SearchBook a call

RESEARCH / ARCHIVE

kestrel

kestrel is a coding CLI in one static Rust binary that drives Claude Code, Cursor, Kimi, Gemini and Codex or any API key, with six harness packs. $99 once.

From the archive. This page preserves the original publication; product plans and capabilities may have changed. See current open source work.

Windows · macOS · Linux

By velofy

An interactive coding CLI in one static binary. Bring the agent CLI you already run, or bring a key. $99, once.

kestrel 0.1.0

The harness stays. The model is yours to swap.

Thesis

kestrel is a coding CLI of the Claude Code class, shipped as one static Rust binary. It drives the agent CLIs already installed on your machine, or it talks straight to an API key. Six harness packs, detected from the repo, go in with whichever engine runs.

The conventions, review rubric and post-edit checklist do not change when the model does. You change the engine; the standard stays with the repository.

Ships as
one static binary
Written in
Rust, no runtime
Agent CLIs driven
5
API presets
6, plus any base URL
Harness packs
6, auto-detected
Tools in the loop
7, each permissioned
Keys kept in
the OS keychain
Price
$99 lifetime

What a run looks like

Session / one ticket, start to finish

Transcript: kestrel greps and reads app/api/refunds.py, edits it, asks permission before running a shell command, generates an Alembic migration, runs ruff, mypy and pytest, clears the FastAPI and Postgres post-edit checklist, then a four-way fan-out returns a ship verdict and the merge command.

Transcript · kestrel · anthropic:claude-sonnet-4-5 · ~/work/payments-api
$ kestrel
kestrel 0.1.0   anthropic:claude-sonnet-4-5
engines: claude, cursor-agent, codex
packs: fastapi + postgres

> add idempotency keys to POST /refunds

⏺ grep("def refund", app/)
  ⎿ 3 matches
⏺ read(app/api/refunds.py)
  ⎿ 84 lines
⏺ edit(app/api/refunds.py)
  ⎿ +34 -6
⏺ shell(alembic revision --autogenerate -m "refund idempotency")
  ⎿ [y]es [a]lways [n]o  >  a
  ⎿ migrations/versions/9f21c_refund_idempotency.py
⏺ shell(ruff check . && mypy app && pytest -q)
  ⎿ 141 passed in 4.6s

post-edit checklist  fastapi + postgres
  ⎿ PASS  response_model set on every route
  ⎿ PASS  no blocking call inside an async def
  ⎿ PASS  migration is reversible, downgrade runs
  ⎿ PASS  idempotency_key column is indexed

> /quit
$ kestrel --ultra "harden the refund replay path"
  ⎿ fleet    4 attempts, 4 worktrees
  ⎿ panel    correctness / architecture / completeness
  ⎿ chief    winner claude-2, 2 caveats
  ⎿ repair   caveats fixed, same branch
  ⎿ SHIP: yes
  ⎿ git merge fanout/20260801-1142/claude-2

Seven tools sit in the loop: read, write, edit, glob, grep, shell and git. The three read-only ones never prompt. Everything that writes asks first, and answering a once writes the rule into .kestrel/settings.toml so it never asks again.

It runs on what you already have

Engines / 5 CLIs, 6 presets, any endpoint

Agent CLIs it drives

Found on your PATH, probed for a version, then handed the task with the harness prepended.

claude
Claude Code
cursor-agent
Cursor
kimi
Kimi CLI
gemini
Gemini CLI
codex
Codex CLI

Endpoints it speaks

Three wire protocols, six presets you name with one word, and a base URL field for everything else.

anthropic
api.anthropic.com
openai
api.openai.com
openrouter
openrouter.ai/api
gemini
generativelanguage.googleapis.com
moonshot
api.moonshot.ai
ollama
localhost:11434, no key
any OpenAI-compatible base URL
Groq, DeepSeek, Together, vLLM, LM Studio, your own proxy. One line of config.

Keys resolve in one order: environment variable, then smbk, then the OS keychain. kestrel auth writes to the keychain only. A key never lands in a plaintext file and is never echoed to the terminal.

Opinions that travel with the task

Each pack is a set of conventions, a review rubric and a deterministic post-edit checklist. kestrel reads the repository, picks the packs that apply, merges them into one document, and injects it into whichever engine runs the task.

Harness / 6 packs, read off the repo

detects fastapi in pyproject or requirements

FastAPI

  • Async DB session per request, no sync I/O in handlers. No handler calls a blocking driver or requests inside an async def path.
  • Pydantic models at every boundary. Request bodies, query params, and response bodies are typed models, never a raw dict. response_model is set on every route.
  • No business logic in route functions. A route parses input, calls a service function, and shapes the output.

detects manage.py

Django

  • select_related/prefetch_related on every list endpoint that touches a foreign key or reverse relation. An N+1 query is a bug.
  • No signals for business logic. post_save/pre_save are for cross-cutting concerns like cache invalidation.
  • Migrations committed in the same PR as the model change, and makemigrations --check is clean.

detects Cargo.toml

Rust

  • thiserror in libraries, anyhow in binaries.
  • No .unwrap()/.expect() outside tests, main's outermost boundary, or a comment proving the invariant that makes panic impossible.
  • Clippy runs in CI with warnings denied (cargo clippy -- -D warnings).

