Changelog
What's new, improved, and fixed in each Muse Code release. For install and upgrade steps, see the Muse Code overview.
1.2.1
New
- Voice input is on by default on macOS: press
Option+Vto dictate, and manage it with/voice - Added a
/rewindcommand that rewinds the conversation to an earlier input — same picker as doubleEsc - Pasted and dropped images get
[Image #N]labels the model can see, so you can ask about a specific image by number; labels and their source paths survive resume, rewind, and forks /mcpshows a live inventory of connected MCP servers and their tools in the transcript- Added a bundled
migrateskill that imports your Claude Code or Codex memory notes and MCP servers into Muse Code - Set
MUSE_TRANSPORT_TRACE=1to print raw provider request and response lines to stderr for debugging model calls; credentials are scrubbed - Sessions can be renamed over the session protocol with
session/rename(withsession/nameChangednotifications), andsession/listcarries display metadata — title, first user prompt, and branch - Edit-tool calls on the session protocol carry a structured diff fact —
patchSummaryline counts plus a durablepatchRef— so clients can render what an edit changed - Programs driving a session can set a session-wide reasoning-effort default with
session/setReasoningEffort, inherited across resume and fork - Workflows now run in
muse servesessions, matching whatmuse execsupports
Improvements
- New sessions start in the Auto-review permission profile: the same access as Ask me, with an automated reviewer deciding eligible approval requests; it falls back to asking you when the reviewer is unavailable
- Permission selections are remembered and applied to new sessions
- MCP tools whose server declares them read-only run without an approval prompt under on-request approvals
- MCP server configs support
${VAR}environment interpolation, and stdio MCP servers receiveMUSE_SESSION_ID - The MCP handshake advertises protocol version 2025-06-18 on both transports
- Hook payloads include the session's canonical
model_provider, so hooks can branch on the active provider - Clearer, typed guidance when a sandboxed command is denied listening on a network port
- Messaging local Claude Code sessions is more robust: interrupted sends cancel cleanly, stale late replies are rejected, and peer discovery shows whether a peer supports read receipts
session/resumeruns the same startup reconciliation as a fresh launch, so work orphaned by a crash settles instead of staying stuck- Launching a subagent with an unknown agent type or an invalid task name is rejected with an explanation of what was wrong and which targets are valid
- Every non-Main viewer's footer shows
Ctrl+Cto return, even when the view isn't focused - Scheduled-task rows keep long prompts to a single header line, and creation receipts are one line, with detail available on expand
Fixes
- Security: commands launched through wrappers such as
envandsetsidare reviewed as the command they actually launch - Security: changing the permission mode mid-session now applies to already-running tools at their next action
- Security: MCP tool grants in custom agent definitions are validated against the prepared toolset instead of falling back to a legacy path
- Security: the Unrestricted permission profile now behaves exactly like
--yolo - Only the main and side sessions can prompt for user input; subagents no longer can
- Smoother
/clearand/new: the screen no longer blanks before the new session's first frame, keystrokes typed during the restart are kept and replayed in order, and aCtrl-Cin the restart window no longer kills the app /clearand/newrefuse trailing text on the command line with a usage hint instead of silently discarding it- MCP servers that fail to start after
/clearor/newnow surface the failure instead of staying silent - Double
Ctrl-Dover a pending approval opens the exit confirmation instead of force-quitting past running background work - With an approval prompt open and text in the composer,
Entergoes to your message instead of being swallowed by the approval panel - Each guarded call in a parallel tool batch gets its own approval prompt
- Permission selections committed during a session survive resume
- Pending approvals survive a headless restart instead of inheriting the predecessor's abort
- After a crash, a tool approval that was still waiting for your answer shows as unresolved on resume — never as already executed
- Saving settings preserves the file's permissions and symlinks, and no longer writes an all-default
tuiblock - MCP
startup_timeout_secis honored, and slow servers that emit newline-delimited JSON are admitted - An MCP server's
requiredflag follows the winning configuration layer - An MCP server's
