mrkeyoor.com_
Wed 30 Sept 20:33 UTC
Dev Toolsevaluationupdated 26 Aug 2026

zero review

Zero is a local terminal coding agent with a Go core and an npm-distributed launcher. It can inspect and edit repositories, run commands, use multiple model providers, keep sessions on disk, and expose its tools through interactive or machine-readable interfaces.

+4stars / 7d
Verdict

Our npm-path run installed 83 packages in 10 seconds, exposed no build or test target, and reported 2 moderate vulnerabilities. Zero is worth trying if model choice, local sessions, and explicit permissions outweigh the cost of adopting a fast-moving v0.8 project. Security-sensitive teams should verify the platform sandbox themselves and review current tool-edit and denial-loop reports before granting autonomous modes.

We ran it

Lab card: what happened when we ran zeroScreenshot of zero (zero.gitlawb.com)
Install✓ · 10s83 packages · 186 MB
Buildn/ano build script
Testsn/ano test script
Known vulns20 critical · 0 high · 2 moderate · 0 low (npm audit)
Repo1466 files~384,283 lines of source · 13.8 MB · 5 CI workflows

Answers from our run

Does zero build from source?

Dependencies installed in 10 seconds (83 packages), and the project has no separate build step. We cloned commit ad34dc8 into a clean Debian container with 3 CPUs and no project-specific setup.

Does zero have tests you can run?

Not through a standard command: the project exposes no test script or target that our harness could run.

Does zero have known vulnerabilities in its dependencies?

npm audit flagged 2 known advisories in the dependency tree at the time of our run.

Who should not use zero?

Teams that require a small, settled codebase: our checkout contained about 384,283 source lines, and GitHub listed 115 combined issues and pull requests.

What are the alternatives to zero?

Aider, OpenHands, Continue. Our npm-path run installed 83 packages in 10 seconds, exposed no build or test target, and reported 2 moderate vulnerabilities.

Setup3/510-second npm install, but source and sandbox paths vary by platform
Docs5/5Detailed install, safety, headless, extension, and support guides
Community4/51,631 stars with heavy August 2026 issue and pull request activity
Maturity2/5v0.8.0 moves quickly and open reports reach editing and sandbox behavior

Who it’s for

Developers who want one terminal agent across OpenAI, Anthropic, Gemini, local models, and compatible endpoints.
Teams that need headless JSON I/O, isolated worktrees, permission prompts, and CI-friendly exit codes.
Power users who want local sessions plus MCP servers, skills, plugins, hooks, and specialist agents.
Go contributors willing to build the main binary and platform sandbox helpers from source.

Who it’s NOT for

Teams that require a small, settled codebase: our checkout contained about 384,283 source lines, and GitHub listed 115 combined issues and pull requests.
Anyone assuming permission denial always stops wasted work: pull request #866 reports a run that made 384 denied calls over 26 minutes before producing nothing.
Windows users who cannot inspect diffs carefully: issue #967 says full-file writes can replace CRLF and remove a UTF-8 BOM.
Operators who treat the sandbox as a proven security boundary on every platform: current work includes Windows write-jail coverage and daemon-token protections.

Setup reality

Our npm-side sandbox install succeeded in 10 seconds, adding 83 packages and using 186 MB. The package exposed no build script and no test script, so both steps were skipped. Npm audit found 2 moderate vulnerabilities, with 0 critical or high findings.

Using the agent needs a supported model provider, credentials or a running local endpoint. Native sandboxing also varies by platform; Linux source installs need an additional helper binary, while Windows and macOS follow different paths.

The checked-out repository is mainly Go even though our measured package path was npm. Source development requires Go 1.26.6 or newer and uses Go test, vet, lint, and vulnerability targets. The npm wrapper relies on platform packages or release binaries.

One agent covers the TUI, scripts, and CI

Zero's interactive mode has provider and model pickers, permission controls, plans, images, session resume, and repository tools. The same binary also runs a single prompt with zero exec, accepts stream JSON, returns meaningful exit codes, and can create an isolated worktree. A developer can explore in the TUI, then move a stable task into automation without changing products.

The breadth is substantial for version 0.8.0. The command list includes local session search, context reports, repository maps, verification, changes, schedules, plugins, skills, specialists, MCP, and provider setup. More capability means more policy surface. Decide which commands an automated run may execute, which directories it may write, and whether network access is allowed before placing it in a CI job or a repository with release credentials.

Provider freedom still leaves credentials and model behavior with you

The README names more than 25 providers and compatible endpoint types. Hosted choices require environment keys or setup-wizard entries; Ollama and LM Studio need local servers. Switching providers is useful for cost and privacy, but models do not share identical tool use, context limits, or authentication behavior. zero doctor, provider listing, and a small repository task should be part of onboarding for every selected profile.

Sessions stay on local disk, and the project says Zero does not upload them as telemetry. Local storage is useful for search, resume, fork, rewind, and side conversations. It also puts retention and workstation access under your control. A 32 KiB cap applies to the combined project instruction files, while each discovered instruction file is capped at 8 KiB. Teams with layered guidance should check which rules reached the prompt.

