It's an agent system that basically embeds the core idea of CodeQL (Datalog extraction from codebases) and then allows a model to pose questions and answer them.
You're right, it's TTL not LRU. The authoritative server publishes a TTL with the record — "you may keep this for N seconds" — and when it's up the resolver has to ask again no matter how popular it is.
LRU does show up in resolvers, but as memory management: cache is full, evict the least recently used early. It can only make something disappear sooner than its TTL, never later.
It's time-based because there's no back-channel. An authoritative server has no idea who's holding a copy of its records, so it can't push an invalidation.
To an extent, though for significant (in monetary terms) violations of the law the teeth tend to pay for themselves (but do so by not fully compensating the people whose behalf they are supposedly acting on).
More problematically there are camouflaged sharp spines pointed primarily in the direction of poorer people, and people not advised by lawyers.
But none of that matters here when the damaged parties include the megacorps of the world.
+1 for qubes. with some effort you can get a really nice stack with segmented git, disposable coding agents, package cachers, firewalls, and network visibility.
Disclosing private repos against the owner's intent is a much more immediate and significant business risk than violating the license of open source code.
reply