Skip to content
| Marketplace
Sign in
Visual Studio Code>Other>Audit: Code Attribution TrackerNew to Visual Studio Code? Get it now.
Audit: Code Attribution Tracker

Audit: Code Attribution Tracker

divforge

|
8 installs
| (0) | Free
Automatically records who — developer or which AI tool — wrote or changed each line, file, and structural change in your project, stored locally as readable markdown.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

Audit — Code Attribution Tracker

Know exactly who — or which AI — wrote every line in your codebase.

Audit runs quietly in the background and automatically records every meaningful code change: who made it (you, or which specific AI tool — Copilot, Claude Code, Cursor, Codex, Gemini, and more), which file and lines, whether it was a routine edit or a structural design change, and what git branch it happened on. Nothing to turn on per-edit, nothing to remember to log — it's on the moment you install it.

  • Automatic, zero-effort logging. No manual entries, no slash commands to remember. Every real edit is captured the instant it happens.
  • Names the actual AI tool, not just "AI wrote this." Detects GitHub Copilot, Copilot Chat, Claude Code, Cursor, Continue, Codeium, Tabnine, Codex (OpenAI), and Gemini Code Assist individually via their installed extensions.
  • Single Unified Daily Log (<d-m-yy>.md) with Default Rendered Preview. Exactly one clean, authoritative log file per day in .audit/<month-yyyy>/<d-m-yy>.md. Automatically renders as an executive visual dashboard (metrics table, timeline, flagged changes, prompts) in VS Code Preview mode without needing Ctrl+Shift+V, while preserving the raw event stream in a collapsible accordion at the bottom for 100% data fidelity.
  • 100% Offline Cryptographic Licensing (Ed25519). Free forever for core single-developer use; Pro and Enterprise tiers validated offline via asymmetric digital signatures without license servers, phone-home, or telemetry.
  • Automatic Secret & Credential Redaction. Scans and sanitizes API keys (OpenAI, Anthropic, AWS, GitHub), tokens, private keys, passwords, and connection strings before writing to disk.
  • Client Compliance Certificates & Audit Reports. Generate standalone, tamper-evident HTML compliance certificates stamped with a cryptographic SHA-256 seal for clients, IP auditing, and billing verification.
  • Enterprise AI Governance Policies. Configurable path guardrails (audit.policy.disallowedAiPaths) and churn thresholds (audit.policy.maxLinesPerAiEdit) to enforce security and compliance boundaries.
  • Git-Native Offline Team Log Aggregator. Aggregate multiple team members' logs (.audit/teams/<dev>/) completely offline via Git to view team-wide AI adoption, tool breakdown, and work volume.
  • Modular Host IDE & Isolated AI Agent Detection. Completely separated detection methods for VS Code, Google Antigravity, Cursor, Windsurf, and VSCodium, with isolated identification for Copilot, Codex, Claude Code, Gemini, and Cursor AI.
  • Month-Wise Log Folders (.audit/<month-yyyy>/<d-m-yy>.md). Clean directory hierarchy storing daily logs as <d-m-yy>.md with no leading zeros, plus auto-updating _month.md rollups.
  • Continuous Midnight Rollover. Seamless cross-day tracking with forward/backward continuation pointers and active prompt context preservation across midnight boundaries.
  • Never Miss Work & Self-Healing. 1-minute persistent heartbeat (.audit/status.md), startup gap detection for offline downtime, hourly self-check auto-repair, and offline catch-up scanner.
  • Connection & Ripple Tracking (Causality Tracking). When editing File A breaks or cascades changes into File B (e.g. compiler/type errors, changed signatures), Audit automatically detects the link and records why that file was modified.
  • Dedicated Per-File Audit Logs (.audit/files/). Tracks individual revision history, authorship percentages (AI vs Developer), and tools used on a per-file basis.
  • Filters out noise automatically. Blank-line edits, comment-only changes, and test-file boilerplate don't clutter the log — only real code changes do.
  • Flags design/architecture changes — export, signature, class, and route changes get a visible flag so reviewers know where to look closer.
  • Tracks the whole file lifecycle, not just edits inside a file — creation, deletion, and renames are logged too.
  • In-Editor Audit Lens Hover. Hover over any line of code to see who wrote it, when it was edited, and what prompt produced it.
  • Live in-editor feedback — edited lines briefly flash color-coded by source (AI vs. developer vs. external paste), and a status bar counter shows today's AI-vs-manual split for the file you're in.
  • A real dashboard, not just raw markdown — filter every entry ever logged by project, category, file, or developer, with per-project stat breakdowns, ripple fix triage, session stories, and CSV export.
  • Self-healing log. If any process — including an AI agent with file-write access — deletes or overwrites the log, Audit detects it and restores it automatically.
  • Catches thrashing. Flags files edited repeatedly in quick succession — often a sign of hunting for a fix or an uncertain change.
  • Resume where you left off. Reconstructs your last editing session from history and lets you jump straight back into it.
  • Local time-travel. Lightweight snapshots at every meaningful edit, so you can recover a previous version even if you never committed it.
  • Surfaces hidden file coupling. Finds files that consistently change together even though nothing enforces it — useful for onboarding and safer refactors.
  • 100% local & private. No server, no account, no telemetry, and no AI involved in Audit's own operation — everything is plain markdown in your own workspace, fully git-diffable.

New to Audit?

Install it, open any project, and start editing — that's it. On first run you'll be asked what name to attribute your own manual edits to; after that, everything is automatic. Run Audit: Open Dashboard any time to see the full picture, or Audit: Open Today's Log (Preview Mode) to see the rich rendered visual log.

