Secret protection must scale with software
GitHub's data shows that the number of pull requests involving AI agents has doubled in the past year, raising concerns about the carelessness of developers.
Intelligence analysis by Qwen 2.5 (3B)

GitHub is seeing a significant increase in pull requests involving AI agents. This has led to concerns about developer carelessness, but the data suggests that developers are becoming more aware of the risks and are less willing to accept them.
GitHub is seeing more pull requests with AI agents. This has made some people worried that developers are becoming less careful. But the data shows that developers are becoming more aware of the risks and are less willing to accept them. To keep code safe, GitHub is working on better ways to stop secrets before they get into the code.
Analysis
Detection and Response
GitHub has seen a significant increase in the number of pull requests involving AI agents. This has led to concerns about developer carelessness, but the data suggests that developers are becoming more aware of the risks and are less willing to accept them. Over the past nine quarters, the number of screened pushes has grown 2.84 times while the number of pushes carrying credentials has grown 2.59 times. These figures challenge the common claim that agents are causing developers to become more careless. More pushes, no clear rise in push prevalence.
Prevention
GitHub has implemented push protection to prevent the introduction of unstructured secrets. The fine-tuned classifier they built with Microsoft Applied Sciences can assess a whole set of candidate secrets in less than two milliseconds and could more than double the number of secrets that they can prevent. Outpaced, not careless.
Remediation
GitHub's push protection stops about 30% of newly detected secrets before they enter repository history. The remaining 70% are already lost, and the cost of cleaning up a secret already lost to visible history is high. As the amount of code grows, the platform must take on the work of recognizing more of these secrets, earlier in development flows, to reduce the human effort required by those that remain.
Key points
- GitHub has seen a significant increase in the number of pull requests involving AI agents.
- The number of screened pushes has grown 2.84 times while the number of pushes carrying credentials has grown 2.59 times over the past nine quarters.
- GitHub has implemented push protection to prevent the introduction of unstructured secrets.
- GitHub's fine-tuned classifier can assess a whole set of candidate secrets in less than two milliseconds and could more than double the number of secrets that they can prevent.
- GitHub's push protection stops about 30% of newly detected secrets before they enter repository history.
As the number of pull requests involving AI agents continues to grow, GitHub will continue to improve its detection and response systems to prevent more exposures and reduce the human effort required by those that remain.
If GitHub does not improve its detection and response systems, the volume of vulnerabilities introduced will become untenable, and the platform will struggle to keep up with the growing number of pull requests involving AI agents.