Which "open source" AI agent tools are not actually open source
Of the 147 projects catalogued here, 140 carry an OSI-approved licence and seven do not. What n8n, AutoGPT, Dify, AutoGen, Crush, Phoenix and TEN Framework restrict, why GitHub's licence field misleads in both directions, and what to check.
Seven entries out of 147
Of the 147 projects in this catalogue, 140 carry an OSI-approved licence and seven do not. The seven are n8n (Sustainable Use License), AutoGPT (PolyForm Shield on the platform, MIT on everything else), Dify (Dify Open Source License), AutoGen (CC-BY-4.0), Crush (FSL-1.1-MIT), Phoenix (Elastic-2.0) and TEN Framework (Apache-2.0 with additional conditions).
One entry in twenty by count, one star in ten by attention: those seven hold 654,198 GitHub stars between them — 9.7% of the 6,767,833 across all 147 entries. n8n, at 202,708, is the third most-starred project listed here; AutoGPT, at 186,963, is sixth, and Dify, at 153,771, tenth. Three of the catalogue’s four visual workflow builders are on this list; Langflow, at 153,816, is the one that is not.
Among the 140 the distribution is dull, which is the good news: MIT 67, Apache-2.0 65, AGPL-3.0 3, BSD-3-Clause 2, BSD-2-Clause 1, the PostgreSQL License covering pgvector, and the MCP specification, whose code and specification text are Apache-2.0 while its documentation is CC-BY-4.0. 132 of the 147 entries are MIT or Apache-2.0 outright. If your dependency is one of those, you can stop here.
What the seven actually restrict
| Project | Licence | The clause that matters | Still permitted |
|---|---|---|---|
| n8n | Sustainable Use License | Reselling it as a hosted service | Internal use, self-hosting |
| AutoGPT | PolyForm Shield 1.0.0, on the platform directory | Offering that platform as a competing product | Internal use, self-hosting; the rest of the repository stays MIT |
| Dify | Dify Open Source License | Multi-tenant hosting, branding changes | Otherwise, what Apache 2.0 allows |
| AutoGen | CC-BY-4.0 | Nothing explicit — that is the problem | Use with attribution |
| Crush | FSL-1.1-MIT | Competing use, until each release turns MIT two years on | Internal use, non-commercial research, professional services |
| Phoenix | Elastic-2.0 | Offering it to others as a managed service | Internal use, self-hosting, modification |
| TEN Framework | Apache-2.0 with additional conditions | Hosting it on end-user devices, and competing with Agora | Deploying your own applications for your own end users |
Six of the seven are readable in a few minutes and say what they mean. The Sustainable Use License permits internal business use and self-hosting, and withholds the right to resell n8n as a hosted product; n8n publishes it under the “fair-code” banner rather than claiming OSI compliance. Dify’s licence is Apache 2.0 with additional conditions on multi-tenant hosting and on branding. Elastic License 2.0 forbids three things: providing the software to third parties as a managed service, circumventing licence-key functionality, and removing or obscuring licensing and copyright notices. AutoGPT splits its repository, applying PolyForm Shield to the platform that is now the product and leaving MIT on everything outside it. Crush uses the Functional Source License, which forbids competing use and then grants MIT on the second anniversary of each release.
All six restrict versions of the same thing: becoming a competing product or hosted service. If you run the software for your own organisation, five of them do not touch you — and the anxiety most teams bring to this question is misplaced.
TEN Framework is the one to read twice. Its additional conditions are the widest in this table: alongside the usual bar on competing with Agora, they prohibit hosting the framework on end-user devices, mobile terminals explicitly included. A voice agent shipped inside a phone app is exactly the deployment that clause reaches, and nothing in the “Apache-2.0” at the top of the file warns you.
AutoGen is a different case, and a worse one. CC-BY-4.0 is a Creative Commons licence written for content — articles, photographs, datasets. It permits commercial use with attribution, so it reads as generous. What it does not do is any of the work a software licence exists to do: no patent grant, no source-versus-object distinction, no permission structure for distributing a compiled derivative. Creative Commons itself advises against applying its licences to software. The honest statement is not “AutoGen is restricted” but “nobody can tell you what its terms mean for a product you ship” — a worse place to be than a restriction you can read.
