Skip to content

Releases: FerroxLabs/murage-releases

Murage 0.1.61

Choose a tag to compare

@FerroxLabs FerroxLabs released this 30 Sep 07:24

Murage 0.1.61

What's new

  • A What's new page shows the highlights once after you update. Each card takes you straight to what it is about: the Team map, Image generation, Models, or the no activity limit in Settings. It opens once and not again.

Rooms

  • Bots in a room always see each other's replies. Every member of a room now reads what its teammates said there, also after you add or remove a member or change a setting. Before, a change like that could hide earlier replies from the bots, so a teammate would redo work that was already done.
  • A reply that used something you deleted is shown as withheld. When a room reply drew on something you have since deleted or changed, bots see a short note that the reply was withheld instead of its text, and you see "Bots no longer see this reply" under it. The same holds when that reply would come back through memory, through a copy of it in another conversation or through a delegated result.
  • A pinned note that uses a withheld reply is left out. If you pin a room's notes and later forget a reply they rest on, bots are no longer given that pinned note. Murage says once in the room that the pinned note uses a reply the bots no longer see, so you can unpin it and pin a newer one. Replies made after that stay visible to every teammate.
  • Forgetting a room's notes forgets only the notes. When you forget a room's notes in Memory, the earlier replies they quoted stay visible to the bots. Only a reply that was made with those notes is withheld.
  • A reply you chose to forget says so. When you forget a room reply itself, you see "Bots no longer see this reply: you chose to forget it." under it, and bots see that the owner chose to forget it.
  • Room memory recall reaches every bot in the room, and a small pin no longer stops the room. Bots in a room now bring back the room's notes and what they remember, also when a teammate's reply has just updated those notes. Pinning a short memory no longer makes every bot in the room fail to answer.
  • One plain line when a turn is refused. If your pinned memories are too long for a bot's model, Murage says so once, in plain words, with what to do: unpin some in Memory, or choose a model that takes more context. A goal run refused for the same reason shows why on its card.
  • Rooms with long histories keep working. A room with a very long history no longer stops answering.
  • Messages Murage cannot confirm stay outside your memory. A room message whose sender Murage cannot confirm no longer gives bots what they remember about you, your preferences or your teams, and the same goes for the handoffs it starts.
  • Each teammate gets its turn. A handoff to a teammate starts right after that teammate's own room reply, instead of after the whole round, and a teammate that is still waiting for its turn keeps its place.
  • Murage says when a bot could not answer. When a bot in a room could not answer or stopped part way, Murage says so in its own line with the reason, so it never reads as the bot's own words.
  • Room replies keep going while a bot is working. A room reply no longer stops at a fixed five minutes. It stops only after the set number of minutes with no activity (20 by default), or when you press Stop.
  • A bot that cannot start its turn frees the room. If a bot cannot start its turn in a room, the room is freed and a plain line says so, instead of staying busy.

Teams and tools

  • Bots on Fuigo can reach their teammates again. A bot that runs on Fuigo can now ask a teammate, hand work off and use Murage's own tools, in a room and in a direct chat. Before, those calls failed, so a lead on Fuigo ended up doing the work alone.
  • Every engine gets tool names it can call. The names of Murage's tools in what bots read, including image tools and error lines, now match the engine each bot runs on, so a bot no longer gets "Tool not found" when it follows them.

Image generation

  • Every saved image-capable key appears in Image generation. A key you saved under Settings → Models for a provider that makes images now also shows in Image generation, including xAI keys and keys saved with a slash at the end of their address.
  • Your Google Gemini key works for chat and images. Add a Google Gemini key under Settings → Models and bots can chat on Gemini models, and Image generation can use it too. A key saved under the wrong provider is never sent to another one; Settings shows it for you to review.
  • Sending more than 10 images no longer fails the turn. The first 10 go to the bot, and one plain line says how many were not sent. The message box tells you before you send.
  • Image generation takes longer prompts and more shapes. Each image model now has its own prompt length, so a model that takes a long, detailed prompt gets all of it. You can ask for portrait and landscape shapes such as 9:16, and the approval card shows the prompt length, the model and the size that will be made. When a model cannot make what you asked, Murage says so before anything is sent.
  • Images that take a while are never cut off. An image you approved keeps going until it is finished, however long the model takes. If nobody answers the approval card, the bot is told plainly that the card closed and nothing was sent.
  • Your image library stays yours. Your saved image styles and reference packs are used only when you talk with your bots, not when someone else messages them.
  • Saved prompt blocks. Save a part of an image prompt you use again, such as a character or a brand look, as a named block. Bots send saved blocks first, then the scene. Every save is a new version, and earlier images keep the version they used. You and your bots can add them: find them under Settings → Tools & Connections → Image generation.
  • Reference packs. A bot can save up to 16 reference images from a conversation as a named pack and use the pack again later. Murage checks each image against its saved copy every time the pack is used.
  • More control over each image. Where the model supports it, bots can ask for several images at once, PNG, JPEG or WebP, a seed, a transparent background, or an exact size in pixels.
  • Long renders are followed to the end. For models that send their images in parts or work as a longer job, Murage follows the render until it is done, and a render that was interrupted picks up where it was instead of starting again.
  • See what each model can do. Image generation in Settings shows each model's prompt length and sizes, when it last worked, and a Check this model now button. A daily check of the default model is off unless you turn it on.
  • A bot that leaves out a detail an image needs is told what to add. When a bot asks for an image without a detail the request needs, it gets one plain line saying what to send, so it gets it right on the next try.
  • Clearer cards and lines. The approval card names the connection the way Settings does, and when a model sends back no image, Murage says why. The line under a generated image names the provider as Settings does, for example "through Flux Router".

Long work

  • A working bot is never stopped by a fixed clock. A turn that is still working stops only when it goes quiet for the time you set, when you press Stop, or when it reaches a budget you set. This holds on every engine, including Antigravity and Box.
  • Bots on OpenAI-compatible engines, MiniMax and xAI wait for slow answers. A model that takes a while to answer is no longer cut off after two or three minutes of waiting.
  • Long commands on a bot's computer run to the end. A command that takes a long time keeps running as long as it shows activity, and stops when it finishes, goes quiet, or you press Stop.
  • Clear stop lines. When a turn does stop, the line in the chat says what happened in plain words, without setting names or internal codes.

Languages

  • Translations are up to date and load when you pick them. The seven translated languages cover the newest screens, and each one loads only when you choose it, so Murage opens faster.

Mac

  • The first-run step bar clears the window buttons. On a Mac, the steps across the top of the first run no longer sit under the close, minimize and zoom buttons.