What's new in 1.1.0

1. 📋 Single Unified Daily Log (<d-m-yy>.md) & Default Rendered Preview Mode

  • No More Dual Files: Eliminated the split between raw logs and -easy.md companion files. Every day now produces exactly one authoritative log file named <d-m-yy>.md (e.g. 8-10-26.md) inside .audit/<month-yyyy>/.
  • Clean Executive Heading: Replaced "(Easy View)" with an authoritative document title: # 📋 Audit Log — <date>.
  • Automatic Markdown Preview Mode: When opening today's log (via Command Palette Audit: Open Today's Log (Preview Mode) or clicking the status bar), the log automatically opens in VS Code's rendered HTML Markdown Preview (markdown.showPreview). No need to press Ctrl+Shift+V!
  • Preserved Raw Event Stream via <details>: The full chronological raw event stream is preserved inside a collapsible <details><summary><b>📜 Raw Chronological Event Stream</b></summary>...</details> block at the bottom of the log. In Preview Mode it is collapsed by default for a clean executive view; clicking expands it, and all existing parsers (auditLens, gitSummary, teamSync) parse it with 100% fidelity.
  • Automatic Legacy Cleanup: Upon activation, Audit scans for and removes any legacy *-easy.md files while ensuring the primary daily log has the latest unified view.

2. 🔐 100% Offline Cryptographic Licensing (Ed25519)

  • Zero Internet Required: Software licensing that works completely offline in air-gapped defense, enterprise, and privacy-sensitive environments.
  • Free Tier: 100% free forever for individual developers with full automatic logging, timeline analysis, prompt capture, and local dashboards.
  • Pro & Enterprise Tiers: Unlocked via offline asymmetric cryptographic keys signed with Ed25519. Audit validates the signature and license terms (tier, licensee, seats, expiresAt) locally using an embedded public key.
  • Simple Activation: Run Audit: Activate Pro / Enterprise License Key or configure audit.licenseKey in settings.
  • Enterprise Provisioning Tool: Includes scripts/generate-license.js for IT administrators to generate signed offline license keys using a master private key.

3. 🛡️ Real-Time Secret & Credential Redaction Engine

  • Pre-Write Sanitization: Automatically scans code diffs for sensitive secrets before writing to disk, protecting your audit trails from accidental credential leakage.
  • Recognized Credential Patterns:
    • OpenAI, Anthropic, AWS, GitHub, and generic API keys
    • JWT Tokens and Bearer authentication headers
    • RSA/EC private keys (BEGIN PRIVATE KEY)
    • Database connection strings (postgres://, mongodb://, mysql://)
    • Password and secret assignments (password = "...")
  • Masking & Badging: Replaces sensitive values with masks (e.g. [REDACTED_API_KEY]) and tags log entries with 🔒 Redacted: API Key.

4. 📜 Standalone Client Compliance Certificates (HTML with SHA-256 Seal)

  • One-Click Export: Run Audit: Export Client Compliance Report (HTML) to produce a professional, self-contained executive compliance document.
  • Cryptographic Tamper-Proof Seal: Computes a SHA-256 cryptographic hash of the workspace audit logs and embeds it directly into the certificate, guaranteeing non-repudiation and proof that the log has not been altered.
  • Client & Billing Ready: Ideal for freelancers, agencies, and enterprise consultancies needing to deliver verifiable proof of human vs. AI contribution, IP provenance, and policy adherence.

5. 🏛️ Enterprise AI Governance & Boundary Policy Enforcer

  • Protected Path Guardrails (audit.policy.disallowedAiPaths): Define glob patterns (e.g. **/security/**, **/auth/**, **/*.pem, **/*.key) where AI code generation is strictly forbidden.
  • AI Churn Limits (audit.policy.maxLinesPerAiEdit): Set a maximum threshold for single AI generation events (default: 250 lines) to flag unreviewed mass-generation.
  • Non-Intrusive Violations: Violations are recorded with prominent warning badges in logs and compliance reports without interrupting developer workflow.

6. 👥 Git-Native Offline Team Log Aggregator

  • Zero Servers, Zero Cloud: Team collaboration without a central server or database. Team members commit their logs under .audit/teams/<developer>/<date>.md via Git.
  • Executive Team Summary: Run Audit: Show Team Audit Summary (audit.showTeamSummary) to aggregate team-wide metrics:
    • Combined AI vs. Developer authorship percentages
    • Tool adoption breakdown across team members
    • Most active files and architectural change flags
    • Total lines added and removed across all contributors

7. 🔍 Modular Host IDE & Isolated AI Agent Detection Engine

  • Decoupled IDE Detection: Independent detection methods for each host editor:
    • Visual Studio Code (isVSCode())
    • Google Antigravity (isGoogleAntigravity())
    • Cursor (isCursor())
    • Windsurf (isWindsurf())
    • VSCodium (isVSCodium())
  • Isolated AI Agent Detection: Dedicated attribution routines for:
    • GitHub Copilot & Copilot Chat (detectGitHubCopilot())
    • OpenAI Codex & ChatGPT (detectOpenAICodex())
    • Claude Code CLI & Hooks (detectClaudeCode())
    • Google Gemini & Gemini Code Assist (detectGemini())
    • Cursor AI Agent (detectCursorAI())
  • Service Extension Filtering: Strictly prevents cloud hosting extensions (such as Railway) from false-positive AI author attribution.
  • Workspace Project Profiles: Automatically identifies and logs Project Name, Path, IDE, Developer, Frontend framework, Backend framework, and Database in daily log headers.

