Changelog
What's new, improved, and fixed in each Muse Code release. For install and upgrade steps, see the Muse Code overview.
1.4.2
New
/deleteasks before removing the current session and its child sessions; video-enabled sessions and sessions with unverified log ownership are kept with an explanation- Background Bash commands return a Work ID so agents can stop the command
- Muse session protocol clients can grant several workspace roots at once โ
session/startandturn/startaccept aworkspaceRootslist of absolute paths; every listed root gets the same write access as the primary root, and aturn/startlist replaces the set for that turn and later turns - Added
muse voice transcribe <file> - Added
muse model-profile show <model> --effort <tier>, which prints what a model actually resolves to for each setting at that effort level session/listaccepts an optionalfilterthat narrows the list by session ID, branch, or name and title words, and echoes the filter it applied asappliedFilter- The TUI serve lane honors several workspace roots at once โ every listed root gets the same write access as the primary root, each extra root's own rules file loads under that root's recorded trust, and the system prompt names every root; extra roots never gain project trust
muse serveaccepts feedback submitted by connected clients- Choose the provider and model for one
muse serveprocess with--providerand--model, without changing saved settings
Improvements
- The
model/listdescribed-tier schema type is nowModelDescribedReasoningEffort, and per-tierdescriptionis omitted when the catalog declares none - Subagent-tree live rows now breathe color smoothly โ the โ/โ/โ glyph brightens and dims smoothly instead of stepping through a few held shades, matching the resume startup row
- A follow-up sent while your lane is still busy gets an immediate "Received, on it." instead of silence until the current step ends
- Show alt(option) in tmux shortcut hints and explain Mac modifier names in shortcut help
- Automatic history-preserving checkpoints every 16 MiB of session log are now off by default while their follow-up fixes land; set
context_compaction.periodic_checkpoint_bytesto a positive byte count (for example 16777216) to opt back in, and compaction checkpoints are unaffected - Retry stalled model responses through the remaining attempt budget
- Verify reminder no longer accepts a scoped "not run" disclosure as cancelling a done or fixed claim, lint alone as the covering gate when a test exercises the change, or "cannot run here" without a failed attempt to acquire the runtime or device (install, lease, launch)
- Grill uses available project checks to focus follow-up questions
- The full-screen monitor view shows the command or script the watch runs, with secret values masked
- The rewind picker shows turns older than the live window as read-only history
- Idle composer tips can now suggest using a workflow or asking the agent to monitor a long-running task
- Compaction now shows
Compacting contextwhile running andContext compactedwhen done - While working on a
/goal, the agent can pause its automatic follow-up turns for up to an hour while it waits on a background command or monitor, instead of checking again and again; the completion notice or your next message resumes the goal at once
Fixes
- Security: Subagent worktree git probes and cleanup dirty checks now run in the actor-confined sandbox, so hostile repo config in an agent-writable nested repo can no longer execute filter commands on the host. When the sandbox cannot be created, cleanup keeps the worktree for inspection instead of deleting it
- Keep human messages that match generated summaries when replaying compacted conversations
- Recover session name changes from saved checkpoints
- Long sessions with a background monitor, running subagents or many open tool calls keep their live view history up to date instead of freezing
- Keep previously completed Workflow indicators from reappearing when a session resumes
- Ignore saved work-stop notices linked to a different session when resuming
- Rejected peer messages no longer appear delivered or read
- Completed message batches with invalid results show an unresolved status, consistent with message headers and groups
- Lost task-stop confirmations no longer appear as a disconnected session
- A subagent's final result stays visible in its detail view instead of briefly disappearing while the view refreshes
- Unstarted subagents from older sessions without saved execution state are now marked failed after a restart instead of staying scheduled forever
- Prompt Hint now sees the full conversation instead of only the last turn, Away Recap has its own session cache key, and side-call model requests carry a purpose label so they are no longer mistaken for the main conversation in session records
- The verify reminder's checker now keeps its fixed
highlevel only on the Muse Spark 1.3 models atmaxeffort โ the configuration that level was actually measured on. On any other model, a session atmaxnow gets a checker at its own level instead. This mattered becausemaxcan be reached on models that do not offer it in the effort picker: a stored setting or an effort carried across a model switch all keepmax, and those sessions were being checked with a level tuned for a different model muse execexits with the run's own result when post-run cleanup stops responding, instead of failing a completed run- Long reasoning turns are no longer cut off by the stream idle timeout while the model is still thinking
- A finished subagent now shows above the agent's final reply in the live transcript, matching a resumed session
- Restore recorded workflow completion and cancellation status when resuming a session
- Stopping a watch shows one completion with its reason available in expanded details
- Prevent
work_stopfrom leaving the session waiting after a subagent's background tools stop - Keep repeated and queued messages distinct when continuing a conversation
- Long sessions no longer fail every later turn with
Duplicate function_call_outputafter an automatic context checkpoint - A session being deleted no longer appears in the session list while its removal is still in progress
- Images read with
read_fileare re-encoded when over 2 MiB and requests keep image payload under a budget instead of failing with HTTP 413 bash_input terminateon a background command that carries a v2 Work ID now stops it (or returns its finished result) instead of failing with a Work Stop contract violation- Reopen saved sessions without losing their original checkpoint capture choice
- Stop child agents consistently from tool requests and confirmed item or bulk actions
- The
/modelflow no longer flashes the bottom status bar between the model and reasoning-effort pickers, and the reasoning-effort picker no longer repeats a hint line on the selected row - Keep restored workflow messages in their original conversation positions after session resume
- Workflow stop receipts show cancellation after the workflow stops
- A turn that includes a video input no longer fails with an invalid-checkpoint error when an automatic history-preserving checkpoint comes due; the checkpoint is skipped with a recorded reason and the previous one stays in place
- Changing the Workflows setting between sessions is announced to the model on the next turn even when the session resumes through a checkpoint
--modelnow accepts the name shown in the /model picker and resolves it to that model's gateway id instead of failing with "model does not exist or you lack access"- Detail lines under the Thinking and Working status now start their connector under the status diamond instead of under the status text
- Sessions no longer become unresumable when a checkpoint grows past the resume reader's size limit; the oversized checkpoint is skipped and the previous one stays in use
- Resuming saved sessions now restores missing conversation history
- Pending approvals listed for a session that is not open now point at the same place in its history as the session's saved view, on any machine
- Sessions no longer exit silently at startup on terminals that never answer the cursor-position query
- Preserve saved subagent stop results when retrying older long request IDs
- Peer messages that cannot start a turn now show as parked until your next turn in the queue instead of looking stuck
- Messages and follow-up instructions sent on later turns reach the original running subagent
- A finished background result no longer stays hidden behind a stuck "Working" indicator when a new prompt lands as the previous turn ends
- Use Up or Ctrl-P to recall a hook-blocked prompt while preserving your current draft
- Oversized tool-call identifiers return a retryable error without interrupting other tool calls
- Keep credentials in macOS Keychain across updates
- Installing a plugin from
/pluginsnow finishes on the plugin's own page with an "Installed <plugin> plugin." note instead of an extra screen, and Discover marks installed plugins so Esc takes you back where you started - When a checkpoint cannot be saved, the turn keeps going from the previous checkpoint instead of failing with
invalid context projection checkpoint; the refused checkpoint leaves nothing behind for a later read or resume to trip on - Starting a session with a chosen id no longer fails with an id conflict while the host is cleaning up an unused session directory for that id
- A clean session end no longer fails on a slow disk while shutdown time remains; the final log flush now uses the whole shutdown window instead of a fixed ten seconds
- Reject new managed-work batches above the session limit while preserving existing work status and controls
- The monitor view's command line keeps the rest of a command after a masked value that is glued to a separator
- A session id carried in a web address (jsessionid or sessionid) is hidden like other address credentials before text reaches the model
- Monitor commands with non-ASCII web addresses no longer crash the task view
- Pasting a large block under load no longer occasionally strands its first character outside the collapsed paste placeholder
- Keep subagent follow-ups working after resuming a session whose latest checkpoint was written with capture enabled, instead of failing the send with a session-read error
- Setting a goal right after resume no longer fails with a goal-store custody error while the previous session-log write settles
- Preserve original instructions across context compaction
- Session views stay readable while the server cleans up old sessions
- Resuming a session after an automatic context checkpoint keeps its todo list, so the todo reminder and later compaction summaries show the accepted items instead of an empty list
- An automatic history-preserving checkpoint (opt-in via
context_compaction.periodic_checkpoint_bytes) now carries the reminder budgets inherited from earlier turns and waits for a turn's first model reply before publishing over an undelivered message, so the next turn keeps its due reminders and never compacts away text the model has not seen - Turns under the denyUnmatched approval mode no longer hang for about a minute after the answer is done
- Switching sessions no longer fails when the previous session is slow to shut down
- Scrolling back through an open session whose saved history stopped updating no longer shows running work as failed; loading history newer than the last save now fails with an error instead
- Resuming a session after an automatic context checkpoint no longer re-records a skill you read earlier or changes the skill reminder's view of it
- Keep loaded skill instructions when trimming old tool results
- Reopen a session whose newest checkpoint cannot be replayed, instead of failing the whole open
- Reconcile a saved reasoning effort against the selected model instead of failing the launch when the model does not serve it
- Approved peer notifications wake idle agents by default and respect explicit delivery and wake settings
- Resume workflows from the session copy you opened instead of a stale source path
serve --no-session-logsessions now emit live frames โturn/started,turn/completed,session/statusChanged, item events, andapproval/requestpresentation โ instead of acknowledging a turn and going silent; approvals parked under the profile's prompt-unmatched ceiling become visible and answerable- Let a resumed session send a follow-up to its dormant subagent after a periodic checkpoint instead of failing the send and repeating the subagent's earlier result
- Resuming a session in the terminal app after its context was compacted delivers, exactly once, the messages from other sessions that were accepted but not yet delivered before the compaction
- Work status reports when background Bash commands finish
- Apps connected to
muse servecan show a manual compaction as running while it runs, not only after it finishes - Start sessions when the app data folder is group-writable
Performance
- Scrolling back through a session that is not open reads its saved view instead of rereading the whole session log
- Long sessions with large retained task failure messages no longer re-copy that text on every refresh
- Finishing background commands and monitors no longer rescan the whole transcript in long sessions
- /fork no longer stalls on large session stores
