Windows · macOS · Linux
By velofy
An interactive coding CLI in one static binary. Bring the agent CLI you already run, or bring a key. $99, once.
The harness stays. The model is yours to swap.
Thesis
kestrel is a coding CLI of the Claude Code class, shipped as one static Rust binary. It drives the agent CLIs already installed on your machine, or it talks straight to an API key. Six harness packs, detected from the repo, go in with whichever engine runs.
The conventions, review rubric and post-edit checklist do not change when the model does. You change the engine; the standard stays with the repository.
- Ships as
- one static binary
- Written in
- Rust, no runtime
- Agent CLIs driven
- 5
- API presets
- 6, plus any base URL
- Harness packs
- 6, auto-detected
- Tools in the loop
- 7, each permissioned
- Keys kept in
- the OS keychain
- Price
- $99 lifetime
What a run looks like
Session / one ticket, start to finish
Transcript: kestrel greps and reads app/api/refunds.py, edits it, asks permission before running a shell command, generates an Alembic migration, runs ruff, mypy and pytest, clears the FastAPI and Postgres post-edit checklist, then a four-way fan-out returns a ship verdict and the merge command.
$ kestrel
kestrel 0.1.0 anthropic:claude-sonnet-4-5
engines: claude, cursor-agent, codex
packs: fastapi + postgres
> add idempotency keys to POST /refunds
⏺ grep("def refund", app/)
⎿ 3 matches
⏺ read(app/api/refunds.py)
⎿ 84 lines
⏺ edit(app/api/refunds.py)
⎿ +34 -6
⏺ shell(alembic revision --autogenerate -m "refund idempotency")
⎿ [y]es [a]lways [n]o > a
⎿ migrations/versions/9f21c_refund_idempotency.py
⏺ shell(ruff check . && mypy app && pytest -q)
⎿ 141 passed in 4.6s
post-edit checklist fastapi + postgres
⎿ PASS response_model set on every route
⎿ PASS no blocking call inside an async def
⎿ PASS migration is reversible, downgrade runs
⎿ PASS idempotency_key column is indexed
> /quit
$ kestrel --ultra "harden the refund replay path"
⎿ fleet 4 attempts, 4 worktrees
⎿ panel correctness / architecture / completeness
⎿ chief winner claude-2, 2 caveats
⎿ repair caveats fixed, same branch
⎿ SHIP: yes
⎿ git merge fanout/20260801-1142/claude-2
Seven tools sit in the loop: read, write, edit, glob, grep, shell and git. The three read-only ones never prompt. Everything that writes asks first, and answering a once writes the rule into .kestrel/settings.toml so it never asks again.
It runs on what you already have
Engines / 5 CLIs, 6 presets, any endpoint
Agent CLIs it drives
Found on your PATH, probed for a version, then handed the task with the harness prepended.
claude- Claude Code
cursor-agent- Cursor
kimi- Kimi CLI
gemini- Gemini CLI
codex- Codex CLI
Endpoints it speaks
Three wire protocols, six presets you name with one word, and a base URL field for everything else.
anthropic- api.anthropic.com
openai- api.openai.com
openrouter- openrouter.ai/api
gemini- generativelanguage.googleapis.com
moonshot- api.moonshot.ai
ollama- localhost:11434, no key
- any OpenAI-compatible base URL
- Groq, DeepSeek, Together, vLLM, LM Studio, your own proxy. One line of config.
Keys resolve in one order: environment variable, then smbk, then the OS keychain. kestrel auth writes to the keychain only. A key never lands in a plaintext file and is never echoed to the terminal.
Opinions that travel with the task
Each pack is a set of conventions, a review rubric and a deterministic post-edit checklist. kestrel reads the repository, picks the packs that apply, merges them into one document, and injects it into whichever engine runs the task.
Harness / 6 packs, read off the repo
FastAPI
- Async DB session per request, no sync I/O in handlers. No handler calls a blocking driver or
requestsinside anasync defpath. - Pydantic models at every boundary. Request bodies, query params, and response bodies are typed models, never a raw
dict.response_modelis set on every route. - No business logic in route functions. A route parses input, calls a service function, and shapes the output.
Django
select_related/prefetch_relatedon every list endpoint that touches a foreign key or reverse relation. An N+1 query is a bug.- No signals for business logic.
post_save/pre_saveare for cross-cutting concerns like cache invalidation. - Migrations committed in the same PR as the model change, and
makemigrations --checkis clean.
Rust
thiserrorin libraries,anyhowin binaries.- No
.unwrap()/.expect()outside tests,main's outermost boundary, or a comment proving the invariant that makes panic impossible. - Clippy runs in CI with warnings denied (
cargo clippy -- -D warnings).
