Mework 1.1.0
Mework 1.1.0 makes WSL and SSH workspaces work like local ones, puts the file tools inside the sandbox, and keeps long-running work going across restarts. The website and documentation now live at mework.dev.
Downloads
| File | Notes | |
|---|---|---|
| Windows installer | Mework_1.1.0_x64-setup.exe |
Per-machine NSIS installer; bootstraps WebView2 if missing. Updates itself from this page. |
| Windows portable | Mework_1.1.0_x64_portable.zip |
Unzip and run mework.exe (keep mework-aisdk.exe beside it). |
| Windows MSIX | Mework_1.1.0_x64.msix + Mework_msix_signing.cer |
Signed with Mework's own certificate: import the .cer into Local Machine → Trusted People once, then open the package. Windows 10 2004 or later. |
| macOS | Mework_1.1.0_aarch64.dmg |
macOS 13 or later on Apple silicon. Developer ID signed and notarized: open it and drag Mework to Applications. |
| Checksums | SHA256SUMS |
SHA-256 of every file above. |
Every file is also on https://dl.mework.dev/v1.1.0/, a mirror that is faster where GitHub's downloads are slow. From this version the in-app updater downloads from the mirror first and falls back to GitHub.
Remote workspaces
- A WSL or SSH workspace reads its own
MEWORK.md,.meworkfiles and rules, keeps its project memory there, and runs its own skills, MCP servers and hooks on its machine. A conversation uses the skills, MCP servers, hooks and project memory of every one of its workspaces. - SSH passwords, key passphrases and new host keys are asked for in the app; a changed host key is refused.
- Each workspace keeps its shell's working directory, locally, in WSL and over SSH; a command that leaves the workspace starts the next one back at its root.
- An isolated workflow step gets its worktree on the machine its workspace is on, and its hooks follow it there.
- Workspaces are named by their absolute path everywhere.
Sandbox
- The sandbox now covers the file tools (
ls,grep,find,read,write,edit) as well as the shell. A machine that cannot sandbox refuses them before the approval card. - The sandbox page warns when a Linux workspace sits on a file system that ignores case, where a protected file could be reached by another spelling.
- Imports in
MEWORK.mdand memory files are workspace files: the import-trust prompts and their settings page are gone, as is the switch that put the app data directory into the system prompt.
Work that keeps going
- Workflow runs interrupted by a quit or a crash resume at the next launch. Skip and Retry are offered on every running step for the whole run, and the 30-minute budget starts when the run does and stops while approval cards wait.
- A conversation whose background task finished wakes up even when it is not on screen.
- A command still running at its timeout moves to the background, in subagents too and with every task slot taken.
- "Always allow", what the model has read, and a paused message queue survive a restart.
- On macOS, background commands and servers end when Mework crashes, not only when it quits.
Hooks, skills and roles
- Hooks copied from Claude Code work unchanged. The hook confirmation says where each hook runs, and a hook card says when its context reached the model.
- A subagent role can pick its own skills, MCP servers and hooks, or follow the conversation's.
- The Skills, MCP and Hooks lists refresh when their files change; a selection whose file is gone shows as dangling and fails the run until it is unticked. A language server restarts when its
lsp.jsonentry changes.
Everything else
- The whole app — menus, approval cards, hook messages, errors and settings — speaks the app language.
- macOS: ⌘ default shortcuts with Mac keycaps, and Settings… (⌘,) in the application menu.
- Approval cards show every shell's whole command and every URL a fetch reads.
- System cards anywhere in the timeline are sent from their place. Branching puts a message back into the composer whole, and a new task opens with its preset's opening messages.
- Preview: hand a page back to the model, answer its dialogs, see it in the app theme;
preview_clickandpreview_filltake snapshot uids. A local HTML file opens with its folder. - Menus open down from the top half of the window and up from the bottom half.
中文说明
Mework 1.1.0 让 WSL 与 SSH 工作区用起来和本机一样,把文件工具也放进沙箱,并让长时间运行的工作在重启后接着跑。官网和文档迁到了 mework.dev。
下载
- Windows 安装版
Mework_1.1.0_x64-setup.exe:按机器安装,缺少 WebView2 时自动引导安装,会从本页自动更新。 - Windows 便携版
Mework_1.1.0_x64_portable.zip:解压后运行mework.exe(mework-aisdk.exe需在同一目录)。 - Windows MSIX
Mework_1.1.0_x64.msix与Mework_msix_signing.cer:先把证书导入「本地计算机 → 受信任人」(只需一次),再打开安装包;需 Windows 10 2004 及以上。 - macOS
Mework_1.1.0_aarch64.dmg:macOS 13 及以上、Apple 芯片;带 Developer ID 签名并经公证。 - 校验
SHA256SUMS:以上所有文件的 SHA-256。
所有文件也在 https://dl.mework.dev/v1.1.0/ 镜像上,GitHub 下载慢的地方更快;从这个版本起,应用内更新先从镜像下载,失败再回到 GitHub。
远程工作区:WSL、SSH 工作区在自己的机器上读取 MEWORK.md、.mework 与规则,在那里保存项目记忆,并运行自己的技能、MCP 和钩子;一个对话可以用它所有工作区的技能、MCP、钩子与项目记忆。SSH 的密码、密钥口令和新主机密钥在应用里询问,主机密钥变了一律拒绝。每个工作区记住 shell 的当前目录,离开工作区后下一条命令回到根目录。隔离的工作流步骤在工作区所在机器上建工作树。工作区一律以绝对路径显示。
沙箱:沙箱现在也覆盖文件工具(ls、grep、find、read、write、edit);不能沙箱的机器在审批前拒绝。Linux 工作区所在文件系统不区分大小写时,沙箱页会提示。MEWORK.md 与记忆文件里的导入视同工作区文件,导入信任的询问和设置页已移除,把应用数据目录写进系统提示词的开关也已移除。
持续运行:退出或崩溃打断的工作流在下次启动后接着跑;运行中的步骤全程可以跳过或重试,30 分钟预算从真正开始时计算、等待审批时暂停。后台任务结束时,即使对话不在屏幕上也会唤醒。超时仍在运行的命令转入后台。「总是允许」、模型读过的内容、暂停的消息队列在重启后保留。macOS 上 Mework 崩溃时也会结束后台命令和服务器。
钩子、技能与角色:从 Claude Code 复制来的钩子原样可用;钩子确认里写明每个钩子在哪里运行。子代理角色可以有自己的技能、MCP 和钩子。技能、MCP、钩子列表随文件变化自动刷新,文件不见了的勾选项显示为悬空并让运行失败,直到取消勾选。
其他:整个应用(菜单、审批卡、钩子消息、错误与设置)都用应用语言显示;macOS 默认快捷键用 ⌘ 并显示 Mac 键帽,应用菜单里有「设置…(⌘,)」;审批卡显示每条 shell 命令全文和每个抓取的网址;时间线中间的系统卡按位置发送;预览页可以交还给模型、处理对话框、跟随应用主题;菜单在窗口上半部向下展开、下半部向上展开。