- Refreshing a session with a generated workflow child no longer rereads and rebuilds all of its settled task history on every refresh, so long workflow sessions stay responsive
/resumeandmuse resumefind new sessions already listed, so they have less to catch up on when they open- Repeated scheduled prompts can use less space when created and delivered within the same run before compaction, while keeping distinct occurrences
1.4.1
Improvements
model/listrows now carry each model's described reasoning-effort tiers (reasoningEffortVariants, with the catalog's per-tier display strings) and the row's catalog default (defaultReasoningEffort), so Muse session protocol clients can render the effort picker without guessing- Expanded peer message rows show readable message details instead of internal status fields
- Forking shows a progress status in the chat until the new session is ready
Fixes
- A long session keeps its live view running when view checkpointing falls behind, instead of going dark
- Unknown peer message results stay unresolved instead of borrowing a known delivery status
- After a crash and reopen, a re-asked tool approval shows the arguments the model wrote again, not the runtime's internal version of them
- Scrolling back through a session while a turn is still running no longer shows the running tool call as failed
- Sessions below
maxeffort, and every model other than Muse Spark 1.3 atmax, get the fuller system instructions back โ including the verification, evidence, and professional-objectivity guidance โ while Muse Spark 1.3 atmaxkeeps the trimmed version. Later formatting and summary improvements are kept in both - Stop failed session recovery from incorrectly quarantining pending subagents
- Sessions on the Muse Spark 1.3 contributor model now get the todo, memory, and goal reminders below
maxeffort, matching the other 1.3 models - Interrupting, cancelling, unqueuing, compacting, or steering a turn from an older session, or one the server started itself (Goal steps, reminders, scheduled runs, queued follow-ups), no longer fails with
invalidParams; IDs the server creates for turns and approvals are now UUIDv7 - Repeating
work_stopfor a stopped subagent reports its terminal state - Support
Ctrl+Jfor newlines in feedback and editor inputs - Use
Ctrl+Alt+Bto background commands when tmux interceptsCtrl+B, with matching shortcut hints - Keep task controls scoped to the selected session, including after recovery
- Preserve each user input's identity when restoring compacted context
- Completed Workflows show one accurate status and keep the full result available in details
Performance
- Long sessions with many completed workflow-child tasks stay responsive instead of re-scanning retained task history on every child update
- Long-running sessions stay responsive when the task list refreshes
1.4.0
New
- Session protocol clients can list a session's invocable skills with
skill/list, receiveskill/changedupdates, and invoke a skill directly through aturn/startskill input part muse serveclients receive live session status changes and an attention flag when a session has a pending approval or input- The serve protocol can now report your remaining subscription usage on demand โ
usage/readreturns the last-seen 5-hour and weekly windows without spending a prompt, andusage/changedpushes updates when they move - Ctrl-R prompt history search gains a per-gesture scope:
Ctrl-Scycles this session, this project, and everywhere, with the scope shown in the search row - Save MCP tool and network destination approvals across sessions with Always allow
- Continue local Claude Code or Codex sessions with
/resume-claudeand/resume-codex /plugins installaccepts--scope useror--scope project, so a local plugin can be installed for the project instead of only for youmuse servenow pushes a best-effortsession/viewHealthChangednotification when a session's live view becomes unavailable, with the reason, so clients need not wait for their next read to learn it- Set
MUSE_SKIP_PROMPT_HISTORY=1to stop saving new prompts to history; prompts already saved still load and recall normally - The Errors tab's detected-plugin row now asks before installing a detected plugin, instead of installing it the moment you press Enter
- The exported session protocol schema now describes the
task/background,task/stop, andtask/stopAllcommands - Choose a local Claude Code conversation in
muse resumeand continue it in a fresh session - Choose the Codex source in
muse resumeto continue a local Codex conversation in a fresh session - A hook can declare an
onFailurefallback โ when the hook fails (non-zero exit, timeout, or invalid output), the declared successor runs as an ordinary hook at the same event and can ask for your approval; a successor can never loosen a decision, widen the original tool call, or grant approval itself - Choose a local Claude Code or Codex conversation in
/resumeand continue it in a fresh session /permissions(choose what Muse Code is allowed to do) is listed in the slash palette, Help, and inline completion instead of being hidden- Install the Python SDK from PyPI โ muse-code-sdk and its wire-types companion muse-code-msp
- Resume a session by its exact Session Name with
muse resume <name> - Native subagents whose spawn result shows a Work ID can be stopped with
work_stop - Choose which fields appear in the bottom status bar with
/hud, with live preview and saved preferences muse exec --output-schema <FILE>makes the final answer schema-shaped JSON by sending the file's JSON schema with the request (Meta provider; other providers refuse the flag at startup)- After a failed tool call, a
PostToolUseFailurehook (or a failing hook'sonFailuresuccessor) can propose a corrected call throughupdatedInput; the correction re-runs as a new call through hooks, policy, and approval, bounded by the declaredonFailurechain depth - Session protocol clients can opt in to a live session-list stream โ request the
sessionListStreamcapability atinitializeto receivesession/listChangedwith the updated row instead of re-pollingsession/list - Sandboxed Bash commands on macOS can request one-time approval to connect to specific Unix sockets
- Plugins that declare Claude-format agents now install and publish those agents as reviewable Agent Definitions, and unsafe or duplicate agent declarations are rejected at install instead of being silently ignored
resume <id> --no-session-logreplays a saved session read-only and says up front that nothing is being recorded;resume --lastand the startup picker still need session logging- Preview pending agent messages above the composer with sender labels
plugins inspectshows a Claude plugin's agent inventory with each agent's review status, and keeps showing it after the plugin's source files are removed/renamealiases/nameplugins approveandplugins rejectaccept plugin agent selectors and persist review decisions safely- Native subagents can now be inspected with
work_statususing their Work ID; the status shows their spawn-time state - The TUI Plugins screen shows each Claude plugin's agent count, one row per Agent definition with its review status, and the passive Agent inventory alongside the live package review
- Review pending plugin hooks at startup, with options to trust them or continue without approval
- Claude plugin command and skill
allowed-toolsdeclarations can now be reviewed in plugin review, and an approved declaration skips approval prompts for matching tool calls while that command's or skill's invocation turn is live - Switch between the main conversation and a side chat with
Ctrl+/without losing drafts or interrupting either run - Added an observation-only
Interrupthook that runs when you cancel a turn with Escape /bugreports a bug with the type already selected- Use passive FTP from sandboxed commands with network approval
- The exported session protocol schema now types the
session/startedandsession/closedlifecycle notifications, so generated clients decode the first frame a session broadcasts instead of hand-parsing an untyped payload /modelspicker now offers a reasoning-level step right after each model switch- Renaming a session now pushes the updated row to
session/listChangedsubscribers โ your own acceptedsession/renamestreams instead of waiting for the nextsession/listpoll - Press Delete on a supported settings row (
/settings) to reset it to its default โ the saved choice is removed and the setting returns to what it would be without it (some rows take effect next session; rows without a reset say so) /copynow opens a scope picker over the last response when it contains code blocks or ran shell commands, so you can copy the full text, one block, or one command; Enter copies,wwrites the focused item to a file, and the Always row (or the new Copy full response setting) skips the picker from then on./copy Ntargets an older responsemuse resumeand/resumenow list sessions with a damaged log by their ID; choosing one starts a new session that continues the work from that log, which is left unchanged- Inspect recorded cross-agent links with
muse trace inspect --session-log --causal
Improvements
- The startup resume picker's "session already open" notice now names the process holding the session (pid, host, and lock age) and, when that process is on your machine and still running, shows the exact
killcommand to free it - Prompts saved by earlier versions and prompts from other projects no longer show on Up/Down; find them with
Ctrl-R - Up/Down prompt recall shows only prompts from the current project, starting with this session's
- Todo, memory, and goal reminders are on by default only in muse-spark-1.2 and muse-spark-1.3 sessions below
maxreasoning effort, and off by default elsewhere - Muse now gets guidance for saving your first memories and importing local Claude Code or Codex memories
- Subagent results report their working folder, starting commit, excluded parent changes, and cleanup status
- Image and video attachments now keep numbered references across prompts and replay
@muse-code/sdknow versions in lockstep with Muse Code, so the SDK version matches the release it ships with- Voice input is enabled by default on Windows x64 and ARM64
muse execreports retained subagent workspace paths and setup or cleanup failures on stderr/upgradeand subscription quota guidance are now available to everyone without a launch flag- New subagents receive explicit guidance to follow parent task updates within the user's constraints and their existing permissions
- Align
/usagecard styling with/statusand/mcp - Running
resumewith--no-session-lognow says the flag turned session logging off, how to resume, and that sensitive-mode launches always set it - Live tool activity uses the same pulsing diamond as Thinking
- When the skills catalog must compress entries to fit, compressed skills keep their short description, plugin and prompt-named skills keep full detail first, and the catalog and
/skillssay how many entries were compressed - Agent tree commands now reject non-sound ancestry while keeping healthy branches controllable
- Preserve shell output colors in
Ctrl+Oand!commands on supported terminals /resume-codexand/resume-claudeask which session to resume when no session ID or log path is given- Show context Warning/Blocked alarms as a percentage whenever the provider's context limit is known
- Subagent views show workspace paths, base commits, and cleanup status, including after reopening a session
- Claude plugin skills that declare
allowed-toolsnow load with plugin statuspartialand a compatibility row forallowed-tools; a malformedallowed-toolsvalue rejects the plugin - Work status results show a plain-language summary instead of raw JSON
- Workflow results show where child tasks ran and whether their workspaces were kept, removed, or could not be cleaned up
- The built-in grill skill credits the upstream skills it adapts, and the core plugin ships their MIT notice
- Recover prompts cleared with
Ctrl+Cfrom prompt history - Recurring scheduled prompts give the agent an expiration countdown on their final three runs
- Built-in capabilities activate without asking for review
- Foreign hooks only ask for re-review when their own command or script changes
- Whole-plugin
plugins reject <plugin-id>reports how many trust rows it disabled instead of listing each capability - Keep pending peer-message sends running in the background after the initial wait
- Feedback reports can include redacted local trace files after you approve file attachments
/stopand Tasks Stop actions now use the same durable Work Stop path for workflows, background commands, and monitors- Avoid repeated plugin hook approval after script-only or metadata-only updates
- Clarified Name and Description in
/namehelp and resume search - Quota in the HUD no longer shows a
(stale)suffix - Keep later session message status updates in the sender's conversation without repeating the original message
- SDK clients can discover each model's supported reasoning-effort choices
- Vim composer editing is available; turn it on for the session with
/vimor persist it withtui.editor_modeset tovim /pluginsno longer lists the TBH Reminders row โ bundled reminders run invisibly like every other builtin- Message results show receipt details alongside the send outcome
- The
