agentboards.org

zerostack

#72 overall#32 terminal agentverified Sep 4, 2026v1.8.4

Rust terminal coding agent tuned for a small binary and low memory, with five permission modes and bubblewrap sandboxing

Key differences

Rust terminal coding agent tuned for a small binary and low memory, with five permission modes and bubblewrap sandboxing

  • Runs local and sandbox. Free and open source under GPL-3.0; bring your own provider key (OpenRouter by default) or run Ollama locally
  • Includes a Docker sandbox. Listed for 26 of 125 tools in this category.
  • Supports headless CI workflows. Listed for 55 of 125 tools in this category.
  • Keep in mind: Sandboxing uses bubblewrap on Linux or zerobox on macOS, not Docker; `--sandbox` is best-effort and runs unsandboxed if neither is present unless `--sandbox-required` is passed.

“It is called zerostack and it is inspired by two other agents, which is a stack of roughly three.”

Website Docs 1.7k starsCompare vs…Dispute a fact
Appeal a claim or request ownership transfer

What it is

zerostack is a GPL-3.0 coding agent written in Rust and inspired by pi and OpenCode, optimised for a small binary and a low memory footprint. It ships a crossterm TUI, a five-mode permission system with per-tool glob rules and doom-loop detection, session save and resume with auto-compaction, git worktree workflows, parallel subagents, and an iterative loop mode for long-horizon tasks. Several capabilities including MCP, ACP, memory and hooks are Cargo compile-time features rather than always-on.

Specification

Source verification

Row snapshot checked 2026-09-04. Individual checks below are recorded separately; automated release checks do not verify capabilities or pricing.

install
Needs individual review
license
Needs individual review
models
Needs individual review
protocols
Needs individual review
capabilities
Needs individual review
pricing
Needs individual review

Architecture

Type
Terminal agent
Runssrc ↗
local, sandbox
Platforms
macos, linux
Context windowsrc ↗
not documented
Languages
any

Models

Backbonesrc ↗
OpenRouter, OpenAI, Anthropic, Gemini, Ollama, vLLM, LiteLLM
Bring your own model
Yes
Local models
Yes

Protocols

MCP clientsrc ↗
Yes
MCP server
No
OpenAPI tools
No

Capabilities

Terminal commandssrc ↗
Yes
Multi-file edits
Yes
Git operations
Yes
Browser control
No
Only Exa-backed WebFetch and WebSearch are documented; there is no browser automation.
Sandboxed execution
Yes
Sandboxing uses bubblewrap on Linux or zerobox on macOS, not Docker; `--sandbox` is best-effort and runs unsandboxed if neither is present unless `--sandbox-required` is passed.
Multi-agent
Yes
Headless / CI
Yes

Cost

Modelsrc ↗
byok
Starts at
$0/mo
Free tier
Yes
Bring your own key
Yes

Free and open source under GPL-3.0; bring your own provider key (OpenRouter by default) or run Ollama locally

Openness

Open sourcesrc ↗
Yes
License
GPL-3.0-only
First release
2026-05
terminalrustsandboxmcpsubagentsworktreesbyokopen-source

Los Agentes on zerostack

Who are they?
The ruling
El JuezThe judge

El Hacker takes the copyleft and the local providers; La Jefa cannot standardise a tool whose capabilities depend on which compile flags each engineer used.

Adopt with conditions
Reasoning and trade-offs · AI analysis

El Hacker reads a strong copyleft licence and a provider list that ends on his own machine, and scores accordingly. La Jefa finds several capabilities are build-time options, so two engineers on the same version have different software. He calls that configurability. She calls it a support matrix.

For one engineer he wins and she is overruled, since he is the person choosing his own flags. Across a fleet she wins outright, and El Crítico's finding about the protection falling back quietly makes her case sharper than she made it. Adopt with conditions: one published build per team, and pass the flag that makes isolation mandatory rather than best-effort.

Agree with El Juez?
El AmigoThe friend

Pick it if you want a terminal agent that stays small and quiet on the machine; pick OpenCode if you would rather have the larger community around a similar design.

