A metadata-only scan of cline/cline measuring how much of the code any currently-active human has genuinely written or engaged with โ and where comprehension debt is concentrating.
53% of its lines are AI-attributed and 45% were written by contributors no longer active. Only 2% of the module was authored by anyone who has committed in the last 90 days โ no single active contributor holds even a 10% share โ yet it received 129 commits in the last 180 days. In our framework, sustained change without living commit-authorship is a leading risk indicator for incident cost and onboarding drag โ an indicator, not a verdict on any contributor.
Modules ranked by comprehension risk: how much of the module lacks a living author, amplified when the code is still changing (heat) and thinly held (bus factor). The green meter is the share written by currently-active humans.
| Module | Risk | Living knowledge | AI-attr. | Departed | Bus factor | Heat (commits/180d) |
|---|---|---|---|---|---|---|
| evals | CRIT 98 | 2% |
53% | 45% | 0 | 129 |
| locales | CRIT 89 | 1% |
0% | 99% | 0 | 30 |
| proto | CRIT 86 | 10% |
5% | 85% | 0 | 42 |
| .changeset | HIGH 72 | 28% |
7% | 64% | 0 | 94 |
| src/standalone | HIGH 72 | 6% |
0% | 94% | 0 | 5 |
| scripts | HIGH 70 | 28% |
7% | 66% | 1 | 43 |
| docs | MED 58 | 37% |
18% | 45% | 2 | 500 |
| .clinerules | MED 56 | 32% |
37% | 31% | 2 | 29 |
| src/shared | MED 54 | 41% |
3% | 56% | 2 | 198 |
| src/api | MED 49 | 35% |
8% | 57% | 1 | 0 |
| src/core | LOW 48 | 48% |
6% | 46% | 2 | 736 |
| src/services | LOW 48 | 48% |
4% | 48% | 2 | 134 |
Modules under 200 changed lines in the window are omitted. src/core scores LOW despite 736 recent commits because roughly half its lines have living authors and knowledge is spread across multiple active contributors โ heat without darkness is healthy activity.
API-sampled signals joining PR timing with diff sizes from git history: 439 merged PRs timed, with review detail on a size-stratified sample of 34 deliberately weighted toward the largest merges โ these figures describe that sample, not all PRs, and describe process patterns, not the diligence of any individual contributor.
Largest fast merge in the sample: PR #11862 โ 2,077 lines touching apps/ and sdk/, merged 24 minutes after opening. Baseline latencies scale sanely with size (median 34 min for โค50-line PRs, 31 hours for 1,000+ lines), which makes the exceptions the signal, not the norm. Note that legitimate workflows produce these patterns too โ pre-coordinated changes, pairing, generated files, release automation, and review conducted outside GitHub's review feature are all invisible to this record.
The same engine run on pallets/flask (16 years old, pre-AI era, 3,812 commits) shows the Index distinguishes different kinds of knowledge risk rather than flattering old code or damning new code.
| cline/cline (AI-era, 2 yrs) | pallets/flask (pre-AI, 16 yrs) | |
|---|---|---|
| Living knowledge (weighted) | 79.2% | 83.8% |
| AI-attributed floor | 5.0% | 0.1% |
| Active humans (90d) | 35 of 322 ever | 1 of 866 ever |
| Worst module | evals โ 2% living, hot | src/flask โ 51% living, quiet |
| Dominant risk shape | Comprehension debt: fast-growing code with no living author, where sampled merges often show comment-free or AI-only recorded review | Concentration risk: knowledge is alive but every module is bus-factor 1 โ a single active contributor holds the dominant commit share |
Flask's headline numbers look healthier โ until you see that its living knowledge is concentrated in a single active contributor. The two repos carry risk in opposite shapes, and a velocity dashboard would flag neither.