monitortool is now available by default /skillslist rows for third-party skills show a short source tag (e.g.[x] threejs ยท threejs.org), andskills inspectreports the skill'ssourceandlicense- Built-in grill skill ships cleaner instructions with corrected upstream credit
- Long assistant answers now show up to 300 lines before folding behind
ctrl+o - Session Name lookup reports former names as unknown and lists affected UUIDs in recovery errors
- Startup memory summary keeps more of your saved notes before trimming
- MCP plugins can declare literal environment values and named host variables
- Plugins with up to 20,000 files and folders now install instead of refusing over 4,096
- Prompts with many media labels, malformed markers, or unpaired marker text are scanned in one forward pass instead of repeatedly searching the remaining prompt, so composer history, launch, and retraction stay responsive on long prompts
- When asked for a short summary, the agent names user-visible features and stops โ no run instructions, ports, file inventories, or version strings
- Plans stay in chat and clearly tell you how to start or revise the work
- Allow sessions to share the same name
- When a file edit finds no exact match, the failure now names where the snippet appears at a different indentation and by how much it is shifted, so the retry can be issued with the file's own indentation instead of guessing
- New sessions at Max effort now allow 64 concurrent agents including the main agent, matching Ultra; set
agents.execution_capacityto keep a smaller pool - Resume search now matches the Settings input, with a visible cursor and the end of long searches kept in view
- Pasted text now searches sessions in both
/resumeand the startup resume picker - Submitted prompts appear dimmer while held above the composer awaiting a response
- The resume startup progress row (muse resume) now breathes with a โ/โ/โ diamond glyph (like the working-activity row) instead of a braille spinner, brightening and dimming smoothly with the breath
- Subagent, workflow, and background terminal rows in the session tree now breathe with the diamond activity glyph instead of a braille spinner, and finished rows show a static diamond in their success or failure color
Fixes
- Security: When
settings.jsoncannot be read, feedback and diagnostic upload stay off instead of turning back on over a saved opt-out - Security: Prompts carrying a credential in a recognized format โ a token with a known vendor prefix such as
sk-orghp_, credentials in a URL, anAuthorization:header, a private key, or/loginwith its argument โ are no longer saved to prompt history or offered by recall; prompts saved before this change are unaffected - Security: The local prompt-history file and its lock file are now created owner-only, so the workspace paths and session ids recorded beside each prompt are not readable by other accounts on a shared machine; a history file that already exists keeps its permissions until the store is next rewritten at the entry cap, when the owner-only replacement takes over
- Security: Plugin agent definitions now bind the plugin package contents into their review approval, so a previously approved agent shows as modified and stays inactive until you approve it again in the plugins drawer
- Security: Background Git status checks now run inside the sandbox, so a program named in a workspace's Git configuration cannot change files on your machine or reach the network
- Security: Plugin agent definitions are no longer loaded from a stale or tampered installed record; a stale record asks for a plugin refresh and a tampered one is refused as an inventory integrity failure
- Security:
MUSE_TRANSPORT_TRACEno longer prints your API bearer token when a request is retried after the credential refreshes - Security: Windows sandbox Root:Read now grants the sandbox group read-only access through an optional background worker; existing write, credential, token, desktop, Job and network limits remain
- Security: The Linux sandbox now drops every capability before running a command, so sandboxed code can no longer unmount the sandbox's own protective mounts
- Security: Subagents keep their admitted permission authority as a ceiling. A committed human mode change reaches running subagents at their next action in either direction, but never widens one beyond that ceiling; a request already pending keeps its captured posture
- Security: Sapling repository commands now run inside the sandbox, so a
[hooks]entry in a repository's own config can no longer execute unconfined when a workspace opens - Security: Limit TCP network approval rules to the exact host and port
- Security: Redact credential-like values from provider error request and trace IDs
- Keep the todo list up to date when long sessions compact older context
- Active goals keep making progress after a mid-run update instead of stalling
- A command that reaches a session just as it stops now fails cleanly instead of waiting forever for its reply
- A video attached to a model that cannot accept video no longer breaks the session with a repeating API error; the video is skipped with an inline note and the conversation continues, including for sessions already stuck before this fix
- A resumed workflow that replays its previous result now settles the workflows row instead of spinning forever
- Collapsed tool headers fit narrow terminals while keeping reminder and goal outcomes visible and marking shortened text with an ellipsis
- Improve recovery of queued subagent messages after interrupted session saves
- Completed subagent command rows no longer reappear when switching between Main and child views
- Subagent commands accept requests containing extra fields
- Forking preserves user messages when the initial prompt changes after a reminder
- A session started while the session-name registry is briefly locked still gets its name once the lock clears
- Context compaction no longer reports you as logged out after
/login - Skills opened with
read_skillnow show their folder location, so helper files open on the first try - Errors for invalid subagent tool lists explain the cause instead of suggesting an ineffective retry
- Pressing
pto resume a paused Workflow no longer answers "resume handoff unavailable" when the monitor still holds a stale stop snapshot; the typed resume handoff reaches the runtime - Allow
git initon Windows around empty.gitdirectories while preserving protected metadata and existing access denials - Goals recovering after a restart keep the finished update instead of starting it over
- Preserve conversation output when loading history needs a retry
- Memories saved after a session starts, on this or another device, now show up in that session at the next turn instead of staying hidden until restart
- Pressing Up to recall a very large prompt from history no longer floods the composer with the whole text โ it comes back as the same
[Pasted Content N chars]placeholder a fresh paste shows, and Enter still sends the full original prompt - When your saved prompt history cannot be read, the footer now says so and names the file instead of starting up as if you had none
- Sessions whose history view was poisoned by a since-fixed defect recover on the next open instead of staying empty
- Trusted project
.mcp.jsonfiles now load MCP servers and override user settings - A command still waiting for its acknowledgement when a session stops now fails at once instead of waiting out its whole budget
- A session without a resolved model (for example a first run without a plan) now fails each prompt with a clear "no model configured" message instead of sending an invalid request and showing a provider 400 error
- Show recovered task failures in the session timeline after restart
read_skillno longer fails with unknown-skill after a plugin is installed or updated from another terminal; the session picks up the current packages on the next prompt submit- Retyping a prompt in a different project saves it to that project's history instead of silently dropping it
- Keep subagent cancellation retries scoped to their original parent session after restart
/newand/clearstart the fresh session with the/effortlevel in force when you typed the command- A failed
muse execrun now shows the recorded reason on its final stderr line instead of a generic exit message - One malformed model catalog row in settings no longer hides every model of that provider
- Context compaction preserves the todo list across turns
- Restore queued subagent input state when resuming from a checkpoint
- Resuming a workflow now keeps healthy tasks available when one task has invalid recovery state
- The TypeScript SDK declares
@types/nodeas an optional peer dependency, so package managers surface the types install strict consumers need instead of missing-type errors - Explicit tool selections consistently limit the main conversation's tools
- A session no longer becomes permanently stuck after the model tries to call a tool that is not available; the invalid call is automatically corrected on the way to the model and the session keeps working, with no conversation history removed
- Manual and automatic context compaction work after multiple tools run together, including after restarting a session
- Keep emoji and joined text intact in terminal tab titles
- Workflow child activity appears reliably when a child run starts
- Resuming a rewound conversation no longer sticks the footer on the tasks-still-running warning once the original session has ended with no live tasks
- Preserve working directory context for pending tool approvals and their hooks
- Pasting Windows image paths with spaces creates an image attachment
/goal setissued during a run that is then cancelled delivers once a later turn finishes instead of stalling- Expanded Workflow blocks label every agent row by name instead of a raw session id
- Interrupted goal runs no longer stall on resume with the goal stuck active
- Preserve Windows sandbox credentials and stored permissions when upgrading sandbox setup
- Messages sent to Claude Code include the command for replying to the source Muse session
- A first run with no interactive terminal now stops with a message naming --trust-workspace instead of waiting on the workspace-trust prompt
- Background reminder agents now follow the same permission setting as the session that started them
- Subagent status shows the command, elapsed time, and latest output when a background command keeps the child running
- Human-approved
require_escalatedcommands run under restricted permission profiles - Keep the main conversation usable when subagent input recovery fails
- Plugin agent definitions reviewed before the source-bound trust review now show a one-time notice explaining why they resolve modified and that reviewing them again clears it
- Apply Windows read-deny rules to the shared sandbox group and protect their saved state
- Subagent settlement warnings appear in the parent conversation without disrupting typing
settings.jsonno longer drops an unrecognized top-level member in silence: startup now names each one (reason=unknown_member location=<member>, with the file path) while the rest of the file still applies, so a wrapped{"schema_version":1,"settings":{...}}document is reported instead of quietly losing its whole configuration- Restored guidance for Markdown tables, clickable links, and consistent answer formatting
- Stopping your own persistent monitor with
work_stopnow settles the Workflow Stop receipt as succeeded instead of "manual reconciliation required" - The
/statuscard ACCESS row shows the permission display name verbatim (Ask me, not Ask ยท me) - Agents keep running when session logs run out of disk space instead of failing while saving tool results
- Preserve drafts, attachments and conversation history when opening and closing side chats
- Reject conflicting command IDs before a new subagent followup changes conversation history
- Preserve saved session activity times in the resume list
- Prevent delayed terminal color replies from appearing in the input box during startup
- A warm
session/resumeon a session started with aworkspaceRootthat carries MCP additions the loaded session was not built with is now rejected withsession_configuration_conflictinstead of acking success with the servers silently unattached - Keep delayed side chat results in the conversation that started them
- Stop unanswered questions from blocking input after resuming an interrupted session
- MCP stdio server processes no longer outlive the session when its terminal or process is killed on Linux
- A launch prompt longer than the screen no longer leaves its own tail and footer in terminal scrollback above the committed prompt
work_statuscalls now show a readable "Checked work status" header instead of the generic "Used tool operation" fallback- Re-sending a turn interrupt after the app restarts now returns its original accepted answer instead of a spurious rejection
- Forked and rewound sessions keep mid-turn instructions (including attached images) sent while a goal reminder fired in the same turn
- Receiver limits declared under
local_session_messaging.receiver_limitsin settings.json now bound the peer-message receiver in the TUI andmuse execinstead of being ignored; an out-of-envelope or malformed entry now makes that receiver refuse every peer message for the session (the session itself keeps running), where before it was silently dropped - Workflow launch preparation refusals no longer leave successful completion receipts