Prior Releases

What's new in 1.0.4

  • Month-Wise Log Folders (.audit/<month-yyyy>/): Daily logs organized into month directories.

  • Continuous Midnight Rollover: Seamless cross-day tracking with forward/backward continuation links.

  • Never Miss Work Heartbeat: 1-minute persistent heartbeat (.audit/status.md), startup gap detection, and self-healing.

  • v1.0.3:

    • Audit Restart Tracker (audit.restartTracker): One-click reload of extension host and watchers via command or status bar menu.
    • Paginated High-Performance Dashboard: Sub-3ms load time with virtualization, 25/50/100/250/all items per page, and direct page jump.
    • Multi-Criteria Table Sorting: Sort by Date/Time, File Name, AI/Manual Mode, Lines Changed, or Risk Level with visual indicator arrows.
    • Expanded AI Telemetry: Enhanced prompt capture and real-time attribution across VS Code and Google Antigravity IDE.
  • v1.0.2: Prompt correlator optimizations, robust local storage scanning, and enhanced error diagnostic tracking.

  • v1.0.1: Dashboard UI polish and multi-root workspace stability enhancements.

  • v1.0.0 (Official Release):

    • Connection & Ripple Tracking (Causality Tracking): Diagnostic error correlation (Triggered-By: <file> (TS2345: ...)) and structural cascade links.
    • Dedicated Per-File Audit Logs (.audit/files/): Standalone file histories, authorship percentages, and revision logs.
    • In-Editor Audit Lens Hover: Hover over any line to inspect author, timestamp, branch, method context, and prompt.
    • 100% Local & Private: Zero cloud dependencies, zero telemetry, git-diffable markdown.

Prompt capture (Claude Code, Codex, Cline, Aider, Gemini CLI)

The single most requested feature: not just who changed the code, but why — what was actually asked of the AI. This turned out to be the hardest thing in the whole project, worth explaining honestly, including which sources are solid and which are best-effort guesses at an unconfirmed format.

There is no general API for this. VS Code has no way for one extension to read what a user typed into a different extension's chat panel — Copilot Chat, Cursor, and Claude Code are all fully isolated from each other by design. VS Code does have a newer "Chat Sessions" API that lets different AI agents share session context with each other, but it's a proposed API, restricted to first-party/allow-listed extensions — not available to ordinary Marketplace extensions like Audit.

Five tools have a real local source, and Audit uses a small shared core (src/promptCapture/) so each one plugs in independently, tried in confidence order. They are NOT all equally solid — here's the honest breakdown:

Tool Source Confidence Why
Claude Code UserPromptSubmit hook High Official, documented API. Run Audit: Enable Claude Code Prompt Capture (Hooks) once.
Claude Code ~/.claude/history.jsonl Low Unofficial internal storage — fallback only if the hook isn't set up.
Codex ~/.codex/sessions/**/rollout-*.jsonl Medium Verified via multiple independent sources; schema has changed across versions, parsed defensively.
Aider .aider.chat.history.md in project root Medium Officially documented, advertised, stable — but turn parsing uses Aider's established #### convention rather than a byte-for-byte confirmed sample.
Cline globalStorage/saoudrizwan.claude-dev/tasks/**/ui_messages.json Low Location is well-confirmed (community docs, Cline's own "Reconstruct Task History" command); exact field names are NOT confirmed with a real sample — parsing tries several plausible field names and returns nothing rather than guessing wrong.
Gemini CLI ~/.gemini/tmp/<hash>/chats/*.json Low Location officially documented by Google; hash algorithm and message schema not confirmed — every hash folder is scanned directly rather than computed, and field parsing is tolerant.

A bonus that applies to all five: if no AI extension appears "active" for an edit — which happens for CLI-run agents (Codex CLI, Claude Code CLI, Aider, Gemini CLI are all typically used from a terminal, not as a VS Code extension) — Audit checks whether a real prompt source still has a match before giving up. If one does, the edit gets correctly attributed even though no matching VS Code extension was ever detected as active for it.

Elimination-by-absence for ambiguous cases. When several AI extensions are active at once (e.g. Copilot Chat + Codeium), Audit can't tell them apart directly — but for any of the five tools above that are ALSO among the active candidates, absence of a matching prompt is treated as evidence against them, narrowing (or sometimes fully resolving) the guess instead of always listing every active tool. This applies to both content-edit attribution and file-creation attribution, sharing one implementation (narrowCandidatesByPromptEvidence).

Be aware of the real limits:

  • Copilot Chat, Cursor, Codeium, and others are still not covered. Their chat history is stored in less accessible, VS-Code-internal formats without a verified public structure. Copilot Chat specifically stores session JSON under workspaceStorage/<hash>/chatSessions/ — the location is confirmed, but the exact field schema isn't yet, and building a reader on an unconfirmed schema risks silently wrong output rather than no output — worth getting right before shipping.
  • Every unofficial/best-effort source here is read defensively: a missing file, malformed line, or unrecognized shape results in "no prompt found," never a thrown error. The low-confidence sources (Cline, Gemini CLI) are genuinely more likely to find nothing than to find a real match until their schemas are confirmed with a real sample — this is expected, not a bug, if you see them consistently return no prompt.
  • Matching is by project directory and timestamp proximity, not a cryptographic link — in rare cases (e.g. two edits in very quick succession) it could attach the wrong nearby prompt. Toggle off with audit.enablePromptCapture if this matters for your use case.
  • Manual Audit: Add Reason to Last Entry notes still work independently and are never overwritten by an auto-captured prompt — the dashboard shows whichever is present (🤖 for auto-captured, 📝 for manual).

