Zerostel

io.github.zerostelv0.1.2更新於 Oct 5, 2026

Checkpoints, timeline and rewind for AI coding agents. Local, no telemetry.

概覽

AI 產生的概覽

在本機記錄 AI 程式代理的每一步,並讓助理讀取時間軸、在出錯後還原檔案。

功能
Zerostel 是針對程式代理的本機飛行記錄器:在每次可能變更檔案的工具呼叫(包含 shell 指令)前後對專案建立快照,並保存提示詞、指令、檔案變更、耗時與 token 數量的時間軸。透過 MCP,代理可以讀取該時間軸並依需求還原。它也支援自訂護欄規則,用來阻擋某次工具呼叫或要求先確認,並產生雜湊鏈日誌與可分享的單頁報告。
適用情境
當你使用會編輯檔案或執行 shell 指令的程式代理,希望在破壞性操作後能回復、逐步查看變更紀錄,並在多個代理之間得到一致行為時,適合安裝。若希望助理自行查看工作階段歷史或依要求復原某一步,也適用。
執行需求
以 stdio 方式作為本機程序執行,透過 npm 安裝(npx zerostel install 或全域安裝)。需要 git 與 Node.js 20 或更新版本;Windows、macOS 與 Linux 也提供內含 Node 的獨立執行檔。與代理整合依賴各代理的 hooks 或外掛機制,需先完成設定。未宣告帳號、API 金鑰或環境變數。
安裝前請注意
它不是沙箱:網路請求、部署與資料庫寫入無法復原,且只能還原已擷取的狀態。護欄依工具呼叫所聲明的對象比對,未指名檔案的指令碼仍可能繞過。稽核金鑰(audit.key)用於保護日誌鏈,但使用你帳號的人可以讀取它並完全改寫日誌;建議把 ~/.zerostel/** 加入拒絕規則。工作階段日誌可能在本機保存環境變數值。還原會寫入專案檔案。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Zerostel,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

[Zerostel]

Rewind any AI agent to point zero.

Zero trust for AI agents: assume they'll break something, record every step, and rewind the files they touched. A flight recorder and time machine for coding agents, with guardrails you set and a log that shows if it was edited.

Website · English · 繁體中文 · 简体中文 · 日本語

[npm] [CI] [License: Apache-2.0] [Node 20+] [Platforms] [Runtime dependencies: 0]

[npx zerostel demo: an agent turn deletes src/legacy with rm -rf and breaks the tests, then npx zerostel undo brings it back]

Quick start

bash
npx zerostel install

Want to see it first? npx zerostel demo makes a throwaway project, plays one agent turn that deletes a folder and breaks the tests, and lets you undo it. No agent needed, and none of your projects are touched.

Then use your agent as usual. When it breaks something:

bash
zerostel log          # what happened, step by stepzerostel undo         # put the files back to before the agent's last turnzerostel rewind 0     # or all the way back to point zero, where the session startedzerostel ui           # the same, clickable, in a local web page

What it does

  • Record. Every prompt, tool call, command, file change, duration and token count, in one timeline per session: zerostel log in the terminal, or zerostel ui in a local web page.
  • Rewind. A snapshot before and after every tool call that can change files, shell commands included. Undo a turn, go back to any step, or all the way to point zero; every rewind can itself be undone.
  • Guard. Your own rules block a tool call, or make the agent ask you first, before it runs. The same rules for every agent.
  • Verify and share. A hash-chained log that shows if it was edited, and a one-page report with a privacy mode for sharing.
  • Stay local. Nothing is uploaded, ~/.zerostel is readable only by you, and your .git is never touched.

It's zero trust for AI agents: assume one can go wrong, see everything it does, and keep a way back (in practice). It isn't a sandbox: network requests, deployments and database writes can't be taken back. See Limits.

Why

Agents edit dozens of files, run rm, git checkout ., migrations and build scripts. When something goes wrong you're left asking what it did and how to get back.

Some agents have checkpoints of their own, and they differ a lot. Claude Code's rewind skips changes made through Bash. Copilot CLI tracks shell commands. Cursor and Codex each have their own model. If you use more than one agent, you get a different answer to "what changed and can I get it back" in each.

Zerostel records every supported agent the same way: a snapshot of the project around each tool call that can change files, a timeline of prompts, commands, files, time and tokens, and a report you can hand to someone else. It never touches your .git.

Agent's own checkpointsCommits / git stashZerostel
Changes made by shell commandsdepends on the agentonly what you committed✅ inside the project, plus files you list
Go back to a specific stepusually per promptper commit✅ per tool call
Timeline of commands, files, tokens, timepartial❌✅
Log that shows if it was edited afterwards❌✅ (commit hashes)✅
Your own rules: block or ask before a tool runsper agent❌✅ same rules for every agent
Same behaviour across agents❌ one each✅✅
Writes to your .gitsome do✅❌ never
Shareable report of the session❌❌✅

Details and sources: docs/comparison.md. The story behind it, with the incidents: What your coding agent's checkpoints can't bring back.

