← All work

whodunit

Go

whodunit adds a plain `AI-Attribution` trailer to commits and can fill it from local agent transcripts. It answers which agent touched a commit, at what confidence level, without reading prompts, keystrokes or file contents.

GoSQLiteGit hooksGrafana
At a glance
  • Commit-level `AI-Attribution` trailer with versioned semantics.
  • Local transcript ingest; no prompts, keystrokes or file contents read.
  • Homebrew, Scoop, `go install`, local reports and optional DevLake sync.

Problem

Engineering leaders are being asked what AI is actually doing to their delivery, and the honest answer is usually a guess. The tempting instrument, watching what developers type, is both invasive and a poor proxy. The name invites the surveillance joke, and the README answers it directly: the suspect is the commit, not the developer. It answers which agent touched this code, not who wrote this line.

Approach

Read the transcripts the agents already write for their own purposes, and stamp a plain git trailer on the commit. Nothing reads prompts, keystrokes, or file contents. Several secondary decisions follow the same discipline. Matching is by content hash rather than commit SHA, because a commit does not exist yet when the observation is recorded and may later be amended, rebased or squashed. The version field comes first in the trailer, because a ratio is well-formed under any definition and a migration can rewrite a column while nothing can rewrite pushed history. Missing fields are stored absent rather than zero, because a zero on a cost panel reads as 'this agent is free'.

Solution

A Cobra CLI with 21 subcommands that installs prepare-commit-msg, commit-msg and pre-push hooks, chaining onto existing hooks rather than clobbering them. Three adapters (Claude Code, Codex, Antigravity) reach the strongest confidence level, meaning the agent's exact text survived into the commit. A local SQLite journal lives under ~/.whodunit with owner-only permissions. dun check --base is the CI gate, because local hooks are advisory and --no-verify bypasses them. Seven Grafana dashboards read the synced data through Apache DevLake.

Impact

whodunit gives engineering leaders an evidence trail for AI-assisted work without turning measurement into surveillance. A commit with evidence can be audited later; a commit without evidence stays `undetermined` rather than being misread as no AI.