v0.9.0
Muse Code installs and signs in from the panel, PDFs and text files become
input, and the Model API backend gains subagents, MCP servers, hooks,
memory, goals and scheduled prompts. Conversations can be rewound or
branched into a side chat. Five paid extras arrive, each off until you turn
it on. The extension also works behind corporate proxies and HTTPS
inspection.
Added
- Install and sign in from the panel (M55). Without the Muse Code CLI,
the sign-in screen offers Install Muse Code: it shows Meta's install
command for your system, runs it in a terminal you can watch once you
confirm, and offers sign-in when the CLI appears; a timed-out install can
be retried. Sign in with your Meta account shows Muse Code's approval
code and sign-in link in the panel, with Cancel and a timeout. Account &
usage offers the same install while you use a Model API key, and lets a
Muse Code user add or replace the key. After Sign out, a note in the
extension's state (no credential) keeps an old CLI credential from
signing the window back in until you sign in again; if the logout terminal
cannot open, the extension still stops its host and says how to finish. - PDFs and text files as input (M54, PLAN.md D47). On the Model API
backend, pick, paste or drop a PDF of up to 32 MB (recognised by its
content, whatever its name), and the agent can read workspace PDFs and
images withread_file. A request stays within Meta's limit of 50 images
and PDF pages together: an attachment that would pass it is refused with
the reason, and older media left out of a replay is announced. A picked
UTF-8 text file from the workspace becomes a named text attachment on both
backends (up to 1 MiB each); private files are refused, and files outside
the workspace stay mentions. Muse Code cannot take PDFs over MSP, so it
says so. When the page count of a PDF cannot be read for certain, it
counts as the full 50. Conversation rewind is not offered for a message
with a PDF or a text file. - MCP servers on the Model API backend (M50, PLAN.md D42). The window
runs the MCP servers in Muse Code's settings file itself, local (stdio)
and remote (streamable HTTP): their tools are offered as
mcp__<server>__<tool>, with schemas fitted to Meta's limits, and their
text and pictures reach the model. A call asks like a command in Manual
and Auto (a tool its server marks read-only runs in Auto, as in Muse
Code); Plan refuses all but read-only tools, which ask; "always allow in
this session" works per tool. None runs in Restricted Mode. A local server
sees only a short list of VS Code's environment variables plus its own
env, never the Model API key;${VAR}, timeouts and tool filters from
its entry are honoured. MCP servers… in the palette shows whether each
server is connected and with how many tools, or why not; a failing server
is a warning, and a required one stops the message with the fix. On
Windows each local server runs in a job object, so stopping it ends
everything it started. Remote error bodies and authentication challenges
stay out of tool errors and logs. The extension's diagnostics tool
(getDiagnostics) is offered on this backend too. - Memory, on both backends (M49, PLAN.md D41). Muse Code keeps Markdown
notes in three scopes: yours for this project (the default, outside the
repository), the project's (.agents/memory, shared with the
repository) and yours for every project. Both backends now read and write
the same notes, found on disk and in a live capture of Muse Code 1.3.0.- Memory… in the palette (
/memory, Muse Spark: Memory) lists
up to 500 notes per scope with their scopes and summaries; open one to
read or edit it, create one, or delete one to the trash after a
confirmation. The scope'sMEMORY.mdindex gains a created note's line
and loses a deleted note's lines. - The Model API backend has Muse Code's
read_memory,add_memory
andedit_memory, with its arguments, refusals and JSON results, so
their rows read the same on both backends; at the start of a
conversation the model gets each scope'sMEMORY.mdand its notes'
names, as Muse Code gives them. A new note gets its index line. Writes
ask in Manual, run in Auto and Edit automatically, and are refused in
Plan; a refused path asks nothing. Not offered in Restricted Mode.
Linked scope folders below the workspace or data home are refused, so
they cannot expose notes outside their intended roots. - A new note is created exclusively and published whole: a synced hidden
copy is hard-linked into a free name, so it never replaces a racing
writer's note or shows partial bytes, and a filesystem without hard
links refuses the create. Names with spaces, brackets or percent signs
are encoded inMEMORY.md, so a note keeps one index line. - Updates to an existing note replace it atomically but do not take Muse
Code's native memory lock; simultaneous writers can still lose an update.
- Memory… in the palette (
- Session goals (M45, PLAN.md D38).
/goal <objective>sets a goal
the agent keeps working toward; a strip above the task list shows its
status, a progress bar and the work now and next, with Pause, Resume, Edit
and Clear (also/goal pause,resume,edit <objective>,clear).