detects go.mod

Go

  • Errors wrapped with %w, never %v or %s, when the caller might need errors.Is/errors.As on the cause.
  • context.Context is the first parameter of every function that can block, call out, or be cancelled, named ctx, never stored on a struct.
  • go vet and staticcheck (or golangci-lint) run clean in CI.

detects postgres in docker-compose, or a migrations directory

Postgres

  • Every foreign key is indexed. No SELECT * in application code.
  • timestamptz always, never bare timestamp. Migrations reversible, or explicitly and permanently not, with a comment saying why.
  • EXPLAIN (ANALYZE, BUFFERS) is run on every new or materially changed list query before it ships.

detects package.json, or any .html or .css

Design

  • Body text >= 4.5:1 contrast; large text and interactive borders >= 3:1 (WCAG 2.1 AA). A palette that cannot meet these floors is rejected.
  • Flat colors only. Every surface, button, badge and chart fill is a flat solid color.
  • Zero em-dash characters (U+2014) anywhere, in copy, code, comments, or commit messages. Use a comma or a colon instead.

Packs stack. A Django service with a migrations/ directory gets both layers, merged under one header. Run kestrel harness export and the merged document lands at .kestrel/HARNESS.md, readable by you and by any other agent you point at the repository.

It has taste, and it shows its working

Design / 11 aesthetics, 13 pairings

Eleven named aesthetics

Ask for one by name and get the pattern, built in flat colour.

  • Glassmorphism
  • Neumorphism
  • Claymorphism
  • Brutalism
  • Neon glow
  • Grain and noise
  • Bento grid
  • Swiss
  • Color-block
  • Duotone and halftone
  • Terminal

Thirteen curated pairings

Display, body and mono, chosen together, all free for commercial use. Five of the thirteen:

Editorial
Playfair Display / Crimson Pro / Space Mono
Developer lab
Bricolage Grotesque / Work Sans / JetBrains Mono
Luxury fintech
Bodoni Moda / EB Garamond / Martian Mono
Neo-brutalist
Unbounded / Archivo / Space Mono
Freight and logistics
Anton / Albert Sans / Fragment Mono

summit.js 0.4.3 ships inside the design pack, 17KB gzipped. Behaviour composed directly in HTML, no build step, no virtual DOM, no eval, so it passes a strict CSP. Scaffolds use the local copy, so a generated page makes no external requests on first load.

When one attempt is not enough

One judge reading four diffs is a single point of failure, so --ultra replaces the judge with a court. Your working tree is never touched. Every attempt settles on its own branch, and you merge the one that won.

Fan-out / many attempts, one verdict

  1. Task

    one ticket, dispatched once

  2. Fleet

    every agent CLI on the machine, each in its own git worktree

    • claude-1
    • claude-2
    • cursor-1
    • codex-1
  3. Panel

    three judges read every diff, one lens each, in parallel

    • correctness skeptic
    • architecture critic
    • completeness auditor
  4. Chief

    tallies the votes, breaks ties on correctness first, merges the panel caveats into one actionable list

  5. Repair

    the winner goes back into its own worktree and fixes those caveats, as a second commit on the same branch

  6. Ship: yes / no

    the chief reads the final cumulative diff and answers

Every commit goes through ak, which refuses to commit on main, never force-pushes, keeps the history to conventional commits, and opens the pull request.

$99, once

Price / once, not monthly

$99

Lifetime All updates included

  • The binary for macOS arm64 and x64, Windows x64, and Linux x64. No runtime to install, no bash required.
  • Every future release, through kestrel update.
  • All six harness packs, and the design assets with summit.js inside.
  • Multi-agent fan-out, the ultra judge court, and the commit desk.
  • A personal download link, issued on the call.
  • No subscription, no seats, no telemetry, no account to create.
Book the call

The call is the checkout. Thirty minutes with the person who built it. Watch it run on a repository of your choosing, ask anything, and leave with your download link.

Status: v1 in build. Buy now and you get every release from the first, at this price.

Before you book

FAQ / six answers

Windows or macOS?

Both, plus Linux. One static binary for macOS arm64, macOS x64, Windows x64 and Linux x64, with no bash dependency. Remote fan-out over SSH is macOS and Linux in v1.

Are updates included?

kestrel update checks a version file, compares the sha256, and pulls the new binary from your own link. Every release, no renewal.

Which models can I use?

Whichever you already pay for. It drives claude, cursor-agent, kimi, gemini and codex when they are on your PATH, and it speaks Anthropic, OpenAI, OpenRouter, Gemini, Moonshot and Ollama by name. Anything else with an OpenAI-compatible base URL is one line of config, which covers Groq, DeepSeek, Together, vLLM, and any open-weight model you host yourself.

Where do my keys live?

In the OS keychain. Lookup order is environment variable, then smbk, then the keychain. Keys are never written to a config file and never printed back to you. Ollama needs no key at all.

Refunds?

Ask on the call or after it and you get your money back. No form, no window.

Do I get the source?

No. You get the binary and every update to it. Everything else velofy publishes is open source, listed at velofy.co/open-source.