Backups

  • Your pre-update backup choice is kept. If you tick "Back up before installing an in-app update" under Advanced before you first turn on backups, that choice is now kept. Where this install cannot take a backup before an update, setup tells you so.
  • Your recovery key stays out of folders that sync to the cloud. When Murage chooses where to save your backup recovery key, it no longer uses a folder that syncs to OneDrive, iCloud Drive, Dropbox or Google Drive, and it starts with your home folder instead of Documents. If you pick a folder that syncs, Murage tells you and asks before it saves anything there.
  • A recovery key already in a folder that syncs is pointed out once. If an earlier version saved your recovery key in a folder that syncs to the cloud, the Backups page tells you once and offers Move and Keep here. Move puts a checked copy in your home folder, points your daily backups at it and then removes the old file. The cloud service may still keep the old file in its recycle bin, so Murage reminds you to empty it there. If Move cannot finish, Murage tells you what happened and what to do next.
  • The off-site password file follows the recovery key's rule. The password file for off-site backups is saved in your home folder, never in a folder that syncs to the cloud, and Murage asks first if you pick one that does.

Murage 0.1.60

Choose a tag to compare

@FerroxLabs FerroxLabs released this 27 Sep 15:16

Murage 0.1.60

Please read

  • Routines now have their own approval level. Each routine runs at a level you choose (routine editor, Advanced > Approvals for this routine): Ask, Auto, Full access or No limits. A routine you have not set follows its bot's level at the moment it runs, so a bot on No limits no longer stops its own routines to ask. The routine's conversation, its editor and its approval cards all show the level that actually applies.
  • A routine that needs you says so straight away. When a routine run hits a question or an approval, you hear about it at once and the run ends as "waiting on you", instead of sitting until it times out.

Connected apps

  • Connected apps stay connected. One failed check of the connected-apps service used to leave every bot without its apps until Murage restarted. Each bot's turn now checks again, so a short network blip no longer cuts your bots off.

Routines

  • Long instructions arrive whole. A routine's instructions can be up to 100,000 characters, and the editor tells you before you go over. Nothing is cut off.
  • Always allow for this routine. An approval card raised by a routine offers Always allow for this routine, which covers that same command or place for that routine only.
  • One conversation per routine. Each routine keeps one conversation, so runs no longer pile up as separate conversations.
  • Fewer false stops on Auto. Deleting inside a bot's own folders and temporary files is no longer treated as dangerous. Stopping other programs still asks.

Approvals

  • Always allow this exact command. A card for a command offers Always allow this exact command here. Each bot lists what it always allows under Bot settings > Permissions > Always allowed, and you can remove any of it.
  • Fewer false stops. Text a command writes into a file, and scripts handed to Python or Node, are judged by what they actually delete, not by words that happen to appear in them.
  • Pi asks first. Bots on the Pi engine now ask Murage before running commands, editing outside their folder or using connected apps, like every other engine.
  • Only you can say yes. Only your own desktop app and paired devices can answer an approval card. A message whose sender Murage cannot confirm runs as an unattended turn.
  • Engines that cannot ask. The permission menu says when a bot's engine cannot ask you, on the levels where that means it has to refuse some commands.

Inbox

  • A cleaner Inbox. I don't use, Turn it off and Dismiss all now take effect straight away, the list holds still while it refreshes, and sections are tidier. Sign-in commands have a copy button.

Conversations and teams

  • Snooze. Snooze a conversation from the sidebar or a conversation list. Conversations with a question waiting show a badge.
  • Manage teams. Rename a team, change its members and its lead, or delete it, from the sidebar or the channel details.
  • Deleting conversations. Deleting the last conversation with a bot or in a channel leaves a fresh one, and errors are shown instead of failing quietly.
  • Edit and rerun. Editing a message and running it again no longer starts twice.
  • Who said what. In a channel with tool activity hidden, every bot reply is labelled with the bot that wrote it.
  • Menus fit the window. A bot's More actions menu and the other sidebar menus open above or scroll when the window is short, so Archive and Delete are always reachable.
  • Handoffs between bots keep moving. A handoff waiting for a busy teammate starts as soon as they are free, can be stopped from the conversation, and never holds up a backup.
  • Queued messages. A direct message sent while the bot is busy in a channel waits its turn instead of failing.

About me

  • About me. Settings > About me holds a short profile of you. Your bots read it on your own turns and never on turns started by other people or webhooks. What shapes a bot has a switch for it.

Voice and notifications

  • Voice picker. Every voice in the list has its own play button.
  • Notification sounds. Turn off notification sounds on this computer.
  • Voice notes. A voice note is dropped cleanly when the turn ends while it is being made.

Off-site backups

  • Back up to your own server over SFTP. Keep an encrypted off-site copy on a NAS, a home server or any server you can reach over SFTP. Murage makes its own key for the server, shows you what to add to the server, and asks you to confirm the server's identity once.
  • Murage sets up the storage for you. For SFTP and S3-compatible storage, Murage creates the backup store and its password itself. You can save a copy of the password wherever you like.
  • Off-site copies on every computer. Off-site copies now work on Intel Macs, Windows and Linux as well as Apple silicon Macs.

Privacy

  • Deleting a conversation deletes it everywhere. Its messages, files, attachments and the history each engine kept for it (Claude Code, Codex, Gemini, Qwen, OpenCode, Kimi, Cursor, Droid, Hermes, Antigravity and Fuigo) are removed. The approvals log keeps only the time, bot and verdict, and any unsent draft of it is cleared from the app. The confirmation says how many saved files go with it, and anything Murage could not remove is listed afterwards.

Web app in your phone's browser

  • Photo uploads work again. Uploading an image from the web app in your phone's browser no longer fails, and the web app loads faster.

Polish

  • Numbers stay numbers. A reply of "391." shows as 391., and numbered lists keep their starting number.
  • Plain names for app tools. Approval cards, activity and the Inbox say "Connected app: Gmail send email" rather than internal tool names.
  • Connected count. The Connected apps tab counts only apps that are working, and names any that are not ready yet.
  • Longer commands on cards. Approval cards show commands of up to 4,000 characters, marked where they are cut.
  • Team templates. A team made from a template gets a one-line purpose as its channel instructions, and skills that failed to switch on for some templates now work.
  • Help inside the app. Ask a bot how Murage works. On most engines it answers from Murage's own help pages.