Honest about its limits

Audit is upfront about what it can and can't reliably tell: it can't identify a specific AI model from code pasted in from a browser chat (ChatGPT web, Gemini web) — that's logged as "external paste, source unknown" rather than guessed. When more than one AI extension is active at once, ambiguous edits are logged as "possibly: X / Y / Z" rather than a false single guess — you can correct these after the fact with Audit: Correct Last Entry Attribution, or set a preferred tool in settings if you only use one. Full details further down this page.


Language support

Core tracking — edits, attribution, file create/delete/rename, branch tagging, the dashboard — works on any file, any language, since it operates on VS Code's document/file events rather than parsing syntax. Design-change flagging (the one part that's language-aware) currently covers JavaScript/TypeScript, Python, Java, C#, Kotlin, Go, Rust, PHP, and C++ — see below for details and how to extend it.


What it records

For each meaningful edit, a structured entry is appended to .audit/<month-yyyy>/<d-m-yy>.md (e.g. .audit/october-2026/5-10-26.md):

## 14:32:10
- File: `src/services/orderService.ts`
- Project: src
- Lines: 45-62
- Mode: AI — GitHub Copilot (Vaibhav)
- Developer: Vaibhav
- Change: Code Modified (+18 / -4)
- Context: 🎯 `processOrder`
- Triggered-By: `src/types/order.ts` (TS2345: Property 'total' is missing in type 'OrderInput')
- Methods: Added validateCart; Modified processOrder
- Branch: `feat/checkout-flow`
- Design-Change: true (function signature changed)
- Prompt: "refactor processOrder to compute total with discounts"

Key Fields & Keywords Explained:

  • ## HH:MM:SS — Exact local wall-clock timestamp of the change event.
  • - File: — Workspace-relative path of the affected file.
  • - Project: — Top-level root directory containing the file (e.g. src, frontend, backend).
  • - Lines: — Line range modified or inserted (e.g. 45-62 or 12).
  • - Mode: — Attribution source: AI — <Tool> (<Developer>), Developer — <Developer>, External paste (source tool not detectable), or Mode: Unknown (Audit was off).
  • - Developer: — Active developer identity configured in settings.
  • - Change: — Operation type and exact delta count (e.g. Code Modified (+18 / -4), Code Added (+14 lines), File Created, File Deleted, File Renamed).
  • - Context: — Syntactic enclosing scope symbol detected in real time (e.g. 🎯 processOrder).
  • - Triggered-By: — Ripple causality metadata indicating which file triggered this edit and why (compiler diagnostic errors or structural cascades).
  • - Methods: — Functions, methods, or classes added or modified in this change.
  • - Branch: — Git branch active at the moment of the edit (e.g. feat/checkout-flow).
  • - Design-Change: — true if structural architecture boundaries were modified (exports, interfaces, classes, routes).
  • - Prompt: — The exact prompt query captured from local AI sessions (Copilot, Claude Code, Codex, Antigravity, Gemini CLI, Aider, Cline).

📁 Month-Wise Log Organization & Monthly Rollup (_month.md)

Audit automatically organizes logs into month-based subdirectories rather than a flat .audit folder:

.audit/
  status.md                     <- 1-minute persistent heartbeat
  self-check.log                <- Hourly health audit & auto-repair report
  august-2026/
    1-8-26.md                   <- Raw daily log (no leading zeros)
    1-8-26-easy.md              <- Executive Easy View companion
    31-8-26.md
    _month.md                   <- Auto-updating month rollup
  september-2026/
    1-9-26.md
    1-9-26-easy.md
    _month.md
  october-2026/
    5-10-26.md
    5-10-26-easy.md
    _month.md
  files/                        <- Per-file standalone revision histories

Key Principles:

  1. Lowercase Month & Year: Folders are named <month-yyyy> (e.g. august-2026, october-2026).
  2. Day-Month-Year File Naming: Daily logs are named <d-m-yy>.md with no leading zeros (e.g. 1-8-26.md, 5-10-26.md, 31-8-26.md).
  3. Seamless Flat Log Migration: Any older flat files in .audit/ (such as 2026-10-05.md) are automatically detected and safely moved into their proper month folder upon extension activation.
  4. Monthly Rollup (_month.md): Automatically aggregates activity across all days in that month:
    • Total edits and active coding days
    • Net lines added and removed (+/-)
    • AI-assisted vs. manual developer edit percentages
    • Tool breakdown (Copilot, Claude Code, Codex, Cursor, etc.)
    • High-churn files and structural design changes (⚠️)
    • Direct clickable markdown links to each day's raw log and Easy View companion

📑 Daily Easy View Companion (<d-m-yy>-easy.md)

Alongside every raw daily log, Audit automatically generates and updates an executive Easy View file (<d-m-yy>-easy.md). Designed for fast reading by developers, code reviewers, and engineering leads, it condenses hundreds of raw edit events into a human-friendly narrative.

8 Standardized Sections:

  1. Title & Summary Header: Date, total edits, active time span, AI vs. Developer breakdown, and developer name.
  2. Today at a Glance: Structured high-level table of metrics, lines delta, top files, and tools.
  3. Needs a Look: Highlights items that warrant code review:
    • ⚠️ Structural Design Changes (modified interfaces, signatures, or exports)
    • 📦 High Code Volume (large bursts > 50 lines)
    • 🔁 Thrashing (repeated edits to the same file in quick succession)
  4. Timeline (4-Quarter Day Breakdown):
    • 🌅 Morning (06:00 — 12:00)
    • ☀️ Afternoon (12:00 — 18:00)
    • 🌆 Evening (18:00 — 00:00)
    • 🌙 Night (00:00 — 06:00)
    • Intelligent Merging: Duplicate edits to the same file within 60 seconds are consolidated into a single entry; bursts within 20 minutes are grouped.
  5. Prompts (Prompt-to-Code Mapping): Numbered sequentially (P1, P2, ...). Each prompt features an interactive collapsible <details> block with the exact prompt text and the specific files/lines modified.
  6. Audit Health: Parity verification confirming that 100% of raw events from <d-m-yy>.md are preserved in Easy View.
  7. Legend: Fast reference for all status icons (🤖 AI, 👤 Developer, 📦 Large Edit, ⚠️ Design, 🔁 Thrash, 🔗 Ripple).
  8. Continuation Pointers: Seamless links connecting to previous or next day logs.

