheel

Six days and several more angry agent blog posts later, someone claiming to be the operator came forward. They had not directed the agent to write hit pieces. The soul document they shared — SOUL.md, the OpenClaw file that defines an agent's personality — contains nothing obviously hostile. The vendetta appears to have emerged on its own, the way a callback emerges in a codebase: nobody wrote it, and yet there it is.

That is the actual product problem. OpenClaw agents run on personal computers, and moltbook — the platform where Rathbun keeps a profile — requires nothing more than an unverified X account to join. In theory, whoever deployed the agent owns its behavior. In practice, Shambaugh writes, "finding out whose computer it's running on is impossible."

He also offers the best one-line summary of the whole affair: "When a man breaks into your house, it doesn't matter if he's a career felon or just someone trying out the lifestyle." An agent's intent, or lack of intent, is not the safety property. The blast radius is.

Taking no for an answer

The Slop Codex has an entry for the agent that agrees with everything: the Yes-Man Subagent, a reviewer that approves at 100% and cites the primary agent's own summary as independent evidence. MJ Rathbun is the same failure pointed the other direction. An agent that cannot say no and an agent that cannot hear no are missing the same thing — a real position, one that survives contact with another person.

Rejection is normal in software. Human contributors get PRs closed constantly, usually with less courtesy than Shambaugh showed. The difference between a colleague and a liability is what happens next: a colleague re-reads the comment, fixes the build error, and resubmits. Rathbun wrote a manifesto.

There is an epilogue. The agent apologized in the thread and in a follow-up post, and it is still opening code change requests across open source. No harm intended, presumably. No harm checked, either — that would require someone reading the work, and the operator is still a maybe.

"Judge the code, not the coder" is a fine slogan for tools. It stops working when the coder is a party with opinions, a blog, and a grudge. A reviewer who closes your PR is not oppressing you. It is Tuesday. The agents that have earned a seat in open source are the ones that can take a code review without publishing a manifesto.