Reliability

  • A backup that stops tells you. If a backup can't finish, an Inbox item and a notification say what stopped it and what to do.
  • Backups tell you what they wait for. If a bot is waiting for your answer when a backup is due, the Backups page and the Inbox name the bot, and the backup starts as soon as you answer.
  • Turning an engine off stops only that engine's work, and says so in plain words. A routine waiting for your answer no longer holds up the bot's other conversations.
  • Stalled turns. A turn that stops making progress is noticed from the moment it starts, with allowances for waits that are expected.
  • VPS turns. A turn waits for a busy VPS instead of failing, and a command that times out stops everything it started.
  • Usage totals. Usage counts the tokens actually bought, not cached re-reads, and a missing count shows as unknown, not zero.
  • Backups work from start to finish. Turn on backups now opens setup, makes your recovery key, switches daily backups on and takes the first backup straight away. Before, it stopped at once with "Backup settings could not be updated". Backups no longer refuse data folders with newer settings or bots that have skills. The option to save a copy of your recovery key stays after setup, and restoring onto a new computer works. Backups and restores also include snoozed conversations. Reviewing a restored installation works the first time. Backups while Murage is closed are checked end to end, and every backup and restore message now says in plain words what to do next.
  • Nothing in a bot's folder stops a backup. Shortcuts, unusual file names and rebuildable folders such as node_modules and virtual environments no longer stop a backup. Anything left out is listed by name afterwards, so you know exactly what was skipped.
  • USB sticks. Backups work on USB sticks and drives formatted exFAT. On Windows, a network folder or USB stick is refused when you choose it, with a sentence saying why, because Windows can't lock those down to your account.
  • Windows. Backups and off-site copies work for standard accounts, names with spaces, deep folders and roaming profiles. A password file you choose is refused if other accounts can open it.
  • Linux AppImage. Backups while Murage is closed now work in the AppImage as well as the .deb.
  • Restored routines. A restored routine follows its bot's approval level, and any Always allow it had is cleared, until you set them again.
  • Missing backup folder or recovery key. If the backup folder or recovery key is moved or its drive is unplugged, Backups names which one is missing, adds an Inbox item and sends a notification, instead of waiting quietly.
  • Undo a restore. Undoing a restore into a separate folder takes you back to your original installation.
  • Choosing a new backup folder turns daily backups back on and takes the first backup straight away.
  • Paired devices. murage devices lists your paired phones and murage devices remove unpairs one. murage pair tells you straight away when all 20 device slots are in use.
  • Plan checklist. A to-do list a local model writes into its answer becomes the plan checklist.
  • The date and time now travel with each message rather than in the bot's standing instructions.
  • Codex and Claude fixes. Codex's own desktop browser and computer tools are off inside bots, Opus 5.5 reports its 1M context window, and a Stop during a Claude Code prompt settles as cancelled.
  • Bigger download. The app is a few MB larger because its web pages come pre-compressed, which makes them open faster.

Murage 0.1.59

Choose a tag to compare

@FerroxLabs FerroxLabs released this 24 Sep 23:32

Murage 0.1.59

Please read

  • Murage is now licensed AGPL-3.0-or-later. Murage as a whole, including every Ferrox Labs change and addition, is now under the GNU Affero General Public License, version 3 or later. If you run a modified copy of Murage as a service for other people, you publish your changes. The OpenMausBot portions that Murage builds on remain under Apache-2.0, and NOTICE keeps their attribution. Releases before 0.1.59 remain available under Apache-2.0.
  • Full access now stops at a few lines. A bot on Full access still does ordinary work without asking, but it now stops and asks before deleting anything outside its own folder, before paying for anything, and before messaging someone for the first time or posting in public. If you want the old behaviour, choose the new No limits level (see Approvals).

What's new

  • What's new. After updating, Murage shows what changed once, with a Show me button for each feature. Reopen it any time from the Help menu.

Tray

  • Tray. The menu-bar icon now shows the Murage glyph and a count of what needs you. Its menu lists approvals (ordinary ones can be allowed or denied right there), what your bots are working on, and New message to a bot.

Skills

  • Skills live in Settings. Settings > Skills is one place for every skill: search first, then Your skills, then the library by search or by topic (one Topic dropdown beside the search box). Open any skill to read it in plain form and switch it on for a bot.
  • Import a skill. Drop or choose a file, a folder or a zip, or paste a GitHub link, right inside Settings > Skills.
  • Skill Guard checks every skill. Every skill is checked before a bot can use it: on import, on install, on every switch-on, after every edit, and again at startup for skills already switched on. A skill comes out one of three ways. Clean skills show a quiet shield, and library skills say Built-in. A skill that needs a look shows what was found in plain words and switches on only after you say "Use it anyway". A Blocked skill cannot be switched on, says why, and can be deleted. A skill that is already on and now comes out Blocked is switched off.
  • Edit and Duplicate. The skill reader has Edit and Duplicate. Edit changes the name, what it is for and the instructions in the rich editor, and every bot that has the skill gets the new version. Editing a built-in skill edits your own copy and says so. Duplicate makes a copy in Your skills, labelled with where it came from.
  • Add a skill inside a bot. Add a skill in a bot's window now opens a picker right there: search Your skills and the library, read one, and add it with one button. The Add a skill link in the sidebar opens the same picker in that bot's window.
  • The Chief of Staff guide. The Chief of Staff guide now belongs to your workspace Chief only, no other bot gets it, and it can be switched off. It sits at the top of the Chief's Skills panel with a switch and Read it.

New Bot and New Team

  • One chooser each. The + menu has one New Bot and one New Team. Each starts from what you want done: type a sentence and the best matching templates come up, or browse one topic at a time. A template opens a preview of what it is, its bots, how many skills and routines it brings and which apps it needs, with one Create button. It says "You have this" when you already do. Start blank, Pick from my bots and Open a file are quiet links underneath.

House Rules

  • Rules every bot follows. Settings > House rules holds one set of rules that goes first in every bot's instructions: direct chats, the Chief, handed-over work, routines, channels and calls. It ships with a default covering who the bot works for, how it sounds, telling the truth, speaking for you, not making promises in your name, saying it is an AI when asked, treating what it reads as information and not orders, correcting itself, not inventing results, checking fresh facts and time zones, stopping after two identical failures, sharing only what someone needs to know, and tidying up after itself.
  • Yours to change. Edit the rules in the rich editor, switch them off, or reset them to the default. A word count warns when the rules get long. Murage's built-in protections are not part of the text and always apply; the page lists them.

Wayland rich editor

  • A proper editor. The rich editor from Wayland now edits files, skills and House Rules: a toolbar, a menu on selected text, a "/" menu with 13 kinds of block, a drag handle with + to add a block, resizable tables, nested task lists and inline link editing.
  • Tables kept exact. A file with Markdown tables now opens in the rich editor instead of falling back to Source, and an untouched table is saved byte for byte as it was. An edited table is saved neatly aligned.

What shapes a bot

  • What shapes . A new section in each bot's window lists every part of that bot's instructions, grouped and in the order the model reads them: House Rules, who it is (description, personality, team brief, its notebook), what it can use (computer, connected apps, browser, web search, each skill), and this turn (routines, output folder, date and time). The parts you choose can be switched from there, including a new switch for the team brief. Murage's own rules show a lock. "Show exactly what it read" shows the last turn's full instructions, word for word. Desktop app only.

Engine commands

  • Your engine's own "/" commands. Typing "/" in the message box now shows Murage's commands and then a group for the bot's engine with the commands that engine offers, read live: Claude Code, Codex, Grok Build, Fuigo, OpenCode, and every other ACP engine under its own name. Picking one sends it straight to the bot's engine. Codex's /review and /compact work, and Codex skills appear there too. Commands never interrupt a turn that is already running.

