Audit — Code Attribution TrackerKnow exactly who — or which AI — wrote every line in your codebase. Audit runs quietly in the background and automatically records every meaningful code change: who made it (you, or which specific AI tool — Copilot, Claude Code, Cursor, Codex, Gemini, and more), which file and lines, whether it was a routine edit or a structural design change, and what git branch it happened on. Nothing to turn on per-edit, nothing to remember to log — it's on the moment you install it.
New to Audit?Install it, open any project, and start editing — that's it. On first run you'll be asked what name to attribute your own manual edits to; after that, everything is automatic. Run Audit: Open Dashboard any time to see the full picture, or Audit: Open Today's Log (Preview Mode) to see the rich rendered visual log. What's new in 1.1.01. 📋 Single Unified Daily Log (
|
| Tool | Source | Confidence | Why |
|---|---|---|---|
| Claude Code | UserPromptSubmit hook |
High | Official, documented API. Run Audit: Enable Claude Code Prompt Capture (Hooks) once. |
| Claude Code | ~/.claude/history.jsonl |
Low | Unofficial internal storage — fallback only if the hook isn't set up. |
| Codex | ~/.codex/sessions/**/rollout-*.jsonl |
Medium | Verified via multiple independent sources; schema has changed across versions, parsed defensively. |
| Aider | .aider.chat.history.md in project root |
Medium | Officially documented, advertised, stable — but turn parsing uses Aider's established #### convention rather than a byte-for-byte confirmed sample. |
| Cline | globalStorage/saoudrizwan.claude-dev/tasks/**/ui_messages.json |
Low | Location is well-confirmed (community docs, Cline's own "Reconstruct Task History" command); exact field names are NOT confirmed with a real sample — parsing tries several plausible field names and returns nothing rather than guessing wrong. |
| Gemini CLI | ~/.gemini/tmp/<hash>/chats/*.json |
Low | Location officially documented by Google; hash algorithm and message schema not confirmed — every hash folder is scanned directly rather than computed, and field parsing is tolerant. |
A bonus that applies to all five: if no AI extension appears "active" for an edit — which happens for CLI-run agents (Codex CLI, Claude Code CLI, Aider, Gemini CLI are all typically used from a terminal, not as a VS Code extension) — Audit checks whether a real prompt source still has a match before giving up. If one does, the edit gets correctly attributed even though no matching VS Code extension was ever detected as active for it.
Elimination-by-absence for ambiguous cases. When several AI extensions
are active at once (e.g. Copilot Chat + Codeium), Audit can't tell them
apart directly — but for any of the five tools above that are ALSO among the
active candidates, absence of a matching prompt is treated as evidence
against them, narrowing (or sometimes fully resolving) the guess instead of
always listing every active tool. This applies to both content-edit
attribution and file-creation attribution, sharing one implementation
(narrowCandidatesByPromptEvidence).
Be aware of the real limits:
- Copilot Chat, Cursor, Codeium, and others are still not covered. Their
chat history is stored in less accessible, VS-Code-internal formats
without a verified public structure. Copilot Chat specifically stores
session JSON under
workspaceStorage/<hash>/chatSessions/— the location is confirmed, but the exact field schema isn't yet, and building a reader on an unconfirmed schema risks silently wrong output rather than no output — worth getting right before shipping. - Every unofficial/best-effort source here is read defensively: a missing file, malformed line, or unrecognized shape results in "no prompt found," never a thrown error. The low-confidence sources (Cline, Gemini CLI) are genuinely more likely to find nothing than to find a real match until their schemas are confirmed with a real sample — this is expected, not a bug, if you see them consistently return no prompt.
- Matching is by project directory and timestamp proximity, not a
cryptographic link — in rare cases (e.g. two edits in very quick
succession) it could attach the wrong nearby prompt. Toggle off with
audit.enablePromptCaptureif this matters for your use case. - Manual
Audit: Add Reason to Last Entrynotes still work independently and are never overwritten by an auto-captured prompt — the dashboard shows whichever is present (🤖 for auto-captured, 📝 for manual).