Supported agents and systems

AgentHowStatus
Claude Codehooks✅ tested on real sessions
Codexhooks (approve once with /hooks)✅ tested on real sessions
Cursorhooks✅ CLI tested on real sessions; the CLI sends no prompt events, so undo goes one change at a time there. On Windows, start it from PowerShell: from Git Bash its hooks don't run
Gemini CLIhooks (trusted folders only)✅ tested end to end¹; for Code Assist Standard/Enterprise and paid API keys, since personal accounts moved to Antigravity in June 2026
Antigravity (CLI, desktop, IDE)hooks✅ tested end to end¹; it doesn't pass on the prompt text, so turns show as "New turn"
Copilot CLIhooks (~/.copilot/hooks)✅ tested on real sessions
opencodeplugin✅ tested on real sessions
DeepSeek Harnessplugin🧪 experimental (dsh itself is a developer preview); tested end to end¹
anything else (Aider, scripts…)zerostel run -- <command> watches the files✅ coarser: no tool calls, tokens or guardrails

¹ The real agent on Windows, with its model swapped for a scripted one: a prompt, a file write, a command, a call blocked by a rule, the end of the turn and an undo.

Experimental agents are installed only when you name them: zerostel install --agent deepseek. Reports from real sessions are welcome.

Zerostel doesn't care which model is behind the agent: Claude, GPT, Gemini, DeepSeek or a local one are all recorded the same way.

Windows, macOS and Linux (WSL too). CI runs every commit on all three with Node 20, 22 and 24.

Install

bash
npx zerostel install          # one-off, nothing installed globallynpm install -g zerostel       # or keep the `zerostel` command around

You need git, and Node 20 or newer. No Node? Every release has a single executable with Node inside for Windows, macOS and Linux: download it from Releases and run zerostel install. Plugins for Claude Code, Codex, Antigravity and Gemini CLI, the agent skill, and how to check a download: docs/install.md.

Documentation

Commandsevery command and option
Guardrailshow rules work, and tested recipes
Configuration~/.zerostel/config.json
CIthe GitHub Action
MCP serverlet the agent read its timeline and rewind when you ask
How it workshooks, the shadow repo, safe rewinds, the audit chain
Zero trusteach principle, and what Zerostel does for it
Security modelwhat it protects and what it doesn't
Agents' own checkpointswhat each agent's undo brings back, with sources
FAQspeed, disk use, git, jj, sandboxes, tokens

Something not working? Run zerostel doctor: it checks Node, git, each agent's hooks, your config and guardrails, and its output is safe to paste into an issue.

Limits

  • Only states that were captured can be restored. Recording that starts after a deletion can't bring the file back.
  • Inside one shell command there are no intermediate states: a file created and deleted by the same command is never seen. zerostel run snapshots when files settle, so it can miss short-lived files too.
  • Outside the project, only files you list under watch are snapshotted, and only files under your home folder. On Windows, user environment variables (HKCU\Environment) are read around commands that change them and put back by rewinds; their values are kept in the session log on your machine, never in reports. Global packages are only listed, with the commands to undo them. Rewinds leave alone watched files that didn't exist at the target point. Everything else outside the project isn't covered; the timeline still shows the command that touched it.
  • Not snapshotted, and listed by zerostel log when present: ignored folders (node_modules, dist/, anything in .gitignore), nested git repositories and submodules, linked folders (symlinks, junctions) and new files above maxFileMB.
  • Agents started in your home directory or a drive root get a timeline but no snapshots.
  • On case-insensitive file systems (Windows, macOS by default) a rename that only changes case, such as readme.md → README.md, isn't seen as a change.
  • Under WSL, projects on the Windows drive (/mnt/c/...) are slow to snapshot. Keep them in the Linux file system.
  • The audit chain shows a log was edited by anything that doesn't have your audit.key. Someone using your own account can read the key and rewrite a log completely; keep ~/.zerostel/** in a deny rule so the agent can't.
  • Guardrails match what a tool call names. A script or command that reaches a file without naming it gets through.

Roadmap

  • Done: recording and rewinding seven agents, point zero, web UI, shareable reports, verifiable logs, guardrails, MCP server, watched files outside the project.
  • Next: signed reports anyone can verify without your key; recording calls to other MCP servers through a Zerostel gateway; test-output parsing to say which test broke; real-session validation of the experimental agents.
  • Help wanted: test reports from macOS and Linux, and anything labeled help wanted.

Contributing

Questions and ideas are welcome in Discussions. Supporting a new agent means adding one adapter to src/agents/adapters.ts. See CONTRIBUTING.md and docs/architecture.md.

bash
npm ci && npm test && npm run smoke

License

Apache-2.0

來源:README.md,提交 04ba7c0

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.2最新Oct 5, 2026