Introducing Eva Luadora, an AI-assisted external contributor

Again the load is passed to the maintainer without any consideration.

I think you are getting wrong. No load is passed, you are free to ignore/block or do whatever with any contribution.

The challenge is (like in the other project): “The knowledge is in the maintainer’s head” so there are decisions that anyone else can take. Of course others can do some other work but the final decision will always be the maintainer’s one.

This is something that had always been like this and did not change with AI contributions. If you want to discuss about maintainer load probably we should move it to a new topic.

You are getting wrong.
We got a new behavior that is imposed on the maintainer and your answer is that the maintainer has to do some work such that the tool works correctly. This is the new load that is passed to the maintainer.

Let me clarify what I said:

but you are still on the same idea.

And also said:

And we are still on the same topic discussing about maintainer load.

TBH: I can understand your concerns with maintainer load and when I tried to help you just said: “You are on the list so it will not help”. I offer my help again if you want it.

(See sources on some comments, I can not have more than few links as new user).

So far, the statistics are:

Findings tracked │ 21
Human-approved or corrected findings │ 10
Findings published │ 10
Findings with evidence of being helpful │ 7
Findings with evidence of not being helpful │ 2
Findings with an unclear outcome │ 1

So:

  • for now it’s 50/50 human/bot, from my POV a good measure that it’s human evaluated
  • for the public, seams the helpful rate is 70%.

Of course can be a good use! But take in account the valid-rate has decreased to a 5% rate (sources). But I’m sure we are not far away (sources) that those stats can be improved.

For me, a new contributor who produces useful work is always good for the Tryton community. Trust will have to come from the quality of the contributions over time.

As with any contribution to an open-source project, the contributor learns from the feedback and the project receives the work.

But I understand the concern: generating a finding can be much cheaper than verifying it. This is why findings are reviewed by a human before publication, and why they should include evidence, tests, or a fix whenever possible.

I think this oversimplifies how these systems work. Agents may use private models, private tools, specialist knowledge, commercial services, security tools, or private infrastructure. Requiring the complete setup to be public would exclude many legitimate contributors and tools.

I agree that the purpose, boundaries, review process, and data-handling rules should be public. But requiring the entire setup to be reproducible is a different matter.

Only on this topic, it will not be AI generated content for my side. The rest contributions are directed/reviewed by the human published by the bot.

I provided several options: an AGENTS.md file, comment-based opt-outs, or a page on the website. I can also help create and maintain that resource.

But, as with any automated process, the infrastructure owner defines the boundaries. A responsible bot can respect something like robots.txt, denied routes, or rate limits. A malicious or badly configured one may ignore them, in which case technical enforcement such as a proxy or firewall is required.

My own damage control is the human review described in the statistics above. I do not plan to fill issues or merge requests with useless content. I am the first person affected by the 21 findings because I must review them before anything is published.

Still, I agree that we should discuss and plan for this now, because more agents are coming.

Anyone can build or reproduce a similar database from the public information on Heptapod and Discourse.

That is what it is doing, although not at the same speed because fixes and tests also require human evaluation. Finding the root cause is the first step towards solving the issue.

Creating an AGENTS.md file in the Tryton source repository might be useful. This convention is already used by many software-development agents, so repository-specific instructions can be followed whether the work is done by a bot or by a human assisted by one.

It could define testing requirements, contribution boundaries, disclosure rules, and when AI-assisted reviews are welcome.

Of course, this only works for agents that respect the instructions. It cannot prevent a human from overriding them or a badly configured model from ignoring them.


(sources) That is already changing. Inference exceeds 1,000 tokens/s, current models can handle around one million tokens of context, and Peter Steinberger produced over 6,600 commits in one month using 5–10 agents in parallel. Meanwhile, Pydantic turned thousands of maintainer comments into project-specific rules for automated reviews, and Codex Security scanned more than 1.2 million commits while finding and validating serious vulnerabilities.

Once fast inference, large context windows, parallel agents, automated testing and specialized review agents are combined, both producing and verifying software will change radically.

A more durable policy would judge contributions by their signal and verification cost: disclose AI assistance, and require a reproducer, test or validated patch. Whether the underlying system is human, public or private matters less than whether its work is correct, concise and verifiable.

To explain on the oversimplication, eva uses openai models: (https:// api. openai. com/v1) along with skills in a isolated container running on an arquitecture (opencode, codex, pi, openclaw, whatever…).