Go
- Errors wrapped with
%w, never%vor%s, when the caller might neederrors.Is/errors.Ason the cause. context.Contextis the first parameter of every function that can block, call out, or be cancelled, namedctx, never stored on a struct.go vetandstaticcheck(orgolangci-lint) run clean in CI.
Postgres
- Every foreign key is indexed. No
SELECT *in application code. timestamptzalways, never baretimestamp. Migrations reversible, or explicitly and permanently not, with a comment saying why.EXPLAIN (ANALYZE, BUFFERS)is run on every new or materially changed list query before it ships.
Design
- Body text >= 4.5:1 contrast; large text and interactive borders >= 3:1 (WCAG 2.1 AA). A palette that cannot meet these floors is rejected.
- Flat colors only. Every surface, button, badge and chart fill is a flat solid color.
- Zero em-dash characters (U+2014) anywhere, in copy, code, comments, or commit messages. Use a comma or a colon instead.
Packs stack. A Django service with a migrations/ directory gets both layers, merged under one header. Run kestrel harness export and the merged document lands at .kestrel/HARNESS.md, readable by you and by any other agent you point at the repository.
It has taste, and it shows its working
Design / 11 aesthetics, 13 pairings
Eleven named aesthetics
Ask for one by name and get the pattern, built in flat colour.
Thirteen curated pairings
Display, body and mono, chosen together, all free for commercial use. Five of the thirteen:
- Editorial
- Playfair Display / Crimson Pro / Space Mono
- Developer lab
- Bricolage Grotesque / Work Sans / JetBrains Mono
- Luxury fintech
- Bodoni Moda / EB Garamond / Martian Mono
- Neo-brutalist
- Unbounded / Archivo / Space Mono
- Freight and logistics
- Anton / Albert Sans / Fragment Mono
summit.js 0.4.3 ships inside the design pack, 17KB gzipped. Behaviour composed directly in HTML, no build step, no virtual DOM, no eval, so it passes a strict CSP. Scaffolds use the local copy, so a generated page makes no external requests on first load.
When one attempt is not enough
One judge reading four diffs is a single point of failure, so --ultra replaces the judge with a court. Your working tree is never touched. Every attempt settles on its own branch, and you merge the one that won.
Fan-out / many attempts, one verdict
- Task
one ticket, dispatched once
- Fleet
every agent CLI on the machine, each in its own git worktree
- Panel
three judges read every diff, one lens each, in parallel
- Chief
tallies the votes, breaks ties on correctness first, merges the panel caveats into one actionable list
- Repair
the winner goes back into its own worktree and fixes those caveats, as a second commit on the same branch
- Ship: yes / no
the chief reads the final cumulative diff and answers
Every commit goes through ak, which refuses to commit on main, never force-pushes, keeps the history to conventional commits, and opens the pull request.
$99, once
Price / once, not monthly
$99
- The binary for macOS arm64 and x64, Windows x64, and Linux x64. No runtime to install, no bash required.
- Every future release, through
kestrel update. - All six harness packs, and the design assets with summit.js inside.
- Multi-agent fan-out, the ultra judge court, and the commit desk.
- A personal download link, issued on the call.
- No subscription, no seats, no telemetry, no account to create.
The call is the checkout. Thirty minutes with the person who built it. Watch it run on a repository of your choosing, ask anything, and leave with your download link.
Status: v1 in build. Buy now and you get every release from the first, at this price.
Before you book
FAQ / six answers
Windows or macOS?
Both, plus Linux. One static binary for macOS arm64, macOS x64, Windows x64 and Linux x64, with no bash dependency. Remote fan-out over SSH is macOS and Linux in v1.
Are updates included?
kestrel update checks a version file, compares the sha256, and pulls the new binary from your own link. Every release, no renewal.
Which models can I use?
Whichever you already pay for. It drives claude, cursor-agent, kimi, gemini and codex when they are on your PATH, and it speaks Anthropic, OpenAI, OpenRouter, Gemini, Moonshot and Ollama by name. Anything else with an OpenAI-compatible base URL is one line of config, which covers Groq, DeepSeek, Together, vLLM, and any open-weight model you host yourself.
Where do my keys live?
In the OS keychain. Lookup order is environment variable, then smbk, then the keychain. Keys are never written to a config file and never printed back to you. Ollama needs no key at all.
Refunds?
Ask on the call or after it and you get your money back. No form, no window.
Do I get the source?
No. You get the binary and every update to it. Everything else velofy publishes is open source, listed at velofy.co/open-source.