
Product
Microsoft Teams Notifications Are Now Available in Socket
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.
@mesadev/agentblame
Advanced tools
Know what the AI wrote. Focus your code reviews where it matters.
Track AI-generated vs human-written code in your Git history. Works with Cursor, Claude Code, and OpenCode.
# Install Bun if you haven't already
curl -fsSL https://bun.sh/install | bash
Run this once on your machine to create the local database:
bunx @mesadev/agentblame@latest setup
In each git repository you want to track:
bunx @mesadev/agentblame@latest init
This sets up everything automatically:
Important: Restart your editor after running init.
Make AI edits, commit, then view attribution:
bunx @mesadev/agentblame@latest blame src/auth.ts
Example output:
src/auth.ts
──────────────────────────────────────────────────────────────────────
Prompts:
[P1] Cursor (gpt-5.2-codex)
"Add a new file hello_world.py in python and add two print st..."
Tools: edit: 1
──────────────────────────────────────────────────────────────────────
7bdf773 Murali Varad 2026-02-03 │ P1 │ 1 │ print("Hello, World1")
7bdf773 Murali Varad 2026-02-03 │ P1 │ 2 │ print("Hello, World2")
──────────────────────────────────────────────────────────────────────
████████████████████████████████████████
AI: 2 lines (100%) │ Human: 0 lines (0%)
| Command | Description |
|---|---|
bunx @mesadev/agentblame@latest setup | One-time machine setup (creates ~/.agentblame database) |
bunx @mesadev/agentblame@latest init | Set up hooks and GitHub Actions workflow for a repo |
bunx @mesadev/agentblame@latest clean | Remove hooks from current repo |
bunx @mesadev/agentblame@latest blame <file> | Show AI attribution for a file |
bunx @mesadev/agentblame@latest sync | Transfer notes after squash/rebase |
bunx @mesadev/agentblame@latest config | Show/set configuration |
bunx @mesadev/agentblame@latest debug | Show detailed debug info |
# Show current config
bunx @mesadev/agentblame@latest config
# Disable prompt content storage (enabled by default)
bunx @mesadev/agentblame@latest config storePromptContent false
┌─────────────────┐ ┌─────────────────┐ ┌─────────────────┐
│ Cursor/Claude │────▶│ Git Hooks │────▶│ Database │
│ Code edits │ │ capture edits │ │ stores pending │
└─────────────────┘ └─────────────────┘ └─────────────────┘
│
▼
┌─────────────────┐ ┌─────────────────┐ ┌─────────────────┐
│ CLI/Extension │◀────│ Git Notes │◀────│ Git Commit │
│ show markers │ │ store metadata │ │ triggers match │
└─────────────────┘ └─────────────────┘ └─────────────────┘
| Problem | Solution |
|---|---|
| Database not found | Run bunx @mesadev/agentblame@latest setup once on your machine |
| Hooks not capturing | Restart your editor; run bunx @mesadev/agentblame@latest debug to check status |
| Notes not on GitHub | Run git push origin refs/notes/agentblame |
| Squash merge lost attribution | Ensure workflow is committed; run bunx @mesadev/agentblame@latest sync locally |
| Bun not found | Install Bun: curl -fsSL https://bun.sh/install | bash |
See AI attribution directly on GitHub PRs:
For full documentation, contributing guidelines, and source code, visit the GitHub repository.
Apache 2.0
FAQs
CLI to track AI-generated vs human-written code
The npm package @mesadev/agentblame receives a total of 24 weekly downloads. As such, @mesadev/agentblame popularity was classified as not popular.
We found that @mesadev/agentblame demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.

Security News
Socket CTO Ahmad Nassri joins AppSec leaders at Black Hat to discuss active malware, package manager risks, and software supply chain defense.