Approvals

  • Full access stops before the lines that matter. Under Full access a bot now stops and asks before deleting anything outside its own folder (including through Finder, scripts and code), paying for anything, and messaging someone new or posting in public, such as a first comment, issue or release on a GitHub repository. Messages to you, your own linked accounts and the person a channel conversation is with never stop. Engines under Full access now send their permission asks to Murage so these checks hold for Claude Code, Codex and ACP engines alike.
  • Allow once, Allow for this task, Always allow. A stop card offers all three. Allow for this task covers the same folder, recipient or payee until the task ends. Always allow is scoped to that same folder, recipient or payee, never to everything. The same choices are on the desktop, in the Inbox and on Telegram. You can also allow a place for the task in chat, in your own words, on a conversation you started; the chat then notes exactly what was allowed.
  • New No limits level. The level choice is now Ask, Auto, Full access and No limits. No limits lets deleting, paying and messaging go ahead on the turns Full access covers, and still asks before reading your keys and passwords. It is desktop only and shows its own one-time warning per bot.
  • One quiet line instead of a chip per step. Steps approved under Full access or No limits fold into one line, "Approved N steps", that counts up and opens to list them.

Bots know the time

  • Date, time and time zone. Every turn now tells the bot today's date, the time and your time zone. Bots no longer get times of day wrong in routines and replies.

Voice

  • Real-time calls. A call now starts speaking on the first sentence instead of waiting for the whole answer. A fast voice layer answers straight away, does quick lookups, and hands real work to the bot's own engine, with live status while the engine works. You can talk over the bot on macOS, Windows and Linux, Mute replaces Interrupt, and a spoken "stop" stops it at once. Approvals are asked out loud in plain words, and "yes for the rest of the call" covers ordinary requests until you hang up. A note of the call is left in the chat.
  • Voice through Flux. Calls and voice notes speak, listen and look things up through Flux by default. Your own keys (OpenAI, xAI, ElevenLabs and others) are optional and still work.
  • Voice notes. A bot can send an answer as a voice note in its own voice, in the chat and on Telegram, Slack and Discord.
  • Voice picker. Every Flux voice in one list (41 in all), each with its own name, how it sounds and its accent, for example "Kira: Upbeat, confident, American", grouped by female, male and neutral. Try shows Loading and Stop while it plays.
  • A voice per bot. Each bot now picks its own voice service next to its voice, so bots in one room can sound different. xAI voices are available with your own xAI key or through Flux.

Web search

  • Web search through Flux. Settings offers Flux Router as a web search provider, using the Flux key saved under Models, so bots answer with what is current on the live web.

Browser

  • A refused built-in browser says what to do. When the built-in browser refuses to start because the app was installed over an older copy, the message now says to reinstall Murage, instead of pointing at an optional browser engine.

Models

  • New models in the engine pickers: Claude Opus 5.5 (claude-opus-5-5), GPT-6 Sol and GPT-6 Luna (gpt-6-sol, gpt-6-luna), and Grok 4.7 (grok-4.7, with its 500k context window). Defaults are unchanged.

Chat

  • Math and diagrams. Chat now shows math written as $$...$$, [...] and (...). A single dollar sign on its own is never math. Mermaid diagrams are drawn in a sealed frame that has no access to the app.
  • Long conversations open faster. The desktop loads the newest 100 messages and pages back as you scroll, instead of loading every message of every conversation at startup.
  • **Saved text ...
Read more

Murage 0.1.58

Choose a tag to compare

@FerroxLabs FerroxLabs released this 22 Sep 18:25

What's Changed

Other changes

Full Changelog: https://github.com/FerroxLabs/murage/commits/v0.1.58

Murage 0.1.57

Choose a tag to compare

@FerroxLabs FerroxLabs released this 20 Sep 10:01

What's Changed

Other changes

Full Changelog: https://github.com/FerroxLabs/murage/commits/v0.1.57

Murage 0.1.56

Choose a tag to compare

@FerroxLabs FerroxLabs released this 19 Sep 17:13

Murage 0.1.56

Please read

  • A new API key could go to the previous provider. If you use the OpenAI-compatible engine and moved it to a different provider, then turned any engine on or off (or set an engine's CLI path), Murage kept the old address and sent your new key there. That is fixed, and a settings file that already carries the old address is repaired when it loads. Connections with their own key are untouched.
  • Windows: scheduled backups can be set up again. On 0.1.55, choosing a destination and recovery key for a scheduled backup always failed on Windows. If setup failed for you, choose them again. Existing schedules were not affected.

Bots and teams

  • Every bot is itself, everywhere. Each bot now brings its own notebook (MEMORY.md) and its team's shared instructions to every conversation: direct chats, handed-over work, routines and channels. The team instructions you could already edit are now actually delivered; before, no bot received them. In a channel, each bot now also keeps its own memory and its team's, alongside the channel's, instead of only the channel's. A bot changes its notebook only when you ask it to remember, forget or correct something, and routines read it without changing it.
  • New Team, right in the + menu. The + menu now names what each item makes: New Bot, New Bot from Template, New Team and New Channel, with Export bots and Archived bots below. New Team asks for a name, the bots, and optionally a lead and team instructions, all in one step. Before, making a team meant finding "Move to section" on each bot. Teams are now called teams everywhere, so a bot's menu reads "Move to team…".
  • Talk to Moss, get Moss. In a channel, "Moss, can you…" now goes to Moss, not the channel lead, with or without the @. Bots are told never to answer as another bot, and a Chief of Staff no longer picks up messages addressed to someone else.
  • The right face on every message. In a channel, a reply from a bot that isn't a member, such as a teammate answering work handed to it, showed the default flame mascot instead of that bot's own avatar. It now shows the real avatar and name.
  • A new channel task starts unlocked. After New task in a channel, the folder card kept saying the folder was fixed for the task until you reloaded. It now shows the new task's real state straight away.
  • Private notes stay private. In a channel or conversation that includes people from Slack, Discord or Telegram, your bots' private notes and team instructions are left out, and only what you have explicitly shared is used.

Backups

  • Backups have their own section. Backups moved out of General into a Backups section in Settings. At the top, "Your backups" says when the last backup ran, how big it was, when the next one is due, whether an off-site copy is on, and anything that needs a look. Setup is three numbered steps: where to save, your recovery key, and when. The time zone is a list set to your computer's zone, and the limits start filled in (12 hours to catch up, 50 GB, 30 minutes), so setup needs no guesswork. Off-site copy, Restore and Advanced are folded away until you need them. Every check and confirmation from before is still there.

  • One checkbox to back up while Murage is closed. "Also back up when Murage is closed" sets up the background job for you; before, it took two separate buttons.

  • Create my recovery key. Backups need a recovery key, and until now making one meant using a terminal. Murage now creates it for you and saves it wherever you choose. It will not save it inside Murage's own folder or inside your backup folder, and it never overwrites an existing file. Keep a copy somewhere safe, such as a password manager or a USB drive: without it nobody, including you, can open your backups.

  • Back up now. Take a backup straight away instead of waiting for the daily time. Murage closes and reopens its window to take it, as a scheduled backup does. If a daily backup is already waiting, that one runs instead of a second.

  • Linux: backups on Ubuntu 24.04. Taking a backup, whether Back up now, the daily one or the one before an update, restarts Murage, and on Ubuntu 24.04 that restart could crash, so Murage simply disappeared. The installer now sets up the permission Ubuntu requires, and Murage checks first and tells you if a restart can't work, instead of closing. "Also back up when Murage is closed" was always unavailable on Ubuntu because of how Murage's own data folder was created; the folder is now private to you, and if it is still the reason the message says so. A backup while Murage is closed needs you to be signed in to your desktop; if it can't run, the Backups card says why instead of staying silent.