What happened when we ran it

Our sandbox measured the npm package path at commit ad34dc8. Installation succeeded in 10 seconds, adding 83 packages and occupying 186 MB. The package exposed no build script or target, so the build step was skipped. It also exposed no test script or target, so our harness had no npm test suite to run.

Npm audit reported 2 known vulnerabilities, both moderate, with 0 critical and 0 high findings. The checkout contained 1,466 files and about 384,283 source lines in 13.8 MB. It had 5 CI workflow files, no Dockerfile, and no tests directory. These are measurements of the checked-out npm-oriented path, not evidence that the repository has no Go tests. The README explicitly directs source contributors to go test ./....

Our 3-CPU, 8 GB container had no secrets and did not connect Zero to a model provider. We did not judge edit quality, task completion, browser control, or sandbox escape resistance. The clean install proves the wrapper resolves in that environment. With no package build or test target, it gives less assurance about the Go agent than a green source test run would.

Permission controls have current edge cases

Zero gates writes, shell commands, network access, out-of-workspace paths, destructive commands, and elevated actions. Extra write roots are explicit, and unsafe modes require opt-in. Release v0.8.0 added a path-jail primitive, credential-store locking, and Git worktree hardening. Those are the right areas to address in a coding agent because a model's proposed command can carry real side effects.

Open pull request #866 documents a failure of the repeated-denial guard. A headless run made 384 denied calls over 26 minutes because each refusal string differed, so the streak never reached its stop threshold. Pull request #726 separately classifies git push as network-sensitive. Until those changes are in the release you deploy, a denied capability should trigger an external time or tool-call budget as well as Zero's internal policy.

File edits need extra care on Windows

Issue #967 reports that reading and rewriting a CRLF file can convert it to LF and remove a UTF-8 BOM. That can turn a small requested change into a whole-file diff or break tools that depend on the marker. Issue #963 reports another editing hazard: a fuzzy block match can accept changed interior lines and replace content that did not match the requested old string byte for byte.

Both reports were open on August 26, 2026, and each concerns a core coding-agent operation. Require diff review for project files with generated formats, Windows line endings, or fragile configuration. A worktree reduces cleanup cost, but it does not tell you whether the edit was semantically right. Teams should run format and test commands after every autonomous edit and reject unexpectedly broad diffs.

MCP and plugins turn configuration into code execution

Zero can connect to MCP servers, expose its own tools over MCP stdio, load markdown skills, and discover user or project plugins. Plugin manifests may declare commands, hooks, prompts, and tools. Project plugins resolve from the current working directory, while personal plugins live under the user configuration directory. These extension points can make one installation fit several teams and languages.

They also expand what must be reviewed. A hook can run before or after tools, and a plugin command is executable configuration. Keep trusted plugins under version control, review manifest changes, and avoid inheriting personal extensions in a controlled CI identity. The README's permission values help, but they cannot make an unknown command safe merely because it arrived through a named plugin.

August 2026 activity is intense and unfinished

GitHub recorded 1,631 stars, 115 combined issues and pull requests, and a last push on August 26, 2026. Release v0.8.0 arrived on August 21, while an automated v0.8.1 release pull request was already open by August 26. The queue includes fixes for TUI input, process timeouts, configuration preservation, Windows sandbox behavior, and secret redaction.

That pace shows active work and a product still discovering edge cases. The MIT license, detailed docs, platform packages, source instructions, and visible security discussions make Zero easier to evaluate than a closed agent. For everyday experimental coding, its range is appealing. For unattended changes to valuable repositories, pin a version, restrict credentials, cap runs externally, and promote upgrades only after platform-specific tests.

Alternatives

ProjectWhat it isPick it when
Aider gh↗A terminal pair-programming tool built around chat, repository maps, and Git-aware edits.pick this instead when you want a narrower terminal workflow with a longer public track record.
OpenHands gh↗An agent platform with a web UI, sandboxed runtime, and software-development tasks.pick this instead when browser-based team workflows matter more than a local TUI.
Continue gh↗An open coding-agent stack centered on IDE use and configurable models.pick this instead when editor integration is the daily surface and terminal operation is secondary.

What people are saying

  1. [producthunt] Zero
  2. [lobsters] Zero-Knowledge Proofs Aren’t Age Verification Silver Bullets
  3. [openai] Offering Zero Data Retention for frontier models
  4. [hackernews] A quick look at zero-knowledge proofs
  5. [github-trending] Gitlawb/zero
  6. [mastodon-trends] Murderous heat, an endangered food supply and no net zero: this is the life the radical right wants you to have

Sources

  1. Zero README
  2. Zero v0.8.0 release
  3. Pull request 866: repeated denied calls
  4. Issue 967: CRLF and BOM rewriting
  5. Issue 963: fuzzy edit mismatch
  6. Pull request 726: git push network classification

More dev tools reviews

gander · lipgloss · roundhouse · GhostTrack · Codex-Dream-Skin · TokenTracker · the whole board →

Related reading