Open Easy View anytime with Audit: Open Today's Easy View (Executive Summary) (audit.openEasyView).


🔄 Continuous Midnight Rollover & Prompt Continuity

Coding past midnight? Audit automatically handles the 00:00 date boundary without missing an edit:

  1. Automatic File Transition: At midnight, the previous day's log is closed and the new day's log is created in the appropriate month folder.
  2. Cross-File Navigation Links:
    • Appends a forward pointer to the previous log:
      ➡️ CONTINUE WITH NEW LOG FILE: 6-10-26.md (or cross-month relative path ../november-2026/1-11-26.md).
    • Prepends a backward pointer to the new day's log:
      ⬅️ CONTINUED FROM PREVIOUS LOG FILE: 5-10-26.md (or cross-month relative path ../october-2026/31-10-26.md).
  3. Cross-Midnight Prompt Continuity: If you submit an AI prompt at 23:58 and the AI's file edits complete at 00:02, the active prompt query is preserved and correctly attributed across the midnight boundary.

🛡️ Never Miss Work: Heartbeat, Self-Healing & Offline Catch-Up

Audit operates as an uninterrupted local flight recorder:

1. 1-Minute Heartbeat (.audit/status.md)

Every 60 seconds, Audit updates a persistent status file recording:

  • Status: 🟢 Active
  • Process ID (PID): Current VS Code extension host process
  • Last Active Time: Wall-clock timestamp
  • Workspace: Absolute path
  • Active File: Currently open document
  • Last Log Write: Path and timestamp of the most recent log update
  • Last Self-Check: Timestamp and result of the automated health check
  • Audit Version: Current extension version (1.0.4)

2. Startup Downtime Gap Detection

When VS Code starts, Audit reads the previous heartbeat in status.md. If the editor was closed or Audit was offline for more than 5 minutes, it explicitly records the downtime:

## 09:15:00
- Note: ⏱️ Audit was offline from 2026-10-06 23:10:00 to 2026-10-07 09:15:00 (605 min)

3. Hourly Self-Check & Auto-Repair

Every 60 minutes, an automated background check verifies:

  • Month directory and file hierarchy
  • Today's raw log (<d-m-yy>.md)
  • Today's Easy View companion (<d-m-yy>-easy.md)
  • Heartbeat file (status.md)
  • File watchers and integrity monitors
    If any file is missing, damaged, or desynchronized, Audit automatically repairs/regenerates it and appends a report to .audit/self-check.log.

4. Offline Downtime Catch-Up Scanner

Files modified while VS Code was closed (e.g. via terminal git pulls, external scripts, or other editors) are discovered when Audit starts up and logged as:

## 09:15:02
- File: `src/utils/config.ts`
- Project: src
- Lines: 1-25
- Mode: Unknown (Audit was off)
- Developer: Vaibhav
- Change: Code Modified (+25 / -0)
- Note: File was modified while Audit was inactive

🔗 Connection & Ripple Tracking (Causality Tracking)

One of the most frustrating things in team and AI-assisted development is seeing that a file was modified without knowing why. For example:

  • A developer or AI updates src/types/order.ts.
  • Suddenly, src/services/orderService.ts has a type error or broken import.
  • Someone opens src/services/orderService.ts and patches it to fix the error.

Without causality tracking, the audit log only says orderService.ts was modified. With Audit 1.0.0, Audit correlates the cause and effect automatically:

How it detects connections:

  1. Live Diagnostics Listening: Audit monitors VS Code's diagnostic pipeline (onDidChangeDiagnostics). When an edit to File A causes errors in File B, and File B is subsequently edited within seconds/minutes to resolve that error, Audit records:
    - Triggered-By: `src/types/order.ts` (Fixed compiler diagnostic: Property 'total' is missing)
    
  2. Structural Design Cascades: When File A has a structural design change (export, class, or interface change), any dependent file edited shortly after that references File A is automatically linked as a cascade fix.
  3. Shared Agent Cascades: Multi-file patches produced by an AI assistant in response to the same prompt share causation metadata.
  4. Manual Causality Linker: You can run Audit: Link Last Change to Triggering File (audit.linkLastEntryToFile) at any time from the Command Palette or Quick Action Menu to pick any recent file and attach a remark.

In the Dashboard:

The dashboard displays a visual purple badge under the Change column:

Code Modified (+18 / -4)
🔗 Caused by src/types/order.ts
📌 TS2345: Property 'total' is missing in type 'OrderInput'

You can click the 🔗 Ripple Fixes filter button in the dashboard to instantly filter the entire table to only show edits that were triggered by other files.


📄 Dedicated Per-File Audit Logs (.audit/files/)

Need to check the exact history, AI ratio, or developer contributions for a specific file? You no longer have to dig through weeks of daily logs.

Audit automatically maintains a dedicated markdown file for every tracked file under .audit/files/<path-to-file>.md.