On Muse Code these are its own goal commands, and a resumed conversation
shows its goal and task list. On the Model API backend the agent gets Muse
Code's four goal tools with the same results, the goal is saved with the
conversation and kept in the instructions while active, Stop pauses it,
and nothing starts a model call you did not ask for. A goal changed while
a request runs does not take that request's tokens or tool calls, and a
rejected/goalkeeps its draft. Built from a live capture of Muse Code
1.3.0. - Your own shell commands:
!(M46, PLAN.md D39). A message that
starts with!runs as a shell command in the workspace, outside any
turn, as Muse Code's!does, and gets its own row: You ran, the
command, its exit code, run time and output. The agent sees it with your
next message. On Muse Code it is the CLI'ssession/userShell; on the
Model API backend it runs through the shell tool's own runner, with a
Stop. Nothing runs in Restricted Mode, a command that could not run
comes back to the prompt with the reason, and one Muse Code could not
start without its Windows sandbox offers the setup, as the shell tool's
failure does. A running Model API!command is saved at once, so
another surface on the conversation shows its row and can stop it.
Markdown export includes a command's termination signal when Muse Code
reports no exit code. - Background work you control (M46). Move to background on a
running shell row, orCtrl+Bwhile the conversation in view runs one,
lets the command go on while the agent carries on; a background task has
Stop on its row and in the Agent map, which also has Stop all
(and the new Muse Spark: Stop Background Tasks command). The header
pill counts running background tasks. Muse Code'stask/background,
task/stopandtask/stopAllon its backend; on the Model API backend a
moved command runs without its time limit until it ends or is stopped,
and what it printed reaches the agent with its next request. Releasing
the last surface of a Muse Code session stops its background tasks;
another surface holding it leaves them running. A resumed or second
surface shows a running foreground shell and can move it withCtrl+B;
while that shell still awaits permission, it shows the same card and
leavesCtrl+Bto VS Code. A fork carries the end or lost-output note
for each inherited background shell. - Explain instead on question cards (M46): an answer in your own words
in place of the options (Muse Code'suserInput/clarify, and the same on
the Model API backend); the row then reads "Explained". - Approvals across panels (M46). A panel joining a conversation shows
its open approval cards on both backends, but never automatically
answers a card that was already pending under another panel's mode. With
several panels attached every approval needs an explicit choice; a sole
Edit automatically panel keeps its automatic plain-edit approval. - Subagents on the Model API backend (M48, PLAN.md D45). With the paid
settingmuseSpark.modelApiSubagentson and its rates accepted, the agent
can start child tasks. Each runs in parallel within fixed limits, with its
own transcript, the same tool approvals and workspace rules, and its usage
counted with the conversation. Every new child task asks first, in every
mode, Bypass included (Plan refuses it), and one consent covers at most
four requests, retries included. The Agent map can steer, stop, read and
reopen children; the child's row and Account & usage show its paid
attempts and tokens. On Muse Code, the map's Read result and Reopen wait
for a capture of Muse Code's replies to them. - Model API hooks (M51, PLAN.md D36). With the machine-scoped
museSpark.modelApiHookson (off by default), the Model API backend runs
Muse Code's hook commands for all 17 documented events: your
administrator's, yours and the project's.muse/hooks.json, in a trusted
workspace only. A hook gets JSON on its standard input (your prompt and
bounded previews of tool and model calls, without images, credential
fields or the Model API key), runs with time and output limits, and is
stopped with everything it started. APreToolUsehook can deny a call or
ask for approval, which a person then answers in every mode; a
PreLLMCallhook can stop a request before it is sent. Unsupported events
and handler types are reported and skipped; not all of Muse Code's
event-specific hook output is supported yet. Muse Spark: Hooks shows
whether the setting is on and opens it. - Scheduled prompts on the Model API backend (M52).
/loopsaves a
prompt with an interval or a five-field cron schedule in the conversation;
the panel lists due prompts and cancels them. A due prompt never runs by
itself: with the paid settingmuseSpark.modelApiScheduledPromptson, you
choose Run now and confirm that run's model and token rates. Prompts
belong to their workspace, conversation and key, and each occurrence runs
at most once, across windows and restarts. Anything that changes while the
price dialog is open cancels that approval. A schedule that would not fire
within its seven days is refused. On Muse Code, its own/loopremains
available through the model. - Conversation rewind and side chats (M53, PLAN.md D46). Rewind
conversation to here on a sent message branches the conversation before
it and puts its prompt back in the composer, with its Model API images
while replay still holds them (otherwise the panel says so). Side chat
opens a Plan-mode branch in its own panel without stopping the main one;
it runs no hooks, refuses outside MCP tools and scheduled prompts, and
closing it returns focus to the main panel. Muse Code 1.3.0 cannot fork
on Windows, so both are hidden there. - A row for every tool Muse Code runs (M43, PLAN.md D36). Memory rows
show the note and where it lives, and an edit as the text replaced; goal
rows show the objective, its status, a progress bar, what is being done
now and next, and the tokens spent; scheduled prompts show their
schedule, next run and how often they ran; web search shows its results
as links with snippets, on both backends; a picture the agent read, or
the Model API backend made, shows in its row. Every other tool in Muse
Code's list has a name, an MCP tool reads "tool (server)", and any other
result is indented JSON. All built from a live capture of Muse Code 1.3.0.
