Infinite undo for AI coding agents.
SafeSandbox is a local-first developer tool that automatically creates snapshots and checkpoints while AI coding agents (Cursor, Claude Code, Codex, Aider, etc.) modify your repository.
- Automatic snapshots — detects bursts of file changes and creates restore points
- Rollback — restore your codebase to any previous snapshot in seconds
- Timeline — view a human-readable history of what changed
- Protection from destructive AI edits — never lose working code again
- Not a cloud service — everything stays on your machine
- Not a remote IDE
- Not a Docker container
- Not an AI model
- Not a code editor
- A local CLI tool
- A filesystem watcher (via chokidar)
- A git-based snapshot manager
npm install -g safesandbox
# or
pnpm add -g safesandboxOr run without installing:
npx safesandbox init# 1. Initialize SafeSandbox in your repo
cd my-project
safesandbox init
# 2. Start watching for changes
safesandbox watch
# 3. Let your AI agent work...
# SafeSandbox auto-creates snapshots when it detects bursts of edits
# 4. View timeline
safesandbox timeline
# 5. Roll back if something goes wrong
safesandbox rollback 12Sets up SafeSandbox in the current repository. Creates:
.safesandbox/directory with metadata storage- A hidden snapshot branch for internal commits
- Config file with default thresholds
Starts filesystem monitoring. Detects:
- Multiple rapid file changes
- Deleted files
package.jsonchanges- Lockfile changes (
package-lock.json,pnpm-lock.yaml,yarn.lock,bun.lockb)
Snapshots are batched — not every single file write triggers one. You will see output like:
[SafeSandbox]
Snapshot #12 created
Reason: 24 files changed in 8 seconds
Shows snapshot history:
#14 — 24 files changed
#13 — package.json modified
#12 — deleted docker-compose.yml
Restores the repository to the state at snapshot <id>. Asks for confirmation before destructive changes.
SafeSandbox uses git internally for snapshots:
- A hidden branch stores internal commits
- Metadata maps snapshot IDs to commit hashes
- Rollback uses
git checkout+git restorefor safe, precise restoration
No Docker. No overlayfs. No cloud. Just your local git repo + a smart watcher.
After init, a config file lives at .safesandbox/config.json:
{
"thresholdFiles": 5,
"thresholdSeconds": 10,
"ignoredPaths": ["node_modules", ".git", "dist", "build", ".safesandbox"]
}thresholdFiles— minimum files changed to trigger a snapshotthresholdSeconds— time window for batching changes
$ cd my-cursor-project
$ safesandbox init
[SafeSandbox] Initialized in /Users/me/my-cursor-project
$ safesandbox watch
[SafeSandbox] Watching for changes...
# ... you prompt Cursor to "add auth" ...
[SafeSandbox]
Snapshot #1 created
Reason: 12 files changed in 6 seconds
# ... you prompt again, it deletes something important ...
[SafeSandbox]
Snapshot #2 created
Reason: 3 files changed in 4 seconds
$ safesandbox timeline
#2 — 3 files changed
#1 — 12 files changed (auth feature)
$ safesandbox rollback 1
[SafeSandbox] This will restore 12 files to the state at snapshot #1.
Are you sure? (y/N) y
[SafeSandbox] Rolled back to snapshot #1.- Node.js >= 20
- Git repository (run
git initfirst if needed)
MIT