- Returning an unanswered prompt to the composer with
EscorCtrl+Cno longer shows anInterruptednotice - Subagent commands in restored sessions remain recorded across crashes
- Approval prompts raised by subagents now appear in connected clients on the parent session and can be approved or denied there
- Recover from subagent startup failures without leaving the child active or blocking later work
- Resume interrupted workflows after a restart without dropping or duplicating the recovery notice
- Keep background run results in the conversation that started them
- Tree header return hint names the workflow it returns to
- Honor the Context option in
/hudwithout enabling an experiment - Limit
Ctrl+Ohistory expansion to at most ten recent terminal screens - The
searchtool acceptsoutput_mode: "content"as an alias oftextinstead of rejecting the call - Keep tool-returned images attached to their matching tool results when using Meta models in tool batches without video
- Preserve every image label and attachment association when a media-bearing turn is rewound or forked
- Multi-stage approvals no longer hang in the TypeScript SDK โ
session.onApprovalis re-invoked with the refreshed requirement when the host advances a compound approval to its next stage - Use Unicode, spaces, punctuation and single words in session names with
/name - A gate override banner printed at the start of an interactive direct resume now stays visible above the resume progress instead of being erased by the spinner, which also no longer leaves a stale "Preparing resume" row behind
- Keep a pending tool approval out of the review list until its request is durably recorded
- Vim mode redraws no longer clear terminal scrollback
- Zed (ACP) adapter: session/set_mode now works โ switching approval mode from the agent panel no longer fails with "Method not found"
muse mcp loginnow keeps and reuses its OAuth client registration across logins (no more one-new-client-per-attempt), asks for the same scopes at registration that it uses at authorize (fixesinvalid_scopeon servers like Clerk), and answers the browser callback tab with a "you can close this window" page โ or the error name when authorization fails- Slow stdio MCP servers now connect on the first try instead of restarting during startup
- Resuming a session with a different
--modelnow keeps that model on later resumes - /clear and /new now refuse a damaged outgoing session journal before switching and name the validator failure instead of blaming session logging; a same-process retry after write access is restored succeeds on the first attempt
/sideand/forkpreserve images returned by tools when reopening saved conversations- Give Japanese halfwidth katakana voiced marks their own column so kana text is not clipped
- Sessions served over
muse servenow send turns to the model pinned atsession/startor viasession/setModel, instead of always using the default model - When a hook corrects a failed tool call, the corrected call and its result now appear in the transcript as their own entry marked as a retry of the original call; previously only the failure was shown
- Subagent transcripts are readable over the SDK โ
session/read,view/page, anditem/readOutputnow accept thechildSessionIdthat session items advertise, instead of answering "session not found" for a child transcript that exists on disk - Keep the session name and description in sync after
/name - Native subagents stopped with Work Stop no longer fail again while the child finishes
- Quitting after browsing
/resumeno longer crashes when session discovery is still running muse servenow sends the interactiveapproval/requestwhen a tool call parks on an approval while a client is attached, so session protocol and ACP clients get the permission prompt instead of a forever-parked turn- Scheduled-task data can be backed up while a session is running
- Show retained subagent workspaces and cleanup failures when
muse execis interrupted - Make workflow names required in model tool instructions
- A subagent's result that finished just before a context checkpoint is now readable after you resume the session, instead of being reported as never ready
- Resumed sessions retain conversation context from interrupted tool calls
- Missing reasoning history provenance is explained without claiming a provider switch
- A
/goalset typed while the previous run is still finishing keeps its usage and reminders attributed to that goal - Redirected subagents resume after their previous attempt settles
- Readable default colors when attaching with tmux control mode
- Retrying a session start after a host restart no longer fails because that host is cleaning up an unused session
- Esc while browsing prompt history during a running turn restores your draft instead of interrupting the turn
- Let Esc leave Vim editing mode before interrupting a running turn
- When an onFailure correction's corrected call is itself rewritten by a PreToolUse updatedInput, that rewrite now counts as exactly one attempt against the same declared chain depth instead of a free extra attempt
- Long pending-input queues preserve the composer and bottom bar in short terminals
- Agent Tree capacity rejections now show the exact cause and next step in the TUI
- Preserve agent recovery state when restarting a session
- Resumed workflows keep their Work ID and show the correct target for the next resume
- Keep recovered Workflows responsive when a missing child history is quarantined
- Forking or rewinding a session with a persistent monitor no longer silently drops the monitor's wake turns from the branch's model context โ the branch now conditions on the same wake bodies and answers the original conversation did
- V1 workflows reject missing or blank names with a retryable error and include the current name in resume guidance
- Keep completed tool failures from hiding later assistant replies
- Prevent duplicate message delivery after reopening a compacted session
- Stopping an approved Bash command after restart now follows the shared Work Stop path and records its real cancelled terminal
- A persistent watch armed while
muse execis settling is stopped with its receipt instead of failing to start - Subagent input status stays correct after interruption and resume
- Clear queued input and show the reply when Enter arrives as a turn finishes
- Agent path-length rejections report byte counts and guidance for shortening the path
- Sessions with one damaged background task now reopen with healthy work still available
- Parent task updates guide the same running subagent on its next eligible model call, without restarting it; downgrading is unsupported when resuming a subagent that received one of these updates
- Accept fenced reports in workflow recovery evaluations
- A persistent
wsmonitor caught by exec end-of-run while still connecting now stops with its normal receipt (stopped terminal plus stop notice) instead of failing the start with no receipt - Reject duplicate keys in standalone Agent Tree authority records before decoding
- Committed Agent Tree Spawn retries remain replayable when a later command has an unconfirmed write
- Keep subagent background command results in their own conversation
- Resume sessions whose failed or cancelled runs lost tool results, and recognize native Windows disk-full errors during log retention
- Launching a subagent without an agent type now trims the requested tools to what the parent has instead of failing
- Keep Work Stop responsive while cancellation settles and report unconfirmed stops after 30 seconds
- Several images sent into one turn keep their separate numbered labels when the session is resumed
- Forked sessions keep the correct conversation history after compaction
- A project
.mcp.jsonentry with Claude's"type": "http"now lights up as a streamable-HTTP server instead of disabling all MCP - Resuming a session and prompting right away no longer skips peer messages that were already waiting for it
- Tools approved after a restart keep their original run identity
- /side and /fork no longer refuse a session because an earlier tool call was cancelled while it was still running; the cancelled turn keeps its committed output with the standard pending-tool placeholder, matching what /resume replays
- Declining workspace trust now also stops the background Sapling snapshot commands from running in that workspace, and a session with no workspace configuration is treated as untrusted
- Refuse session forks when retained history cannot establish consistent delegation settings
- Paste text into clarification answer notes and custom choices
- Keep installed plugin files available while their capabilities are being loaded
- Finished background tasks no longer stick in the subagent tree โ press
xto dismiss one, or it retires on its own after 30 seconds - On resuming a session mid-correction, a corrected tool call now appears next to the call it retried instead of at the bottom of the transcript
- Typing right after approving a command no longer loses the first
p,y, or digit to the finished approval prompt - Typing a plugin skill name in the
/palette shows one row instead of both/nameand/plugin:name - A steer you send while a reviewed command's or skill's turn is running now ends that turn's approved-tool suppression even when the steer itself is rejected, so the turn's next matching tool call asks for approval again
- Sessions created by
muse exec --session-idwith--yolo,--disable-approval, or an explicit human permission profile now publish context checkpoints like TUI sessions, so resuming them reads only the newest checkpoint plus its suffix instead of replaying the whole log - Generated plugin runtime files no longer disable an otherwise valid plugin
- Plugin skill reads keep their selected files available across plugin updates
- Refuse unsafe image replay when retained session authority is missing or ambiguous
- After a blocked command is corrected and succeeds, the assistant reports the corrected result on the current turn, not only after the session is resumed
- An open child thread view refreshes its status card when the child finishes instead of showing running until reopen
- Retry a peer message whose receiver briefly answers owner_unavailable instead of dropping it after the first attempt
- Previously approved plugin hooks carry over once without re-approval after upgrade; later declaration changes still require review
- Start default plugin installation after headless startup finishes so a stalled clone cannot block startup plugin reads
- A subagent result that arrives after its turn has finished no longer breaks resume of that turn or blocks later context checkpoints
- Trust prompt actions now appear directly after the workspace safety text
- The
/feedbacknote screen now answers arrow keys, Home/End, and Delete so typed feedback can be edited in place - Peer message summaries retain reported progress when no final send outcome is available
- Messages accepted by another app no longer appear as unsent
- A reviewed plugin command no longer skips the approval prompt when it reaches a symlink planted inside the installed plugin package, and every
read_filepath refuses to follow a symlink inside a plugin package instead of only the direct one - A peer message admitted while the session is idle always reaches the very next turn, even when the runtime is CPU-starved
- Resuming a paused workflow after restarting lets its new child submit the result
- An expired or rejected credential reported after a response starts streaming now shows as a sign-in problem instead of a model error
- Malformed message receipts no longer use the normal sender status marker
- Queued parent updates stay visible in the child view through exit and resume
- Subagent rows show queued parent-message counts, and child views distinguish queued messages from delivered messages
- Prevent Windows sandbox permission failures after repeated commands
- Preserve browser sign-in URL parameters on Windows for
muse mcp login - First-login sessions on muse-spark-1.3 models now show max reasoning effort immediately instead of high until restart
- Downgrade-save-upgrade cycles no longer re-run the one-time legacy hook trust amnesty
- Side chats (
/side,/btw) now use the main session's history to answer questions about its work, progress, or status instead of claiming they have no context - Recover background task handles after context compaction so active work can still be stopped
- Peer message headers preserve waiting, held, and unavailable states. Generic rejection and missing-target results now use "Message status"; admission timeouts, expired reply contexts, and unsupported requests use warning-colored "Message status" headers
- A resume refused at startup no longer duplicates a session-log sequence, so the session log stays readable afterwards
plugins validateandplugins installnow warn (agent-definition-unsupported) and name the file when a plugin Agent Definition resolves no identity โ for example anameoutside the^[a-z]+(?:-[a-z]+)*$grammar โ andplugins inspectcarries the closed reason; the definition was already inert but nothing told the author- Tab-completing a slash command that takes an argument (e.g.