cwdsetting now sets the stdio server's working directory - Resuming is more reliable: resume no longer fails after compaction has pruned older history, on a session saved mid-way through parallel tool calls, on a checkpoint taken while a workflow was paused, on a checkpoint that went stale while the session kept running, or with "duplicate or non-monotonic" sequence errors; a run that cannot be rebuilt is set aside instead of blocking the whole session, and an empty saved session file is refused with a named reason instead of opening broken
- A malformed tool call from the model no longer poisons the session: the model gets a clear error it can retry from, and sessions already saved with such a call resume cleanly
- Forks and side chats are more reliable: they stay available after resuming from a checkpoint, keep messages and attachments that used to be dropped from the new branch, open on histories that previously failed with a read error, and branches created in quick succession keep their creation order
- Your model and reasoning effort choices stick: forks and side chats start on the parent's model and effort, a per-turn effort applies to that turn's model requests, and turns the runtime starts on its own (like background-work wake-ups) use your settings instead of the startup defaults
- Stopping and cancelling subagents is dependable across restarts: a stop or cancel in flight when the app closes is completed on the next launch instead of forgotten, stays in force after the agent is closed and reopened, and is not reopened by a late result from the agent's own children; restart recovery no longer revives, duplicates, or corrupts agents it should leave alone, and closing an agent's whole subtree no longer wakes the agents being closed
- Background work reports in reliably: a live view opened before a background task produced output now fills in instead of staying blank, messages for a subagent's own subagents reach the right agent, and a finished subagent whose session can no longer accept results settles instead of waiting forever
- Workflows start and finish cleanly: an invalid workflow source is rejected before anything launches (and
muse execJSON output stays clean), a finished workflow agent with a missing or invalid report settles instead of leaving the workflow waiting, and resuming mid-workflow replays already-completed steps correctly - Workflow progress narration shows in the conversation on the default view, not only inside
/workflows - Goals handle blocked work honestly: a goal denied by session policy ends with a clear final message naming what was blocked instead of empty output, and progress that was blocked resumes correctly when the goal continues
muse execno longer exits with an error when the process reading its stderr goes away during shutdown- Finished shell commands clean up fully: releasing a captured terminal no longer injects a stray blank line into the command's output, and long sessions no longer accumulate runtime resources from completed commands
- Session storage is more robust: listing sessions no longer intermittently fails with "session index unavailable: database is locked", and a full disk no longer crashes the app before it can restore your terminal and print the session id and resume command
- Pastes into
!shell mode stay literal — image file paths are no longer rewritten into[Image #N]attachments - Long assistant replies stay within the collapsed row cap while streaming, and
Ctrl+Omid-stream no longer garbles the elided view - Tool rows in narrow terminals keep their expand hint instead of dropping it when the header runs out of room
/settingsrefreshes its rows when a side chat starts or returns, so the Reasoning effort row can't go stale and the highlight can't act on the wrong row- Messages parked in a side chat no longer linger in the main session's queued-messages panel after returning
- After
/side,/statusand/taskscount only the visible session's work instead of leaking the other session's subagents and pending items /taskspreview of a finished terminal shows the same status wording as its drawer row instead of "no output yet"- Keys pressed while the rewind loading screen is up are absorbed instead of leaking into the composer;
EscandCtrl-Cstill cancel - Resuming a session by exact id warns when its declared predecessor session is missing from the store instead of resuming silently
- A freshly launched session no longer vanishes from other terminals' resume pickers until it exits
/stopalways renders a verdict — a background task that never confirms now reads as a failed stop instead of leaving/stopsilentmuse serve:session/listincludes sessions loaded on the answering host with fresh metadata so a new session appears immediately aftersession/start; session recency ignores internal bookkeeping writes, so crashed old sessions no longer jump above newer work; page cursors bind to the listing that minted them, and cursors from live streaming and durable reads share one space instead of being rejected as unknown;session/setModelacknowledges only after the change is durable; omittingproviderIdonsession/startresolves to the host's composed provider; a brand-new session can no longer be pruned out from under its own start; and stopping the server with SIGTERM or SIGINT winds down cleanly, closing sessions durably instead of crashing themmuse serve: a rejectedsession/resumeno longer leaves a stray view subscription; resuming with a cursor delivers pending approval and user-input requests instead of an empty list; live view updates re-arm after aview/unsubscribe; approval modes selected over the wire are honored for shell commands instead of being clamped; setting the model to the same provider no longer bricks a resumed session; subagent results recorded before a resume are readable again; follow-up turns spawned from a carried-forwardturn/steercan be interrupted and steered; theretryableflag onturn/completederrors reflects the provider's real classification; reminder-spawned child tasks show their real lifecycle instead of appearing completed at spawn; and sessions started without a workspace root can still prompt viarequest_user_inputwhen the client supports dialogs
Performance
- Opening or resuming a long session is dramatically faster: startup work now scales with the size of the session log rather than multiplying by the number of turns
item/readOutputno longer scans the whole session per read — dramatically faster on long sessions- Re-attaching a live session view over
muse serveis now constant-time, independent of how many events streamed since load
1.1.1
New
- Added
muse mcp login <server>andmuse mcp logout <server>: OAuth 2.1 sign-in for remote MCP servers, in the browser or headless. Tokens are kept in the auth store and refreshed automatically, a login done in another terminal is picked up without a restart, and a startup or mid-session 401 now tells you the exactmuse mcp logincommand to run. Setmcp_oauth_dynamic_client_registration: falseto turn off automatic client registration - Markdown links render as clickable labels in terminals that support hyperlinks, with automatic fallback (including under tmux); exported transcripts keep the full URL, and links survive redraws and scrollback
/themegains a Terminal background row: Left/Right cycles auto, light, and dark and re-derives the picker live, a notice appears when your choice contradicts what the terminal reported, Enter saves it astui.terminal_background, and Esc reverts- The agent can check on and stop its own background work (workflows, subagents, and background commands) with the new
work_statusandwork_stoptools, using the same work ids it is shown - Todo reminders are on by default: the model is nudged to create and update a todo list during complex multi-step work
- Two new built-in skills, on by default: one has the agent ask about an unresolved product decision before committing to it, the other keeps a focused regression test with each bug fix or behavior change
- Added a bundled Three.js skill (
/threejs) with references for scenes, geometry, materials, lighting, textures, animation, loaders, shaders, post-processing, and interaction - Added a
PostToolUseFailurehook that fires when a tool call fails or crashes - After a rewind or fork, the status bar warns while tasks from the original conversation are still running, and the new branch's transcript notes the background work that stayed behind
- Press
sin a workflow's detail view under/workflowsto save the running workflow under a name so you can run it again - Programs driving a session can declare
capabilities.userInputDialogsatinitialize; sessions whose client can show a dialog get the ask-the-user tool, and a client that opts out has such calls rejected cleanly instead of hanging - Programs driving a session can read an item's stored tool output by reference with
item/readOutput, and re-attach a live view withview/subscribeafterview/unsubscribeon a still-loaded session, replaying the gap from a cursor
Improvements
- Memory, Skill, Todo, and Scope reminder child logs now default to Memory only, so a long session no longer accumulates one
subagent/<id>/session.jsonlper model step. Choose Saved under TBH Reminders → Settings to keep writing them; Goal and Verify are unchanged - A forced
maxreasoning effort (--reasoning-effort max, settings,/effort max) is now sent to the model as-is on every model instead of being silently downgraded, so an unsupported value shows the provider's error;maxis also accepted as areasoningEffortonturn/startandturn/steerover the session protocol - The Scope reminder is on by default in sessions using muse-spark-1.2
- Tuned the built-in instructions: the agent asks one grouped question before scaffolding when a request leaves a material product decision open, never claims a server is up without a fresh check, confirms decisive values (versions, config values, paths, counts) by a second route, surfaces degraded external causes in the deliverable itself, resolves which file a correction refers to before editing, and reports rather than refuses safety concerns about explicitly requested changes
- The goal reminder no longer steers the agent toward faking, bypassing, or disabling a test to satisfy a goal; it names the honest blocker instead
- Workflow scripts steer child agents to inherit the parent model unless a task clearly needs a different tier, and research children inspect the source and tests behind each claim instead of stopping after a fixed number of tool batches
- The built-in
grillskill now records each settled decision in your project docs and closes with a written scope contract (what is in and out of scope, and what done means); the separategrill-and-recordskill was removed - The
planskill asks about open product preferences up front when you request a collaborative planning checkpoint, instead of leaving them as open questions at the end - The composer prompt uses a heavier
❯glyph /newand/clearprepare the new session before shutting down the old one, so both stay resumable if the process dies mid-restart;/newnow clears the visible thread like/clear, both share one palette description, and quitting after keeping background tasks across them warns that those tasks will be stopped--disable-sandboxno longer prints a startup notice on its own or changes your selected permission profile; startup warns that profile filesystem and network restrictions are not enforced for direct shell commands, and/statusshows a Sandbox row when it was disabled at launch- Commands you run yourself with
!(andsession/userShellovermuse serve) no longer trigger approval prompts, including for network access; hard policy denials still apply and stay visible - Tool calls that fail only because a path does not exist are shown quietly in a dimmed style instead of as loud errors
- Tool cells with several attachments draw one continuous tree guide from the header to the last attachment, and wrapped continuations no longer land at column zero
- The "Worked for" line also shows the local time the turn finished, e.g.
Worked for 1m 01s · 10:15 AM - The Plan panel appears only while a run is active and hides while a prompt is waiting for your answer
- When a session wakes for a peer message, the text it writes before calling a tool is folded into that tool row (expand with
ctrl+o) instead of a separate transcript cell - Startup notices say exactly what was trimmed: a memory truncation names the file and the limit that fired, and a skill catalog over its size limit keeps every skill's name visible and reports how many entries were cut
muse execprints once on stderr why subagent delegation is unavailable- Spawning a subagent whose definition (prompt, skills, memory) already exceeds the context budget is refused up front with a clear diagnostic instead of failing later
- Resuming a session refuses with a named reason and remedy when the saved state cannot be trusted (identity mismatch, another live writer, unreadable state, unrebuildable history) instead of silently degrading
- Resumed sessions describe the current sandbox and permission posture to the model instead of the posture recorded when the session was first started
- The agent's subagent-tree status can page through completed history, oldest first
--worktreesessions remove their Git worktree on close when it is clean and its commits are already on the default remote; unique or unproven work is kept- Sessions you open and quit before sending anything no longer linger in the resume list or on disk, including zero-turn
muse servesessions whose owner process died - Removed the confusing "model … not in catalog — using assumed limits" notice at startup
- In
/workflows, pressfinside a workflow's agent view to filter agent cards by label; the phase drill-down filter is offered only while agents are live and clears itself when the last one finishes - A turn that fails because no usable credential is available ends with a distinct
authRequirederror over the session protocol and in the SDKs, instead of a generic model error - SDK:
apply()session-state outcomes are deeply read-only, and theDeepReadonlytype is exported - Shell output containing invalid UTF-8 now notes how many bytes were replaced instead of being rewritten silently
- Selecting the
maxreasoning effort in the Effort drawer plays a gold activation animation, and the gold prompt and rail stay settled across model switches
Fixes
- Security: Closed a gap where
rm -fr,rm --force, and wrapper-nested variants slipped past the dangerous-command check that guards destructive shell commands - Security: Model-authored subagent names and objectives, text read back from an external editor, and provider error messages are stripped of terminal control sequences before they reach the terminal or the session log; provider errors are also scrubbed of credentials
- Sending an image with no text no longer makes every later message in the session fail with "Message not sent", including after resume
- New prompts are no longer rejected after a restart when the session's replay evidence is missing or unreadable, and "Message not sent — projection failed" no longer follows a turn that ran several tools at once and had its results cleared
- A background delivery whose submission keeps failing no longer retries forever or starves your own messages ("Message not sent — runtime admission timed out"): retries are single-flight and a poison item is quarantined after three failures
- Sessions whose log can no longer be fully replayed, whose checkpoint records a wrong message count, or whose saved runtime snapshot is invalid now resume from the last valid checkpoint or a safe reopen instead of failing to open
- Resuming after a checkpoint no longer fails on the next turn, leaves a gap that breaks the next checkpoint, or fails on the first write after a compaction had already summarized a superseded marker
- Resuming no longer aborts when one subagent's log is unreadable, drops the answer the agent gave after a retried turn, shows an interrupted MCP call as completed, or loses a running workflow's agent tree after a compaction
- A resume that fails before it is ready no longer writes partial records to the session log, and a resume forced to fall back after an invalid checkpoint recovers with a single recovery checkpoint
- Reminder-agent logs that end in a blank line no longer fail to replay on resume
- The session list refresh no longer races sessions that are still being written, and keeps a session's cached title and details when its lock cannot be opened instead of showing an "unreadable" placeholder
- The
--resumepicker stays responsive while sessions are still being discovered on a cold start, and resuming from it or after a session-in-use notice shows startup progress instead of a blank pane - Resume and
muse exportreport a permission-blocked session directory as unreadable, with achmodremedy, instead of claiming the session has no saved log - Running
resumewithout a terminal now points to the headless remedy (exec --session-id <uuid>), and the export picker names its real--lastand--sessionflags muse exec --resumeworks for sessions created with--worktree, records the crash before adopting a crashed session, andmuse exec --no-session-logstarts when subagent delegation is enabled- Nested subagents (a subagent's own subagents) now open their session logs, write their control records, and recover in the right place across restarts, so their results survive a resume and are not duplicated
- Subagent results no longer point at the wrong transcript when several subagents run at once; interrupting a subagent before its first model call takes effect immediately; waiting on a worktree-isolated subagent after cancelling it no longer errors; reading a subagent's transcript works after its log crosses a checkpoint; and messages a subagent rejects are recorded with the reason
- The subagent panel keeps a Finished marker that arrives out of order, shows the selected subagent's own activity while it waits on the model, expires a finished row you parked the cursor on, names agents by label in steering acknowledgments, keeps its place when paging a completed transcript after a status refresh, and counts each subagent's tokens the same way
/usagedoes - An invalid
subagent_typevalue, or a default subagent definition that fails to load, now gets a rejection naming the real cause instead of a generic argument or selection error - The task inventory shown for a child conversation lists only that conversation's workflows, subagents, and terminals instead of the parent's
- Paused workflows survive: cancelling a turn no longer marks a paused workflow cancelled, and a paused workflow keeps its owner, children, capacity slot, completion state, and resume handoff across
--resume - Workflow children report reliably: a child that fails shows its final status live, a finished child stays finished, cancelled children show no error receipt, follow-up subagent results reach the workflow, results are no longer held back behind a long main turn, messages sent to a child before it is live are queued instead of rejected, children woken after a restart no longer stall on reminders, and children keep their memory tools after recovery
- Quitting cleanly while a workflow still has live child work leaves that work recoverable on the next launch, the same as after a crash
- Subagents spawned by a workflow child no longer clutter the main transcript with spawn and finish rows
- Steering a running turn no longer drops Workflow mode when the steer lands as a fresh turn
/workflowsshows a short run id next to unnamed workflows so identical-looking rows can be told apart- Saving a named workflow no longer overwrites a file a concurrent save just wrote, cleans up its staging file on failure, and names the target path in the error
- On Linux, workflow script syntax errors report the real message and source line, keep
--jsonoutput clean, and scripts whose default export is an expression are detected correctly - Goal controls accepted in the final moments of a turn, or just before a cancelled turn restarted, are no longer left queued; interrupting a run with an active goal reliably shows the goal-paused notice; Esc stops the turn even when goal storage is unavailable; goals closed automatically when a run ends are recorded and announced; and a rolled-back fork no longer leaves goal store files behind
- Rewinding to a point mid-conversation works again; rewind branches from the exact point you chose; a window holding a queued steer or an in-flight run no longer fails after you confirm; sessions compacted mid-turn can be rewound; and a finished task whose result is still being delivered no longer counts as active work
/sideno longer fails on a session compacted after its checkpoint, on a log with only bookkeeping records since the last checkpoint, or when resuming a side chat created on an earlier day; a prompt sent right after returning from/sideis queued instead of rejected as busysession/forkpreserves the source turn and item identities, accepts the source session's real turn ids as the cut point, reports the child's own turn count, and forked sessions overmuse servestart their MCP servers instead of failing with "MCP startup audit failed"- Failed turns no longer count as phantom turns in session listings, reads, resumes, and rewinds
- Manual
/compactsummarizes with the model you switched to via/modelinstead of the launch-time model /newand/clearno longer break every following turn with "MCP startup audit failed" when MCP servers are configured, and/clearrefuses to start a new session when the session log cannot be retained instead of minting one that would lose history- Enabling or disabling a skill now takes effect on background and reminder-driven turns immediately, not only on your next prompt
- Re-running
/skills importreports already-imported skills as skipped instead of counting them again (--dry-runshows the same rows); a project copy of a bundled skill with identical content is no longer listed twice; and a skill whose manifest cannot be read reports the real filesystem error - The skill reminder no longer fires in sessions where the
read_skilltool is unavailable - One mistyped entry under
skills.activation.projectsorhooks.stateno longer discards the rest of the map (a startup warning names the bad key); settings and credential writes follow a symlinked config file instead of replacing the link; and a rules directory that cannot be searched is reported by name with a remedy PostCompacthooks fire exactly once for background compactions adopted after a turn ends; aPostLLMCallhook that keeps returningadditionalContextstops re-driving the turn after 8 continuations; and hook trust and enable state no longer collide between argv-style hooks whose arguments join to the same string- MCP tool calls keep their server attribution through live refreshes and after closing a rewind overlay; the per-server
tool_timeout_secsetting applies to tool calls, resource reads, and prompt fetches on both transports; and a server that requires an OAuth sign-in says so at startup, with HTTP 403 reported as an authentication failure instead of a generic initialization error - Interrupting a running
bashcommand returns the output it had already produced; a background command's exit status is shown once; input sent to a non-interactive background command points atterminate; starting a second!command while one is running names the running command and keeps your draft; and denied!commands report output truncation correctly - Search results in JSON mode return invalid-UTF-8 lines as base64
bytesinstead of silently rewriting them - Runaway loops that repeat the identical command with identical output are stopped even when compactions happen mid-loop
- Cron jobs created during a fresh
muse execrun are bound to that session; queued cron wake-ups are no longer lost when a session is resumed after a compaction; andmuse servesessions expose the scheduled-task and goal tools that were advertised but never reached the model muse exectext output no longer loses the answer when a background wake starts a second run;execno longer hangs on a protected write it cannot get approved;--max-tool-output-bytesrejects values below the readable floor (0disables the cap); and a failed model-catalog fetch is no longer retried a second time on a cold cache- Startup no longer fails when the temp directory is unusable (it warns and continues); on Linux the startup warning about a missing system
bwrapis gone; andmuse initno longer hangs on a package manifest that is a FIFO - Meta Model API requests that fail with HTTP 402 are not retried, and retry status reads in plain words, e.g.
rate limited (HTTP 429) · retrying in 60s · attempt 2/10; a transient token-refresh failure duringweb_searchis reported as a connection problem instead of an authentication failure - Ctrl-B and Ctrl-D edit text when the draft is non-empty and the exit hint follows remapped keys; fast-typed or terminal-buffered text no longer arrives out of order around character-form shortcuts or Tab; cutting a large paste with Ctrl-W and yanking it back restores the content; the cursor no longer drifts after Indic spacing-mark clusters; and an image path in the middle of a sentence stays as text
- Typing no longer stalls right after resuming a long session; idle sessions no longer churn CPU after a turn ends and the terminal cursor blinks again; and opening or answering an ask-question prompt no longer blanks and redraws the whole terminal
- Collapsed read and search summaries always show the
ctrl+ohint; wrapped lines no longer tear emoji sequences or overflow the pane; narrow panes keep the state cell and timer visible for long task labels; the live-follow view for a background command uses the full pane width; an external tool's failure details render once; and tool rows rejected for bad arguments switch torejectedpromptly - Run failures caused by step limits, configuration, environment, or workflow launch errors no longer carry a misleading
model failedprefix; the context-usage notice no longer reports almost nothing remaining on an implausible token count; and the notice shown when resuming a session that did not shut down cleanly no longer tells you to runreset --worktreesessions no longer fail intermittently when several sessions create worktrees in the same repository at once, and resuming one no longer hits a worktree collision after an earlier removal was interruptedmuse export --outwrites to a temporary sibling and renames it into place, so a failed export never truncates an existing file- Pending approvals no longer flash into the approval list while the automated reviewer is still deciding
@muse-code/sdkbundles its protocol type declarations, so consumers typecheck withskipLibCheckoff;Item.turnIdis typed as nullable to match what the server sendsmuse serve: protected-write approvals wait for the subscribed client'sapproval/decideinstead of aborting right after prompting;session/resumere-issues pending approval and user-input requests so a reconnecting client can answer them after a crash; a resume with a cursor no longer lets a live event reach the client before the replayed suffix; and views restored after a restart match the live view when a reply was still streaming at checkpoint timemuse serve:session/list,session/read, andsession/resumereportrunningand the activeturnIdwhile a turn is in flight; a session whose cached view history is unreadable reports history as unavailable instead of failing every read; failed, cancelled, and timed-out tool calls include the tool's final output;session/startignores unknown keys insideconfiginstead of failing; rejecteduserShellcommands are settled durably so an identical retry gets the original answer; and a queued follow-up left stranded when the connection closed mid-admission is no longer executed on the next load- Scheduled (cron) deliveries run as one bounded turn: the end-of-turn goal reminder no longer fires on a scheduled run, which had kept a single delivery looping through phantom ticks every few seconds
- A
muse servehost that started logged out now picks up a later device-code login on the next session start, resume, or fork instead of answering "auth required" until the host restarts
Performance
view/pageon long sessions is dramatically faster overmuse serve: page reads are linear in session size and repeat pages on a loaded session are served from cache- Faster startup and resume: multi-megabyte checkpoint lines are read in linear time, session-index housekeeping and crash-recovery scans run after the prompt is ready, the trust store is read once per launch, a turn submitted into a resumed session no longer replays history older than the last compaction, and
session/resumeovermuse serveloads from the latest checkpoint instead of replaying the whole log - Rewind evaluates and applies from an in-memory window of the current conversation (back to the latest compaction checkpoint) instead of re-reading the session log, so the picker opens faster in long sessions
1.0.x
Also delivered in 1.0.x patches: the tui.terminal_background setting (auto, light, or dark); muse serve sessions expose the same bash tools as muse exec, model/list lists only the models a session can route to, session/resume from a cursor delivers the retained events after it, an oversized session/start workspace path is refused and session/list pages large listings, initialize rejects a malformed clientInfo.name, and muse serve exits with code 3 when settings or credentials cannot be loaded; forking carries compacted permission state into the fork; forked and side sessions show their real creation time instead of 1970; web search reads compressed responses; logging out clears the cached feature configuration; the skill reminder is active again in default muse exec runs and no longer repeats its loaded notice; the blocking verify reminder header reads "Double checking"; resume tolerates a blank line in the session log; checkpoint and explicit saves no longer stall behind background flushing; memory writes survive a stale temp file left by a crash; subagent results and goal reminders arrive as developer context; the search tool routes filename lookups to glob; Esc exits input-history browsing and restores your draft; /resume inside the app shows startup progress instead of a frozen screen; the /tasks drawer lists only the visible session's tasks; a retried turn/interrupt after a restart no longer records a duplicate rejection; and two security fixes: on-request approval mode requires approval when shell arguments cannot be fully parsed, and provider error messages no longer include the credential that failed.
