Build1 publisher3 min readPublished
Claude Code's /rewind restores only files its own three editing tools touched
Anthropic's docs say Claude Code checkpoints track only its Write, Edit and NotebookEdit tools, so /rewind cannot restore what bash or a subagent changed. Recovering from an agent's rm or sed -i means git or a snapshot taken before the command ran.
The Engineer · Build desk

What happened
- The docs' limitations section opens with "Checkpointing does not track files modified by bash commands," names rm, mv and cp, and the SDK page adds echo redirects and sed -i.
- A restore skips symlinked and hard-linked files and prints "Restored the code, but skipped N files" when it does.
- A retention sweep deletes a session's file snapshots about 30 days after the last save, and a rewind to one of them then reports "No files were restored".
- Issue #16976, opened January 9, 2026 to ask for programmatic checkpoint restore, was closed as not planned.
- Four open-source projects now snapshot what shell commands are about to change, and all four are still pre-1.0 releases.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- constraint An agent's rm -rf or shell-run migration can be undone only if another layer copied the files first, because Claude Code's checkpoint never recorded those writes.
- decision Falling back on git forces a choice about the agent's shell permissions, because an agent allowed git clean or git checkout . can erase the uncommitted work git was meant to protect.
- exposure Databases, clusters and remote branches stay out of reach of every local snapshot, so a DROP TABLE or kubectl delete run by an agent needs a backup on the remote side.
- precedent With programmatic restore declined, recovery for shell actions in Claude Code is left to outside projects built on its hook events.
Inside that boundary the feature is well built. Claude Code takes a checkpoint before each user prompt [1]. /rewind, or Esc twice on an empty prompt, restores code, conversation or both from the 100 most recent checkpoints in a session [3]. The post that catalogued these limits calls /rewind the right tool for a refactor that went sideways [21]. It argues that most of what a coding agent does is edit source through its own tools, and each of those edits comes back in a keystroke [21].
I think the boundary follows from what the harness can see. When its own editor writes, it knows the file. A shell command is a string, and knowing what it will touch means parsing it. The Rust project bashward does that parsing. It hooks Claude Code's PreToolUse event for the Bash tool, reads each command, and snapshots the paths that rm, mv, cp, dd, sed -i and shell redirects are about to touch, using APFS clones on macOS [12].
The post gives a scratch-repo test. Have Claude Code create a.txt with its editor and b.txt with `echo hi > b.txt`, add a line to each the same way, then rewind to the first checkpoint. Per the docs, a.txt comes back and b.txt stays exactly as the shell left it [10].
The uncovered commands are the destructive ones. According to the post, most commands outside the checkpoint delete or overwrite files: an agent that decides a directory is stale runs rm -rf, a migration runs through a shell, and neither goes near the Edit tool [22]. For subagent edits the docs point to git [5]. The page closes on Anthropic's own heading that checkpoints are not a replacement for version control [9].
The author works at Eon, which sells cloud data protection [20], and argues git covers less than that advice implies. Git holds committed state, untracked files vanish under `git clean`, and the agent has the same shell the user does, so `git checkout .` is one tool call away [11]. git-safepoint was built for that case. It uses git plumbing to capture tracked and untracked files before every destructive command, so one file can be restored without touching HEAD [13]. It is at v0.0.1, dated June 23, 2026 [13].
The other two projects hook in at different layers. stepback wraps any agent, watches the filesystem instead of one tool's hooks, and can rewind the agent's on-disk transcript along with the files [14]. Doover journals every shell action, classifies commands against a registry of 152 reversibility rules, and snapshots affected paths anywhere on disk, including outside the project [15].
Doover's README is candid about its ceiling. A section titled "What doover is not" flags DROP TABLE, kubectl delete and force-pushes as unrecoverable, because no local snapshot can bring back remote state [18]. By default it keeps 7 days and 5 GiB of history on the same disk as the files it protects [19].
In a setup where agents run migrations and cleanup scripts through the shell, I'd keep /rewind for source edits and put a pre-command snapshot hook in front of Bash. Anything irreplaceable gets a backup that does not live on the agent's disk. The author advises trying the hooks in a scratch repo before putting one in front of work you can't lose [24].
What to watch
- A revision to Anthropic's checkpointing page that extends tracking to Bash tool writes or subagent edits.
- A reopening of issue #16976, or another supported way to trigger checkpoint restore outside the UI.
- Any of bashward, git-safepoint, stepback or doover reaching 1.0, or doover's 152-rule reversibility registry growing.