Zerostel Zerostel
Open source · local · no telemetry

Rewind any AI agent to point zero.

Zero trust for AI coding agents: assume they'll break something, record every step, and rewind the files they touched. One timeline, one undo and one set of guardrails for Claude Code, Codex, Cursor and more.

$ npx zerostel install

Try it first without an agent or your own project: npx zerostel demo. Or play with the example.

Interactive example An agent session, recorded. Drag to rewind it.

  1. #1❯Remove the old auth code
  2. #2$npm testpass
  3. #3·Read src/app.ts
  4. #4✎Edit src/app.ts+1 −2
  5. #5$rm -rf src/legacy3 deleted ⚠
  6. #6✗npm testfail

Files in the project

  • src/app.ts
  • src/cart.ts
  • src/legacy/auth.ts
  • src/legacy/session.ts
  • src/legacy/tokens.ts

Now: src/legacy is gone and the tests fail.

Works with the agents you already use

Hooks for each agent, the same timeline and rules for all of them, and a file watcher for anything else. Whatever model is behind the agent: Claude, GPT, Gemini, DeepSeek or a local one.

Claude Code Codex Cursor Copilot CLI Antigravity Gemini CLI enterprise opencode DeepSeek Harness experimental Anything else zerostel run

Plug it in wherever you work

A command for your terminal, a plugin or extension inside the agent, a server the agent can call, a step in CI. Every route ends at the same recorder and the same rules on your machine.

Install

Puts Zerostel on your machine. Then zerostel install adds the hooks to every agent it finds.

  • npm any OS

    npx zerostel install
  • Homebrew macOS · Linux

    brew install zerostel/tap/zerostel
  • Scoop Windows

    scoop install zerostel
  • Executable no Node needed

Inside the agent

Claude Code's plugin records on its own. The others add the skill; recording still comes from zerostel install (Codex asks you to approve new hooks with /hooks).

  • Claude Code plugin

    /plugin install zerostel@zerostel
  • Codex plugin

    codex plugin marketplace add zerostel/zerostel
  • Antigravity plugin

    agy plugin install https://github.com/zerostel/zerostel
  • Gemini CLI extension

    gemini extensions install https://github.com/zerostel/zerostel
  • Agent skill SKILL.md

    npx skills add zerostel/zerostel

Around the agent

MCP lets the agent read its own timeline and rewind on request. The Action records agents in CI. zerostel run watches any other tool: files only, no guardrails.

  • MCP io.github.zerostel/zerostel

    claude mcp add zerostel -- zerostel mcp
  • GitHub Actions CI

    uses: zerostel/zerostel@v0
  • Any other CLI file watcher

    zerostel run -- <command>

Agents move fast. So do their mistakes.

A deleted folder, a sed -i across the repo, a migration that ran twice. Some agents' checkpoints don't see shell commands at all, and every agent has its own idea of undo. Zerostel gives you one record and one way back, whichever agent did it.

Record

Every prompt, tool call, command, file change, duration and token count, in one timeline per session.

zerostel log

Rewind

A snapshot around every tool call that can change files. Undo a turn, go back to any step, or all the way to point zero.

zerostel rewind 0

Guard

Your own rules stop a tool call, or make the agent ask you first, before it runs. Same rules for every agent.

zerostel policy init

Share and verify

One HTML page per session, with a privacy mode for sharing, and a hash-chained log that shows if it was edited.

zerostel report --share

Zero trust, in practice

Don't trust an agent because it usually behaves. Assume it can go wrong, see everything it does, and keep a way back.

PrincipleWhat Zerostel does
Assume breachSnapshots before and after every tool call that can change files, once a project's first snapshot is done. Every rewind can itself be undone.
See everythingPrompts, tool calls, commands, files and time, plus tokens where the agent reports them, in a timeline you can read in the terminal or a local web page.
Verify the recordEach log line is chained to the one before with a keyed hash. zerostel verify says which line was edited, removed or reordered.
Least privilegeGuardrails deny or ask before a tool runs: credentials, force pushes, global installs, deploys. You write the rules.
Limit the blast radiusRewinds cover the project, files you list (like ~/.zshrc) and Windows user environment variables. What can't be undone is listed with the commands that would.
Trust nothing it readsEvery project is treated as hostile: no programs run from it, no links followed out of it, terminal escape codes stripped.

It isn't a sandbox: it can't undo a network request or a deploy, and an agent running as you can still do what you can do. The limits are written down, not hidden.

A security tool should be built like it's under attack

Zerostel runs inside every agent session you start, in projects you didn't write. So it treats each of them as an adversary.

  • Everything stays on your machine. No account, no cloud, no telemetry. On macOS and Linux ~/.zerostel is readable only by you; on Windows it lives in your private user profile.
  • Zero runtime dependencies. One bundled file, plus git. Or a single executable with Node inside.
  • Never runs what a repo ships. git and other helpers are found by absolute path, skipping the project folder and any node_modules.
  • Rewinds stay inside the lines. No following symlinks or junctions out of the project; nothing deleted that isn't backed up.
  • Reviewed, and honest about limits. Reviewed in several rounds, by more than one reviewer; findings are fixed with a regression test. The security model says what it protects and what it doesn't.
  • Releases you can trace. npm packages are built and published by CI with provenance, and the package refuses to publish without it.
$ zerostel policy test "cat ~/.aws/credentials"
✗ blocked by rule 1: credentials, and Zerostel's
  own records, are off limits
 
$ zerostel policy test "git push --force origin main"
? asks first (rule 3): rewrites or throws away
  git history
 
$ zerostel verify
✓ claude-code 4f2a91c0  214 events · chain intact

How it compares

Use your agent's own checkpoints and git too; they don't conflict. Zerostel is the part that works the same everywhere.

Agent checkpointsCommits / stashZerostel
Shell command changesdepends on the agentwhat you saved with a commit or stashinside the project
Back to a specific stepusually per promptper commitper tool call
Timeline with tokens and timepartialnoyes
Your rules, before a tool runsper agentnosame for every agent
Log that shows editsnoyesyes
Touches your .gitsome doyesnever
Shareable session reportvaries by agentnoyes

Questions

Isn't git enough?

Git keeps what you commit. Agents change things between commits, often through shell commands, and nobody commits before every tool call. Zerostel does the equivalent automatically, in a repository of its own, so your history stays clean.

Does undo reverse everything the agent did?

No. It puts captured files back: the project and the files you list. Network requests, deploys and database writes can't be taken back by any tool on your laptop, which is why the starter guardrails ask before those.

Does it slow the agent down?

Measured on Windows 11, where starting processes is slowest: about 0.16 seconds for a tool call that only reads, and 1 to 2 seconds for one that edits, which gets a snapshot before and after. A project's first snapshot reads every file once (3 seconds for 1,000 files, 5 minutes for 50,000); it runs in the background as the session opens, and the agent doesn't wait for it. scripts/bench.mjs measures your machine.

Where does my data go?

Nowhere. Snapshots and logs stay in ~/.zerostel on your machine. Reports are files you choose to share, and the share mode leaves out prompts, commands, output and diffs.

Can the agent use it too?

Yes. zerostel mcp is an MCP server: the agent can save a checkpoint before something risky, read its timeline, and rewind when you ask, showing you a preview first.

Why the name: zero trust + stella, the stars. AI agents are multiplying like stars; Zerostel is the single point they all come back to.

Give your agent a flight recorder

Node 20+ and git. Windows, macOS and Linux.

$ npx zerostel install