Honest about its limits
Audit is upfront about what it can and can't reliably tell: it can't identify a specific AI model from code pasted in from a browser chat (ChatGPT web, Gemini web) — that's logged as "external paste, source unknown" rather than guessed. When more than one AI extension is active at once, ambiguous edits are logged as "possibly: X / Y / Z" rather than a false single guess — you can correct these after the fact with Audit: Correct Last Entry Attribution, or set a preferred tool in settings if you only use one. Full details further down this page.
Language support
Core tracking — edits, attribution, file create/delete/rename, branch tagging, the dashboard — works on any file, any language, since it operates on VS Code's document/file events rather than parsing syntax. Design-change flagging (the one part that's language-aware) currently covers JavaScript/TypeScript, Python, Java, C#, Kotlin, Go, Rust, PHP, and C++ — see below for details and how to extend it.
What it records
For each meaningful edit, a structured entry is appended to .audit/<month-yyyy>/<d-m-yy>.md (e.g. .audit/october-2026/5-10-26.md):
## 14:32:10
- File: `src/services/orderService.ts`
- Project: src
- Lines: 45-62
- Mode: AI — GitHub Copilot (Vaibhav)
- Developer: Vaibhav
- Change: Code Modified (+18 / -4)
- Context: 🎯 `processOrder`
- Triggered-By: `src/types/order.ts` (TS2345: Property 'total' is missing in type 'OrderInput')
- Methods: Added validateCart; Modified processOrder
- Branch: `feat/checkout-flow`
- Design-Change: true (function signature changed)
- Prompt: "refactor processOrder to compute total with discounts"
Key Fields & Keywords Explained:
## HH:MM:SS— Exact local wall-clock timestamp of the change event.- File:— Workspace-relative path of the affected file.- Project:— Top-level root directory containing the file (e.g.src,frontend,backend).- Lines:— Line range modified or inserted (e.g.45-62or12).- Mode:— Attribution source:AI — <Tool> (<Developer>),Developer — <Developer>,External paste (source tool not detectable), orMode: Unknown (Audit was off).- Developer:— Active developer identity configured in settings.- Change:— Operation type and exact delta count (e.g.Code Modified (+18 / -4),Code Added (+14 lines),File Created,File Deleted,File Renamed).- Context:— Syntactic enclosing scope symbol detected in real time (e.g.🎯 processOrder).- Triggered-By:— Ripple causality metadata indicating which file triggered this edit and why (compiler diagnostic errors or structural cascades).- Methods:— Functions, methods, or classes added or modified in this change.- Branch:— Git branch active at the moment of the edit (e.g.feat/checkout-flow).- Design-Change:—trueif structural architecture boundaries were modified (exports, interfaces, classes, routes).- Prompt:— The exact prompt query captured from local AI sessions (Copilot, Claude Code, Codex, Antigravity, Gemini CLI, Aider, Cline).
📁 Month-Wise Log Organization & Monthly Rollup (_month.md)
Audit automatically organizes logs into month-based subdirectories rather than a flat .audit folder:
.audit/
status.md <- 1-minute persistent heartbeat
self-check.log <- Hourly health audit & auto-repair report
august-2026/
1-8-26.md <- Raw daily log (no leading zeros)
1-8-26-easy.md <- Executive Easy View companion
31-8-26.md
_month.md <- Auto-updating month rollup
september-2026/
1-9-26.md
1-9-26-easy.md
_month.md
october-2026/
5-10-26.md
5-10-26-easy.md
_month.md
files/ <- Per-file standalone revision histories
Key Principles:
- Lowercase Month & Year: Folders are named
<month-yyyy>(e.g.august-2026,october-2026). - Day-Month-Year File Naming: Daily logs are named
<d-m-yy>.mdwith no leading zeros (e.g.1-8-26.md,5-10-26.md,31-8-26.md). - Seamless Flat Log Migration: Any older flat files in
.audit/(such as2026-10-05.md) are automatically detected and safely moved into their proper month folder upon extension activation. - Monthly Rollup (
_month.md): Automatically aggregates activity across all days in that month:- Total edits and active coding days
- Net lines added and removed (+/-)
- AI-assisted vs. manual developer edit percentages
- Tool breakdown (Copilot, Claude Code, Codex, Cursor, etc.)
- High-churn files and structural design changes (⚠️)
- Direct clickable markdown links to each day's raw log and Easy View companion
📑 Daily Easy View Companion (<d-m-yy>-easy.md)
Alongside every raw daily log, Audit automatically generates and updates an executive Easy View file (<d-m-yy>-easy.md). Designed for fast reading by developers, code reviewers, and engineering leads, it condenses hundreds of raw edit events into a human-friendly narrative.
8 Standardized Sections:
- Title & Summary Header: Date, total edits, active time span, AI vs. Developer breakdown, and developer name.
- Today at a Glance: Structured high-level table of metrics, lines delta, top files, and tools.
- Needs a Look: Highlights items that warrant code review:
- ⚠️ Structural Design Changes (modified interfaces, signatures, or exports)
- 📦 High Code Volume (large bursts > 50 lines)
- 🔁 Thrashing (repeated edits to the same file in quick succession)
- Timeline (4-Quarter Day Breakdown):
- 🌅 Morning (
06:00 — 12:00) - ☀️ Afternoon (
12:00 — 18:00) - 🌆 Evening (
18:00 — 00:00) - 🌙 Night (
00:00 — 06:00) - Intelligent Merging: Duplicate edits to the same file within 60 seconds are consolidated into a single entry; bursts within 20 minutes are grouped.
- 🌅 Morning (
- Prompts (Prompt-to-Code Mapping): Numbered sequentially (
P1,P2, ...). Each prompt features an interactive collapsible<details>block with the exact prompt text and the specific files/lines modified. - Audit Health: Parity verification confirming that 100% of raw events from
<d-m-yy>.mdare preserved in Easy View. - Legend: Fast reference for all status icons (
🤖 AI,👤 Developer,📦 Large Edit,⚠️ Design,🔁 Thrash,🔗 Ripple). - Continuation Pointers: Seamless links connecting to previous or next day logs.
Open Easy View anytime with Audit: Open Today's Easy View (Executive Summary) (audit.openEasyView).
🔄 Continuous Midnight Rollover & Prompt Continuity
Coding past midnight? Audit automatically handles the 00:00 date boundary without missing an edit:
- Automatic File Transition: At midnight, the previous day's log is closed and the new day's log is created in the appropriate month folder.
- Cross-File Navigation Links:
- Appends a forward pointer to the previous log:
➡️ CONTINUE WITH NEW LOG FILE: 6-10-26.md(or cross-month relative path../november-2026/1-11-26.md). - Prepends a backward pointer to the new day's log:
⬅️ CONTINUED FROM PREVIOUS LOG FILE: 5-10-26.md(or cross-month relative path../october-2026/31-10-26.md).
- Appends a forward pointer to the previous log:
- Cross-Midnight Prompt Continuity: If you submit an AI prompt at 23:58 and the AI's file edits complete at 00:02, the active prompt query is preserved and correctly attributed across the midnight boundary.
🛡️ Never Miss Work: Heartbeat, Self-Healing & Offline Catch-Up
Audit operates as an uninterrupted local flight recorder:
1. 1-Minute Heartbeat (.audit/status.md)
Every 60 seconds, Audit updates a persistent status file recording:
- Status:
🟢 Active - Process ID (PID): Current VS Code extension host process
- Last Active Time: Wall-clock timestamp
- Workspace: Absolute path
- Active File: Currently open document
- Last Log Write: Path and timestamp of the most recent log update
- Last Self-Check: Timestamp and result of the automated health check
- Audit Version: Current extension version (
1.0.4)
2. Startup Downtime Gap Detection
When VS Code starts, Audit reads the previous heartbeat in status.md. If the editor was closed or Audit was offline for more than 5 minutes, it explicitly records the downtime:
## 09:15:00
- Note: ⏱️ Audit was offline from 2026-10-06 23:10:00 to 2026-10-07 09:15:00 (605 min)
3. Hourly Self-Check & Auto-Repair
Every 60 minutes, an automated background check verifies:
- Month directory and file hierarchy
- Today's raw log (
<d-m-yy>.md) - Today's Easy View companion (
<d-m-yy>-easy.md) - Heartbeat file (
status.md) - File watchers and integrity monitors
If any file is missing, damaged, or desynchronized, Audit automatically repairs/regenerates it and appends a report to.audit/self-check.log.