The same engine run across 22 public repositories in five cohorts: AI-era agents and apps, AI vendor SDKs, modern human-led projects, and pre-AI controls. Sorted darkest first by living knowledge.
| Repository | Cohort | Living knowledge | AI-attr. floor | Departed | Active / all-time humans |
|---|---|---|---|---|---|
| openai/openai-python | AI SDK | 3% |
64.5% | 32% | 7 / 158 |
| anthropics/anthropic-sdk-python | AI SDK | 5% |
64.0% | 31% | 11 / 62 |
| gin-gonic/gin | pre-AI control | 11% |
19.9% | 69% | 13 / 540 |
| expressjs/express | pre-AI control | 15% |
0.0% | 85% | 10 / 389 |
| All-Hands-AI/OpenHands | AI-era agent | 22% |
48.8% | 29% | 38 / 499 |
| langchain-ai/langchain | AI-era app | 24% |
1.1% | 75% | 41 / 3,683 |
| langgenius/dify | AI-era app | 32% |
36.4% | 32% | 167 / 1,400 |
| crewAIInc/crewAI | AI-era agent | 48% |
39.7% | 12% | 28 / 310 |
| sst/opencode | AI-era agent | 53% |
30.1% | 17% | 147 / 989 |
| continuedev/continue | AI-era agent | 55% |
3.6% | 41% | 4 / 534 |
| browser-use/browser-use | AI-era agent | 60% |
3.5% | 37% | 17 / 355 |
| django/django | pre-AI control | 62% |
1.6% | 37% | 59 / 3,409 |
| RooCodeInc/Roo-Code | AI-era agent | 62% |
15.5% | 23% | 22 / 308 |
| fastapi/fastapi | modern human-led | 69% |
12.0% | 19% | 12 / 907 |
| vercel/ai | AI SDK | 72% |
15.6% | 13% | 88 / 681 |
| lobehub/lobe-chat | AI-era app | 73% |
23.8% | 3% | 42 / 354 |
| tailwindlabs/tailwindcss | modern human-led | 78% |
1.1% | 21% | 23 / 372 |
| cline/cline ยท this report | AI-era agent | 79% |
5.0% | 16% | 35 / 322 |
| astral-sh/ruff | modern human-led | 83% |
0.4% | 16% | 111 / 945 |
| pallets/flask | pre-AI control | 84% |
0.1% | 16% | 1 / 866 |
| psf/requests | pre-AI control | 86% |
0.1% | 14% | 12 / 792 |
| curl/curl | pre-AI control | 94% |
0.0% | 6% | 55 / 1,579 |
What the corpus shows. Cohort medians: modern human-led 78% ยท pre-AI controls 73% ยท AI-era agents 55% ยท AI-era apps 32% ยท AI SDK cohort 5% (two of its three members โ the OpenAI and Anthropic Python SDKs โ score 3% and 5%; the third, vercel/ai, is largely hand-written and scores 72%). An essential reading note on the SDK repos: both are produced by automated code-generation pipelines from API specifications โ a deliberate, industry-standard engineering choice. Low living commit-authorship in a generated repo reflects that workflow; the relevant human comprehension plausibly resides in the generator and the API specification, which repository-level metrics structurally cannot observe. These scores describe public commit history only โ they are not a claim that any organization's engineers do not understand their products, and not a claim about the quality, security, or fitness of any software. Elsewhere the pattern is starker: comprehension debt predates AI. Express โ 15 years old and foundational to the npm ecosystem โ shows 85% of its recent lines authored by contributors no longer active, while 25-year-old curl is the healthiest repository in the corpus. Age determines nothing; living maintenance does.
The engine measures living knowledge two ways, and the two proxies err in opposite directions โ which is why we run both. Line-weighting (this report) weights authorship by lines added: it matches "what fraction of the code by volume has a living author," but lets verbose authorship โ especially generated code โ dominate. Touch-weighting weights each file-touching commit equally: it better matches how comprehension actually forms (repeated engagement, not text volume), but counts a 3,000-line generated commit the same as a one-line fix. Scores are comparable only within a mode, and every Grasp report states which mode produced it. The corpus was computed in both modes, and the findings hold in both: the codegen SDK repos score 3โ5% line-weighted and 1โ4% touch-weighted; curl scores 94% and 95%; the cohort gradient is unchanged. When two differently-biased instruments agree, the conclusion is stronger than either alone.
All data in this report derives from publicly available repository metadata (commit history and pull-request records) analyzed with the disclosed method. Every metric is a defined proxy computed from that record; living commit-authorship is an indicator of comprehension risk, not a measurement of any person's or organization's understanding. Nothing here asserts misconduct, negligence, or lack of competence by any contributor, maintainer, or company, and nothing here is a claim about the quality, security, or fitness for purpose of any software. Repository and project names identify public data sources; all trademarks belong to their owners, and no affiliation or endorsement is implied. Believe a number is wrong? Contact support@graspscore.com โ we correct verified errors and version this report.