Tool-row pictures now use the checked workspace target and a bounded,
single-handle read, so a changing link or growing file cannot bypass the
10 MiB preview limit. - Workflows (M47, PLAN.md D40). A multi-agent workflow Muse Code runs
is a read-only card that keeps updating after the reply: its label,
status, what started it, each agent's state, attempt, time and tokens,
and the result or failure it reported. The N agents pill counts
workflow agents, the Agent map lists the runs and says how Muse Code is
set to start workflows (run.workflow_trigger_mode, read from its
settings file, never written), and Diagnostics reports that setting too.
Built from a live capture of Muse Code 1.3.0. Cancel, Skip and Retry wait
for a capture of Muse Code's replies to them. - Web search (M33). With
museSpark.modelApiWebSearchon, the model can
search the web on the Model API backend ($2.50 per 1,000 searches). Each
search is a row marked paid with its query and results, and a reply lists
the pages it cites under it (also in/export). - Image generation (M34). With
museSpark.modelApiImageGenerationon,
the model can create a PNG in the workspace withmuse-image-1.0($0.01
per image). Every image asks first, in every permission mode, Bypass
included, showing the prompt and the price, with no "always allow"; Plan
refuses it. A path that is taken, outside the workspace or not a.png
is refused before anything is billed, and a new image never overwrites a
file. - Muse Voice (M35). With
museSpark.modelApiVoiceon, the microphone
records for Meta's Muse Voice Transcribe instead of your computer's own
recogniser ($0.18 per hour of audio), streamed as you speak; the
transcript lands at the caret. The recorder isnative/windows/capture.ps1
on Windows, the macOS helper's new--capturemode, andarecordor
parecon Linux, which gets a microphone for the first time. - Opt in and loud (M33–M35, PLAN.md D30, D34). Off by default and
machine-scoped; a confirmation names the price when one is turned on, from
the palette's new toggles or in settings, and declining it turns the
setting back off. The composer's badge names what is on, the microphone
says when it is paid, and Account & usage tallies this window's searches,
images and seconds of audio with their estimated cost. - Image edits (M44, PLAN.md D37). With image generation on, the model
can also change one workspace image, or combine up to four, by a prompt,
into a new PNG (edit_image, Meta's/images/edits, $0.01 per image).
The card names the images it starts from; everything that could fail is
checked before anything is asked or billed. Image-edit sources now read
their checked canonical targets if a workspace link retargets. New image
output is reserved at its checked target before any paid request. - Images and Muse Voice on the Muse Code backend (M44). While a Model
API key is stored, the extension's ownidetool server offers Muse Code
an image and an image-edit tool, and the microphone can use Muse Voice:
billed to the key, never to the subscription, each image confirmed with
its price first, the rows marked paid, and the tally in Account & usage.
The key never reaches the Muse Code CLI. - Enterprise networks (M56, PLAN.md D43).
museSpark.sandboxNetwork(machine-scoped) passes Muse Code's
--sandbox-network:proxy-only(each new destination asks),
restricted(no network for commands) orenabled;defaultleaves
Muse Code's own default or an administrator's managed configuration.
It applies while the shell sandbox is on, and changing it restarts the
host.- Muse Spark: Diagnostics states the network posture (whether a proxy
is set, never its address; VS Code's proxy and certificate settings;
where Muse Code's proxy comes from;NODE_EXTRA_CA_CERTS,
SSL_CERT_FILE) and printsmuse config status, Muse Code's managed
configuration's recognized source and generation fields. Unrecognized
lines and failed-command output are withheld. - A Model API request that never reached Meta says why and what to check:
an untrusted certificate (a network that inspects HTTPS), a proxy that
wants credentials or refused the tunnel, or no route, with Node's own
detail beside it; it read "fetch failed". Quoted credential fields in
that detail are redacted in full, including spaces. - A permission mode above Muse Code's ceiling (its default permission
profile, or a managed policy) is refused with a sentence saying so and
what to choose instead.
- Prompt caching as Meta documents it (M56). The Model API backend's
prompt_cache_keynames the prefix every request starts with (model,
instructions, tools) instead of the session, so conversations in a
workspace share their cached start, andprompt_cache_retentionasks for
Meta's shorterin_memorydefault. The machine-scoped
museSpark.modelApiPromptCacheRetentionsetting lets the user choose 24
hours at the same cached-input price; a repository cannot extend it.