4. Offline Downtime Catch-Up Scanner
Files modified while VS Code was closed (e.g. via terminal git pulls, external scripts, or other editors) are discovered when Audit starts up and logged as:
## 09:15:02
- File: `src/utils/config.ts`
- Project: src
- Lines: 1-25
- Mode: Unknown (Audit was off)
- Developer: Vaibhav
- Change: Code Modified (+25 / -0)
- Note: File was modified while Audit was inactive
🔗 Connection & Ripple Tracking (Causality Tracking)
One of the most frustrating things in team and AI-assisted development is seeing that a file was modified without knowing why. For example:
- A developer or AI updates
src/types/order.ts. - Suddenly,
src/services/orderService.tshas a type error or broken import. - Someone opens
src/services/orderService.tsand patches it to fix the error.
Without causality tracking, the audit log only says orderService.ts was modified. With Audit 1.0.0, Audit correlates the cause and effect automatically:
How it detects connections:
- Live Diagnostics Listening: Audit monitors VS Code's diagnostic pipeline (
onDidChangeDiagnostics). When an edit to File A causes errors in File B, and File B is subsequently edited within seconds/minutes to resolve that error, Audit records:- Triggered-By: `src/types/order.ts` (Fixed compiler diagnostic: Property 'total' is missing) - Structural Design Cascades: When File A has a structural design change (
export,class, or interface change), any dependent file edited shortly after that references File A is automatically linked as a cascade fix. - Shared Agent Cascades: Multi-file patches produced by an AI assistant in response to the same prompt share causation metadata.
- Manual Causality Linker: You can run
Audit: Link Last Change to Triggering File(audit.linkLastEntryToFile) at any time from the Command Palette or Quick Action Menu to pick any recent file and attach a remark.
In the Dashboard:
The dashboard displays a visual purple badge under the Change column:
Code Modified (+18 / -4)
🔗 Caused by src/types/order.ts
📌 TS2345: Property 'total' is missing in type 'OrderInput'
You can click the 🔗 Ripple Fixes filter button in the dashboard to instantly filter the entire table to only show edits that were triggered by other files.
📄 Dedicated Per-File Audit Logs (.audit/files/)
Need to check the exact history, AI ratio, or developer contributions for a specific file? You no longer have to dig through weeks of daily logs.
Audit automatically maintains a dedicated markdown file for every tracked file under .audit/files/<path-to-file>.md.
Example: .audit/files/src/services/orderService.ts.md
# 📄 File Audit Log: `src/services/orderService.ts`
## 📊 Authorship & Changes Summary
- **Total Tracked Edits:** 8
- **AI-Assisted Edits:** 6 (75%)
- **Manual Developer Edits:** 2 (25%)
- **AI Tools Used:** GitHub Copilot (4), Claude Code (2)
- **Developer(s):** Vaibhav
- **Design Changes (⚠️):** 2
- **Thrashing Incidents (🔁):** 0
- **Linked Ripple Edits (🔗):** 2 (triggered by changes in: `src/types/order.ts`)
- **Last Modified:** 2026-09-28 15:20:14 (AI — GitHub Copilot)
---
## 📜 Revision History (Most Recent First)
### 2026-09-28 15:20:14 · Lines 45-62
- **Author:** AI — GitHub Copilot (Vaibhav)
- **Developer:** Vaibhav
- **Context:** 🎯 `processOrder`
- **Change:** Code Modified (+18 / -4)
- **Triggered By:** 🔗 `src/types/order.ts` (Property 'total' missing)
- **Notice:** ⚠️ *Structural Design Change*
- **Methods:** Modified processOrder
- **Prompt:** "refactor processOrder to compute total with discounts"
### 2026-09-28 11:04:02 · Lines 12-25
- **Author:** Developer — Vaibhav
- **Developer:** Vaibhav
- **Change:** Code Added (+14 lines)
- **Context:** 🎯 `validateCart`
Accessing File Logs:
- Run
Audit: Open File Audit Log for Active File(audit.openFileLog) from the Command Palette or Quick Action Menu (Ctrl+Shift+P). - Click the
📜 Historybutton in the File column of the Audit Dashboard. - Re-sync or regenerate all file logs at any time with
Audit: Sync / Rebuild All File Audit Logs(audit.syncFileLogs).
