

I don’t audit the code, but I do somewhat audit the project. I look at:
- recent commits
- variety of contributors
- engagement in issues and pull requests by maintainers
I think that catches the worst issues, but it’s far from an audit, which would require digging through the code and looking for code smells.
The ecological costs don’t need to be very high. We host our own LLM models at my company on a Mac Mini, which doesn’t use a ton of power and works pretty well.