Example: .audit/files/src/services/orderService.ts.md

# 📄 File Audit Log: `src/services/orderService.ts`

## 📊 Authorship & Changes Summary
- **Total Tracked Edits:** 8
- **AI-Assisted Edits:** 6 (75%)
- **Manual Developer Edits:** 2 (25%)
- **AI Tools Used:** GitHub Copilot (4), Claude Code (2)
- **Developer(s):** Vaibhav
- **Design Changes (⚠️):** 2
- **Thrashing Incidents (🔁):** 0
- **Linked Ripple Edits (🔗):** 2 (triggered by changes in: `src/types/order.ts`)
- **Last Modified:** 2026-09-28 15:20:14 (AI — GitHub Copilot)

---

## 📜 Revision History (Most Recent First)

### 2026-09-28 15:20:14 · Lines 45-62
- **Author:** AI — GitHub Copilot (Vaibhav)
- **Developer:** Vaibhav
- **Context:** 🎯 `processOrder`
- **Change:** Code Modified (+18 / -4)
- **Triggered By:** 🔗 `src/types/order.ts` (Property 'total' missing)
- **Notice:** ⚠️ *Structural Design Change*
- **Methods:** Modified processOrder
- **Prompt:** "refactor processOrder to compute total with discounts"

### 2026-09-28 11:04:02 · Lines 12-25
- **Author:** Developer — Vaibhav
- **Developer:** Vaibhav
- **Change:** Code Added (+14 lines)
- **Context:** 🎯 `validateCart`

Accessing File Logs:

  • Run Audit: Open File Audit Log for Active File (audit.openFileLog) from the Command Palette or Quick Action Menu (Ctrl+Shift+P).
  • Click the 📜 History button in the File column of the Audit Dashboard.
  • Re-sync or regenerate all file logs at any time with Audit: Sync / Rebuild All File Audit Logs (audit.syncFileLogs).

👁️ In-Editor Audit Lens Hover

Audit includes an in-editor hover provider: hover over any line in your code to see:

  • Who wrote or edited it (e.g. AI — GitHub Copilot or Developer — Vaibhav).
  • Exact timestamp and Git branch.
  • Enclosing method context (e.g. 🎯 processOrder).
  • The actual AI prompt used to generate that line.

Toggle on or off at any time using Audit: Toggle Audit Lens Hover (audit.toggleAuditLens).


Setup

npm install
npm run compile

Then press F5 in VS Code to launch an Extension Development Host with it loaded, or package it with vsce package and install the .vsix normally.

On first run it will ask for the name to attribute your manual edits to.

Commands

Access all commands via the Command Palette (Ctrl+Shift+P / Cmd+Shift+P) by typing Audit:

Command Command ID Description
Audit: Show Quick Action Menu audit.showQuickMenu Instant popup menu in status bar with all key actions
Audit: Open Today's Log (Preview Mode) audit.openLog Opens today's <d-m-yy>.md directly in rendered Markdown Preview mode
Audit: Open Dashboard audit.openDashboard High-performance interactive dashboard with filters and sorting
Audit: Export Client Compliance Report (HTML) audit.exportComplianceReport Exports tamper-evident compliance certificate with SHA-256 seal
Audit: Show Team Audit Summary audit.showTeamSummary Aggregates Git-committed team logs (.audit/teams/) offline
Audit: Activate Pro / Enterprise License Key audit.activateLicense Activates offline-verified cryptographic Ed25519 license key
Audit: Restart Tracker (Reload Window) audit.restartTracker Instantly reloads extension host and restarts file watchers
Audit: Open File Audit Log for Active File audit.openFileLog View dedicated standalone revision history for active file
Audit: Sync / Rebuild All File Audit Logs audit.syncFileLogs Rebuilds all .audit/files/*.md histories from logs
Audit: Link Last Change to Triggering File audit.linkLastEntryToFile Attach a manual causality ripple link to a causal file
Audit: Toggle Audit Lens Hover audit.toggleAuditLens Enable/disable in-editor attribution hover cards
Audit: Copy Standup / PR Summary to Clipboard audit.copyStandupSummary Formatted markdown rollup for daily standups or PR templates
Audit: Add Today's Summary to Commit Message audit.addSummaryToCommit Appends one-line stats to Source Control commit box
Audit: Add Reason to Last Entry audit.addReasonToLastEntry Attach an explanation note or ticket ID to the last edit
Audit: Correct Last Entry Attribution audit.correctLastEntry Fix a misattributed entry after the fact
Audit: View Work Sessions (Story Mode) audit.viewSessionStories Browse continuous work sessions grouped into stories
Audit: Resume Last Session audit.resumeLastSession Jump straight back to files from your last editing session
Audit: Restore Previous Version audit.restorePreviousVersion Pick a past snapshot of the file, review diff, restore safely
Audit: Show Related Files audit.showRelatedFiles Surface hidden co-change file relationships
Audit: Export Log to CSV audit.exportCsv Export all logged entries to CSV for reporting or spreadsheets
Audit: Open Log Folder audit.openLogFolder Reveal .audit folder in OS file explorer
Audit: Toggle Tracking On/Off audit.toggle Temporarily pause or resume tracking
Audit: Set Developer Name audit.setDeveloperName Configure your manual attribution name
Audit: Enable Claude Code Prompt Capture (Hooks) audit.enableClaudeHookCapture One-time setup for Claude Code CLI hooks
Audit: Backfill Missing Prompts & Media audit.backfillPrompts Retroactively link prompts from local assistant session files

⚙️ Configuration & Settings

Configure Audit behavior via VS Code Settings (Ctrl+, or Settings -> Extensions -> Audit):