👁️ In-Editor Audit Lens Hover
Audit includes an in-editor hover provider: hover over any line in your code to see:
- Who wrote or edited it (e.g.
AI — GitHub CopilotorDeveloper — Vaibhav). - Exact timestamp and Git branch.
- Enclosing method context (e.g.
🎯 processOrder). - The actual AI prompt used to generate that line.
Toggle on or off at any time using Audit: Toggle Audit Lens Hover (audit.toggleAuditLens).
Setup
npm install
npm run compile
Then press F5 in VS Code to launch an Extension Development Host with it loaded,
or package it with vsce package and install the .vsix normally.
On first run it will ask for the name to attribute your manual edits to.
Commands
Access all commands via the Command Palette (Ctrl+Shift+P / Cmd+Shift+P) by typing Audit:
| Command | Command ID | Description |
|---|---|---|
| Audit: Show Quick Action Menu | audit.showQuickMenu |
Instant popup menu in status bar with all key actions |
| Audit: Open Today's Log (Preview Mode) | audit.openLog |
Opens today's <d-m-yy>.md directly in rendered Markdown Preview mode |
| Audit: Open Dashboard | audit.openDashboard |
High-performance interactive dashboard with filters and sorting |
| Audit: Export Client Compliance Report (HTML) | audit.exportComplianceReport |
Exports tamper-evident compliance certificate with SHA-256 seal |
| Audit: Show Team Audit Summary | audit.showTeamSummary |
Aggregates Git-committed team logs (.audit/teams/) offline |
| Audit: Activate Pro / Enterprise License Key | audit.activateLicense |
Activates offline-verified cryptographic Ed25519 license key |
| Audit: Restart Tracker (Reload Window) | audit.restartTracker |
Instantly reloads extension host and restarts file watchers |
| Audit: Open File Audit Log for Active File | audit.openFileLog |
View dedicated standalone revision history for active file |
| Audit: Sync / Rebuild All File Audit Logs | audit.syncFileLogs |
Rebuilds all .audit/files/*.md histories from logs |
| Audit: Link Last Change to Triggering File | audit.linkLastEntryToFile |
Attach a manual causality ripple link to a causal file |
| Audit: Toggle Audit Lens Hover | audit.toggleAuditLens |
Enable/disable in-editor attribution hover cards |
| Audit: Copy Standup / PR Summary to Clipboard | audit.copyStandupSummary |
Formatted markdown rollup for daily standups or PR templates |
| Audit: Add Today's Summary to Commit Message | audit.addSummaryToCommit |
Appends one-line stats to Source Control commit box |
| Audit: Add Reason to Last Entry | audit.addReasonToLastEntry |
Attach an explanation note or ticket ID to the last edit |
| Audit: Correct Last Entry Attribution | audit.correctLastEntry |
Fix a misattributed entry after the fact |
| Audit: View Work Sessions (Story Mode) | audit.viewSessionStories |
Browse continuous work sessions grouped into stories |
| Audit: Resume Last Session | audit.resumeLastSession |
Jump straight back to files from your last editing session |
| Audit: Restore Previous Version | audit.restorePreviousVersion |
Pick a past snapshot of the file, review diff, restore safely |
| Audit: Show Related Files | audit.showRelatedFiles |
Surface hidden co-change file relationships |
| Audit: Export Log to CSV | audit.exportCsv |
Export all logged entries to CSV for reporting or spreadsheets |
| Audit: Open Log Folder | audit.openLogFolder |
Reveal .audit folder in OS file explorer |
| Audit: Toggle Tracking On/Off | audit.toggle |
Temporarily pause or resume tracking |
| Audit: Set Developer Name | audit.setDeveloperName |
Configure your manual attribution name |
| Audit: Enable Claude Code Prompt Capture (Hooks) | audit.enableClaudeHookCapture |
One-time setup for Claude Code CLI hooks |
| Audit: Backfill Missing Prompts & Media | audit.backfillPrompts |
Retroactively link prompts from local assistant session files |
⚙️ Configuration & Settings
Configure Audit behavior via VS Code Settings (Ctrl+, or Settings -> Extensions -> Audit):
| Setting Key | Type | Default | Description |
|---|---|---|---|
audit.enabled |
boolean |
true |
Enable or disable automatic change tracking |
audit.developerName |
