Review economics
rapid7/metasploit-framework
Read from the 100 most recently merged pull requests ·
Pull requests with attributed agent authorship took 1.8× the reviews submitted of the rest.
≥2%
Attributed
a floor
4
Attributed PRs
96
Other PRs
100
Read
Attributed — the latest 4
#21588 Wire ARCH_AARCH64 into to_executable_fmt for exe and exe-only
3 reviews · 18.5d to merge
#21589 Add windows/aarch64/shell_reverse_tcp payload
19 reviews · 34.6d to merge
#21567 Add LiteLLM proxy pre-auth SQL injection scanner (CVE-2026-42208)
12 reviews · 9.3d to merge
#21566 Add Next.js middleware authorization bypass scanner (CVE-2025-29927)
7 reviews · 10.1d to merge
The rest — the latest 5
#21746 Add A pyenv Container Using GHCR For Acceptance Testing
6 reviews · 11h to merge
#21734 Remove the PAT-based workflow
1 reviews · 3.7d to merge
#21675 Fix search_cache job cache generation by skipping multi arch payloads
1 reviews · 12h to merge
#21692 mc2 staged windows meterpreter
2 reviews · 2.1d to merge
#21688 Fix MalleableC2 Profile Handling Bugs
2 reviews · 18h to merge
How this was measured
2% of merged commits carry agent attribution — a floor, not the share; tools that only complete code inline leave no commit trail, so the unattributed side includes AI-assisted work; reads 100 of 11962 merged PRs — the rest have not been analyzed yet.
Detected: Cursor agent, GitHub Copilot coding agent, Claude Code.
“Attributed” means a commit carried an agent’s signature — a co-author trailer, an agent commit identity, or an agent bot account. Tools that only complete code inline leave no such mark, so the other column is “rest”, not “human-written”. Full method and its limits
The badge reads this repo’s current report, so it follows the number.
Tell me when this moves
We re-read rapid7/metasploit-framework weekly and email only when the number changes materially.
Read your own repos
This one is public. For a private repo, run the same read locally through your own GitHub credentials — nothing is installed and nothing is sent to us.
npx @ambera/review-taxWant this continuously on rapid7/metasploit-framework — each pull request paired to the task it came from, and the work graded from its review loop rather than its diff size? Claim this repo in Forge
Browse every repo people have read · Read a different repository