by Twigpine
The coding agent that answers to you, your model, your machine, your rules.
# Add to your Claude Code skills
git clone https://github.com/Twigpine/zeroLast scanned: 9/30/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@hono/node-server: Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "hono: Hono: ReDoS in CORS middleware via Access-Control-Request-Headers",
"severity": "medium"
},
{
"file": "README.md",
"line": 68,
"type": "remote-install",
"message": "Install command (remote install script piped to a shell — review the source before running): \"curl -fsSL https://raw.githubusercontent.com/Gitlawb/zero/main/scripts/install.s\"",
"severity": "low"
}
],
"status": "PASSED",
"scannedAt": "2026-09-30T10:18:39.826Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}See how zero compares with popular alternatives.
zero is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by Twigpine. The coding agent that answers to you, your model, your machine, your rules. It has 1,686 GitHub stars.
Yes. zero passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/Twigpine/zero" and add it to your Claude Code skills directory (see the Installation section above).
zero is primarily written in Go. It is open-source under Twigpine on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh zero against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
Zero is an AI coding agent for your local terminal. It can inspect a repository, edit files, run commands, use browser/terminal helpers, and keep durable local sessions while you choose the model and the permission level.
zero
zero exec "fix the failing test in ./pkg"
zero exec --output-format stream-json < turns.jsonl
zero exec is scriptable, supports text/JSON/
stream-JSON I/O, isolated worktrees, spec-first runs, and meaningful exit
codes for CI.npm install -g @gitlawb/zero
zero
The npm package is a small wrapper whose platform build (Linux and macOS on
x64/arm64, Windows on x64 — including the browser/terminal control helpers)
installs as an optional dependency straight from the npm registry — no install
scripts, no downloads outside npm. Bun, pnpm, and yarn work the same way with
no trust or approval steps. Installs that skip optional dependencies
(--omit=optional) still work: the wrapper fetches the binary from the
matching GitHub Release whenever it is missing. Windows on ARM runs the x64
build under emulation. See docs/NPM_PACKAGING.md for
how the package is put together.
Linux/macOS:
curl -fsSL https://raw.githubusercontent.com/Gitlawb/zero/main/scripts/install.sh | bash
Windows PowerShell:
irm https://raw.githubusercontent.com/Gitlawb/zero/main/scripts/install.ps1 | iex
Source builds require Go 1.26.6+.
git clone https://github.com/Gitlawb/zero.git
cd zero
go run ./cmd/zero
Release installers and the npm wrapper require published GitHub Release assets. If you are testing before the first public release, build from source:
go build -o zero ./cmd/zero
On Linux, build the sandbox helper too if you want native sandboxing:
go build -o zero-linux-sandbox ./cmd/zero-linux-sandbox
go build -o zero-seccomp ./cmd/zero-seccomp # optional compatibility wrapper
Put zero and zero-linux-sandbox in the same directory on PATH
(~/.local/bin is a good default). macOS does not need an extra helper binary.
Windows source builds can use the main zero.exe as their sandbox helper; release
archives still ship standalone Windows helper executables.
More install details: docs/INSTALL.md.
Start the TUI:
zero
The setup wizard helps you pick a provider and model. You can also configure providers from the command line:
zero setup
zero providers list
zero models list
zero doctor
For API providers, set the matching environment variable before setup or enter the key in the wizard:
export OPENAI_API_KEY=sk-...
export ANTHROPIC_API_KEY=...
export GEMINI_API_KEY=...
export AIMLAPI_API_KEY=...
export LONGCAT_API_KEY=...
export FIREWORKS_API_KEY=...
export MINIMAX_API_KEY=...
export MINIMAXI_API_KEY=...