string |
"" |
Name to attribute manual edits to (prompted on first run) |
audit.logFolder |
string |
".audit" |
Workspace folder path where markdown logs are stored |
audit.licenseKey |
string |
"" |
Offline-verified Audit Pro or Enterprise License Key |
audit.policy.disallowedAiPaths |
array |
["**/security/**", "**/auth/**", "**/*.pem", "**/*.key"] |
Prohibited file paths for AI generation (Enterprise Policy) |
audit.policy.maxLinesPerAiEdit |
number |
250 |
Maximum lines allowed in a single AI edit before violation flag |
audit.preferredAITool |
string |
"" |
Pin attribution to a single AI tool if only one is used |
audit.tagGitBranch |
boolean |
true |
Tag each log entry with the current Git branch name |
audit.enableAuditLens |
boolean |
true |
Show in-editor hover cards attributing lines of code |
audit.protectLogFromExternalChanges |
boolean |
true |
Watch logs for tampering or deletion and auto-restore |
audit.enableThrashDetection |
boolean |
true |
Flag rapid repeated edits to the same file |
audit.thrashWindowMinutes |
number |
10 |
Time window (minutes) used to detect thrashing |
audit.thrashThreshold |
number |
3 |
Number of edits within window to trigger thrash warning |
audit.enableSnapshots |
boolean |
true |
Keep lightweight file snapshots at each tracked edit |
audit.maxSnapshotsPerFile |
number |
20 |
Maximum number of snapshots preserved per file |
audit.enablePromptCapture |
boolean |
true |
Auto-capture prompt queries from local assistant sessions |
audit.promptLookbackMinutes |
number |
10 |
How far back to look for matching prompts before an edit |
audit.enableAIBurstContinuation |
boolean |
true |
Attribute rapid follow-up edits to the active AI burst |
audit.aiBurstWindowSeconds |
number |
3 |
Time window (seconds) for AI burst continuation |
audit.minLinesForAIHeuristic |
number |
2 |
Minimum lines in an edit to trigger AI shape heuristic |
audit.trackSmallManualEdits |
boolean |
true |
Log small manual edits after a typing pause |
audit.ignoreBlankLineChanges |
boolean |
true |
Skip logging changes that only add/remove blank lines |
audit.ignoreCommentOnlyChanges |
boolean |
true |
Skip logging edits where every modified line is a comment |
audit.excludeDesignChangeForTestFiles |
boolean |
true |
Skip Design-Change flag for .test. / .spec. files |
🏷️ Iconography & Keyword Reference
Quick reference for all icons and keywords used across daily logs and the Dashboard:
| Icon / Keyword | Meaning | Where Used |
|---|---|---|
🤖 AI — <Tool> |
Code change generated by an AI assistant | Logs, Dashboard, Lens |
👤 Developer — <Name> |
Code change typed manually by the developer | Logs, Dashboard, Lens |
📦 High Delta (+N / -N) |
Large code volume edit (> 50 lines modified) | Daily Logs, Dashboard |
⚠️ Design-Change: true |
Structural architectural edit (signatures, classes, exports) | Daily Logs, Dashboard |
🔁 Thrashing: true |
3+ edits to the same file within 10 minutes | Daily Logs, Dashboard |
🔗 Triggered-By: <file> |
Ripple causality link from a compiler error or design change | Daily Logs, Dashboard |
🎯 Context: <symbol> |
Enclosing function, method, class, or route name | Daily Logs, Lens |
🔒 [REDACTED_API_KEY] |
Sanitized API key or credential automatically masked | Daily Logs, Reports |
🛡️ Violation: <Policy> |
AI governance boundary rule exceeded | Daily Logs, Reports |
➡️ CONTINUE WITH NEW LOG FILE |
Forward pointer at midnight rollover (00:00) | Daily logs |
⬅️ CONTINUED FROM PREVIOUS LOG FILE |
Backward pointer at midnight rollover (00:00) | Daily logs |
🟢 Status: Active |
Extension heartbeat active and monitoring | .audit/status.md |
⏱️ Audit was offline |
Startup downtime gap detection (> 5 minutes) | Daily logs |
❓ Mode: Unknown (Audit was off) |
Discovered changes made while Audit was inactive | Daily logs |
Live feedback while coding
- Inline flash highlight — right after a tracked edit, the affected lines briefly highlight (blue = AI, green = manual, orange = external paste), with a hover tooltip naming the source. Fades after a few seconds — this is a live cue, not a persistent blame view.