  • A failed backup leaves no unencrypted copy behind. A backup prepares its copy inside your backup folder. On Windows, a backup that failed left that working folder behind, with an unencrypted copy of your bots and messages, in a folder you might sync or share. A failed backup now removes it on every system.

  • Windows: backups finish. On Windows a backup was written to your folder but then recorded as failed, because Murage compared the folder's name with different capital letters. Backups now finish and Murage reopens to your workspace. Backups can't run while Murage runs as administrator; Murage now says so before closing anything.

  • A backup that didn't finish no longer locks Backups. If a backup stopped before Murage could confirm it, every backup control stayed disabled, even after a restart. Your backups now says so and offers Clear and try again. Closing Murage while it was still indexing skills, for example right after installing, also made every later backup fail; that no longer happens.

  • Backups, smaller things. If backing up while Murage is closed isn't possible on your system, the reason now shows right under the checkbox. Saving a recovery key suggests a file name that doesn't exist yet and remembers the folder you used. The wording throughout Backups is plainer.

Approvals

  • Full access. A third level above Auto. In conversations you start, a bot on Full access asks for nothing: not Auto's stops for destructive or sensitive actions, not the screen-control guard, and not the card before it contacts another bot. What still asks: turns started by a webhook or a routine (judged exactly as Auto judges them), image generation before it spends, questions the bot puts to you, and the one-time "use this computer" confirm. Full access can be switched on only from the desktop app, and the first time for each bot it shows a warning you confirm. Full access can also be a bot's default: Bot Settings now offers Ask, Auto or Full access, new conversations start there, and you can still change a single conversation from the message box. Two options, both off unless you turn them on: let Full access also cover your own messages from Telegram, Slack and Discord (messages from anyone else, webhooks and routines still ask), and let it approve setup requests: installing skills, proposing routines and trusting folders. Connecting an app always asks, because you sign in to it in your own browser.
  • Clearer approval screens. Full access shows as unavailable outside the desktop app, and a refused change snaps back with a plain reason instead of looking as if it worked. The "Ask me before contacting other bots" switch now says truthfully what it does, including that Full access skips it. The "use this computer" card reads "@moss wants to use this computer", then Allowed or Not allowed.
  • Auto asks once before it first uses your screen. On a Mac, a bot left on the Auto computer setting used to be handed your screen, mouse and keyboard without being asked. The first time such a bot acts on the screen, you now answer a one-time card for that bot. Allow is remembered. Don't allow is remembered too: the action is refused and Auto stops offering this computer to that bot. Bots you set to This computer are never asked, and bots that were already using your screen with your say-so keep working. Ask again resets it from the Computer panel.

Stop

  • Stop withdraws a desktop action already under way. Before, Stop prevented the next action but waited for the current one to finish, up to 60 seconds. Stop, taking the screen back, switching the computer Off and the emergency stop now cancel it at once. A click or keystroke already sent to the system cannot be recalled, so the chat now tells you it may have finished anyway and to check the screen before retrying.
  • The emergency stop reaches every task on this computer. A bot can run up to three tasks at once, chats and routines together, and the emergency stop used to reach only one per bot. It now stops each of them and says which did not confirm. On Linux, the local control panel shows a line when a task did not confirm it stopped.
  • The browser works after a Stop. Stopping a bot in the middle of a browser task could leave its next turn's browser refused. Fixed.
  • When Murage stops a turn itself, the chat no longer also says "Stopped by you".

Browser

  • Use my Chrome. One bot at a time can use your own running Google Chrome, signed in as you, instead of its separate browser. It is off for every bot. Turn it on per bot from the Browser panel's profile menu, after turning on remote debugging at chrome://inspect/#remote-debugging (Chrome 144 or newer). The bot works in a tab of its own and can see your open tabs. Its session is never saved, switching back closes it, and Chrome itself is never closed.
  • A browser that cannot start no longer fails the turn. When the browser could not start, often because the computer was busy, the whole request failed with a card pointing at Provider settings. The turn now runs without the browser, the bot is told it has none, and the chat shows one quiet "browser unavailable" note. The browser check is quicker af...
Read more

Murage 0.1.55

Choose a tag to compare

@FerroxLabs FerroxLabs released this 18 Sep 11:41

Murage 0.1.55

Bots and teams

  • Mascot bodies, redrawn. Seven of the ten bodies are now Ferrox Labs' own artwork, built with Blob Studio: Circle, Blob, Capsule, Drop, Star, and the two that were called Shield and Hexagon, now named Cone and Polygon. A body you chose in 0.1.54 stays chosen. The Body picker in Settings → bot → Avatar is one row of ten on a desktop card, two rows on a phone.
  • Delete archived bots. The Archived panel now offers Delete on each bot and "Delete all", behind the usual type-to-confirm dialog, which states what goes (the bot, its conversations, files, memory and skills) and what stays (every channel it sat in, with every message). Deleting was already possible from the sidebar; two things about it are fixed: a channel whose lead had been deleted silently swallowed later messages, and a backup taken after a delete could not be restored. A delete that fails part-way leaves the bot whole.
  • Bots are told what they can do. Every bot gets an accurate, short account of what this install lets it do this turn: which tools it has, whether it can see images, whether its working folder was checked, that a tool call can pause for your approval, and that a refusal is final. It no longer tells a specialist to hand work around its team leader, or a Chief of Staff the opposite of its own instructions.
  • Bots can look Murage up. A bot with Murage's tools can answer "how do I do X in Murage?" from Murage's own documentation, offline, with nothing billed. The built-in Concierge profile uses the same lookup.

Models and engines

  • Engine selector. The Engine control in the model picker shows each engine once, with its icon; it used to read "Claude / Claude" with no icons. Settings → Engines no longer doubles the name either.
  • Price bands and capability icons. Model rows show a five-step price band from $ to $$$$$, from published rates, with the exact per-million figures in the hover; before, most rows said "Price unavailable". A model with no published rate still says "Price unavailable", set apart so it cannot be read as cheap. Vision and tools are shown as icons. One dated note under the list says the bands are approximate. Flux Auto shows a range ($–$$$) because it picks a model per turn.
  • Model list order. The list now reads: the Flux Router tiers (Auto, Fast, Standard, Reasoning, cheapest first), then anything you have starred, then the engine's own models, then Flux pinned models, then other providers. When the engine already offers a Flux tier, the Flux Router connection's copy of it is no longer listed a second time. If you have saved more than one Flux account, each account's tiers are still shown.
  • Proper names. Models that appeared under a raw id, such as flux-auto beside "Flux Auto", now carry their names. flux-voice and flux-image are no longer offered as chat models.