To configure AI/ML API directly, run:
zero providers setup aimlapi --set-active
To configure Meituan LongCat (LongCat-2.0) directly, run:
zero providers setup longcat --set-active
To configure Fireworks AI directly, run:
zero providers setup fireworks --set-active
MiniMax presets use the Anthropic-compatible endpoints for the global and China regions:
zero providers add minimax --set-active
zero providers add minimaxi-cn --set-active
To use the OpenAI-compatible endpoints instead, add a custom compatible profile for the required region:
zero providers add custom-openai-compatible \
--name minimax-openai \
--model MiniMax-M3 \
--base-url https://api.minimax.io/v1 \
--api-key-env MINIMAX_API_KEY \
--set-active
zero providers add custom-openai-compatible \
--name minimax-cn-openai \
--model MiniMax-M3 \
--base-url https://api.minimaxi.com/v1 \
--api-key-env MINIMAXI_API_KEY \
--set-active
For local models, run Ollama, LM Studio, or the Atomic Chat
desktop app, then use zero setup or zero providers detect. For Atomic Chat,
load a model and enable its local OpenAI-compatible API (default
http://127.0.0.1:1337/v1). Choose atomic-chat-local; detection includes the
loaded model ID in the add command. If no usable ID is discovered, load a model
and retry. Model IDs requiring shell-specific quoting use interactive setup.
zero
Useful controls:
| Control | Action |
|---|---|
Enter |
send the prompt |
/ |
open slash-command suggestions |
Ctrl+X then letter |
common slash commands (e.g. m → /model; Ctrl+X ? for full list) |
Ctrl+P / Ctrl+N |
previous / next item in menus (arrows still work) |
Shift+Tab |
cycle permission mode |
Ctrl+B |
show/hide the sidebar |
Ctrl+C |
cancel, exit, or return from a /btw conversation |
Common slash commands:
| Command | Purpose |
|---|---|
/model, /provider |
switch the active model/provider |
/spec, /plan |
draft and review a plan before building |
/image |
attach an image for vision-capable models |
/resume, /rewind |
continue or roll back local sessions |
/new |
start a fresh session in place (previous session stays on disk) |
/btw [question] |
ask in an isolated fork without adding the side conversation to the main session |
/loop |
repeat a prompt or custom /command on an interval (/loop 5m /babysit-prs) or self-paced |
/compact, /context |
manage context usage |
/permissions, /tools |
inspect available tools and policy |
/add-dir |
allow an extra write directory for this session |
/theme, /doctor, /config |
adjust appearance and inspect setup |
execzero exec "explain internal/agent/loop.go"
zero exec --model claude-sonnet-4.5 "refactor the config loader"
zero exec --use-spec "add rate limiting to the API client"
zero exec --worktree "try the migration in an isolated worktree"
zero exec --resume
zero exec --fork <session-id> "try the other approach"
Programmatic use:
zero exec --input-format stream-json --output-format stream-json < turns.jsonl
The stream-JSON contract is documented in docs/STREAM_JSON_PROTOCOL.md.
Zero is designed to make side effects visible.
--add-dir <path> and /add-dir <path> grant additional write roots without
giving the agent the whole filesystem.Example:
zero --add-dir ../docs-site
zero exec --add-dir ../shared "update both repos"
Sandbox behavior can be inspected with:
zero sandbox policy
zero sandbox grants list
Zero includes local file/search/edit/shell tools, web_fetch for public URLs,
and MCP support for additional tools.
web_fetch refuses loopback, private and other special-use addresses: it checks
the URL before asking permission, resolves the host, and dials the address it
validated so a name cannot resolve to something else in between.
If HTTP_PROXY/HTTPS_PROXY is set, web_fetch and the provider connectivity
probe use it, and that last step changes: the proxy is dialed and the target
hostname is sent to it, so the proxy decides which address the request actually
reaches. The URL is still checked and resolved locally first, but a proxy that
answers differently can reach a private service. A forward proxy already sees
and can rewrite every request through it, so this is the trust you accept by
configuring one. Leave the variables unset for the checks to be enforced end to
end.
For local dev servers, use shell commands such as curl through exec_command
so the normal sandbox and permission policy applies. Long-running commands stay
attached to a background terminal session and can be listed or stopped from the
TUI.
The npm package also includes browser and terminal helper packages used by local
browser/terminal tools. Source builds can use the same helpers when they are on
PATH or configured in Zero's local-control settings.
zero interactive TUI
zero exec one-shot or scripted agent