Picture a genuinely open RAG library, MIT licensed, every line of core code auditable. One optional module calls a hosted embedding API. Without the key, the library still runs on local models, but that module exists for users who want better results. I think calling that a leash ignores how open source actually works. The 65% statistic blends optional integrations with hard dependencies. A paid API dependency doesn't violate the open-source definition either; that definition governs the code's licensing freedoms, not whether every service it touches is self-hostable. By that logic, an open-source app running on Windows or GitHub Actions would fail the test too. Openness is about the project license, not absolute architectural purity.