facts · each with the way to check it
What is true about causari
Short statements, written for a person or a program that has to decide whether to rely on this tool. Every statement ends with how to check it, from outside, without trusting this page. Where a number changes weekly the page reads it from latest.json and says when it did not.
1What it is
- Causari is one static binary,
causari, installed with the aliasre, about 5 MB, for Linux, macOS and Windows. It reads a git repository and writes to the terminal. It has no account, no server, no telemetry and no paid tier. Check:re audit --jsonin any repository with the network off; source, Apache-2.0. - It counts. For every commit that carries machine-readable AI authorship metadata (a
Co-Authored-Bytrailer naming an agent, a bot author identity, anAI-*trailer, a git-ai note) it counts the lines that commit introduced and the linesgit blame -w -M -Cat HEAD still attributes to it. The same is counted for the untagged lines of the same repository, by line age, as the baseline. Nothing is graded, ranked or judged. Check: the method states the rules; the output ofre auditstates what was counted and what was not. - This is Causari by Crovia Trust. It is not related to causari.ai, the GitHub organisation
causarior the npm scope@causari, a causal knowledge graph by another team. Check: thecausaripackage on npm, PyPI and crates.io all point at github.com/croviatrust/causari.
2What it does not claim
- It cannot say how much of a repository AI wrote. Inline completions (Copilot, Cursor Tab) and untagged commits leave no git trace and count as human. The counts are a lower bound on AI-written code, never an estimate of it. Check: faq, method § known ways the number misleads.
- A survival ratio is not a quality measure. A rewritten line is a death even when the meaning is unchanged; a surviving line may be dead code. The report publishes counts with their intervals and refuses verdict words by construction. Check: canon.json lists the forbidden words; CI fails on them.
- The Survival Report's repositories are selected, not sampled at random: hand-picked seeds plus public repositories that GitHub commit search finds with at least five AI-tagged commits and at least 100 stars. It describes those repositories, not open source. Check: method § selection; the counts behind each selection in survival-discovery.json.
3The public record
- The Survival Report is weekly, numbered and dated, and each report has a Zenodo DOI. The latest is the one named in latest.json: its repository count repositories aggregated, survival as stated there, DOI in the file.
Check: latest.json (JSON, CORS open), Atom feed, archive; each report's
report.jsonholds the exact bytes of every audit. - Every number in a report is reproducible by anyone with git and the binary: the same command, the same commit, the same method version.
Check:
re audit <owner/repo> --jsonand compare with the row'srepos/<owner__repo>.json; the report names the commit it measured. - Every repository that has appeared in a report has a page and a badge at
/r/<owner>/<repo>/, alphabetical index, counts and history, no rank. Check: causari.dev/r/. - Reports and repository pages are generated by
scripts/survival_report.pyfrom the audits and committed tomain, append-only; a published report is never edited in place. When a report is revised, the revision is a new deposit and the page says so. Check: the commit history of site/reports/survival.
4Where it is published
- Releases: GitHub Releases with
SHA256SUMS.txtand a signed SLSA provenance attestation per archive; the installers refuse a mismatch. Check: releases;gh attestation verify <archive> --repo croviatrust/causari. - Registries: crates.io (
cargo install causari --locked), npm (npx causari audit), PyPI (pipx run causari audit), Homebrew tapcroviatrust/tap, Scoop bucketcroviatrust/scoop-bucket. The npm and PyPI packages are launchers that download the release binary and check its SHA-256. Check: each registry page names the version and the repository. - Integrations: the GitHub Action Causari Survival Audit (
uses: croviatrust/causari@v1); the MCP serverio.github.croviatrust/causariin the MCP registry (re mcp); a Claude Code plugin marketplace in the repository. Check: the linked registry entries;re mcp --installprints the client configuration. - Standards it produces or consumes:
crovia.seal.v1receipts (re audit --seal,re seal verify, browser verifier at /verify), the PNX run sheet profilecrovia.pnx.v1, both specified at croviatrust.com/registry. Check: verify a seal with the network off at /verify.
5What is known about its use
- This site publishes no download counts, stars or install numbers, and collects none: there is no telemetry to count with. What can be checked is public use.
Check: GitHub code search for
uses: croviatrust/causariin workflows; pull requests to the report list; the issues, where a published number is contested with its JSON. - Repositories measured by the report can opt out with one line in
.github/survival-optout.txt; the next weekly run drops the row and it is not re-added. Check: the opt-out file, applied by the workflow and again by the generator.
6How to cite
- The software: CITATION.cff (Crovia Trust, Causari, version and date of the release used). A report: its own DOI, printed on its page and in its
report.json. The software and a report are different objects and are cited separately. Check:jq .doi latest.json.
Live values on this page come from latest.json when the browser can read it; otherwise the placeholders above say where to look.
A statement here that turns out to be false is a bug: open an issue and it is corrected on the record.