Changed
- The Windows job helpers' C# ships beside the host bundle (M55, M56;
PLAN.md D6). The shell job type, the MCP launcher and the Win32 half they
share are.csfiles undernative/windows/, read and compiled when a
helper is first needed, instead of strings indist/extension.js, which
stays under its 600 KiB budget. A helper built from the earlier source is
rebuilt once. - The Model API backend saves memory with the memory tools (M49). It
used to be told to write.agents/memorywith the file tools, which as
protected writes asked every time. The personal scopes, left out before
(PLAN.md D13), are now read and written too, and a memory note must be
UTF-8, as Muse Code requires. - CI (contributors). Pull requests run the seven cross-platform jobs
once per reviewed tree; merges tomaindo not repeat them, and a manual
branch dispatch remains for diagnostics. On Windows, unit test files run
one at a time and the accessibility gate opens at most two pages at once,
so the hosted runner is not starved; the pre-commit hook runs its lint and
format tasks serially. No check, threshold or deadline changed. An
opt-in live sweep (npm run test:e2e:live:modelapi, never in CI) runs the
Model API backend against Meta's real API, one case per feature, on the
contributor tier.
Security
- A Model API conversation belongs to the key that made it (M55). Each
saved conversation and scheduled prompt records a one-way SHA-256 digest
of its key, never the key. History, reads, resume and fork list and open
only the stored key's sessions. Replacing the key stops the old host
first and starts a fresh conversation; a paid image waiting for approval
or retry is refused rather than billed to the new key. Conversations
saved before 0.9.0 stay on disk but cannot be reopened. - Signing out or changing account clears the panel (M55). The previous
account's transcript, tool output, agent views, usage, model and skill
lists and file chips are cleared; unsent draft text stays. A read, History
event, rename or message still in flight cannot refill the panel or run
under the next account. Overlapping sign-outs share one operation, and a
key write or backend restart already under way finishes before the key is
cleared. - Workspace file access re-checks its target at the moment of I/O
(M54). Picked files,read_file,write_file,edit_file, tool-row
image previews and paid image output read or write the checked canonical
file through one bounded handle. A link or junction swapped after the
check, or a file that grows, cannot expose or overwrite anything outside
the workspace or exceed its size cap.
Fixed
- Model API keys in Meta's current format are accepted. A key that
starts withLLM_(Meta's current keys have no|) was refused as
malformed; both shapes are now accepted, and both are redacted from logs. - A question answered the moment it appears is taken (Model API). The
card was shown before the question was held as pending, so an answer in
that instant was refused and the turn waited for ever. Found by the live
sweep. - Account & usage reset timing (M53 follow-up). The open modal updates its
countdown each minute and stops treating an expired report as current. It
uses Muse Code's reported account-level percentages and reset timestamps
without guessing model or plan multipliers. Sign-out and authentication
changes clear visible usage; the old global snapshot is no longer read and
is removed during activation when storage permits. An empty CLI read also
clears a same-host snapshot. A late read cannot replace a newer report or
restore a stopped host's usage. - A resumed Muse Code conversation shows its task list (M45). A resume
asked for inline history, which carries no task list; it now asks for the
folded snapshot, which carries the task list and the goal. - A stopped task read "Failed" (M46): a row stopped by you or by Stop
now reads "Stopped" with the reason, and is read out so. - The Agent map's note about Muse Code's delegation setting showed only
once Account & usage had been opened in that panel (M47). Opening the map
now reads the setting itself. A map with background tasks also no longer
says it is empty merely because it has no subagent row. - Muse Code behind a proxy lost the IDE tools (M56). With
http.proxy
set andhttp.noProxyempty, Muse Code sent its requests to the
extension's loopbackideserver (diagnostics, images) to the proxy,
which cannot reach them. Loopback is now always in Muse Code'sNO_PROXY
whenever it has a proxy, VS Code's or its own. - Malformed VS Code proxy settings (M56). A wrong-typed
http.proxyor
http.noProxyvalue is ignored before Muse Code's child environment is
built; Diagnostics reports the same validated setting state. - A command Muse Code moved to the background read "Interrupted" when
its turn ended (M43). It now shows what it printed, says it is still
running, and is listed among the background tasks. - Model API conversations that narrate before a tool (M42, PLAN.md D35).
Text the model writes before a tool call is replayed as commentary, as
Meta requires; replayed as an answer, it made the next request fail with
a 400. A reasoning item is replayed with its summary (empty when there was
none), and a reply that was reasoning alone is followed by the minimal
message the docs ask for. - A server that stops mid-reply (M42). A stream that ends because the
instance shut down or was overloaded is sent again, with the retry notice
in the transcript; a 502 is retried like the other server errors.