The licence question is moot anyway: AutoGen is in maintenance mode, accepting only bug fixes, security patches and documentation, with the README routing new projects to Microsoft Agent Framework. If you are choosing today, that decides it before the licence does.
Why GitHub’s licence field is not an answer
The licence shown on a repository page comes from matching the LICENSE file against a set of known templates. It is right most of the time, and when it misleads it misleads in both directions. This catalogue holds a clean example of each.
AutoGen is the first direction: the field reports exactly what the repository declares, and the declaration is a content licence on a code repository. The API is not lying; it simply has no way to tell you the instrument is wrong for the job.
OpenClaw is the other direction. It is the most-starred entry in this catalogue at 387,929 stars, and GitHub reports its licence as NOASSERTION — the value returned when template matching fails. Open the file and it is the MIT licence, verbatim, with one line appended at the end pointing at THIRD_PARTY_NOTICES.md. That one sentence is enough to break the match. This catalogue records MIT because a person opened the file and read it.
Both mistakes are cheap to make and expensive to inherit: a directory assembled from the API would call AutoGen unremarkable and OpenClaw unknown, and be wrong twice.
The most-installed skills in this ecosystem are not open source at all
There is a third way the licence field misleads, and it is the one with the widest reach: it says nothing, and people read that as nothing to worry about.
anthropics/skills is the reference repository for Agent Skills, at roughly 172k stars the most-starred collection of its kind, and it is laid out as something you install — a plugin marketplace manifest at the root, nineteen skill directories underneath. GitHub reports no licence for it, because there is no LICENSE file at the root. Eighteen of the nineteen skill directories have one, and it is not an open-source licence:
© 2025 Anthropic, PBC. All rights reserved. […] users may not: extract these materials from the Services or retain copies of these materials outside the Services […] reproduce or copy these materials […] create derivative works based on these materials […] distribute, sublicense, or transfer these materials to any third party.
That is not a source-available licence with a competing-service clause, of the kind the seven above use. It withholds copying, modification and redistribution outright, and scopes permitted use to Anthropic’s own services. The source is published; the right to take it is not granted.
None of this is hidden or improper — Anthropic ships these skills inside its own products, and the terms describe that model accurately. The gap is between how the repository reads and what the files say. It reads like every other skills repository: public, browsable, structured for installation, with a SKILL.md in each directory exactly like the ones you are meant to copy. A reader who checks the sidebar, sees no licence, and concludes “unlicensed, probably fine” has it backwards.
The contrast is one entry away. Google’s skills repository does the same job for Google Cloud, Ads and Analytics, is a comparable collection of directories, and is Apache-2.0 — copy it, change it, ship it. Two repositories that look alike from the outside, and the difference only appears in a file GitHub’s sidebar does not read.
This is checklist item 3 with a real bill attached: in a monorepo, check per package. Here the root tells you nothing and every directory underneath tells you something you needed to know.
AGPL is open source, and still a decision
Three entries are AGPL-3.0: Firecrawl at 173,614 stars, SearXNG at 36,209 and Skyvern at 22,873. AGPL-3.0 is OSI-approved. It belongs in the 140, not the seven, and nothing here is a complaint about it.
What AGPL adds to the GPL is the network clause: if you modify the program and let users interact with it over a network, those users are entitled to your modified source. That is a copyleft obligation, not a usage restriction, and it is triggered by your modifications reaching users — not by the software being present in your stack.
The consequence is a design choice, and I would make it the same way every time: run these as their own service and call them over HTTP, unmodified. Both ship as self-hostable servers built to be used exactly that way. What creates real exposure is vendoring their source into your tree and patching it, which turns the boundary between their code and yours into an argument you do not want to have later.
If your organisation has a blanket AGPL prohibition — plenty of large ones do, and it rarely comes with an appeals process — treat it as settled rather than fighting it, because permissive alternatives exist for both jobs. Crawl4AI (Apache-2.0) does the crawl-to-markdown work Firecrawl does, at the cost of owning proxy handling and rate limiting yourself (the two compared). For browser automation, Browser Use and Stagehand are both MIT. One category over, Langfuse against Phoenix is MIT against Elastic-2.0 for much the same job.