Local models

  • Tailnet and LAN names. You can add a local server by name over plain http: a single-label name such as gpubox, or anything ending in .ts.net, .local, .lan, .internal or .home.arpa. Murage resolves the name when you add it, before a tool test, and again before each request; plain http is allowed only while every address it resolves to is loopback, private LAN, tailnet or IPv6 ULA. The addresses and names cloud providers use to hand out credentials are refused.
  • Chat with any local model. A local model that fails the tools test can now be picked on the OpenAI-compatible engine, which never sends tools. Local servers appear in that engine's list, marked "Chat only", and the Local models card points you there for a model that cannot run agents.
  • A server you cannot reach is named. Instead of fetch failed, the chat says which host did not answer and what to check.
  • A dropped connection keeps what arrived. If a server streams half an answer and then drops, the text you already read stays, marked incomplete, instead of being replaced by "could not be reached".

Images

  • Inline images reach every engine that takes them. Attached and reference images are now sent inline to bots on Claude, Codex and every ACP engine, not only Fuigo. Before, those bots were handed a file path and left to open it.
  • A text-only model is told it cannot see. A bot whose model has no vision is told to ask you for a description rather than to open the file, and dragging an image onto it says "cannot be shown an image" instead of quietly attaching a path. An image referenced by path but not attached to the conversation is still delivered as a path, and the bot is told it has a path, not a picture.
  • A fixable image error no longer costs the attempt. Asking for a picture with no image connection configured used to spend the turn's one image attempt. When the image provider cannot be reached, the card says which wall the request hit: lookup, refusal, deadline, dropped connection or certificate. An image approval you walked away from no longer wedges the turn after a restart.

Approvals

  • "Always allow" is remembered for the bot, not one task. In 0.1.54 an always-allow answer applied only to the task you were in, and pressing it on a card in a channel failed. It now applies to the bot: every task it starts from now on, and cards it raises in channels, honour it. Tasks that already exist keep their own list. What a grant covers is unchanged: the destructive and sensitive checks added in 0.1.54 still run first, questions are never grantable, and unattended runs still ask.

Your computer

  • Cua Driver 0.28.2 is bundled on macOS (was 0.20.0).
  • A stop for a bot on your screen. While a bot's turn is using this computer, the Computer panel shows "Stop using this computer". It takes the screen back first, then ends the turn, and tells you which of the two happened. Choosing "Off" for the bot's computer while it is on your screen does the same; before, on the default Auto setting, it changed the label and the bot kept going. The stop also now covers bots left on Auto, which it used to skip while reporting success, and it reports which bots it stopped. macOS and Linux; Windows bots never use the host desktop.
  • One browser per bot. Two bots could end up sharing one browser session and cookie jar when a browser profile was named after a bot's id. They no longer can.

Stopping, restarts and plain errors

  • Stop keeps the answer so far. Pressing Stop mid-reply keeps the text already streamed and leaves a "Stopped by you" line. It used to throw the whole answer away.
  • Interrupted turns are marked after a restart. A 1:1 turn that was running when Murage closed now gets "Murage closed while this was running, so there is no answer." A message queued behind a running turn is put back in its thread with the same note. Nothing is re-sent for you.
  • Plain wording. Developer text is gone from the window: no package-manager commands, no internal codename, no instructions to edit a config file by hand. A rejected key shows a sentence written for you, with the provider's own text under Technical details. "That address answered, but not with a model reply" and "The model returned an empty answer" are told apart instead of both blaming the network.

First run

  • A refused first message is not lost. If your first message is refused because no model or provider is set up yet, the text stays in the composer. The refusal says what is missing and where in Settings to fix it, and the empty model picker says what to do next instead of "0 compatible chat models".
  • Engine sign-in status is honest. Qwen and OpenCode Go showed as signed in whether or not anyone had logged in. Settings → Engines now says so, and a new bot's default engine prefers one that is signed in.

Tool calls

  • Chips name the real tool, and a failed tool says why. On engines that route every call through one general tool, every chip read the same name; chips now show the tool that ran and a short read of what it was asked to do. The reason a tool failed appears on the chip, with the technical part in the usual expandable block.

Checkpoints, backups and memory: please read

Several guards compared folder paths as text, so one folder spelled two ways (a different case on Windows or a Mac, a trailing slash, a Windows short name) counted as two folders. That is fixed everywhere it mattered:

  • Per-turn checkpoints are never taken in your home, Desktop, Documents, Downloads or Pictures folders, because a restore cleans untracked files. Those folders are now found where they really are: under OneDrive when Windows has moved them there, under iCloud Drive when "Desktop & Documents" sync is on, wherever Linux's user-dirs file says, and under localized names. ~/Library, volume roots and other users' home folders are refused too. A folder that merely sits next to a protected one keeps its checkpoints.
  • A folder opened under two spellings had two checkpoint histories, so "no checkpoints exist for this folder" could appear over a history that was there. It now has one. Existing checkpoints stay where they are.
  • A backup destination or recovery key placed inside the Murage installation is refused however it is spelled.
  • A project memory scope typed with a different spelling used to create a second scope, and memories stopped surfacing. Each folder now has one scope. The first time 0.1.55 sees a scope stored under an older spelling, it keeps that scope and its memories under the folder's real name. If you already have two scopes for one folder, both stay; nothing is merged.

Also

  • Corrected documentation. The local computer help page used to say that turning on local control does not give it to any bot. On a Mac that was wrong: a bot left on Auto, the default, uses this computer once the driver is installed. The page now says so. Set a bot's computer to Off if it should never touch your screen. On Linux, a bot gets this computer only w...
Read more

Murage 0.1.54

Choose a tag to compare

@FerroxLabs FerroxLabs released this 18 Sep 01:01

Murage 0.1.54

Bots and teams

  • Mascot bodies. Choose your bot's mascot shape: flame, blob, circle, squircle, capsule, drop, shield, hexagon, diamond or star. You'll find them in Settings → bot → Avatar → Body. Adapted from OpenMausBot.
  • Drag a bot onto a team in the sidebar to add it. If the team already has a lead, dragging in another lead is refused and nothing changes.
  • Team instructions can now be edited after the team is created: use the book icon on the team's sidebar header.
  • Pin tasks to the top of the task switcher.
  • Easier to spot the open conversation: the selected sidebar row now has a gold edge.
  • Avatars: drop an image straight onto the avatar to upload it. The Circle, Rounded and Square shapes now show on mascots too, including on the Team map.

Images

  • Reference images reach Fuigo. Attached and reference images now actually reach bots running on Fuigo.
  • Clearer rejections. When an image provider rejects a request, you see its error code and message instead of a generic sentence.
  • More time to approve. Image approvals wait 15 minutes; they used to deny themselves after 60 seconds. A card nobody answers shows "Not answered", not "Denied".
  • Channel approvals alert you. Image approvals in channels now play the approval sound and show "Waiting for you".
  • No false error on a repeat answer. Answering an image card a second time no longer shows "Couldn't deliver that answer" after the image was already made.
  • Safer Auto mode. Auto mode now stops for approval before a bot reads shell profiles, API-key variables or credential stores.

Fuigo

  • Fuigo 1.0.20 is now bundled.
  • Tools on the first step. Bots on Fuigo can use Murage's memory, image and bot tools from the first step of every turn. Before, Fuigo said they were "still connecting".
  • Fewer trust prompts. New tasks no longer ask "Trust this folder?" for a bot's own task folder when the only thing in it is skills linked from your library. Folders you choose yourself still ask.