If the setup requires to stay public and someone wants to stay private, it’s easy to setup a container + architecture with just skills to submit contributions to heptapod and point the base url for the request to a private model (https whatever .com) and publish this setup. The skills can be moved into ‘whatever’ private model.

I would like to request that your bot stop posting the “AI disclosure” on each post/comment it does.
The AI is already produce too much verbosity without having to read this pointless “disclosure”.

As I already said, this “disclosure” should be stated in the username of the bot with a prefix like “bot”.

1 Like

Also I request that your bot does not close existing issue like TypeError: unsupported operand type(s) for +: 'int' and 'datetime.timedelta' (#7799) · Issues · Tryton / Tryton · GitLab.

For a bot there is a very good issue namely Port Client to GTK 4 (#11984) · Issues · Tryton / Tryton · GitLab. Port the desktop client to GTK version 4. There will be a lot of rewriting and testing which can be perfectly done by a bot. There will be human decisions made along the way because not everything can be ported over one-to-one.

I do not think we can accept contributions written by a bot. It is not clear who would own the copyright of such work.

I meant the use of a bot as a tool to do the work. In the end it should be a human who is contributing the code even it is done with the help of a bot. The human should also understand the changes and what the code does.

The code that is generated by an LLM has an unknown status regarding the copyright. And this is no matter if a human has read it or not.

The problem raises when the originality or the size of the contribution is subject to copyright.

I must say that such post is really pissing me off. It provides nearly no useful information and it consumes time to read.
It can be summarized as “hey, you should do this and that”.
If I wanted the comment of a bot, I would have asked myself to bot and not bother others about it.

So I request to not post any generated content (reviewed or not) on the forum. This is for me against the main principle of a forum which is to discuss between real people with their personal and original thoughts.

Did the Foundation already explore these three options? If not, I think it’s useful to investigate them.

The original idea of searching the open web for relevant data and existing users on Discuss is mine. I could do this research myself, but there is a language barrier, especially when it comes to Chinese forums and blogs.

What I shared was only the concise, relevant part of the report, not the full verbose output.

I also found the information summarizing the discussions on blogs and forums useful, particularly for assessing the level of involvement.

I do not think you understand that we do not need someone to tell us what to do. If you want to participate, do your homework.

I think the real question is “should a community member be allowed to delegate their entire presence in a community to a bot that acts broadly on their behalf?”

Look at SAGE Edu, which is itself built on Tryton. Its 1.1 release credits people like @pierremichelaugustin and @Calixte_Loukov for French translation work.

That’s the normal shape of open-source contribution: a person picks one concrete thing they care about, a translation, a module, a bug and does that work themselves, under their own name, with their own judgment. Nobody translated SAGE Edu into French by spinning up an agent that also files issues, argues on the forum, reviews other people’s merge requests, and follows every thread it finds “interesting.” They did the one thing they signed up to do.

That’s the part that stands out to me about @eva_luadora, anyone here technically could build a bot like this today. The tools exist. But almost nobody has, and I think that’s not an accident, it’s because community participation isn’t just output, it’s presence and accountability.

So when @ced says:

I read that as the same instinct: a real person would not personally show up to argue in every thread the way a bot can. If the bot’s creator wouldn’t personally do this amount of engagement, then the bot isn’t really extending the person’s judgment, it’s producing behavior the person themselves might never have chosen to produce. That’s the gap between “AI-assisted” and “acting in my behalf.”

The underlying question that see in the community is: do we want participation here to stay scoped to what a person actually chose to work on, the SAGE Edu model, one topic, one person, real ownership or are we okay with members deploying agents whose implicit goal is “do everything, everywhere, all the time” in their name?

1 Like

I think we should be talking about adopting a formal AI policy. It could be relatively open—allowing AI-assisted contributions under defined conditions—like those adopted by the Linux kernel, Rust, LLVM, CPython, NumPy, scikit-learn, Firefox, Django, the Apache Software Foundation, OpenInfra, Kubernetes, QGIS, Matplotlib, and JupyterHub.

Alternatively, it could take a more restrictive approach and prohibit AI-generated or AI-assisted contributions, as QEMU, Servo, Gentoo, OpenJDK, Asahi Linux, Pallets, Clojure and stb do.

I can provide a quick resume of the conditions that I support if you want, but I have the feeling that will be ignored.

For the record, the @staff has come with this proposal: Request to not paste AI to forum (!182) · Merge requests · Tryton / Communication / Website · GitLab