What to check, in what order
1. Decide what you will do with it before reading any licence. Three questions settle nearly every case: does it run inside your product or beside it, do people outside your company reach it over a network, and will you modify it. If the answers are beside, no and no, every entry in this catalogue is fine — all seven included.
2. Open the LICENSE file, not the sidebar. Ten seconds, and it is the whole of the previous section.
3. In a monorepo, check per package. A licence at the root does not guarantee that every published package underneath carries the same terms.
4. Search the text for “service” and “hosting”. The clauses that bite are about providing the software to third parties. If those words are absent, the licence probably does not restrict your plan.
5. Read the bespoke ones properly. The Sustainable Use License and Elastic License 2.0 run about a page each; Dify’s is Apache 2.0 with two extra conditions stated up front. Five minutes removes the guessing.
6. Record the answer with a date. Licences change, and more often toward restriction than away from it. Every entry here carries a last-reviewed date for that reason, and the methodology page explains how.
The restrictions are reasonable. One of the names is not.
Source-available licensing answers a recurring event: a company funds years of engineering, a larger company repackages the result as a managed service, and the funder keeps the maintenance burden without the revenue. The Sustainable Use License and Elastic License 2.0 are narrow, legible responses, and both permit far more than they forbid.
The texts are honest. n8n says “fair-code” rather than claiming OSI compliance. Arize ships Phoenix under a licence whose entire text fits on a page. Dify states its additional conditions at the top of its licence file, as numbered sections 1 and 2 — multi-tenant hosting, then branding — so anyone who opens the file learns within a paragraph what is being withheld.
The name on that file is the problem. It is headed simply “Open Source License”, and the name the project gives it — recorded here, as it must be, as “Dify Open Source License” — asserts the exact status the conditions underneath it rule out. Read the body and you are well informed; read the name, skip the body, and you are worse off than if you had never looked. AutoGen has the same defect from the other direction: CC-BY-4.0 is a real, familiar identifier, which is why it survives an eye-scan its actual terms would not.
That is why this catalogue records a licence type on every entry, not a licence name alone. A name can say anything; a type has to be one of three, and the criteria are published: an OSI-approved licence, an explicitly documented source-available one, or a proprietary one. The first two are listed here. The third is not, and anything whose licence cannot be established is not listed either — but a proprietary licence on a repository the whole ecosystem installs from is worth writing about rather than quietly skipping, which is why anthropics/skills appears above and not in the catalogue. The looseness the rest of the ecosystem runs on — third-party lists, conference slides, “it’s open source, we can just self-host it” in a planning meeting — starts every time with someone reading a name instead of a file.
Projects in this post
n8nWire services together as workflows you draw on screen, with an AI agent node available anywhere in them
AutoGPTThe 2023 autonomous-agent project, rebuilt as a block-based visual builder with a hosted twinDifyVisual builder for LLM apps, with RAG and agents included
AutoGenAgents that solve problems by conversing with one another
CrushA single-binary terminal agent from the Charm terminal-UI people, source-available until it turns MIT
PhoenixTracing and evaluation that runs inside a notebook
TEN FrameworkA real-time multimodal conversational stack — voice, telephony, avatars — under Apache terms with conditions
SearXNGSelf-hosted metasearch — web search for an agent with no API key and no per-query bill
FirecrawlTurns whole sites into clean markdown for model consumption
SkyvernBrowser workflow automation that survives layout changesopenclawA single-operator assistant that runs as a local Gateway and reaches you in the chat apps you use.
Crawl4AIAsync Python crawler that emits model-ready output
Browser UseGives an agent a real browser, driven by the DOM rather than pixels
StagehandPlaywright you can mix with natural-language instructions
LangflowDrag-and-drop flow builder that exports to running code
LangfuseTracing, prompt management and evaluation for LLM applicationsModel Context ProtocolThe MCP specification itself — the schema and rules every SDK implements
skillsGoogle's own Agent Skills for Google Cloud, Ads and Analytics