Rewind any AI agent to point zero.
Zero trust for AI coding agents: assume they'll break something, record every step, and rewind the files they touched. One timeline, one undo and one set of guardrails for Claude Code, Codex, Cursor and more.
npx zerostel install
Try it first without an agent or your own project: npx zerostel demo. Or play with the example.
Interactive example An agent session, recorded. Drag to rewind it.
- #1❯Remove the old auth code
- #2$npm testpass
- #3·Read src/app.ts
- #4✎Edit src/app.ts+1 −2
- #5$rm -rf src/legacy3 deleted ⚠
- #6✗npm testfail
Files in the project
- src/app.ts
- src/cart.ts
- src/legacy/auth.ts
- src/legacy/session.ts
- src/legacy/tokens.ts
Now: src/legacy is gone and the tests fail.
Works with the agents you already use
Hooks for each agent, the same timeline and rules for all of them, and a file watcher for anything else. Whatever model is behind the agent: Claude, GPT, Gemini, DeepSeek or a local one.
Plug it in wherever you work
A command for your terminal, a plugin or extension inside the agent, a server the agent can call, a step in CI. Every route ends at the same recorder and the same rules on your machine.
Install
Puts Zerostel on your machine. Then zerostel install adds the hooks to every agent it finds.
-
npm any OS
npx zerostel install -
Homebrew macOS · Linux
brew install zerostel/tap/zerostel -
Scoop Windows
scoop install zerostel -
Executable no Node needed
Inside the agent
Claude Code's plugin records on its own. The others add the skill; recording still comes from zerostel install (Codex asks you to approve new hooks with /hooks).
-
Claude Code plugin
/plugin install zerostel@zerostel -
Codex plugin
codex plugin marketplace add zerostel/zerostel -
Antigravity plugin
agy plugin install https://github.com/zerostel/zerostel -
Gemini CLI extension
gemini extensions install https://github.com/zerostel/zerostel -
Agent skill SKILL.md
npx skills add zerostel/zerostel
Around the agent
MCP lets the agent read its own timeline and rewind on request. The Action records agents in CI. zerostel run watches any other tool: files only, no guardrails.
-
MCP io.github.zerostel/zerostel
claude mcp add zerostel -- zerostel mcp -
GitHub Actions CI
uses: zerostel/zerostel@v0 -
Any other CLI file watcher
zerostel run -- <command>
Agents move fast. So do their mistakes.
A deleted folder, a sed -i across the repo, a migration that ran twice. Some agents' checkpoints don't see shell commands at all, and every agent has its own idea of undo. Zerostel gives you one record and one way back, whichever agent did it.
Record
Every prompt, tool call, command, file change, duration and token count, in one timeline per session.
zerostel log
Rewind
A snapshot around every tool call that can change files. Undo a turn, go back to any step, or all the way to point zero.
zerostel rewind 0
Guard
Your own rules stop a tool call, or make the agent ask you first, before it runs. Same rules for every agent.
zerostel policy init
Share and verify
One HTML page per session, with a privacy mode for sharing, and a hash-chained log that shows if it was edited.
zerostel report --share
Zero trust, in practice
Don't trust an agent because it usually behaves. Assume it can go wrong, see everything it does, and keep a way back.
| Principle | What Zerostel does |
|---|---|
| Assume breach | Snapshots before and after every tool call that can change files, once a project's first snapshot is done. Every rewind can itself be undone. |
| See everything | Prompts, tool calls, commands, files and time, plus tokens where the agent reports them, in a timeline you can read in the terminal or a local web page. |
| Verify the record | Each log line is chained to the one before with a keyed hash. zerostel verify says which line was edited, removed or reordered. |
| Least privilege | Guardrails deny or ask before a tool runs: credentials, force pushes, global installs, deploys. You write the rules. |
| Limit the blast radius | Rewinds cover the project, files you list (like ~/.zshrc) and Windows user environment variables. What can't be undone is listed with the commands that would. |
| Trust nothing it reads | Every project is treated as hostile: no programs run from it, no links followed out of it, terminal escape codes stripped. |
It isn't a sandbox: it can't undo a network request or a deploy, and an agent running as you can still do what you can do. The limits are written down, not hidden.
A security tool should be built like it's under attack
Zerostel runs inside every agent session you start, in projects you didn't write. So it treats each of them as an adversary.
- Everything stays on your machine. No account, no cloud, no telemetry. On macOS and Linux
~/.zerostelis readable only by you; on Windows it lives in your private user profile. - Zero runtime dependencies. One bundled file, plus git. Or a single executable with Node inside.
- Never runs what a repo ships. git and other helpers are found by absolute path, skipping the project folder and any
node_modules. - Rewinds stay inside the lines. No following symlinks or junctions out of the project; nothing deleted that isn't backed up.
- Reviewed, and honest about limits. Reviewed in several rounds, by more than one reviewer; findings are fixed with a regression test. The security model says what it protects and what it doesn't.
- Releases you can trace. npm packages are built and published by CI with provenance, and the package refuses to publish without it.
$ zerostel policy test "cat ~/.aws/credentials" ✗ blocked by rule 1: credentials, and Zerostel's own records, are off limits $ zerostel policy test "git push --force origin main" ? asks first (rule 3): rewrites or throws away git history $ zerostel verify ✓ claude-code 4f2a91c0 214 events · chain intact
How it compares
Use your agent's own checkpoints and git too; they don't conflict. Zerostel is the part that works the same everywhere.
| Agent checkpoints | Commits / stash | Zerostel | |
|---|---|---|---|
| Shell command changes | depends on the agent | what you saved with a commit or stash | inside the project |
| Back to a specific step | usually per prompt | per commit | per tool call |
| Timeline with tokens and time | partial | no | yes |
| Your rules, before a tool runs | per agent | no | same for every agent |
| Log that shows edits | no | yes | yes |
| Touches your .git | some do | yes | never |
| Shareable session report | varies by agent | no | yes |
Questions
Isn't git enough?
Git keeps what you commit. Agents change things between commits, often through shell commands, and nobody commits before every tool call. Zerostel does the equivalent automatically, in a repository of its own, so your history stays clean.
Does undo reverse everything the agent did?
No. It puts captured files back: the project and the files you list. Network requests, deploys and database writes can't be taken back by any tool on your laptop, which is why the starter guardrails ask before those.
Does it slow the agent down?
Measured on Windows 11, where starting processes is slowest: about 0.16 seconds for a tool call that only reads, and 1 to 2 seconds for one that edits, which gets a snapshot before and after. A project's first snapshot reads every file once (3 seconds for 1,000 files, 5 minutes for 50,000); it runs in the background as the session opens, and the agent doesn't wait for it. scripts/bench.mjs measures your machine.
Where does my data go?
Nowhere. Snapshots and logs stay in ~/.zerostel on your machine. Reports are files you choose to share, and the share mode leaves out prompts, commands, output and diffs.
Can the agent use it too?
Yes. zerostel mcp is an MCP server: the agent can save a checkpoint before something risky, read its timeline, and rewind when you ask, showing you a preview first.
Why the name: zero trust + stella, the stars. AI agents are multiplying like stars; Zerostel is the single point they all come back to.
Give your agent a flight recorder
Node 20+ and git. Windows, macOS and Linux.
npx zerostel install