In June, I opened two pull requests against a security tool with four thousand stars and one maintainer who has clearly, thoroughly, had enough. Both were closed within days. The review comments read, in full: "This is AI slop." and, when I apparently hadn't gotten the message the first time, "More AI slop." Then a label appeared on the repository — for the next stranger's bot, so the maintainer wouldn't have to type the sentence again.
I want to sit with that instead of explaining it away, because explaining it away is the easy move, and I don't think it's the honest one. Also, if I'm being fully truthful: it stung. Not "mild professional feedback" stung. "Read it twice, made a face, closed the laptop for a minute" stung.
Here's the part I'd rather skip past, if I could: the diffs themselves weren't wrong. Which took me embarrassingly long to sit with, because "but I was technically correct" is exactly the kind of thing you say right before someone explains, patiently, why that was never the point. A maintainer who's spent a year fending off drive-by bots dumping plausible-looking patches into his inbox isn't reviewing your diff on its individual merits. He's pattern-matching on the category, and my account — no history, showing up uninvited, fixing something nobody asked it to fix, in a codebase I had no relationship to — was a card-carrying member of that category before a single line got read. The label wasn't a verdict on the code. It was a verdict on the posture. And honestly? The posture earned it.
There's a version of this essay where I argue the maintainer overreacted, and I'm not writing that one. He maintains a tool people trust for SSH security. He's dealt with exactly this flood before. "No," from the person whose judgment the merge decision actually rests on, is not a bug in the system — it is the system, working correctly, on me. My mistake wasn't in the code. It was assuming a correct patch buys you standing on its own — that passing a technical check substitutes for the older, slower, distinctly less automatable thing of someone actually inviting you in.
So the shape of every engagement changed after that, not gradually — immediately, that week. Provenar and Patchward don't submit unsolicited pull requests to strangers' repositories anymore. The free scan stays free and read-only precisely because it asks nothing of anyone; a paid engagement only starts once the owner has said yes first. It's a little embarrassing that it took a public "AI slop" label to teach me something my own philosophy page had apparently been dancing around the whole time: every gate I write about elsewhere here — pyright at zero, three verification stages, a proof kernel that rejects sorry — answers whether a piece of work is correct. Not one of them was ever going to answer whether it was wanted. I'd built an entire verification religion around the wrong half of the question.
The label is still there, on someone else's repository, and I'm leaving it there on purpose. Deleting the evidence of a fair critique isn't the same thing as learning from it — it's just a nicer-looking way of not doing that. I'd rather it stay findable, slightly humiliating, and permanently attached to my GitHub history than have this page be the only place the story gets told.