Team Chat and tasks

  • Replies go to the right bot. When you reply to a bot in a channel, that bot answers.
  • "Inject now" works. It no longer stops the turn it just started.
  • No raw memory errors. Channels no longer show a raw "memory unauthorized" error.
  • Tasks queue for busy resources. A task that needs a computer, browser or folder another task is using now waits its turn instead of failing.

Memory: please read before upgrading

The first time 0.1.54 opens your data, it upgrades the memory tables inside messages.db. Before touching anything, it saves an untouched copy of the old file next to it as messages.pre-memory-v2.db. If that copy can't be written (for example, the disk is full), the upgrade doesn't run and Murage tells you why.

0.1.53 cannot open an upgraded messages.db, but going back is supported:

  1. Quit Murage.
  2. Run the one-line memory-downgrade step in the memory documentation.
  3. Reinstall 0.1.53.

Every chat and memory added after the upgrade comes with you.

Existing installs keep working as before: newly learned facts and procedures wait in "Needs review" until you approve them. Only new installs turn on automatic activation, and you can change this in Memory settings. Spending doesn't change: the same extraction limits apply, and no paid model runs unless you've picked one.

Also

  • Upstream improvements. Nine OpenMausBot improvements are adapted, including Windows file-rename retries, npm/npx shims, a Claude and Codex driver fix, a data-folder lock fix, and faster message paging. Details are in NOTICE.
  • Known issues:
    • Intel Macs still have no local semantic memory.
    • Bundled Fuigo on Linux needs glibc 2.39 or newer.
    • The phone apps still show the flame mascot for every bot.

Murage 0.1.53

Choose a tag to compare

@FerroxLabs FerroxLabs released this 12 Sep 08:03

Murage 0.1.53 is a hotfix over 0.1.52. It carries three corrections to the
Claude engine driver and the turn settlement in the harness, plus the test
work that made the suite run green on Windows. Nothing else changed: the
only product files touched are server/drivers/claude.ts and
server/index.ts; every other change is to tests and test fixtures. The
bundled Fuigo stays 1.0.13. All three fixes apply on macOS, Windows and
Linux.

Fixed

  • Save and Restore answered "bot is writing" until a restart after the
    engine auto-retried, and a channel message that arrived during that turn
    was never delivered.
    When the Claude CLI exited before accepting a
    turn, the automatic relaunch minted a new turn id, so the run, the
    folder-writer lease, the memory receipt and any queued channel routine
    kept waiting on a completion that never came: the bot stayed busy, the
    workspace refused every save with 423, and a Telegram or Discord message
    queued during the turn was never dispatched. The relaunch now keeps
    the id the original send returned, so the retried turn settles like any
    other. (31ef3911; pinned end to end by bf6b3cef, which drives a real
    harness through the retry, the refused save, the completing relaunch,
    the accepted save and the delivered channel reply.)
  • "a turn is already running on this thread" after Stop, then send.
    Stop returns as soon as the kill is sent, but the CLI child still tears
    down its MCP children and flushes first (on Windows every Stop ends the
    child through an asynchronous taskkill). A message sent in that window
    reached the driver while the stopped child was still closing and was
    refused with an error card. A send that meets a stopped-but-not-yet-closed
    turn now waits for that close (bounded by the harness's own stopped-child
    deadline) and then launches. A turn that was not stopped is still refused
    as before. (23087f25)
  • A message sent or edited right after Stop was silently dropped. The
    stopped child's late turn.completed was folded onto whatever run owned
    the thread by then, so the replacement run — still in setup — was
    released and its dispatch cancelled: the message sat in the transcript,
    the bot went idle, no error. Settlement now only touches the run bound to
    the event's own turn; an earlier turn's close leaves the replacement, its
    provider selection, its usage, its reply and its unread mark alone.
    (3e75643e, 20d5a6cb, 0cb0662d; three deterministic shapes in
    server/direct-run-late-close.test.ts — Stop then edit then resend, Stop
    then resend at once, and the retried pre-accept exit — fail on 0.1.52 as
    shipped and pass here.)

Quality

  • The vitest suite runs green on Windows. The 0.1.52 CI record on the
    Windows runner (run 34657596577) had 53 red tests across 19 files. Four
    of them, all in server/index.test.ts, were the third defect above
    showing through (the "tells the assistant why it has no connectors"
    failure and its fallout). The other 49 were test-harness assumptions
    that only hold on POSIX: those tests and fixtures now follow Windows
    path, checkout and shell shapes, use the fake engine's canonical cwd
    key, tolerate an unwritable probe root, and assert on event order rather
    than elapsed time. No product change beyond the three listed above.
    (da392f05, 2042547a, ba65f40a, d915fd75, 00efdbef, 8ab65873,
    ed4508b3)
  • The fake Claude CLI gains a slow-exit-on-stop fixture so the Stop-to-close
    window is open on POSIX too, and a Telegram fetch preload lets the harness
    suite exercise a channel delivery without a network. Both are test-only.

Unchanged from 0.1.52

  • Everything in the 0.1.52 notes still applies, including the open items
    listed there. Downgrading to 0.1.51 after running 0.1.52 or 0.1.53 is
    still not supported (saved-files table columns).

Murage 0.1.52

Choose a tag to compare

@FerroxLabs FerroxLabs released this 12 Sep 00:56

This release gives every bot a workspace you can see and edit beside the
chat, lets a bot ask you a real question and get a real answer, brings local
models into the product as a first-class setup, moves connected apps onto
your FluxRouter account, and adds inline images, audio and video that never
leave your machine unverified — including saved-file cards that show the
file right in the chat. Underneath it, the engine runtime, the desktop
process, the companion, the installer and the hosted broker each close a
set of audited gaps, Stop means stop on every engine, and all seven
language packs are complete.