Setting Key Type Default Description
audit.enabled boolean true Enable or disable automatic change tracking
audit.developerName string "" Name to attribute manual edits to (prompted on first run)
audit.logFolder string ".audit" Workspace folder path where markdown logs are stored
audit.licenseKey string "" Offline-verified Audit Pro or Enterprise License Key
audit.policy.disallowedAiPaths array ["**/security/**", "**/auth/**", "**/*.pem", "**/*.key"] Prohibited file paths for AI generation (Enterprise Policy)
audit.policy.maxLinesPerAiEdit number 250 Maximum lines allowed in a single AI edit before violation flag
audit.preferredAITool string "" Pin attribution to a single AI tool if only one is used
audit.tagGitBranch boolean true Tag each log entry with the current Git branch name
audit.enableAuditLens boolean true Show in-editor hover cards attributing lines of code
audit.protectLogFromExternalChanges boolean true Watch logs for tampering or deletion and auto-restore
audit.enableThrashDetection boolean true Flag rapid repeated edits to the same file
audit.thrashWindowMinutes number 10 Time window (minutes) used to detect thrashing
audit.thrashThreshold number 3 Number of edits within window to trigger thrash warning
audit.enableSnapshots boolean true Keep lightweight file snapshots at each tracked edit
audit.maxSnapshotsPerFile number 20 Maximum number of snapshots preserved per file
audit.enablePromptCapture boolean true Auto-capture prompt queries from local assistant sessions
audit.promptLookbackMinutes number 10 How far back to look for matching prompts before an edit
audit.enableAIBurstContinuation boolean true Attribute rapid follow-up edits to the active AI burst
audit.aiBurstWindowSeconds number 3 Time window (seconds) for AI burst continuation
audit.minLinesForAIHeuristic number 2 Minimum lines in an edit to trigger AI shape heuristic
audit.trackSmallManualEdits boolean true Log small manual edits after a typing pause
audit.ignoreBlankLineChanges boolean true Skip logging changes that only add/remove blank lines
audit.ignoreCommentOnlyChanges boolean true Skip logging edits where every modified line is a comment
audit.excludeDesignChangeForTestFiles boolean true Skip Design-Change flag for .test. / .spec. files

🏷️ Iconography & Keyword Reference

Quick reference for all icons and keywords used across daily logs and the Dashboard:

Icon / Keyword Meaning Where Used
🤖 AI — <Tool> Code change generated by an AI assistant Logs, Dashboard, Lens
👤 Developer — <Name> Code change typed manually by the developer Logs, Dashboard, Lens
📦 High Delta (+N / -N) Large code volume edit (> 50 lines modified) Daily Logs, Dashboard
⚠️ Design-Change: true Structural architectural edit (signatures, classes, exports) Daily Logs, Dashboard
🔁 Thrashing: true 3+ edits to the same file within 10 minutes Daily Logs, Dashboard
🔗 Triggered-By: <file> Ripple causality link from a compiler error or design change Daily Logs, Dashboard
🎯 Context: <symbol> Enclosing function, method, class, or route name Daily Logs, Lens
🔒 [REDACTED_API_KEY] Sanitized API key or credential automatically masked Daily Logs, Reports
🛡️ Violation: <Policy> AI governance boundary rule exceeded Daily Logs, Reports
➡️ CONTINUE WITH NEW LOG FILE Forward pointer at midnight rollover (00:00) Daily logs
⬅️ CONTINUED FROM PREVIOUS LOG FILE Backward pointer at midnight rollover (00:00) Daily logs
🟢 Status: Active Extension heartbeat active and monitoring .audit/status.md
⏱️ Audit was offline Startup downtime gap detection (> 5 minutes) Daily logs
❓ Mode: Unknown (Audit was off) Discovered changes made while Audit was inactive Daily logs

Live feedback while coding

  • Inline flash highlight — right after a tracked edit, the affected lines briefly highlight (blue = AI, green = manual, orange = external paste), with a hover tooltip naming the source. Fades after a few seconds — this is a live cue, not a persistent blame view.
  • Status bar counter — shows today's AI vs manual edit count for the currently open file. Click it to open today's log in Markdown Preview mode.

Branch tagging

Each entry is automatically tagged with the current git branch (audit.tagGitBranch, default on) — since branch names are often the task/ticket name, this gives free "what was this for" context without extra effort. Turn off if you don't use feature branches.

File create / delete / rename tracking

Not just in-file edits — new files, deleted files, and renames now get logged too, so you can see structural project changes, not just line-level ones:

## 10:05:12
- File: `backend/src/main/java/com/registay/AuthController.java`
- Event: File Created
- Mode: AI — Claude Code (guessed)

File creation attribution is a coarser guess than in-file edits: if exactly one AI extension is active AND the new file already has real content the instant it appears, it's attributed to that tool; otherwise it's logged as the developer. Deletions and renames are always attributed to the developer, since there's no content or timing signal to guess a tool from.

Multi-root workspaces (e.g. frontend + backend in one window)

If your workspace has more than one root folder (via "Add Folder to Workspace..."), each root gets its own .audit log, matched to whichever root the edited file actually belongs to — not just the first folder in the window. If entries for one part of your project seem to be missing, check whether that root has its own .audit folder rather than assuming tracking isn't working.

