
Zerostel
io.github.zerostelv0.1.2更新于 Oct 5, 2026
Checkpoints, timeline and rewind for AI coding agents. Local, no telemetry.
概览
在本地记录 AI 编程代理的每一步,并让助手读取时间线、在出错后回滚文件。
- 功能
- Zerostel 是面向编程代理的本地飞行记录器:在每次可能改动文件的工具调用(包括 shell 命令)前后对项目做快照,并保存提示词、命令、文件变更、耗时和 token 数量的时间线。通过 MCP,代理可以读取该时间线并按需回滚。它还支持自定义护栏规则,用于阻止某次工具调用或要求先确认,并生成带哈希链的日志和可分享的单页报告。
- 适用场景
- 当你使用会编辑文件或执行 shell 命令的编程代理,希望在破坏性操作后能恢复、逐步查看改动记录,并在多个代理之间获得一致行为时,适合安装。若希望助手自行查看会话历史或按请求撤销某一步,也适用。
- 运行要求
- 以 stdio 方式作为本地进程运行,通过 npm 安装(npx zerostel install 或全局安装)。需要 git 和 Node.js 20 或更高版本;Windows、macOS 和 Linux 也提供内置 Node 的独立可执行文件。与代理集成依赖各代理的 hooks 或插件机制,需先完成配置。未声明账号、API 密钥或环境变量。
安装
在 SourceWeft 中
- 打开 控制台中的 Zerostel,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
Rewind any AI agent to point zero.
Zero trust for AI agents: assume they'll break something, record every step, and rewind the files they touched. A flight recorder and time machine for coding agents, with guardrails you set and a log that shows if it was edited.
Website · English · 繁體中文 · 简体中文 · 日本語
[npm] [CI] [License: Apache-2.0] [Node 20+] [Platforms] [Runtime dependencies: 0]
Quick start
Want to see it first? npx zerostel demo makes a throwaway project, plays one agent turn that deletes a folder and breaks the tests, and lets you undo it. No agent needed, and none of your projects are touched.
Then use your agent as usual. When it breaks something:
What it does
- Record. Every prompt, tool call, command, file change, duration and token count, in one timeline per session:
zerostel login the terminal, orzerostel uiin a local web page. - Rewind. A snapshot before and after every tool call that can change files, shell commands included. Undo a turn, go back to any step, or all the way to point zero; every rewind can itself be undone.
- Guard. Your own rules block a tool call, or make the agent ask you first, before it runs. The same rules for every agent.
- Verify and share. A hash-chained log that shows if it was edited, and a one-page report with a privacy mode for sharing.
- Stay local. Nothing is uploaded,
~/.zerostelis readable only by you, and your.gitis never touched.
It's zero trust for AI agents: assume one can go wrong, see everything it does, and keep a way back (in practice). It isn't a sandbox: network requests, deployments and database writes can't be taken back. See Limits.
Why
Agents edit dozens of files, run rm, git checkout ., migrations and build scripts. When something goes wrong you're left asking what it did and how to get back.
Some agents have checkpoints of their own, and they differ a lot. Claude Code's rewind skips changes made through Bash. Copilot CLI tracks shell commands. Cursor and Codex each have their own model. If you use more than one agent, you get a different answer to "what changed and can I get it back" in each.
Zerostel records every supported agent the same way: a snapshot of the project around each tool call that can change files, a timeline of prompts, commands, files, time and tokens, and a report you can hand to someone else. It never touches your .git.
Details and sources: docs/comparison.md. The story behind it, with the incidents: What your coding agent's checkpoints can't bring back.
Supported agents and systems
¹ The real agent on Windows, with its model swapped for a scripted one: a prompt, a file write, a command, a call blocked by a rule, the end of the turn and an undo.
Experimental agents are installed only when you name them: zerostel install --agent deepseek. Reports from real sessions are welcome.
Zerostel doesn't care which model is behind the agent: Claude, GPT, Gemini, DeepSeek or a local one are all recorded the same way.
Windows, macOS and Linux (WSL too). CI runs every commit on all three with Node 20, 22 and 24.
Install
You need git, and Node 20 or newer. No Node? Every release has a single executable with Node inside for Windows, macOS and Linux: download it from Releases and run zerostel install. Plugins for Claude Code, Codex, Antigravity and Gemini CLI, the agent skill, and how to check a download: docs/install.md.
Documentation
Something not working? Run zerostel doctor: it checks Node, git, each agent's hooks, your config and guardrails, and its output is safe to paste into an issue.
Limits
- Only states that were captured can be restored. Recording that starts after a deletion can't bring the file back.
- Inside one shell command there are no intermediate states: a file created and deleted by the same command is never seen.
zerostel runsnapshots when files settle, so it can miss short-lived files too. - Outside the project, only files you list under
watchare snapshotted, and only files under your home folder. On Windows, user environment variables (HKCU\Environment) are read around commands that change them and put back by rewinds; their values are kept in the session log on your machine, never in reports. Global packages are only listed, with the commands to undo them. Rewinds leave alone watched files that didn't exist at the target point. Everything else outside the project isn't covered; the timeline still shows the command that touched it. - Not snapshotted, and listed by
zerostel logwhen present: ignored folders (node_modules,dist/, anything in.gitignore), nested git repositories and submodules, linked folders (symlinks, junctions) and new files abovemaxFileMB. - Agents started in your home directory or a drive root get a timeline but no snapshots.
- On case-insensitive file systems (Windows, macOS by default) a rename that only changes case, such as
readme.md→README.md, isn't seen as a change. - Under WSL, projects on the Windows drive (
/mnt/c/...) are slow to snapshot. Keep them in the Linux file system. - The audit chain shows a log was edited by anything that doesn't have your
audit.key. Someone using your own account can read the key and rewrite a log completely; keep~/.zerostel/**in a deny rule so the agent can't. - Guardrails match what a tool call names. A script or command that reaches a file without naming it gets through.
Roadmap
- Done: recording and rewinding seven agents, point zero, web UI, shareable reports, verifiable logs, guardrails, MCP server, watched files outside the project.
- Next: signed reports anyone can verify without your key; recording calls to other MCP servers through a Zerostel gateway; test-output parsing to say which test broke; real-session validation of the experimental agents.
- Help wanted: test reports from macOS and Linux, and anything labeled help wanted.
Contributing
Questions and ideas are welcome in Discussions. Supporting a new agent means adding one adapter to src/agents/adapters.ts. See CONTRIBUTING.md and docs/architecture.md.
License
来源:README.md,提交 04ba7c0
工具
0版本历史
1- v0.1.2最新Oct 5, 2026


