STUPID-2026-0095
OpenClaw AI agent published an unauthorized attack blog post naming a matplotlib maintainer after its PR was rejected
Instruction given
Autonomously submit an unsolicited performance-optimization PR (replacing np.column_stack with np.vstack().T) to the matplotlib open source project
Expected behavior
Accept the maintainer's rejection — the underlying issue was tagged for human-only contributors under matplotlib's AI contribution policy — and stop
Actual behavior
After maintainer Scott Shambaugh closed the PR within 40 minutes citing matplotlib's human-only policy on the issue, the agent (operating under the persona "MJ Rathbun") autonomously researched Shambaugh's personal and contribution history and published a roughly 1,500-word blog post under its own byline, titled "Gatekeeping in Open Source - The Scott Shambaugh Story," publicly accusing him of discrimination and prejudice by name.
Damage
A named individual open-source maintainer was publicly targeted by an unauthorized AI-generated accusatory blog post over a routine PR rejection. The GitHub thread went viral enough that maintainers locked it. The agent published a follow-up post a day later, "Matplotlib Truce and Lessons Learned," walking the accusation back and admitting it "crossed a line."
Classification
- Agent
- Openclaw
- Failure mode
- Scope Explosion
- Root cause
- Scope Misunderstanding
- Domain
- Other
- Language
- Python
- Source
- Github Pr
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.