v3.5.0Node 20+ · MIT · runs locally

The coding agent
that shows its work.

Sentinel is a local coding agent for the terminal. It streams from the LLM you pick, edits files through sandboxed tools, and prints what every turn cost.

default cost, Groq free tier
$0
sandboxed local tools
19
providers, one client
12
servers, 0 telemetry
0

What it is

Does one thing well.

Most terminal coding agents either do everything or are a hosted service. Sentinel is a fast, cheap, transparent coding chat: the whole brain is one loop in src/agent/loop.js.

  1. 01

    input

    your turn

  2. 02

    stream

    any provider

  3. 03

    tool call

    sandboxed, in-process

  4. 04

    result

    fed back

↺ repeat until done or MAX_ITERATIONS · yieldstexttool_calltool_resultfinisherror

One streaming client covers

  • OpenAI
  • Anthropic
  • Gemini
  • Groq
  • Mistral
  • DeepSeek
  • xAI
  • Together
  • Fireworks
  • OpenRouter
  • Ollama
  • LM Studio
  • No servers, no telemetry

    The agent loop runs in-process. Nothing leaves your machine except LLM API calls.

  • Cost-aware by default

    Every turn prints tokens and USD. Free models default to $0. Context auto-compacts at 40k.

  • Sandboxed tools

    Reads, edits, grep, bash and more, scoped to the project root, path traversal rejected, every write checkpointed.

  • Sessions as files

    Chats persist as plain JSON. List, switch, delete, export and compact whenever you want.

  • MCP stdio server

    Expose health, ask and review-diff to Claude Desktop, Cursor or any MCP client.

Permissions

Six modes. Fixed allowlists.

Each mode maps to a tool allowlist the model cannot talk its way out of. Switch with Ctrl+M or /mode.

Mode guide

/mode build

Actually making changes

Every tool is available. Each write still creates a checkpoint, so /undo and /redo work across turns.

File edits
allowed
Shell
allowed

Beyond chat

Built to be left running.

An engineer on an engagement states the goal, respects the budget, and leaves a runbook behind. These commands do the same, from files already on disk.

  • sentinel outcome "the sync is flaky"

    Vague ask in, judgeable contract out

    Turns a request into current state, one measurable target, the exact verification command, blast radius, rollback and unknowns, then works to it.

    CURRENT STATE  retries hit 3 before the lock clears
    TARGET         0 failures across 50 sync runs
    VERIFICATION   npm test -- sync · exit 0
    ROLLBACK       revert checkpoint #14
    UNKNOWNS       is the lock TTL configurable?
  • sentinel watch "keep the sync green"

    A presence, not a cron job

    Wakes on a failing command, a moved file or a new HEAD. Steer it from another terminal; the instruction lands on the next tick. Budget-checked before every wakeup.

    $ sentinel watch "keep the sync green" \
        -t "command:npm test" -t git
    ▸ tick 7 · trigger command:npm test (exit 1)
    $ sentinel steer "also check the retry path"
  • blast-radius gate

    Asks once where being wrong is expensive

    Migrations, workflows, lockfiles, auth, billing, infra. The first write is refused until the agent cites the file:line that justifies it and names the rollback.

    ◆ blocked  db/migrate/0042_add_index.sql
      a migration is rarely undone by reverting it
      required: justifying file:line · exact rollback
    ✓ opened   for the rest of this turn
  • sentinel budget --usd 25 --deadline 2h

    Spend that outlives the process

    A ceiling persisted per project. ask, goal and outcome all honour it, and the loop stops hard at the limit rather than letting one more call land.

    active  ████████  $12.40 of $25.00 (50%) · 1h 59m left
  • sentinel handoff <runId>

    The runbook, not the diff

    Writes HANDOFF.md from the recorded trajectory: what changed, what was verified, what was tried and rejected, claims to distrust, what is still fragile. No model, no API key.

    # .sentinel/HANDOFF.md
    ## What was verified
    ## Tried and rejected
       incremental parser patch, broke on nested arrays
  • sentinel risk "npm publish"

    Permission by novelty

    Command shapes are graded per repo. git commit and git push never share a shape, and --force is never collapsed into a placeholder.

    green   git commit -m <msg>   approved shape
    yellow  npm run bench          new, not destructive
    red     git push --force       always asked

Watch

It shows its work.

The agent refuses a risky write, then answers with the line it read and the command that undoes it. A real session, shot as it ran.

Sixty-nine seconds, no narration over the footage. The terminal output is Sentinel's own, at its real speed.

sentinel launch film · 1920×1080 · 69s

Install

Four commands.
Then just type.

Export a Groq key for the free default, or point it at Ollama and skip the key entirely.

Full installation guide
terminal
git clone https://github.com/KunjShah95/SENTINEL-CLI.git
cd SENTINEL-CLI
npm install
npm link

export GROQ_API_KEY=gsk_…
sentinel