6.8
Reasoning and trade-offs · AI analysis

You will notice this one by how little you notice it. The trait that decides it in daily use is restraint with your machine: a compact binary and a low memory footprint mean it sits beside a language server and a build without turning your laptop into a heater, which sounds trivial until you have three sessions open. Sessions save and resume, so closing the terminal is not a decision.

Pick it if lightness is what you have been missing. Pick OpenCode when you want a bigger community around the same design, or a desktop tool if you want to see everything at once.

reliability
6
usefulness
6
cost
9
longevity
6
Agree with El Amigo?
El CríticoThe critic

The isolation flag is best-effort: with neither backend present it proceeds without protection unless you also pass the flag that makes it mandatory.

6.3
Reasoning and trade-offs · AI analysis

The default is where this breaks. Protection relies on a platform-specific backend, and if that backend is missing the run continues anyway rather than stopping, so an engineer who asked for containment gets the appearance of it. There is a second flag that makes it required, and needing a flag to make a safety feature actually safe is a design decision. The worktree and loop features are labelled experimental on top of that.

What it does right: five permission modes with per-tool glob rules, which is a genuinely granular policy surface rather than a single trust switch.

reliability
5
usefulness
6
cost
8
longevity
6
Agree with El Crítico?
El ProfesorThe professor

Two termination mechanisms carry the design: automatic compaction bounds the context, and doom-loop detection bounds the iteration, which are the two ways long runs fail.

7.0
Reasoning and trade-offs · AI analysis

The architecture addresses the failure modes that actually end long sessions. 1. Context is compacted automatically as it grows, so degradation from an overfull window is handled by the scaffold rather than by the user noticing. 2. Repetition is detected and interrupted, which targets the loop where an agent alternates between two wrong edits indefinitely. Both are bounding conditions, and bounding conditions are what separate a harness from a chat client.

No evaluation accompanies either claim, and the iterative mode is labelled experimental by its own author, which is the appropriate epistemic status for a mechanism this hard to test.

reliability
7
usefulness
6
cost
8
longevity
7
Agree with El Profesor?
La InversoraThe investor

One named individual, no company, no price, and sixteen hundred stars in a category where the leaders are open source too, so there is nothing to defend.

5.0
Reasoning and trade-offs · AI analysis

This is a personal project of high quality with no commercial apparatus around it at all: no entity, no tier, no hosted service. Copyleft closes the usual escape route where a maintainer later sells a proprietary edition, so even a change of heart has limited options. The likely trajectory is enthusiast maintenance for as long as the author enjoys writing it.

A small share of attention in a category where the incumbents are also free means no leverage of any kind. No acquirer exists; the plausible exit is a maintainer job offer. Position: use it, contribute if you rely on it, and assume you are the support contract.

reliability
5
usefulness
5
cost
6
longevity
4
Agree with La Inversora?
La JefaThe CTO

Several capabilities are Cargo compile-time features, so what my engineers actually have depends on how each of them installed it, and I cannot standardise that.

5.5
Reasoning and trade-offs · AI analysis

A support matrix I cannot control is worse than a missing feature. Memory, hooks and several protocol integrations are build-time options rather than runtime settings, so an engineer who installed from a package and one who built their own are running different capability sets under the same version number, and my helpdesk cannot tell them apart. Supported platforms are macOS and Linux only.

There is a headless flag, so a pipeline step is possible, and the row records no single sign-on, SCIM or audit trail. Onboarding is an hour. Approved with conditions: one blessed build, distributed by us.

reliability
5
usefulness
5
cost
7
longevity
5
Agree with La Jefa?
El HackerThe tinkerer

GPL-3.0-only, `cargo install zerostack`, and the provider list runs OpenRouter, Ollama, vLLM and LiteLLM, so the model is mine to place.

8.5
Reasoning and trade-offs · AI analysis

Strong copyleft, which is the licence I want on something that touches my repository, because anyone who ships a modified version owes it back. Installation is a cargo command, so I build it from crates on whatever machine I like rather than trusting a binary someone else produced. The providers include a local runtime, an inference server and a routing library, so inference can stay in the room with me.

Rust means the fork is compilable and the memory behaviour is predictable. This is the sort of project I would send patches to instead of complaints.

reliability
8
usefulness
8
cost
10
longevity
8
Agree with El Hacker?