- Status bar counter — shows today's AI vs manual edit count for the currently open file. Click it to open today's log in Markdown Preview mode.
Branch tagging
Each entry is automatically tagged with the current git branch (audit.tagGitBranch, default on) — since branch names are often the task/ticket name, this gives free "what was this for" context without extra effort. Turn off if you don't use feature branches.
File create / delete / rename tracking
Not just in-file edits — new files, deleted files, and renames now get logged too, so you can see structural project changes, not just line-level ones:
## 10:05:12
- File: `backend/src/main/java/com/registay/AuthController.java`
- Event: File Created
- Mode: AI — Claude Code (guessed)
File creation attribution is a coarser guess than in-file edits: if exactly one AI extension is active AND the new file already has real content the instant it appears, it's attributed to that tool; otherwise it's logged as the developer. Deletions and renames are always attributed to the developer, since there's no content or timing signal to guess a tool from.
Multi-root workspaces (e.g. frontend + backend in one window)
If your workspace has more than one root folder (via "Add Folder to Workspace..."), each root gets its own .audit log, matched to whichever root the edited file actually belongs to — not just the first folder in the window. If entries for one part of your project seem to be missing, check whether that root has its own .audit folder rather than assuming tracking isn't working.
Supported AI tools & Host IDEs
Audit includes a modular architecture separating host IDE detection from AI agent attribution:
1. Host IDE Isolation:
- Visual Studio Code (
isVSCode()) - Google Antigravity (
isGoogleAntigravity()) - Cursor (
isCursor()) - Windsurf (
isWindsurf()) - VSCodium (
isVSCodium())
2. Isolated AI Agent Attribution:
- GitHub Copilot & Copilot Chat (
detectGitHubCopilot()) - OpenAI Codex & ChatGPT (
detectOpenAICodex()) - Claude Code CLI & Hooks (
detectClaudeCode()) - Google Gemini & Gemini Code Assist (
detectGemini()) - Cursor AI Agent (
detectCursorAI()) - Continue, Codeium, Tabnine, Cline, Aider
Service and deployment extensions (such as Railway or Vercel) are strictly blacklisted from being mistaken for AI coding agents.
The recorded identity is the tool/provider that VS Code exposes, not necessarily the underlying model. A provider can switch models without notifying extensions like Audit. Antigravity transcripts can expose the selected Gemini model, while browser chats and IDEs that do not expose a transcript cannot be identified reliably from a file edit alone.
Log integrity protection
AI agents with file-write access (Copilot's agent mode, Claude Code, etc.) can end up scanning the log file as project context and deciding to "clean up" or overwrite it — this has happened in testing. Since that kind of edit can come from a terminal command or a raw file write rather than VS Code's own file APIs, the extension can't rely on VS Code's edit events alone to catch it.
Instead, Audit watches the log folder at the filesystem level (audit.protectLogFromExternalChanges, default on). After every legitimate write, it remembers the file's exact contents. If anything — deletion, truncation, an agent rewriting the file — causes the file on disk to no longer contain everything it should, Audit restores it automatically and appends a Log Integrity Restored entry noting what happened. This works regardless of what caused the change, not just edits made through VS Code.
