Independent register of AI agents & harnesses · no sponsored placementsEdition 2026-09 · 107 entries · evidence to 26 Sept 2026
AgentsWisdom

The Register / Coding agents / Cline

Register entry · Coding agents · updated 26 Sept 2026

Cline

Cline Bot Inc. · Coding agents

Cline is an Apache-2.0 coding agent that reads and edits files, runs terminal commands and uses MCP tools, asking for approval unless auto-approve is enabled. It ships as a VS Code extension, a JetBrains extension, a CLI, a TypeScript SDK (@cline/sdk), a Kanban app for running agents in parallel git worktrees, and since July 2026 a desktop app. Users bring their own model keys or buy inference through Cline at cost; ClinePass is an optional $9.99/month subscription for open-weight models. Version 4.0 (June 2026) moved the extension onto the new SDK runtime.

What reviewers and users praise

  • Model freedom: bring your own API keys and switch to any provider, including local and open-weight models (tech-insider.org review; HN users running local Qwen/DeepSeek)
  • Diff review and approval workflow in VS Code that users find easier to follow than terminal agents (r/CLine)
  • No seat fee for the open-source tier; pay only for inference

What they criticise

  • Variable, sometimes high per-task cost with pay-per-token models (PromptQuorum)
  • Tool-calling reliability complaints, especially with local or non-frontier models (HN, Aug-Sep 2026)
  • Regressions reported after the v4.0 SDK migration, including Plan mode editing files (GitHub issues #11906, #13140)
  • Long sessions degrade as context fills (HN)

Rating · evidence to 26 Sept 2026

67
  • No. 7 of 16 in category
  • Medium confidence
  • Trust B
  • Open source
Adoption81
Experts64
Crowd54
Experts vs the crowdcrowd cooler by 11
Experts64
Crowd54
PriceFree, paid from $9.99
Use it viaIDE extension, CLI, Desktop app, API, MCP server
Runs onmacos, linux, windows
LicenceApache-2.0
UpdatedEvidence collected 26 Sept 2026

How the rating was worked out

Weights for Coding agents: adoption 35%, experts 40%, crowd 25%. Pillars without enough evidence are left out and the others re-weighted. The method.

Adoption & momentumweight 35%81GitHub stars 69k → 86 · npm weekly downloads 54k → 47 · VS Code / Open VSX installs 5.4M → 74 · Reported users 11M → 82 · 136 releases in 90 days → 100
reach × 0.7 + momentum × 0.3
Expertsindependent reviews · weight 40%644 independent reviews (2 positive · 2 mixed · 0 negative), averaged toward 50 for small samples.
Crowdcommunity sample · weight 25%548 dated posts from hackernews, reddit: 4 positive · 1 mixed · 3 negative
(positive + ½ mixed) ÷ n, averaged toward 50 for small samples
Rating67medium confidence (3 of 3 pillars, 8 community posts).

Evidence checks. 2 GitHub issues not counted as sentiment. How evidence is checked.

Editorial adjustment. Incident-history re-grade under methodology revision 2 (see the trust section).

Trust & safety

Seven dimensions graded A–D from documented facts. Overall: B.

B

Permission model

Per-tool-call approval with documented auto-approve categories (read/edit project files, read/edit outside workspace, safe/all commands, browser, MCP) and an opt-in YOLO mode; docs recommend leaving edits/commands off. No default sandbox for the IDE extension (Kanban isolates tasks in git worktrees, which is not a sandbox). source

A

Data access scope

Read and edit permissions are scoped to the workspace; access outside the workspace is a separate opt-in toggle. Docs note .clineignore is not a security boundary and recommend an enforcing PreToolUse hook. source

A

Data storage

Client-side execution; enterprise docs state code is processed locally with no uploads and no codebase indexing (prompts still go to the chosen model provider). source

B

Data retention & training

Docs state code and prompts are not used for model training. No stated retention period found for inference routed through Cline's own provider or ClinePass; with BYOK, retention follows the chosen provider. source

C

Incident history (24 months)