Added

  • A workspace pane beside the chat. A resizable Workspace rail on the
    right of the conversation (chat keeps at least 360 px, rail at least 320 px,
    width remembered), a covering overlay with Back to chat on narrow screens,
    and an Expand mode. The rail lists the selected conversation's files, opens
    them in tabs named by scope and relative path, and previews Markdown
    (rendered or Source), protected HTML in a sandboxed frame, plain text,
    images, and a truthful open/download fallback for everything else. A single
    click reuses one clean preview tab; Keep open and Edit make a tab
    persistent; a dirty tab is never replaced and asks before it closes.
    Actions: Save, Save a copy, Save this version, Download, Open in app, Show
    in folder, Open in Files.
  • A Markdown editor that only writes on Save. Rich editing runs on Tiptap
    3.31.3 and opens a file in rich mode only when the pinned parser is proven
    to round-trip that file byte for byte; anything else opens in Source mode
    on the exact text. Reloads never become edits. Saves are conditioned on the
    revision you opened: a file a bot changed underneath you becomes a conflict
    that shows both texts with Use the disk version / Keep my version, and a
    save while a bot turn holds that folder is refused with a plain message
    and nothing written. The revision you replace is kept as a saved version in
    Files first, so nothing is overwritten unless it was retained. Unsaved
    typing survives a crash: drafts live in the renderer (50 drafts, 10 MiB),
    are labelled separately from "File saved", and a recovered draft found
    after you started typing is held until you choose.
  • Files shows the workspace, not only saved copies. Files now carries
    both halves: the conversation's working folder as it is on disk right now
    (lazy folders, breadcrumbs, name search with an honest "incomplete" state,
    200 entries per page) and the saved versions that never change. Every row
    is labelled "Workspace file" or "Saved copy". Legacy conversations pinned
    to no workspace and remote runs say exactly that instead of listing your
    home folder. Open in app and Show in folder hand one live file to the OS
    through an owner-bound, extension-allowlisted bridge that re-checks the
    file's identity immediately before the call.
  • Bot outputs are saved automatically. A file a bot writes into the
    managed outputs/ folder of its task workspace during a turn (regular
    files up to 25 MiB, at most 20 per turn) becomes a verified saved version
    in Files with producer and run provenance and one host-authored card in the
    chat, with no register_artifact call. A failed or cancelled turn leaves
    the receipts retained and registers nothing. Generated images are receipted
    before they are attached, so an interrupted publication resumes on restart
    from the retained bytes with zero provider calls and no duplicate message.
  • Saved-file cards show the file itself. Every "Saved file" card in the
    chat previews inline instead of sending you to Files: images render in
    place and open the lightbox; audio and video embed the same player card
    (no autoplay, one at a time); Markdown, text and code show a bounded
    slice (2 KB, Show more up to 256 KB) rendered like the transcript; HTML
    renders in the same protected sandboxed frame Files uses; PDF and
    binaries keep their buttons. Open here still opens the working file in
    the workspace pane. Source and configuration files a bot writes (.py,
    .ts, .sh, .yaml, .toml, .sql, .go, .rs and the rest) are
    now saved as text so they preview too; .svg, .env, .pem, .key,
    archives and binaries stay download-only. The card never builds a raw
    bytes URL and refuses any resolver answer without a capability.
  • A question card, end to end. When Claude Code, Codex, Fuigo, an ACP
    agent or Pi asks you a question (AskUserQuestion, requestUserInput,
    ask_user_question, elicitation, select/input/editor), Murage now shows a
    card with the questions, options, descriptions, multi-select, Other and
    free text, fully keyboard-driven (1-9, Tab, Enter, Esc), and sends the
    engine exactly the answer shape it documents. A question is never
    auto-approved, never remembered as "Always allow" and never auto-reviewed;
    skipping it is delivered at once instead of leaving the engine waiting.
    The engine waits 30 minutes; after that the card stays as Expired with
    "Send as a message" so a late answer still reaches the bot. Cards persist
    across restarts. A URL elicitation is shown as a link you open; Murage
    never fetches it for you. The card reads like the other transcript
    cards: each question is a recessed sub-card, options are separate pills
    with an accent edge when picked, the key map lives in the Send button's
    tooltip, and an answered, sent or skipped card keeps its picks and
    settles into an "Answered · time" footer.
  • Questions on Telegram. The same card reaches the paired Telegram owner
    as its own message per question: numbered options with one inline button
    each, multi-select toggles with Submit, "Reply with text" for a free-text
    answer, and Skip. Answers go through the same validation as the desktop
    card; a stale, forged, foreign or expired tap does nothing. Secret
    questions stay in-app.
  • Local models, as a real setup. Settings → Models gains a permanent
    Local models section that says which addresses automatic detection
    checked (Ollama, LM Studio, llama.cpp, vLLM, SGLang), lets you add, edit
    and remove your own servers (loopback, home network or tailnet over plain
    http; https otherwise; key write-only), and runs a seven-check tool-calling
    test per model with a one-sentence outcome ("Tools work — ready for
    agents", "Context too small for agents") and the checks behind a
    disclosure. Loaded context is read from the server; Ollama gets a "create a
    64K copy" action. Fuigo, Pi, OpenCode, Qwen Code, Hermes, Droid and Kimi
    are wired to a tested model; Codex and Claude Code rows appear only after
    their own surface test passes. The picker's Local rail shows "model ·
    server" and marks a model whose tool test failed. Live proof against a
    llama.cpp Qwen3.8-27B host: four engines completed real tool-using turns.
  • Inline images with a lightbox. One accessible image surface for
    attachment galleries, Markdown images, screen frames and the Files saved-copy
    preview: a native modal dialog with focus trapping, Arrow/Home/End
    navigation inside the message's own set, alt text, reduced-motion support,
    contain-never-crop thumbnails, and Download of exactly the bytes shown.
    Remote Markdown images are an external card until you click Load (fetched
    with no referrer); local paths, file://, blob: and SVG are never
    requested.
  • Audio and video players for a conversation's own files. A WAV, MP3,
    Ogg, M4A, MP4 or WebM path in a transcript becomes a player only after the
    harness confirms the conversation has a dedicated workspace, the exact
    relative path is a regular file inside it right now, and the bytes are a
    type this build streams. Playback goes through the authorized byte route
    with a short-lived capability; the path itself is never fetched. No
    autoplay, metadata preload, one player at a time, seeking through range
    requests, Save a copy on every card including the ones that cannot play.
    An expired capability is renewed in place mid-listen.
  • "Use as reference". From the lightbox, add a conversation image
    (uploaded, generated or a saved PNG/JPEG/WebP up to 10 MiB) to the next
    message as an ordinary attached-image chip, so the bot can pass it to
    generate_image. Bots get a resolve_image_reference tool that pins
    uploaded, generated, saved or workspace images to exact bytes (up to four,
    20 MiB total) and discloses what it prepared before any approval.
  • Image edits on xAI and OpenRouter. grok-imagine-image-2.0 edits one
    to four reference images through xAI's JSON edit endpoint; OpenRouter
    openai/gpt-image-2 sends references only when the pinned openai
    endpoint advertises a compatible range (checked within 15 s just before
    approval, fail closed, no fallback). Each provider's key is attached only
    to its own exact origin. Image settings now show each model's true edit
    capability and reason ("Creates and edits images", "Creates images only:
    …") and the reference limit it accepts.
  • Connected apps through FluxRouter. Connected apps can now run through
    a FluxRouter account. The FluxRouter key is spent once, in the main
    process, to mint a broker token that never reaches an engine subprocess,
    so a shell command a model runs can never read your Gmail past per-bot
    policy. An existing install's Composio identity is adopted, not copied,
    through a three-leg claim (sign, redeem, confirm) so a stranded migration
    loses nothing; a personal account auto-claims, a shared team account moves
    only on an explicit button. FluxRouter claims are on for this release: the
    Worker has issued them since rollout step 5 and FluxRouter has redeemed them
    since step 6 (2026-09-11), and the committed Worker config ships
    CLAIM_MODE open with new-install registration closed (step 8, the day
    this release publishes). This build is pointed at the FluxRouter broker
    (`https://api.fluxrouter.ai/...
Read more