/effort) now leaves one space after the command, so typing the argument no longer fuses it into the command name and sends it to the model as prose /sideand/forkno longer refuse a session whose earlier turn died while a tool was running; that turn is left out of the branch exactly as it is left out of a resumed session, a side chat survives its own interrupted turn, and a rewind past a turn that failed at the provider no longer carries that failed prompt into the child- Steering a running turn stops a reviewed plugin command from skipping approval prompts right away
- An approved plugin
allowed-toolsrule such asBash(cat ${CLAUDE_PLUGIN_ROOT}/notes.md), where the plugin folder placeholder is not the first word, now skips the approval prompt for the command it describes instead of asking every time - Verified peer messages show receipt progress, keep receipt conditions visible when expanded, and preserve full message text; safety refusals hide the body. Accepted messages keep normal grouping, and unknown results retain their diagnostic details
- Unconfirmed peer messages stay separate instead of appearing as a successful send count
- Subagents keep large structured results instead of failing the submission
- Hook-blocked prompts keep their source and reason visible in the conversation, including after reopening the session
- Resuming a session after a clean exit no longer marks a long-completed turn as interrupted when its compaction checkpoint was followed by a late background-task notice, and a session already carrying that stale mark opens and accepts prompts again instead of failing every message and /compact with a duplicate-terminal projection error
- Plugins installed just before a capability scan are no longer silently skipped while other programs are being launched
- Installing a Claude plugin no longer fails when one skill or command writes its
allowed-tools:*marker in a place Muse cannot use; that one rule goes inert and the rest of the package installs /compactafter a background-task notification now compacts the latest conversation turn instead of answering "no compactable run is available"- Restore compaction for older saved sessions hosted by
muse serve - Background commands started by subagents stop without timing out
- Paste clipboard images on Linux, with
Ctrl+Alt+Vas an alternate shortcut - Workflow sub-agents keep repository instructions instead of losing them
- Retry transient macOS Keychain reads and preserve unsent messages when credential access fails
- Preserve conversation context when forking sessions with unfinished turns or unrecognized history records
- Conversation summaries follow the selected provider after an account change
- Peer messages with a receipt but no send outcome show the available receipt progress and full message text when expanded; they remain unresolved in message groups and batch status
- Stopping a background task no longer shows as unresolved once it has stopped
- Quitting after a resumed workflow finishes no longer warns about its earlier paused tasks
- Show the process observation error when MCP cleanup must keep waiting
/skillsshows a credited skill's full source URL under the selected row- Toggling a skill in
/skillsno longer flashes the status bar - Sessions you leave with
/new,/clear, or/resumecan be resumed from another window right away instead of being reported as already open - Resumed workflows stop showing as running after their recovered agents finish
- Resuming a conversation keeps earlier messages after a prompt is taken back
- Withheld peer replies hide message text and private identifiers
- Plain
muse execshows progress while retrying an interrupted model turn - A resume that is refused at startup no longer writes anything to the session log; the previous run's crash marker now lands together with the resume record only when the resume succeeds
- Git over SSH uses system SSH configuration correctly on Linux
- Side chat follows Main for message steering, queueing, and draft recovery
- While an approval is waiting, typing no longer leaks into the hidden composer and Enter approves the selected choice instead of sending the draft
- Approving or denying a tool action now works after you rename a session; the decision no longer fails with an "approval not found" error
write_fileandedit_fileno longer fail with "tool output storage failed before result publication" when the Muse data directory is on NFS or another filesystem without renameat2 flag support, and the local session registry stops logging "Invalid argument" there- Keep delayed terminal color replies out of the input box
- On-request approval now prompts before
sl hideandsl phase --secretinstead of auto-allowing them - Oversized session records and traces attached to /feedback are truncated to fit instead of being dropped
- Rewind in long sessions now drops history the latest compaction checkpoint already covers, keeping memory bounded and the picker scoped to entries after that checkpoint
- Workflow authoring guidance preserves large child result references and explains compact summaries and file artifacts
- Paged transcript history, live-stream replays, and approval replies now number events like the live stream when the model reports context usage, so paged history lines up with live updates in most sessions
- Avoid duplicate background compaction cancellations after a temporary storage error
- Keep images and compatible reasoning when continuing or compacting Muse sessions
- The
/statuscontext row keeps projecting after a fast follow-up turn instead of falling back to not projected - Resume saved subagent launches after restarting a session
- Resumed Workflow monitors stop spinning after followup agents finish
- Checkpoint suffix writing no longer rescans all retained session records for every distinct task owner, so resuming sessions with many subagent-owned tasks stays fast instead of slowing quadratically
- Fixed startup failing with
meta provider resolution did not construct its credential-provider handlewhen a saved login was paired with a keyless custom endpoint; the session now starts without the withheld credential - The resume picker and
--lastno longer offer sessions that another Muse window is still using; they reappear once that window exits - An MCP server's
tool_timeout_secabove 600 seconds now takes effect instead of being silently capped by the foreground tool deadline, so long-running MCP tools can run to their configured budget - Mark read subagent results closed and display final text once
- Preserve known message receipts when background tracking cannot start
- Session protocol clients get a retryable
commandRejected(runtime_busy) instead of an internal error when a session is busy and refusesturn/startorturn/steer - A new
/loopjob now runs until you delete it instead of stopping on its own after about a week โ for a loop you started earlier, delete it and run/looponce more - Cancel unfinished SessionEnd hooks before they exhaust the session shutdown budget
- Prevent macOS diagnostic messages from overwriting the input composer
- The verify reminder's checker now runs at the session's own reasoning effort instead of a fixed level. Previously every session was checked at
high, so a session thinking harder than that โxhigh,max, orultraโ was judged by a weaker model than the one doing the work, and a session belowhighwas judged by a stronger one. Sessions atmaxkeep the existinghighchecker;highis unchanged;xhighandultragain a checker at their own level; andmediumandlownow get a checker at their own level rather thanhigh - Make
work_statusreport ordinary Workflow launches by their returned v1 work IDs muse loginandmuse auth setsave credentials again on Windows and Linux- Fix event-log errors when resuming work after tool output
- Keep composer text visible while typing during an active run
- A session no longer stays busy for the rest of the process after a finished turn's Goal accounting fails; the next turn starts normally while the accounting retries a few times in the background
- Preserve Markdown formatting and handoff notes in conversation summaries
- Reading or resuming a session you already opened no longer re-reads its whole history each time
- Exit confirmation stops listing completed Workflows after a later prompt
- Approving or denying a tool action no longer fails with an "approval not found" error in a session where MCP startup audit failed
Performance
- Read-only MCP tools called in one model turn now run in parallel instead of one at a time
muse resumeno longer hangs for minutes at "Initializing runtime" on sessions whose subagent logs carry many run generations โ startup now reads each subagent journal once instead of once per run- Faster exit from long-running saved sessions
- Resuming a long session needs far less memory for the pre-open log read, and hydration checks for the next keystroke less often
- Resuming a long session no longer keeps a second copy of the whole saved log in memory while the session opens
- Resuming a long session is about a third faster and uses less memory, thanks to a new memory allocator
- Resuming a session with many runs no longer re-walks the whole saved log once per run while goal progress is recovered
- Long sessions resume faster when a large amount of history follows the last checkpoint
- Keymap validation in
tui.keymapsettings stays fast even when one action lists hundreds of bindings - Resuming a session with many orphaned or unreadable runs recovers them with a single shared history pass instead of rescanning the whole log for each run
- Keymap validation in
tui.keymapsettings stays fast when bindings repeat one key under different spellings - Submitting a draft with many collapsed large pastes no longer slows down as the paste count grows
- Long sessions publish a history-preserving checkpoint every 16 MiB of retained log (tunable with
context_compaction.periodic_checkpoint_bytes;0disables it), so a later resume reads the checkpoint plus its suffix instead of the whole log; compaction keeps publishing its own checkpoints unchanged - Task-status refreshes stay fast in long sessions with many completed tool tasks
- Reduce terminal lag when refreshing child command status in sessions with many completed tasks
- Task-status refreshes stay fast in long sessions as more tool tasks complete, instead of slowing down with every finished task
1.2.1
New
- Voice input is on by default on macOS: press
Option+Vto dictate, and manage it with/voice - Added a
/rewindcommand that rewinds the conversation to an earlier input โ same picker as doubleEsc - Pasted and dropped images get
[Image #N]labels the model can see, so you can ask about a specific image by number; labels and their source paths survive resume, rewind, and forks /mcpshows a live inventory of connected MCP servers and their tools in the transcript- Added a bundled
migrateskill that imports your Claude Code or Codex memory notes and MCP servers into Muse Code - Set
MUSE_TRANSPORT_TRACE=1to print raw provider request and response lines to stderr for debugging model calls; credentials are scrubbed - Sessions can be renamed over the session protocol with
session/rename(withsession/nameChangednotifications), andsession/listcarries display metadata โ title, first user prompt, and branch - Edit-tool calls on the session protocol carry a structured diff fact โ
patchSummaryline counts plus a durablepatchRefโ so clients can render what an edit changed - Programs driving a session can set a session-wide reasoning-effort default with
session/setReasoningEffort, inherited across resume and fork - Workflows now run in
muse servesessions, matching whatmuse execsupports
Improvements
- New sessions start in the Auto-review permission profile: the same access as Ask me, with an automated reviewer deciding eligible approval requests; it falls back to asking you when the reviewer is unavailable
- Permission selections are remembered and applied to new sessions
- MCP tools whose server declares them read-only run without an approval prompt under on-request approvals
- MCP server configs support
${VAR}environment interpolation, and stdio MCP servers receiveMUSE_SESSION_ID - The MCP handshake advertises protocol version 2025-06-18 on both transports
- Hook payloads include the session's canonical
model_provider, so hooks can branch on the active provider - Clearer, typed guidance when a sandboxed command is denied listening on a network port
- Messaging local Claude Code sessions is more robust: interrupted sends cancel cleanly, stale late replies are rejected, and peer discovery shows whether a peer supports read receipts
session/resumeruns the same startup reconciliation as a fresh launch, so work orphaned by a crash settles instead of staying stuck- Launching a subagent with an unknown agent type or an invalid task name is rejected with an explanation of what was wrong and which targets are valid
- Every non-Main viewer's footer shows
Ctrl+Cto return, even when the view isn't focused - Scheduled-task rows keep long prompts to a single header line, and creation receipts are one line, with detail available on expand
Fixes
- Security: commands launched through wrappers such as
envandsetsidare reviewed as the command they actually launch - Security: changing the permission mode mid-session now applies to already-running tools at their next action
- Security: MCP tool grants in custom agent definitions are validated against the prepared toolset instead of falling back to a legacy path
- Security: the Unrestricted permission profile now behaves exactly like
--yolo - Only the main and side sessions can prompt for user input; subagents no longer can
- Smoother
/clearand/new: the screen no longer blanks before the new session's first frame, keystrokes typed during the restart are kept and replayed in order, and aCtrl-Cin the restart window no longer kills the app /clearand/newrefuse trailing text on the command line with a usage hint instead of silently discarding it- MCP servers that fail to start after
/clearor/newnow surface the failure instead of staying silent - Double
Ctrl-Dover a pending approval opens the exit confirmation instead of force-quitting past running background work - With an approval prompt open and text in the composer,
Entergoes to your message instead of being swallowed by the approval panel - Each guarded call in a parallel tool batch gets its own approval prompt
- Permission selections committed during a session survive resume
- Pending approvals survive a headless restart instead of inheriting the predecessor's abort
- After a crash, a tool approval that was still waiting for your answer shows as unresolved on resume โ never as already executed
- Saving settings preserves the file's permissions and symlinks, and no longer writes an all-default
tuiblock - MCP
startup_timeout_secis honored, and slow servers that emit newline-delimited JSON are admitted - An MCP server's
requiredflag follows the winning configuration layer - An MCP server's
cwdsetting now sets the stdio server's working directory - Resuming is more reliable: resume no longer fails after compaction has pruned older history, on a session saved mid-way through parallel tool calls, on a checkpoint taken while a workflow was paused, on a checkpoint that went stale while the session kept running, or with "duplicate or non-monotonic" sequence errors; a run that cannot be rebuilt is set aside instead of blocking the whole session, and an empty saved session file is refused with a named reason instead of opening broken
- A malformed tool call from the model no longer poisons the session: the model gets a clear error it can retry from, and sessions already saved with such a call resume cleanly
- Forks and side chats are more reliable: they stay available after resuming from a checkpoint, keep messages and attachments that used to be dropped from the new branch, open on histories that previously failed with a read error, and branches created in quick succession keep their creation order
- Your model and reasoning effort choices stick: forks and side chats start on the parent's model and effort, a per-turn effort applies to that turn's model requests, and turns the runtime starts on its own (like background-work wake-ups) use your settings instead of the startup defaults
- Stopping and cancelling subagents is dependable across restarts: a stop or cancel in flight when the app closes is completed on the next launch instead of forgotten, stays in force after the agent is closed and reopened, and is not reopened by a late result from the agent's own children; restart recovery no longer revives, duplicates, or corrupts agents it should leave alone, and closing an agent's whole subtree no longer wakes the agents being closed
- Background work reports in reliably: a live view opened before a background task produced output now fills in instead of staying blank, messages for a subagent's own subagents reach the right agent, and a finished subagent whose session can no longer accept results settles instead of waiting forever
- Workflows start and finish cleanly: an invalid workflow source is rejected before anything launches (and
muse execJSON output stays clean), a finished workflow agent with a missing or invalid report settles instead of leaving the workflow waiting, and resuming mid-workflow replays already-completed steps correctly - Workflow progress narration shows in the conversation on the default view, not only inside
/workflows - Goals handle blocked work honestly: a goal denied by session policy ends with a clear final message naming what was blocked instead of empty output, and progress that was blocked resumes correctly when the goal continues
muse execno longer exits with an error when the process reading its stderr goes away during shutdown- Finished shell commands clean up fully: releasing a captured terminal no longer injects a stray blank line into the command's output, and long sessions no longer accumulate runtime resources from completed commands
- Session storage is more robust: listing sessions no longer intermittently fails with "session index unavailable: database is locked", and a full disk no longer crashes the app before it can restore your terminal and print the session id and resume command
- Pastes into
!shell mode stay literal โ image file paths are no longer rewritten into[Image #N]attachments - Long assistant replies stay within the collapsed row cap while streaming, and
Ctrl+Omid-stream no longer garbles the elided view - Tool rows in narrow terminals keep their expand hint instead of dropping it when the header runs out of room
/settingsrefreshes its rows when a side chat starts or returns, so the Reasoning effort row can't go stale and the highlight can't act on the wrong row- Messages parked in a side chat no longer linger in the main session's queued-messages panel after returning
- After
/side,/statusand/taskscount only the visible session's work instead of leaking the other session's subagents and pending items /taskspreview of a finished terminal shows the same status wording as its drawer row instead of "no output yet"- Keys pressed while the rewind loading screen is up are absorbed instead of leaking into the composer;
EscandCtrl-Cstill cancel - Resuming a session by exact id warns when its declared predecessor session is missing from the store instead of resuming silently
- A freshly launched session no longer vanishes from other terminals' resume pickers until it exits
/stopalways renders a verdict โ a background task that never confirms now reads as a failed stop instead of leaving/stopsilentmuse serve:session/listincludes sessions loaded on the answering host with fresh metadata so a new session appears immediately aftersession/start; session recency ignores internal bookkeeping writes, so crashed old sessions no longer jump above newer work; page cursors bind to the listing that minted them, and cursors from live streaming and durable reads share one space instead of being rejected as unknown;session/setModelacknowledges only after the change is durable; omittingproviderIdonsession/startresolves to the host's composed provider; a brand-new session can no longer be pruned out from under its own start; and stopping the server with SIGTERM or SIGINT winds down cleanly, closing sessions durably instead of crashing themmuse serve: a rejectedsession/resumeno longer leaves a stray view subscription; resuming with a cursor delivers pending approval and user-input requests instead of an empty list; live view updates re-arm after aview/unsubscribe; approval modes selected over the wire are honored for shell commands instead of being clamped; setting the model to the same provider no longer bricks a resumed session; subagent results recorded before a resume are readable again; follow-up turns spawned from a carried-forwardturn/steercan be interrupted and steered; theretryableflag onturn/completederrors reflects the provider's real classification; reminder-spawned child tasks show their real lifecycle instead of appearing completed at spawn; and sessions started without a workspace root can still prompt viarequest_user_inputwhen the client supports dialogs
Performance
- Opening or resuming a long session is dramatically faster: startup work now scales with the size of the session log rather than multiplying by the number of turns
item/readOutputno longer scans the whole session per read โ dramatically faster on long sessions- Re-attaching a live session view over
muse serveis now constant-time, independent of how many events streamed since load
1.1.1
New
- Added
muse mcp login <server>andmuse mcp logout <server>: OAuth 2.1 sign-in for remote MCP servers, in the browser or headless. Tokens are kept in the auth store and refreshed automatically, a login done in another terminal is picked up without a restart, and a startup or mid-session 401 now tells you the exactmuse mcp logincommand to run. Setmcp_oauth_dynamic_client_registration: falseto turn off automatic client registration - Markdown links render as clickable labels in terminals that support hyperlinks, with automatic fallback (including under tmux); exported transcripts keep the full URL, and links survive redraws and scrollback
/themegains a Terminal background row: Left/Right cycles auto, light, and dark and re-derives the picker live, a notice appears when your choice contradicts what the terminal reported, Enter saves it astui.terminal_background, and Esc reverts- The agent can check on and stop its own background work (workflows, subagents, and background commands) with the new
work_statusandwork_stoptools, using the same work ids it is shown - Todo reminders are on by default: the model is nudged to create and update a todo list during complex multi-step work
- Two new built-in skills, on by default: one has the agent ask about an unresolved product decision before committing to it, the other keeps a focused regression test with each bug fix or behavior change
- Added a bundled Three.js skill (
/threejs) with references for scenes, geometry, materials, lighting, textures, animation, loaders, shaders, post-processing, and interaction - Added a
PostToolUseFailurehook that fires when a tool call fails or crashes - After a rewind or fork, the status bar warns while tasks from the original conversation are still running, and the new branch's transcript notes the background work that stayed behind
- Press
sin a workflow's detail view under/workflowsto save the running workflow under a name so you can run it again - Programs driving a session can declare
capabilities.userInputDialogsatinitialize; sessions whose client can show a dialog get the ask-the-user tool, and a client that opts out has such calls rejected cleanly instead of hanging - Programs driving a session can read an item's stored tool output by reference with
item/readOutput, and re-attach a live view withview/subscribeafterview/unsubscribeon a still-loaded session, replaying the gap from a cursor
Improvements
- Memory, Skill, Todo, and Scope reminder child logs now default to Memory only, so a long session no longer accumulates one
subagent/<id>/session.jsonlper model step. Choose Saved under TBH Reminders โ Settings to keep writing them; Goal and Verify are unchanged - A forced
maxreasoning effort (--reasoning-effort max, settings,/effort max) is now sent to the model as-is on every model instead of being silently downgraded, so an unsupported value shows the provider's error;maxis also accepted as areasoningEffortonturn/startandturn/steerover the session protocol - The Scope reminder is on by default in sessions using muse-spark-1.2
- Tuned the built-in instructions: the agent asks one grouped question before scaffolding when a request leaves a material product decision open, never claims a server is up without a fresh check, confirms decisive values (versions, config values, paths, counts) by a second route, surfaces degraded external causes in the deliverable itself, resolves which file a correction refers to before editing, and reports rather than refuses safety concerns about explicitly requested changes
- The goal reminder no longer steers the agent toward faking, bypassing, or disabling a test to satisfy a goal; it names the honest blocker instead
- Workflow scripts steer child agents to inherit the parent model unless a task clearly needs a different tier, and research children inspect the source and tests behind each claim instead of stopping after a fixed number of tool batches
- The built-in
grillskill now records each settled decision in your project docs and closes with a written scope contract (what is in and out of scope, and what done means); the separategrill-and-recordskill was removed - The
planskill asks about open product preferences up front when you request a collaborative planning checkpoint, instead of leaving them as open questions at the end - The composer prompt uses a heavier
โฏglyph /newand/clearprepare the new session before shutting down the old one, so both stay resumable if the process dies mid-restart;/newnow clears the visible thread like/clear, both share one palette description, and quitting after keeping background tasks across them warns that those tasks will be stopped--disable-sandboxno longer prints a startup notice on its own or changes your selected permission profile; startup warns that profile filesystem and network restrictions are not enforced for direct shell commands, and/statusshows a Sandbox row when it was disabled at launch- Commands you run yourself with
!(andsession/userShellovermuse serve) no longer trigger approval prompts, including for network access; hard policy denials still apply and stay visible - Tool calls that fail only because a path does not exist are shown quietly in a dimmed style instead of as loud errors
- Tool cells with several attachments draw one continuous tree guide from the header to the last attachment, and wrapped continuations no longer land at column zero
- The "Worked for" line also shows the local time the turn finished, e.g.
Worked for 1m 01s ยท 10:15 AM - The Plan panel appears only while a run is active and hides while a prompt is waiting for your answer
- When a session wakes for a peer message, the text it writes before calling a tool is folded into that tool row (expand with
ctrl+o) instead of a separate transcript cell - Startup notices say exactly what was trimmed: a memory truncation names the file and the limit that fired, and a skill catalog over its size limit keeps every skill's name visible and reports how many entries were cut
muse execprints once on stderr why subagent delegation is unavailable- Spawning a subagent whose definition (prompt, skills, memory) already exceeds the context budget is refused up front with a clear diagnostic instead of failing later
- Resuming a session refuses with a named reason and remedy when the saved state cannot be trusted (identity mismatch, another live writer, unreadable state, unrebuildable history) instead of silently degrading
- Resumed sessions describe the current sandbox and permission posture to the model instead of the posture recorded when the session was first started
- The agent's subagent-tree status can page through completed history, oldest first
--worktreesessions remove their Git worktree on close when it is clean and its commits are already on the default remote; unique or unproven work is kept- Sessions you open and quit before sending anything no longer linger in the resume list or on disk, including zero-turn
muse servesessions whose owner process died - Removed the confusing "model โฆ not in catalog โ using assumed limits" notice at startup
- In
/workflows, pressfinside a workflow's agent view to filter agent cards by label; the phase drill-down filter is offered only while agents are live and clears itself when the last one finishes - A turn that fails because no usable credential is available ends with a distinct
authRequirederror over the session protocol and in the SDKs, instead of a generic model error - SDK:
apply()session-state outcomes are deeply read-only, and theDeepReadonlytype is exported - Shell output containing invalid UTF-8 now notes how many bytes were replaced instead of being rewritten silently
- Selecting the
maxreasoning effort in the Effort drawer plays a gold activation animation, and the gold prompt and rail stay settled across model switches
Fixes
- Security: Closed a gap where
rm -fr,rm --force, and wrapper-nested variants slipped past the dangerous-command check that guards destructive shell commands - Security: Model-authored subagent names and objectives, text read back from an external editor, and provider error messages are stripped of terminal control sequences before they reach the terminal or the session log; provider errors are also scrubbed of credentials
- Sending an image with no text no longer makes every later message in the session fail with "Message not sent", including after resume
- New prompts are no longer rejected after a restart when the session's replay evidence is missing or unreadable, and "Message not sent โ projection failed" no longer follows a turn that ran several tools at once and had its results cleared
- A background delivery whose submission keeps failing no longer retries forever or starves your own messages ("Message not sent โ runtime admission timed out"): retries are single-flight and a poison item is quarantined after three failures
- Sessions whose log can no longer be fully replayed, whose checkpoint records a wrong message count, or whose saved runtime snapshot is invalid now resume from the last valid checkpoint or a safe reopen instead of failing to open
- Resuming after a checkpoint no longer fails on the next turn, leaves a gap that breaks the next checkpoint, or fails on the first write after a compaction had already summarized a superseded marker
- Resuming no longer aborts when one subagent's log is unreadable, drops the answer the agent gave after a retried turn, shows an interrupted MCP call as completed, or loses a running workflow's agent tree after a compaction
- A resume that fails before it is ready no longer writes partial records to the session log, and a resume forced to fall back after an invalid checkpoint recovers with a single recovery checkpoint
- Reminder-agent logs that end in a blank line no longer fail to replay on resume
- The session list refresh no longer races sessions that are still being written, and keeps a session's cached title and details when its lock cannot be opened instead of showing an "unreadable" placeholder
- The
--resumepicker stays responsive while sessions are still being discovered on a cold start, and resuming from it or after a session-in-use notice shows startup progress instead of a blank pane - Resume and
muse exportreport a permission-blocked session directory as unreadable, with achmodremedy, instead of claiming the session has no saved log - Running
resumewithout a terminal now points to the headless remedy (exec --session-id <uuid>), and the export picker names its real--lastand--sessionflags muse exec --resumeworks for sessions created with--worktree, records the crash before adopting a crashed session, andmuse exec --no-session-logstarts when subagent delegation is enabled- Nested subagents (a subagent's own subagents) now open their session logs, write their control records, and recover in the right place across restarts, so their results survive a resume and are not duplicated
- Subagent results no longer point at the wrong transcript when several subagents run at once; interrupting a subagent before its first model call takes effect immediately; waiting on a worktree-isolated subagent after cancelling it no longer errors; reading a subagent's transcript works after its log crosses a checkpoint; and messages a subagent rejects are recorded with the reason
- The subagent panel keeps a Finished marker that arrives out of order, shows the selected subagent's own activity while it waits on the model, expires a finished row you parked the cursor on, names agents by label in steering acknowledgments, keeps its place when paging a completed transcript after a status refresh, and counts each subagent's tokens the same way
/usagedoes - An invalid
subagent_typevalue, or a default subagent definition that fails to load, now gets a rejection naming the real cause instead of a generic argument or selection error - The task inventory shown for a child conversation lists only that conversation's workflows, subagents, and terminals instead of the parent's
- Paused workflows survive: cancelling a turn no longer marks a paused workflow cancelled, and a paused workflow keeps its owner, children, capacity slot, completion state, and resume handoff across
--resume - Workflow children report reliably: a child that fails shows its final status live, a finished child stays finished, cancelled children show no error receipt, follow-up subagent results reach the workflow, results are no longer held back behind a long main turn, messages sent to a child before it is live are queued instead of rejected, children woken after a restart no longer stall on reminders, and children keep their memory tools after recovery
- Quitting cleanly while a workflow still has live child work leaves that work recoverable on the next launch, the same as after a crash
- Subagents spawned by a workflow child no longer clutter the main transcript with spawn and finish rows
- Steering a running turn no longer drops Workflow mode when the steer lands as a fresh turn
/workflowsshows a short run id next to unnamed workflows so identical-looking rows can be told apart- Saving a named workflow no longer overwrites a file a concurrent save just wrote, cleans up its staging file on failure, and names the target path in the error
- On Linux, workflow script syntax errors report the real message and source line, keep
--jsonoutput clean, and scripts whose default export is an expression are detected correctly - Goal controls accepted in the final moments of a turn, or just before a cancelled turn restarted, are no longer left queued; interrupting a run with an active goal reliably shows the goal-paused notice; Esc stops the turn even when goal storage is unavailable; goals closed automatically when a run ends are recorded and announced; and a rolled-back fork no longer leaves goal store files behind
- Rewinding to a point mid-conversation works again; rewind branches from the exact point you chose; a window holding a queued steer or an in-flight run no longer fails after you confirm; sessions compacted mid-turn can be rewound; and a finished task whose result is still being delivered no longer counts as active work
/sideno longer fails on a session compacted after its checkpoint, on a log with only bookkeeping records since the last checkpoint, or when resuming a side chat created on an earlier day; a prompt sent right after returning from/sideis queued instead of rejected as busysession/forkpreserves the source turn and item identities, accepts the source session's real turn ids as the cut point, reports the child's own turn count, and forked sessions overmuse servestart their MCP servers instead of failing with "MCP startup audit failed"- Failed turns no longer count as phantom turns in session listings, reads, resumes, and rewinds
- Manual
/compactsummarizes with the model you switched to via/modelinstead of the launch-time model /newand/clearno longer break every following turn with "MCP startup audit failed" when MCP servers are configured, and/clearrefuses to start a new session when the session log cannot be retained instead of minting one that would lose history- Enabling or disabling a skill now takes effect on background and reminder-driven turns immediately, not only on your next prompt
- Re-running
/skills importreports already-imported skills as skipped instead of counting them again (--dry-runshows the same rows); a project copy of a bundled skill with identical content is no longer listed twice; and a skill whose manifest cannot be read reports the real filesystem error - The skill reminder no longer fires in sessions where the
read_skilltool is unavailable - One mistyped entry under
skills.activation.projectsorhooks.stateno longer discards the rest of the map (a startup warning names the bad key); settings and credential writes follow a symlinked config file instead of replacing the link; and a rules directory that cannot be searched is reported by name with a remedy PostCompacthooks fire exactly once for background compactions adopted after a turn ends; aPostLLMCallhook that keeps returningadditionalContextstops re-driving the turn after 8 continuations; and hook trust and enable state no longer collide between argv-style hooks whose arguments join to the same string- MCP tool calls keep their server attribution through live refreshes and after closing a rewind overlay; the per-server
tool_timeout_secsetting applies to tool calls, resource reads, and prompt fetches on both transports; and a server that requires an OAuth sign-in says so at startup, with HTTP 403 reported as an authentication failure instead of a generic initialization error - Interrupting a running
bashcommand returns the output it had already produced; a background command's exit status is shown once; input sent to a non-interactive background command points atterminate; starting a second!command while one is running names the running command and keeps your draft; and denied!commands report output truncation correctly - Search results in JSON mode return invalid-UTF-8 lines as base64
bytesinstead of silently rewriting them - Runaway loops that repeat the identical command with identical output are stopped even when compactions happen mid-loop
- Cron jobs created during a fresh
muse execrun are bound to that session; queued cron wake-ups are no longer lost when a session is resumed after a compaction; andmuse servesessions expose the scheduled-task and goal tools that were advertised but never reached the model muse exectext output no longer loses the answer when a background wake starts a second run;execno longer hangs on a protected write it cannot get approved;--max-tool-output-bytesrejects values below the readable floor (0disables the cap); and a failed model-catalog fetch is no longer retried a second time on a cold cache- Startup no longer fails when the temp directory is unusable (it warns and continues); on Linux the startup warning about a missing system
bwrapis gone; andmuse initno longer hangs on a package manifest that is a FIFO - Meta Model API requests that fail with HTTP 402 are not retried, and retry status reads in plain words, e.g.
rate limited (HTTP 429) ยท retrying in 60s ยท attempt 2/10; a transient token-refresh failure duringweb_searchis reported as a connection problem instead of an authentication failure - Ctrl-B and Ctrl-D edit text when the draft is non-empty and the exit hint follows remapped keys; fast-typed or terminal-buffered text no longer arrives out of order around character-form shortcuts or Tab; cutting a large paste with Ctrl-W and yanking it back restores the content; the cursor no longer drifts after Indic spacing-mark clusters; and an image path in the middle of a sentence stays as text
- Typing no longer stalls right after resuming a long session; idle sessions no longer churn CPU after a turn ends and the terminal cursor blinks again; and opening or answering an ask-question prompt no longer blanks and redraws the whole terminal
- Collapsed read and search summaries always show the
ctrl+ohint; wrapped lines no longer tear emoji sequences or overflow the pane; narrow panes keep the state cell and timer visible for long task labels; the live-follow view for a background command uses the full pane width; an external tool's failure details render once; and tool rows rejected for bad arguments switch torejectedpromptly - Run failures caused by step limits, configuration, environment, or workflow launch errors no longer carry a misleading
model failedprefix; the context-usage notice no longer reports almost nothing remaining on an implausible token count; and the notice shown when resuming a session that did not shut down cleanly no longer tells you to runreset --worktreesessions no longer fail intermittently when several sessions create worktrees in the same repository at once, and resuming one no longer hits a worktree collision after an earlier removal was interruptedmuse export --outwrites to a temporary sibling and renames it into place, so a failed export never truncates an existing file- Pending approvals no longer flash into the approval list while the automated reviewer is still deciding
@muse-code/sdkbundles its protocol type declarations, so consumers typecheck withskipLibCheckoff;Item.turnIdis typed as nullable to match what the server sendsmuse serve: protected-write approvals wait for the subscribed client'sapproval/decideinstead of aborting right after prompting;session/resumere-issues pending approval and user-input requests so a reconnecting client can answer them after a crash; a resume with a cursor no longer lets a live event reach the client before the replayed suffix; and views restored after a restart match the live view when a reply was still streaming at checkpoint timemuse serve:session/list,session/read, andsession/resumereportrunningand the activeturnIdwhile a turn is in flight; a session whose cached view history is unreadable reports history as unavailable instead of failing every read; failed, cancelled, and timed-out tool calls include the tool's final output;session/startignores unknown keys insideconfiginstead of failing; rejecteduserShellcommands are settled durably so an identical retry gets the original answer; and a queued follow-up left stranded when the connection closed mid-admission is no longer executed on the next load- Scheduled (cron) deliveries run as one bounded turn: the end-of-turn goal reminder no longer fires on a scheduled run, which had kept a single delivery looping through phantom ticks every few seconds
- A
muse servehost that started logged out now picks up a later device-code login on the next session start, resume, or fork instead of answering "auth required" until the host restarts
Performance
view/pageon long sessions is dramatically faster overmuse serve: page reads are linear in session size and repeat pages on a loaded session are served from cache- Faster startup and resume: multi-megabyte checkpoint lines are read in linear time, session-index housekeeping and crash-recovery scans run after the prompt is ready, the trust store is read once per launch, a turn submitted into a resumed session no longer replays history older than the last compaction, and
session/resumeovermuse serveloads from the latest checkpoint instead of replaying the whole log - Rewind evaluates and applies from an in-memory window of the current conversation (back to the latest compaction checkpoint) instead of re-reading the session log, so the picker opens faster in long sessions
1.0.x
Also delivered in 1.0.x patches: the tui.terminal_background setting (auto, light, or dark); muse serve sessions expose the same bash tools as muse exec, model/list lists only the models a session can route to, session/resume from a cursor delivers the retained events after it, an oversized session/start workspace path is refused and session/list pages large listings, initialize rejects a malformed clientInfo.name, and muse serve exits with code 3 when settings or credentials cannot be loaded; forking carries compacted permission state into the fork; forked and side sessions show their real creation time instead of 1970; web search reads compressed responses; logging out clears the cached feature configuration; the skill reminder is active again in default muse exec runs and no longer repeats its loaded notice; the blocking verify reminder header reads "Double checking"; resume tolerates a blank line in the session log; checkpoint and explicit saves no longer stall behind background flushing; memory writes survive a stale temp file left by a crash; subagent results and goal reminders arrive as developer context; the search tool routes filename lookups to glob; Esc exits input-history browsing and restores your draft; /resume inside the app shows startup progress instead of a frozen screen; the /tasks drawer lists only the visible session's tasks; a retried turn/interrupt after a restart no longer records a duplicate rejection; and two security fixes: on-request approval mode requires approval when shell arguments cannot be fully parsed, and provider error messages no longer include the credential that failed.
0.2.1
New
- Rewind the conversation with a double Esc: pick an earlier point, confirm before anything is undone, and only safe rewind points are offered
- Automatic approval pre-screening: a model-based reviewer clears tool requests it judges safe, so you see fewer prompts. Anything it doesn't clear still comes to you, and it can be disabled
- When the sandbox blocks a command, the agent can ask for a one-time approval to run that exact command outside it
- Added a "Review plan" action to step through long plans that overflow the panel
- Added
muse configto validate enterprise-managed configuration documents - Added a built-in skill for setting up isolated Python environments
- Added a built-in skill for handing off and verifying browser apps the agent builds
- Hook commands now receive a selected set of environment variables
- The input box can show a short contextual hint after a turn finishes
Improvements
- Approval dialogs wait for a pause in your typing before appearing, so they stop stealing keystrokes mid-sentence
- Permission decisions are retained in the session log and restored on resume
- The resume picker surfaces sessions that were previously hidden
--modelaccepts any model id; unknown ids use sensible assumed metadata instead of being rejected- Settings accept the standard
mcpServerskey, matching the common ecosystem format - MCP configuration across multiple files and scopes merges consistently
- Clearer diagnostics when an MCP server fails to start, reported once instead of pinned in the interface
- Optional MCP servers that fail at startup no longer spam the transcript
- You can see which of your hooks are running in the live activity area
- Messages sent as a turn finishes are delivered together in one follow-up turn
- Text typed as part of a rewind is kept and restored
- The agent can ask longer questions, up to 500 characters
- The Write tool flags when a new file nearly duplicates an existing one
- Sessions at Ultra reasoning effort default to maximum parallel-agent capacity unless you set a limit
- Session export stitches in subagent transcripts that finish independently
- Redesigned
/statusas a cleaner summary card /usageand/modelslabel costs explicitly as USD- Skill slash commands are highlighted while you type
- Tables stay narrow enough to read in a terminal
- The bundled plan skill researches sources first and presents the plan for review before starting work
- Rewrote the built-in plan, doctor, and source-control skills with clearer guidance
- The design skill reliably engages before the assistant writes visual web frontend code
- Within a session, the agent remembers which skills it already read and avoids redundant re-reads
- Skills with aliases appear once under their canonical name
skills import --fromerrors now list the accepted values
Fixes
- Security: a malicious repository's git configuration can no longer run arbitrary commands
- Security: git commands on your repos ignore repo-configured hooks, so a malicious repo can't run code through them
- Security: skill text containing hidden terminal-control characters is rejected, preventing display spoofing
- Security: Linux sandboxed commands can no longer reach host services through Unix-domain sockets
- Security: a folder carrying both Mercurial and Sapling metadata is no longer probed for repository status
- Fixed a crash when resuming a session whose background agent run couldn't be re-read
- Fixed a panic when piping output into commands such as
head - Fixed a crash on non-UTF-8 command-line arguments
- Partial model responses cut off mid-stream are kept and marked incomplete instead of lost
- Model calls fail fast with a clear status when the network is down, instead of hanging through silent retries
- The working indicator and retry countdown stay visible when a response drops mid-stream
- Streamed answer text no longer appears in the wrong place before the response type is known
- HTTP and HTTPS proxy environment variables are respected for all network traffic
- Keystrokes are no longer lost while an approval decision is submitting
- Multi-line pasted text stays together, including in terminals without bracketed-paste support
- Fixed shifted keys being misread in older VS Code terminals
- Prompts typed in quick succession while a run starts are accepted instead of dropped
- Prompts appear in the transcript as soon as you submit them, even while the run is still starting
- Ctrl-C withdraws queued messages that hadn't started yet
- A steering message you already sent is no longer lost when you retract the turn
- Retracting a turn just after a steering message went through no longer freezes the interface
- Prompts entered when forking a session run in the forked session, not the original
- Esc interrupts the end-of-turn reminder wait instead of appearing to hang
- Tools no longer time out while waiting for you to answer an approval prompt
- Resume restores permission prompts that were still awaiting an answer
- Resumed sessions keep the approval mode you chose
- Permission prompts stay visible when the side panel refreshes
- Denying a network permission request now tells the agent and shows in the transcript
- The automatic permission reviewer is more predictable, with consistent verdicts, retry caps, and timeouts
/compactcompacts the session's real working set, including after forks and side chats/compactruns in the background instead of blocking the session- Branching into a side chat after a restart no longer breaks conversation history
- Resume replays subagent activity recorded in the parent session log, with the original identity
- Resumed sessions keep subagent lifecycle events in their original order
- Output from background subagents started before a resume is replayed instead of disappearing
- Subagent results that finished before you pressed Esc are preserved instead of disappearing with the cancelled turn
- Long-running background subagents reliably deliver their final answer
- Input submitted just before the app stops is no longer stranded on resume
- Resume no longer writes checkpoints from a half-replayed log, or breaks on expected gaps in the checkpoint log
- Resume no longer risks adopting the wrong
/compactresult during recovery - Manual
/compactruns are recorded durably and survive restarts - A log truncated mid-write no longer restores a partially written permission record
- Session goals are restored with working controls after a kill and resume, and usage totals stay correct when a goal is replaced
- Resumed session goals restore their usage totals instead of failing to resume
- Session goals pause when successive turns stop making progress, instead of looping indefinitely
- Exported sessions keep the full record of permission prompts and decisions
- Sessions get a proper end record on normal exit, keeping history and resume listings accurate
- Closing or losing your terminal is no longer misreported as a crash
- Starting two sessions at the same moment no longer fails to open the local session store on a first run
- Starting from a missing or unreadable folder fails immediately with a clear error
- A prompt passed at startup is no longer occasionally captured as blank
- Fixed a race at run start that could leave the session in a confused launch state
- Headless runs pass your prompt text through unmodified by default
- A
!shell command whose process dies unexpectedly settles cleanly instead of leaving the session stuck - Background processes are cleaned up more reliably when a session exits
- The agent gets correct guidance for backgrounding commands from the shell tool on macOS
- Stopping a background task no longer hangs when two stop requests race
- Background reminder checks are tied to their own run, so no activity lingers after it ends
- Headless runs no longer hang after finishing because an older reminder task is still open
- Background command and task ids are globally unique and time-ordered
- Scheduled tasks with a timezone problem warn once instead of every tick
- A corrupt scheduled-task database now warns at startup and identifies where the quarantined data was retained
- A failed subagent launch no longer permanently consumes a capacity slot
- Subagents that finish without a result show a proper final state
- Notes typed in a subagent's view reach the running subagent
- Subagent worktrees whose ownership can't be proven after a crash are quarantined instead of wrongly cleaned up
- Status lines for cancelled and waiting agents show the agent name instead of a raw UUID
- Messages with pasted images sent while the agent is busy arrive in order
- Pasting an image alongside a pending rewind routes correctly
- Hook output starting with a UTF-8 BOM has its allow or deny decision honored
- Project hooks take effect as soon as you trust a folder, without a restart
- Hooks triggered by
!shell commands are durably recorded and survive resume and export - Structured JSON output from file hooks is preserved instead of flattened
- Rejected hook output produces a bounded, readable diagnostic
- Shell approval prompts keep the command's original line breaks
- Invalid todo-list tool arguments produce a proper structured error
- A malformed skill on or off value in settings is ignored gracefully instead of breaking loading
- Prompt hints only suggest commands that exist in your session
- A symlinked user config directory no longer breaks loading of project and built-in agent definitions
- Fixed a settings file lock held longer than needed, which could block later writes
- Ctrl-L clears the screen without redraw artifacts
/helpshows the full shortcut list in an 80ร24 terminal- Fixed a wildly wrong elapsed time in the activity row after reattaching to a session
- The task panel no longer glitches while old checkpoints are retired
- The Ultra reasoning-effort display and activation animation no longer pop, flicker, or dim
- On Linux, the command sandbox is selected once at startup so behavior stays consistent for the session
- The built-in doctor skill's session-evidence collection and redaction work correctly again
Performance
- Faster startup with a large skill catalog, and an accurate count of skills dropped from the catalog
- Git operations for isolated subagent worktrees no longer block the agent runtime
0.1.x
Also delivered in 0.1.x patches: attaching the session recording when reporting a bug as well as a bad result; correct truecolor detection for Ghostty over SSH; reliable replay of terminal command output in long sessions; subagent results shown once with the correct outcome; and a rollback of a built-in instruction change that had regressed answer quality.
0.1.0
- Launch version