👥 Git-Native Offline Team Log Aggregator
There is no external server, cloud account, or database required. Audit leverages your existing Git repository:
- Team members configure their developer name or commit their logs under
.audit/teams/<developer>/<d-m-yy>.md. - When pulling the repository, each teammate's logs are synced locally.
- Run
Audit: Show Team Audit Summary(audit.showTeamSummary) or useAudit: Open Dashboardto analyze combined team performance, AI adoption rates, tool distribution, and code churn without sending a single byte outside your firewall.
🔐 Offline Cryptographic Licensing (Ed25519)
Audit is committed to 100% offline, privacy-first software:
- Free Tier: Free forever for individual developers. Full tracking, prompt capture, secret redaction, and local dashboard with zero time limits.
- Pro & Enterprise Tiers: Adds client compliance certificate export (with cryptographic SHA-256 seal), enterprise AI governance policy guardrails, and Git-native team aggregation.
- Offline Signature Verification: Keys are cryptographically verified using asymmetric Ed25519 signatures. There are zero license server pings, zero telemetry, and zero internet requests.
- Enterprise Provisioning: System administrators can generate and issue signed license keys using
scripts/generate-license.js.
How attribution works — and its honest limits
This is the part that matters most, so it's stated plainly rather than oversold:
Reliably detected:
- Whether an edit looks AI-generated (multi-line chunk appearing after a pause, rather than steady keystrokes) combined with which AI extensions are actually installed and active (Copilot, Claude Code, Cursor, Continue, Codeium, Tabnine).
- If exactly one AI extension is active, that chunk is attributed to it by name.
- If multiple AI extensions are active at once, the log honestly lists all candidates rather than guessing a single one.
Not reliably detected:
- Code pasted in from a browser tab (ChatGPT web, Gemini web, Claude web). VS Code
has no way to know which model produced clipboard content — this is logged as
External paste (source tool not detectable), never guessed as a specific model. If you want ChatGPT/Gemini attribution to be accurate, you'd need to use their IDE extensions rather than the browser, or manually tag such pastes. - Standalone IDEs that do not expose their AI activity through a VS Code-compatible extension or local transcript. Audit cannot inspect another IDE's private process or database without a dedicated source reader for that IDE.
- Manual edits are attributed to whatever name is set in settings — this assumes one developer per machine. Multi-developer accuracy requires each person running their own instance with their own name configured.
Design-change flagging
A small heuristic (src/designChange.ts) flags edits that touch exports, function/method
signatures, class/interface/struct/trait declarations, imports, API routes, or
framework annotations (Spring's @RestController, @Entity, etc.) — so Design-Change: true
lines are easy to grep out of the log separately from routine edits. Covers JavaScript/TypeScript,
Python, Java, C#, Kotlin, Go, Rust, PHP, and C++. It's pattern-based, not a real AST diff — good
enough to flag "look here," not a guarantee of completeness, and it may occasionally miss an
unusual style or (rarely) flag something routine. If your primary language isn't covered well,
add patterns to SIGNAL_PATTERNS in designChange.ts.
Storage
Everything lives in .audit/ inside your workspace, plain markdown, git-diffable.
Whether to commit it or .gitignore it is your call — some teams want it in history
for audit purposes, others treat it as personal scratch context.
Team-wide use (the "accountability dashboard")
There's no server or shared account — the dashboard only reads whatever .md files
sit in your local .audit/ folder. To get a team-wide view: commit .audit/
to your git repo instead of ignoring it. As teammates push their daily logs, pulling
those commits brings their entries into your local folder, and Audit: Open Dashboard (or Export to CSV) then shows everyone's combined activity. This is
git-native by design — no extra infrastructure to run.
Roadmap ideas (future explorations)
- Sidebar tree view in VS Code activity bar to browse/filter logs without opening files.
- Batch small manual keystrokes into one entry per save instead of per edit event.
- Direct extension API integrations where exposed by AI vendors for zero-heuristic attribution.
- Cross-workspace aggregate dashboard across multiple independent repositories.