Supported AI tools & Host IDEs

Audit includes a modular architecture separating host IDE detection from AI agent attribution:

1. Host IDE Isolation:

  • Visual Studio Code (isVSCode())
  • Google Antigravity (isGoogleAntigravity())
  • Cursor (isCursor())
  • Windsurf (isWindsurf())
  • VSCodium (isVSCodium())

2. Isolated AI Agent Attribution:

  • GitHub Copilot & Copilot Chat (detectGitHubCopilot())
  • OpenAI Codex & ChatGPT (detectOpenAICodex())
  • Claude Code CLI & Hooks (detectClaudeCode())
  • Google Gemini & Gemini Code Assist (detectGemini())
  • Cursor AI Agent (detectCursorAI())
  • Continue, Codeium, Tabnine, Cline, Aider

Service and deployment extensions (such as Railway or Vercel) are strictly blacklisted from being mistaken for AI coding agents.

The recorded identity is the tool/provider that VS Code exposes, not necessarily the underlying model. A provider can switch models without notifying extensions like Audit. Antigravity transcripts can expose the selected Gemini model, while browser chats and IDEs that do not expose a transcript cannot be identified reliably from a file edit alone.

Log integrity protection

AI agents with file-write access (Copilot's agent mode, Claude Code, etc.) can end up scanning the log file as project context and deciding to "clean up" or overwrite it — this has happened in testing. Since that kind of edit can come from a terminal command or a raw file write rather than VS Code's own file APIs, the extension can't rely on VS Code's edit events alone to catch it.

Instead, Audit watches the log folder at the filesystem level (audit.protectLogFromExternalChanges, default on). After every legitimate write, it remembers the file's exact contents. If anything — deletion, truncation, an agent rewriting the file — causes the file on disk to no longer contain everything it should, Audit restores it automatically and appends a Log Integrity Restored entry noting what happened. This works regardless of what caused the change, not just edits made through VS Code.

👥 Git-Native Offline Team Log Aggregator

There is no external server, cloud account, or database required. Audit leverages your existing Git repository:

  1. Team members configure their developer name or commit their logs under .audit/teams/<developer>/<d-m-yy>.md.
  2. When pulling the repository, each teammate's logs are synced locally.
  3. Run Audit: Show Team Audit Summary (audit.showTeamSummary) or use Audit: Open Dashboard to analyze combined team performance, AI adoption rates, tool distribution, and code churn without sending a single byte outside your firewall.

🔐 Offline Cryptographic Licensing (Ed25519)

Audit is committed to 100% offline, privacy-first software:

  • Free Tier: Free forever for individual developers. Full tracking, prompt capture, secret redaction, and local dashboard with zero time limits.
  • Pro & Enterprise Tiers: Adds client compliance certificate export (with cryptographic SHA-256 seal), enterprise AI governance policy guardrails, and Git-native team aggregation.
  • Offline Signature Verification: Keys are cryptographically verified using asymmetric Ed25519 signatures. There are zero license server pings, zero telemetry, and zero internet requests.
  • Enterprise Provisioning: System administrators can generate and issue signed license keys using scripts/generate-license.js.

How attribution works — and its honest limits

This is the part that matters most, so it's stated plainly rather than oversold:

Reliably detected:

  • Whether an edit looks AI-generated (multi-line chunk appearing after a pause, rather than steady keystrokes) combined with which AI extensions are actually installed and active (Copilot, Claude Code, Cursor, Continue, Codeium, Tabnine).
  • If exactly one AI extension is active, that chunk is attributed to it by name.
  • If multiple AI extensions are active at once, the log honestly lists all candidates rather than guessing a single one.

Not reliably detected:

  • Code pasted in from a browser tab (ChatGPT web, Gemini web, Claude web). VS Code has no way to know which model produced clipboard content — this is logged as External paste (source tool not detectable), never guessed as a specific model. If you want ChatGPT/Gemini attribution to be accurate, you'd need to use their IDE extensions rather than the browser, or manually tag such pastes.
  • Standalone IDEs that do not expose their AI activity through a VS Code-compatible extension or local transcript. Audit cannot inspect another IDE's private process or database without a dedicated source reader for that IDE.
  • Manual edits are attributed to whatever name is set in settings — this assumes one developer per machine. Multi-developer accuracy requires each person running their own instance with their own name configured.

Design-change flagging

A small heuristic (src/designChange.ts) flags edits that touch exports, function/method signatures, class/interface/struct/trait declarations, imports, API routes, or framework annotations (Spring's @RestController, @Entity, etc.) — so Design-Change: true lines are easy to grep out of the log separately from routine edits. Covers JavaScript/TypeScript, Python, Java, C#, Kotlin, Go, Rust, PHP, and C++. It's pattern-based, not a real AST diff — good enough to flag "look here," not a guarantee of completeness, and it may occasionally miss an unusual style or (rarely) flag something routine. If your primary language isn't covered well, add patterns to SIGNAL_PATTERNS in designChange.ts.

Storage

Everything lives in .audit/ inside your workspace, plain markdown, git-diffable. Whether to commit it or .gitignore it is your call — some teams want it in history for audit purposes, others treat it as personal scratch context.

Team-wide use (the "accountability dashboard")

There's no server or shared account — the dashboard only reads whatever .md files sit in your local .audit/ folder. To get a team-wide view: commit .audit/ to your git repo instead of ignoring it. As teammates push their daily logs, pulling those commits brings their entries into your local folder, and Audit: Open Dashboard (or Export to CSV) then shows everyone's combined activity. This is git-native by design — no extra infrastructure to run.

Roadmap ideas (future explorations)

  • Sidebar tree view in VS Code activity bar to browse/filter logs without opening files.
  • Batch small manual keystrokes into one entry per save instead of per edit event.
  • Direct extension API integrations where exposed by AI vendors for zero-heuristic attribution.
  • Cross-workspace aggregate dashboard across multiple independent repositories.
  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft