Skip to content

Instantly share code, notes, and snippets.

@tohuw
Created July 31, 2026 01:20
Show Gist options
  • Select an option

  • Save tohuw/5a59750e647740fa082e7c480fc2059d to your computer and use it in GitHub Desktop.

Select an option

Save tohuw/5a59750e647740fa082e7c480fc2059d to your computer and use it in GitHub Desktop.
Prompt for any coding agent: enforce Model:/Host: provenance trailers on AI-agent git commits

Prompt: record AI-agent provenance on every git commit

Copy everything below into your coding agent (Claude Code, Codex, or any other) on the machine you want covered.


Set up this machine so that every git commit made by an AI agent automatically records which model was active and which machine it was made from, as commit-message trailers:

Model: <model id, or the agent's name if the model can't be determined>
Host: <this machine's name>

Motivation: when an agent-authored change causes a problem (for example, leaking information it shouldn't have), the git history must show which model, on which machine, produced each commit.

Design requirements

  1. Enforce at the git layer, not the agent layer. Use a prepare-commit-msg hook installed through a global core.hooksPath directory. Do not rely on agent memory, instructions files, or skills — the mechanism must work even when the agent forgets, and for agents that were never told about it.
  2. Detect the agent from the commit-time environment. Identify which agent is running from environment variables present in its subprocesses (for example, Claude Code sets CLAUDECODE=1 and CLAUDE_CODE_SESSION_ID; detect Codex and others by whatever they expose — inspect your own environment to find out). Commits with no agent detected — i.e. human commits — must pass through completely untouched.
  3. Record the model that is active now, not at session start. If the agent exposes no model identifier in the environment, find a live source — e.g. Claude Code's current model is readable as the newest "model" field in the session's own transcript (locatable via CLAUDE_CODE_SESSION_ID under ~/.claude/projects/), which stays correct after a mid-session model switch. If no source exists for the detected agent, fall back to <agent name> (model unrecorded) — never silently omit the trailer.
  4. Break nothing. A global core.hooksPath replaces every repo's .git/hooks lookup, so the global directory must delegate to the repo's own hook of the same name for all standard hook names (husky-style repos must keep working). Additionally, scan the user's project directories for repos that set a local core.hooksPath — those bypass the global directory entirely and need a copy of the hook in their configured hooks directory.
  5. Idempotent and amend-safe. Re-committing or --amend must not duplicate trailers (git interpret-trailers --if-exists doNothing is a good fit).
  6. Portable. Use the platform's native way to get the machine name and the appropriate script form for the OS (POSIX sh on macOS/Linux; on Windows account for how git-for-windows executes hooks).

Acceptance tests (run them in a scratch repo, then show the results)

  • A commit made by you (the agent) carries correct Model: and Host: trailers.
  • A commit made with the agent-identifying environment variables stripped carries no trailers.
  • A repo-local hook (e.g. a pre-commit echo) still executes after the global hooksPath is active.
  • git commit --amend does not duplicate trailers.

Report what you installed, where, which repos needed local copies, and anything you couldn't cover (e.g. an agent whose model can't be determined).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment