Skip to content

v0.9.0

Choose a tag to compare

@github-actions github-actions released this 27 Sep 22:58
· 171 commits to main since this release
2f4f669

Muse Code installs and signs in from the panel, PDFs and text files become
input, and the Model API backend gains subagents, MCP servers, hooks,
memory, goals and scheduled prompts. Conversations can be rewound or
branched into a side chat. Five paid extras arrive, each off until you turn
it on. The extension also works behind corporate proxies and HTTPS
inspection.

Added

  • Install and sign in from the panel (M55). Without the Muse Code CLI,
    the sign-in screen offers Install Muse Code: it shows Meta's install
    command for your system, runs it in a terminal you can watch once you
    confirm, and offers sign-in when the CLI appears; a timed-out install can
    be retried. Sign in with your Meta account shows Muse Code's approval
    code and sign-in link in the panel, with Cancel and a timeout. Account &
    usage offers the same install while you use a Model API key, and lets a
    Muse Code user add or replace the key. After Sign out, a note in the
    extension's state (no credential) keeps an old CLI credential from
    signing the window back in until you sign in again; if the logout terminal
    cannot open, the extension still stops its host and says how to finish.
  • PDFs and text files as input (M54, PLAN.md D47). On the Model API
    backend, pick, paste or drop a PDF of up to 32 MB (recognised by its
    content, whatever its name), and the agent can read workspace PDFs and
    images with read_file. A request stays within Meta's limit of 50 images
    and PDF pages together: an attachment that would pass it is refused with
    the reason, and older media left out of a replay is announced. A picked
    UTF-8 text file from the workspace becomes a named text attachment on both
    backends (up to 1 MiB each); private files are refused, and files outside
    the workspace stay mentions. Muse Code cannot take PDFs over MSP, so it
    says so. When the page count of a PDF cannot be read for certain, it
    counts as the full 50. Conversation rewind is not offered for a message
    with a PDF or a text file.
  • MCP servers on the Model API backend (M50, PLAN.md D42). The window
    runs the MCP servers in Muse Code's settings file itself, local (stdio)
    and remote (streamable HTTP): their tools are offered as
    mcp__<server>__<tool>, with schemas fitted to Meta's limits, and their
    text and pictures reach the model. A call asks like a command in Manual
    and Auto (a tool its server marks read-only runs in Auto, as in Muse
    Code); Plan refuses all but read-only tools, which ask; "always allow in
    this session" works per tool. None runs in Restricted Mode. A local server
    sees only a short list of VS Code's environment variables plus its own
    env, never the Model API key; ${VAR}, timeouts and tool filters from
    its entry are honoured. MCP servers… in the palette shows whether each
    server is connected and with how many tools, or why not; a failing server
    is a warning, and a required one stops the message with the fix. On
    Windows each local server runs in a job object, so stopping it ends
    everything it started. Remote error bodies and authentication challenges
    stay out of tool errors and logs. The extension's diagnostics tool
    (getDiagnostics) is offered on this backend too.
  • Memory, on both backends (M49, PLAN.md D41). Muse Code keeps Markdown
    notes in three scopes: yours for this project (the default, outside the
    repository), the project's (.agents/memory, shared with the
    repository) and yours for every project. Both backends now read and write
    the same notes, found on disk and in a live capture of Muse Code 1.3.0.
    • Memory… in the palette (/memory, Muse Spark: Memory) lists
      up to 500 notes per scope with their scopes and summaries; open one to
      read or edit it, create one, or delete one to the trash after a
      confirmation. The scope's MEMORY.md index gains a created note's line
      and loses a deleted note's lines.
    • The Model API backend has Muse Code's read_memory, add_memory
      and edit_memory, with its arguments, refusals and JSON results, so
      their rows read the same on both backends; at the start of a
      conversation the model gets each scope's MEMORY.md and its notes'
      names, as Muse Code gives them. A new note gets its index line. Writes
      ask in Manual, run in Auto and Edit automatically, and are refused in
      Plan; a refused path asks nothing. Not offered in Restricted Mode.
      Linked scope folders below the workspace or data home are refused, so
      they cannot expose notes outside their intended roots.
    • A new note is created exclusively and published whole: a synced hidden
      copy is hard-linked into a free name, so it never replaces a racing
      writer's note or shows partial bytes, and a filesystem without hard
      links refuses the create. Names with spaces, brackets or percent signs
      are encoded in MEMORY.md, so a note keeps one index line.
    • Updates to an existing note replace it atomically but do not take Muse
      Code's native memory lock; simultaneous writers can still lose an update.
  • Session goals (M45, PLAN.md D38). /goal <objective> sets a goal
    the agent keeps working toward; a strip above the task list shows its
    status, a progress bar and the work now and next, with Pause, Resume, Edit
    and Clear (also /goal pause, resume, edit <objective>, clear).
    On Muse Code these are its own goal commands, and a resumed conversation
    shows its goal and task list. On the Model API backend the agent gets Muse
    Code's four goal tools with the same results, the goal is saved with the
    conversation and kept in the instructions while active, Stop pauses it,
    and nothing starts a model call you did not ask for. A goal changed while
    a request runs does not take that request's tokens or tool calls, and a
    rejected /goal keeps its draft. Built from a live capture of Muse Code
    1.3.0.
  • Your own shell commands: ! (M46, PLAN.md D39). A message that
    starts with ! runs as a shell command in the workspace, outside any
    turn, as Muse Code's ! does, and gets its own row: You ran, the
    command, its exit code, run time and output. The agent sees it with your
    next message. On Muse Code it is the CLI's session/userShell; on the
    Model API backend it runs through the shell tool's own runner, with a
    Stop. Nothing runs in Restricted Mode, a command that could not run
    comes back to the prompt with the reason, and one Muse Code could not
    start without its Windows sandbox offers the setup, as the shell tool's
    failure does. A running Model API ! command is saved at once, so
    another surface on the conversation shows its row and can stop it.
    Markdown export includes a command's termination signal when Muse Code
    reports no exit code.
  • Background work you control (M46). Move to background on a
    running shell row, or Ctrl+B while the conversation in view runs one,
    lets the command go on while the agent carries on; a background task has
    Stop on its row and in the Agent map, which also has Stop all
    (and the new Muse Spark: Stop Background Tasks command). The header
    pill counts running background tasks. Muse Code's task/background,
    task/stop and task/stopAll on its backend; on the Model API backend a
    moved command runs without its time limit until it ends or is stopped,
    and what it printed reaches the agent with its next request. Releasing
    the last surface of a Muse Code session stops its background tasks;
    another surface holding it leaves them running. A resumed or second
    surface shows a running foreground shell and can move it with Ctrl+B;
    while that shell still awaits permission, it shows the same card and
    leaves Ctrl+B to VS Code. A fork carries the end or lost-output note
    for each inherited background shell.
  • Explain instead on question cards (M46): an answer in your own words
    in place of the options (Muse Code's userInput/clarify, and the same on
    the Model API backend); the row then reads "Explained".
  • Approvals across panels (M46). A panel joining a conversation shows
    its open approval cards on both backends, but never automatically
    answers a card that was already pending under another panel's mode. With
    several panels attached every approval needs an explicit choice; a sole
    Edit automatically panel keeps its automatic plain-edit approval.
  • Subagents on the Model API backend (M48, PLAN.md D45). With the paid
    setting museSpark.modelApiSubagents on and its rates accepted, the agent
    can start child tasks. Each runs in parallel within fixed limits, with its
    own transcript, the same tool approvals and workspace rules, and its usage
    counted with the conversation. Every new child task asks first, in every
    mode, Bypass included (Plan refuses it), and one consent covers at most
    four requests, retries included. The Agent map can steer, stop, read and
    reopen children; the child's row and Account & usage show its paid
    attempts and tokens. On Muse Code, the map's Read result and Reopen wait
    for a capture of Muse Code's replies to them.
  • Model API hooks (M51, PLAN.md D36). With the machine-scoped
    museSpark.modelApiHooks on (off by default), the Model API backend runs
    Muse Code's hook commands for all 17 documented events: your
    administrator's, yours and the project's .muse/hooks.json, in a trusted
    workspace only. A hook gets JSON on its standard input (your prompt and
    bounded previews of tool and model calls, without images, credential
    fields or the Model API key), runs with time and output limits, and is
    stopped with everything it started. A PreToolUse hook can deny a call or
    ask for approval, which a person then answers in every mode; a
    PreLLMCall hook can stop a request before it is sent. Unsupported events
    and handler types are reported and skipped; not all of Muse Code's
    event-specific hook output is supported yet. Muse Spark: Hooks shows
    whether the setting is on and opens it.
  • Scheduled prompts on the Model API backend (M52). /loop saves a
    prompt with an interval or a five-field cron schedule in the conversation;
    the panel lists due prompts and cancels them. A due prompt never runs by
    itself: with the paid setting museSpark.modelApiScheduledPrompts on, you
    choose Run now and confirm that run's model and token rates. Prompts
    belong to their workspace, conversation and key, and each occurrence runs
    at most once, across windows and restarts. Anything that changes while the
    price dialog is open cancels that approval. A schedule that would not fire
    within its seven days is refused. On Muse Code, its own /loop remains
    available through the model.
  • Conversation rewind and side chats (M53, PLAN.md D46). Rewind
    conversation to here
    on a sent message branches the conversation before
    it and puts its prompt back in the composer, with its Model API images
    while replay still holds them (otherwise the panel says so). Side chat
    opens a Plan-mode branch in its own panel without stopping the main one;
    it runs no hooks, refuses outside MCP tools and scheduled prompts, and
    closing it returns focus to the main panel. Muse Code 1.3.0 cannot fork
    on Windows, so both are hidden there.
  • A row for every tool Muse Code runs (M43, PLAN.md D36). Memory rows
    show the note and where it lives, and an edit as the text replaced; goal
    rows show the objective, its status, a progress bar, what is being done
    now and next, and the tokens spent; scheduled prompts show their
    schedule, next run and how often they ran; web search shows its results
    as links with snippets, on both backends; a picture the agent read, or
    the Model API backend made, shows in its row. Every other tool in Muse
    Code's list has a name, an MCP tool reads "tool (server)", and any other
    result is indented JSON. All built from a live capture of Muse Code 1.3.0.
    Tool-row pictures now use the checked workspace target and a bounded,
    single-handle read, so a changing link or growing file cannot bypass the
    10 MiB preview limit.
  • Workflows (M47, PLAN.md D40). A multi-agent workflow Muse Code runs
    is a read-only card that keeps updating after the reply: its label,
    status, what started it, each agent's state, attempt, time and tokens,
    and the result or failure it reported. The N agents pill counts
    workflow agents, the Agent map lists the runs and says how Muse Code is
    set to start workflows (run.workflow_trigger_mode, read from its
    settings file, never written), and Diagnostics reports that setting too.
    Built from a live capture of Muse Code 1.3.0. Cancel, Skip and Retry wait
    for a capture of Muse Code's replies to them.
  • Web search (M33). With museSpark.modelApiWebSearch on, the model can
    search the web on the Model API backend ($2.50 per 1,000 searches). Each
    search is a row marked paid with its query and results, and a reply lists
    the pages it cites under it (also in /export).
  • Image generation (M34). With museSpark.modelApiImageGeneration on,
    the model can create a PNG in the workspace with muse-image-1.0 ($0.01
    per image). Every image asks first, in every permission mode, Bypass
    included, showing the prompt and the price, with no "always allow"; Plan
    refuses it. A path that is taken, outside the workspace or not a .png
    is refused before anything is billed, and a new image never overwrites a
    file.
  • Muse Voice (M35). With museSpark.modelApiVoice on, the microphone
    records for Meta's Muse Voice Transcribe instead of your computer's own
    recogniser ($0.18 per hour of audio), streamed as you speak; the
    transcript lands at the caret. The recorder is native/windows/capture.ps1
    on Windows, the macOS helper's new --capture mode, and arecord or
    parec on Linux, which gets a microphone for the first time.
  • Opt in and loud (M33–M35, PLAN.md D30, D34). Off by default and
    machine-scoped; a confirmation names the price when one is turned on, from
    the palette's new toggles or in settings, and declining it turns the
    setting back off. The composer's badge names what is on, the microphone
    says when it is paid, and Account & usage tallies this window's searches,
    images and seconds of audio with their estimated cost.
  • Image edits (M44, PLAN.md D37). With image generation on, the model
    can also change one workspace image, or combine up to four, by a prompt,
    into a new PNG (edit_image, Meta's /images/edits, $0.01 per image).
    The card names the images it starts from; everything that could fail is
    checked before anything is asked or billed. Image-edit sources now read
    their checked canonical targets if a workspace link retargets. New image
    output is reserved at its checked target before any paid request.
  • Images and Muse Voice on the Muse Code backend (M44). While a Model
    API key is stored, the extension's own ide tool server offers Muse Code
    an image and an image-edit tool, and the microphone can use Muse Voice:
    billed to the key, never to the subscription, each image confirmed with
    its price first, the rows marked paid, and the tally in Account & usage.
    The key never reaches the Muse Code CLI.
  • Enterprise networks (M56, PLAN.md D43).
    • museSpark.sandboxNetwork (machine-scoped) passes Muse Code's
      --sandbox-network: proxy-only (each new destination asks),
      restricted (no network for commands) or enabled; default leaves
      Muse Code's own default or an administrator's managed configuration.
      It applies while the shell sandbox is on, and changing it restarts the
      host.
    • Muse Spark: Diagnostics states the network posture (whether a proxy
      is set, never its address; VS Code's proxy and certificate settings;
      where Muse Code's proxy comes from; NODE_EXTRA_CA_CERTS,
      SSL_CERT_FILE) and prints muse config status, Muse Code's managed
      configuration's recognized source and generation fields. Unrecognized
      lines and failed-command output are withheld.
    • A Model API request that never reached Meta says why and what to check:
      an untrusted certificate (a network that inspects HTTPS), a proxy that
      wants credentials or refused the tunnel, or no route, with Node's own
      detail beside it; it read "fetch failed". Quoted credential fields in
      that detail are redacted in full, including spaces.
    • A permission mode above Muse Code's ceiling (its default permission
      profile, or a managed policy) is refused with a sentence saying so and
      what to choose instead.
  • Prompt caching as Meta documents it (M56). The Model API backend's
    prompt_cache_key names the prefix every request starts with (model,
    instructions, tools) instead of the session, so conversations in a
    workspace share their cached start, and prompt_cache_retention asks for
    Meta's shorter in_memory default. The machine-scoped
    museSpark.modelApiPromptCacheRetention setting lets the user choose 24
    hours at the same cached-input price; a repository cannot extend it.

Changed

  • The Windows job helpers' C# ships beside the host bundle (M55, M56;
    PLAN.md D6). The shell job type, the MCP launcher and the Win32 half they
    share are .cs files under native/windows/, read and compiled when a
    helper is first needed, instead of strings in dist/extension.js, which
    stays under its 600 KiB budget. A helper built from the earlier source is
    rebuilt once.
  • The Model API backend saves memory with the memory tools (M49). It
    used to be told to write .agents/memory with the file tools, which as
    protected writes asked every time. The personal scopes, left out before
    (PLAN.md D13), are now read and written too, and a memory note must be
    UTF-8, as Muse Code requires.
  • CI (contributors). Pull requests run the seven cross-platform jobs
    once per reviewed tree; merges to main do not repeat them, and a manual
    branch dispatch remains for diagnostics. On Windows, unit test files run
    one at a time and the accessibility gate opens at most two pages at once,
    so the hosted runner is not starved; the pre-commit hook runs its lint and
    format tasks serially. No check, threshold or deadline changed. An
    opt-in live sweep (npm run test:e2e:live:modelapi, never in CI) runs the
    Model API backend against Meta's real API, one case per feature, on the
    contributor tier.

Security

  • A Model API conversation belongs to the key that made it (M55). Each
    saved conversation and scheduled prompt records a one-way SHA-256 digest
    of its key, never the key. History, reads, resume and fork list and open
    only the stored key's sessions. Replacing the key stops the old host
    first and starts a fresh conversation; a paid image waiting for approval
    or retry is refused rather than billed to the new key. Conversations
    saved before 0.9.0 stay on disk but cannot be reopened.
  • Signing out or changing account clears the panel (M55). The previous
    account's transcript, tool output, agent views, usage, model and skill
    lists and file chips are cleared; unsent draft text stays. A read, History
    event, rename or message still in flight cannot refill the panel or run
    under the next account. Overlapping sign-outs share one operation, and a
    key write or backend restart already under way finishes before the key is
    cleared.
  • Workspace file access re-checks its target at the moment of I/O
    (M54). Picked files, read_file, write_file, edit_file, tool-row
    image previews and paid image output read or write the checked canonical
    file through one bounded handle. A link or junction swapped after the
    check, or a file that grows, cannot expose or overwrite anything outside
    the workspace or exceed its size cap.

Fixed

  • Model API keys in Meta's current format are accepted. A key that
    starts with LLM_ (Meta's current keys have no |) was refused as
    malformed; both shapes are now accepted, and both are redacted from logs.
  • A question answered the moment it appears is taken (Model API). The
    card was shown before the question was held as pending, so an answer in
    that instant was refused and the turn waited for ever. Found by the live
    sweep.
  • Account & usage reset timing (M53 follow-up). The open modal updates its
    countdown each minute and stops treating an expired report as current. It
    uses Muse Code's reported account-level percentages and reset timestamps
    without guessing model or plan multipliers. Sign-out and authentication
    changes clear visible usage; the old global snapshot is no longer read and
    is removed during activation when storage permits. An empty CLI read also
    clears a same-host snapshot. A late read cannot replace a newer report or
    restore a stopped host's usage.
  • A resumed Muse Code conversation shows its task list (M45). A resume
    asked for inline history, which carries no task list; it now asks for the
    folded snapshot, which carries the task list and the goal.
  • A stopped task read "Failed" (M46): a row stopped by you or by Stop
    now reads "Stopped" with the reason, and is read out so.
  • The Agent map's note about Muse Code's delegation setting showed only
    once Account & usage had been opened in that panel (M47). Opening the map
    now reads the setting itself. A map with background tasks also no longer
    says it is empty merely because it has no subagent row.
  • Muse Code behind a proxy lost the IDE tools (M56). With http.proxy
    set and http.noProxy empty, Muse Code sent its requests to the
    extension's loopback ide server (diagnostics, images) to the proxy,
    which cannot reach them. Loopback is now always in Muse Code's NO_PROXY
    whenever it has a proxy, VS Code's or its own.
  • Malformed VS Code proxy settings (M56). A wrong-typed http.proxy or
    http.noProxy value is ignored before Muse Code's child environment is
    built; Diagnostics reports the same validated setting state.
  • A command Muse Code moved to the background read "Interrupted" when
    its turn ended (M43). It now shows what it printed, says it is still
    running, and is listed among the background tasks.
  • Model API conversations that narrate before a tool (M42, PLAN.md D35).
    Text the model writes before a tool call is replayed as commentary, as
    Meta requires; replayed as an answer, it made the next request fail with
    a 400. A reasoning item is replayed with its summary (empty when there was
    none), and a reply that was reasoning alone is followed by the minimal
    message the docs ask for.
  • A server that stops mid-reply (M42). A stream that ends because the
    instance shut down or was overloaded is sent again, with the retry notice
    in the transcript; a 502 is retried like the other server errors.