Three security advisories in 2026: the Feb 2026 npm supply-chain compromise (cline@2.3.0), a critical cross-origin WebSocket hijack in the Kanban server (CVE-2026-44211, May 2026) and a high-severity cross-origin WebSocket hijack in the Cline Hub dashboard (CVE-2026-59723, June 2026). Each was disclosed. Regraded from D: Revision 2: serious issues that were each fixed and publicly disclosed grade C; D is kept for unresolved issues or slow or undisclosed fixes. source

n/e

Compliance

A trust center exists at trust.cline.bot but renders client-side and could not be read; no SOC 2/ISO 27001 attestation found on cline.bot pricing or enterprise docs. A third-party page (search snippet) says Cline had no SOC 2 or ISO 27001 as of Q2 2026 — unverified. source

A

Transparency

Apache-2.0 source on GitHub with public release notes for every release. source

The experts

4 named independent reviews found; dated reviews from the last 12 months are scored.

  • mixed
    Cline wins if you want open-source code, your own API keys, the ability to swap to any frontier model on release daySofia Lindström (tech-insider.org) · 28 May 2026 · tech-insider.org
  • mixed
    Not for predictable, fixed-cost budgeting — because it is agentic and bring-your-own-API-key, a single complex task can cost several dollars.Hans Kuepper (PromptQuorum) · 5 Sept 2026 · promptquorum.com
  • positive
    Cline has earned a permanent spot in my workflowBuild with AI (techfind777 Substack) · 31 Mar 2026 · aiproductweekly.substack.com
  • positive
    Cline does not offer inline completions at all; every Cline interaction is an explicit task request.baeseokjae (RockB blog) · 28 Apr 2026 · baeseokjae.github.io

The crowd

8 coded posts from hackernews, reddit.

4 positive1 mixed3 negative
  • negative
    I usually use Cline but I'm giving up on it for this exact reason.Which tools do Claude, Codex and Cursor choose? · 4 Sept 2026 · news.ycombinator.com
  • negative
    I've noticed 0 improvement. If anything a downgrade. The agents often refuse to use the tools after 1 try because the results are so trash.Which tools do Claude, Codex and Cursor choose? · 4 Sept 2026 · news.ycombinator.com
  • negative
    The model works perfectly when called directly, but the agent integration doesn't actually execute the tools.Anomalyco/OpenCode, Aider-AI/aider, and Cline Review · 27 Aug 2026 · news.ycombinator.com
  • mixed
    Cline works well early on in a session but I find I regularly need to start new tasks, past a certain point the context window gets clutteredDeepSeek Harness developer preview · 13 Aug 2026 · news.ycombinator.com
  • positive
    It works well in one shot with Cline or Opencode.DeepSeek V4 Pro 0813 · 12 Aug 2026 · news.ycombinator.com
  • positive
    But note that you have to use Cline (or other harness) if using vscode. I was shocked at how poor the recent versions of GitHub Copilot areDeepSeek V4 Flash 0731 · 8 Aug 2026 · news.ycombinator.com
  • positive
    I do turn-based work via Cline + Claude). Case in point: I was able to ship this [1] in one month flatNever Enough · 22 Jul 2026 · news.ycombinator.com
  • positive
    I find the integrations and the user of Cline far far easier, easier to see my usage, easier to also see the diffs on larger files.r/CLine · 21 Jan 2026 · search snippet · reddit.com

Pricing

As published, checked 26 Sept 2026.

PlanPriceNotes
Open SourceFreeVS Code extension and CLI; pay for inference at cost via Cline or bring your own key.
ClinePass$9.99 / monthlyOptional subscription for curated open-weight models; docs claim 2-5x the usage vs standard API rate.
EnterpriseCustomContact sales. Adds JetBrains extension, SSO, SLA, RBAC, provider limits, authentication logs, team dashboard.

Recent changes

Ranked alongside

Other ranked entries in Coding agents.

Compare with the top two
OpenCodeAnomaly75
Claude CodeAnthropic73
Zed (Agent Panel)Zed Industries73
GitHub CopilotGitHub (Microsoft)72

Sources

Every figure above traces to one of these, observed up to 26 Sept 2026.

  1. Cline homepage (11M+ installs, product surfaces)
  2. Cline pricing
  3. Cline docs index
  4. The Hacker News: Cline CLI 2.3.0 supply chain attack
  5. Snyk: How Clinejection turned an AI bot into a supply chain attack
  6. Open VSX: 6,732,842 downloads