Inspiration

AI coding agents can make correct and incorrect changes in the same task. A full rollback removes useful work, while a blind restore may overwrite newer human edits. We wanted recovery that is selective, verifiable, and honest about failure.

What it does

CodeJam Kill Switch creates a host-controlled snapshot before every Agent Run and records the real file changes afterward. Users can restore only selected files across multiple Runs. If a file was later edited by a human, the server reports a conflict and writes nothing.

How we built it

We used React, TypeScript, Fastify, Codex CLI, Volcengine Ark, and a disposable container Runtime. A SHA-256 content-addressed Change Journal stores snapshots outside the Agent workspace. Restore operations use conflict checks, atomic records, and persistent per-file outcomes.

Challenges

The hardest problems were partial restore failures, service interruption, concurrent file changes, sensitive Diff content, and reviewing hundreds of changed files without presenting uncertain states as success.

Accomplishments

We demonstrated a real three-Run recovery: one incorrect file returned to its original state, a correct file remained unchanged, and a later human edit was protected by a structured conflict. Automated tests cover restore failures, restart recovery, conflicts, sensitive content, and large ChangeSets.

What we learned

Safe Agent systems need more than isolation. They need trustworthy evidence, selective recovery, and clear failure states that users can verify.

Built With

Share this project:

Updates

Submission history