Skip to content
Search
paperJanuary 2026Unreviewed

Security in the Age of AI Teammates: An Empirical Study of Agentic Pull Requests on GitHub

Mohammed Latif Siddiq, Xinye Zhao, V. C. Lopes, B.K. Casey, Joanna C. S. Santos

arXiv.org

Abstract

Autonomous coding agents are increasingly deployed as AI teammates in modern software engineering, independently authoring pull requests (PRs) that modify production code at scale. This study aims to systematically characterize how autonomous coding agents contribute to software security in practice, how these security-related contributions are reviewed and accepted, and which observable signals are associated with PR rejection. We conduct a large-scale empirical analysis of agent-authored PRs u

Categories

Cite

@misc{siddiq2026security,
  title = {{Security in the Age of AI Teammates: An Empirical Study of Agentic Pull Requests on GitHub}},
  author = {Mohammed Latif Siddiq and Xinye Zhao and V. C. Lopes and B.K. Casey and Joanna C. S. Santos},
  year = {2026},
  month = jan,
  eprint = {2601.00477},
  archivePrefix = {arXiv},
  doi = {10.48550/arXiv.2601.00477},
  url = {https://www.semanticscholar.org/paper/53ed867f0c124539c1521dec5d052779cb8a0f2a}
}