0.2.1
New
- Rewind the conversation with a double Esc: pick an earlier point, confirm before anything is undone, and only safe rewind points are offered
- Automatic approval pre-screening: a model-based reviewer clears tool requests it judges safe, so you see fewer prompts. Anything it doesn't clear still comes to you, and it can be disabled
- When the sandbox blocks a command, the agent can ask for a one-time approval to run that exact command outside it
- Added a "Review plan" action to step through long plans that overflow the panel
- Added
muse configto validate enterprise-managed configuration documents - Added a built-in skill for setting up isolated Python environments
- Added a built-in skill for handing off and verifying browser apps the agent builds
- Hook commands now receive a selected set of environment variables
- The input box can show a short contextual hint after a turn finishes
Improvements
- Approval dialogs wait for a pause in your typing before appearing, so they stop stealing keystrokes mid-sentence
- Permission decisions are retained in the session log and restored on resume
- The resume picker surfaces sessions that were previously hidden
--modelaccepts any model id; unknown ids use sensible assumed metadata instead of being rejected- Settings accept the standard
mcpServerskey, matching the common ecosystem format - MCP configuration across multiple files and scopes merges consistently
- Clearer diagnostics when an MCP server fails to start, reported once instead of pinned in the interface
- Optional MCP servers that fail at startup no longer spam the transcript
- You can see which of your hooks are running in the live activity area
- Messages sent as a turn finishes are delivered together in one follow-up turn
- Text typed as part of a rewind is kept and restored
- The agent can ask longer questions, up to 500 characters
- The Write tool flags when a new file nearly duplicates an existing one
- Sessions at Ultra reasoning effort default to maximum parallel-agent capacity unless you set a limit
- Session export stitches in subagent transcripts that finish independently
- Redesigned
/statusas a cleaner summary card /usageand/modelslabel costs explicitly as USD- Skill slash commands are highlighted while you type
- Tables stay narrow enough to read in a terminal
- The bundled plan skill researches sources first and presents the plan for review before starting work
- Rewrote the built-in plan, doctor, and source-control skills with clearer guidance
- The design skill reliably engages before the assistant writes visual web frontend code
- Within a session, the agent remembers which skills it already read and avoids redundant re-reads
- Skills with aliases appear once under their canonical name
skills import --fromerrors now list the accepted values
Fixes
- Security: a malicious repository's git configuration can no longer run arbitrary commands
- Security: git commands on your repos ignore repo-configured hooks, so a malicious repo can't run code through them
- Security: skill text containing hidden terminal-control characters is rejected, preventing display spoofing
- Security: Linux sandboxed commands can no longer reach host services through Unix-domain sockets
- Security: a folder carrying both Mercurial and Sapling metadata is no longer probed for repository status
- Fixed a crash when resuming a session whose background agent run couldn't be re-read
- Fixed a panic when piping output into commands such as
head - Fixed a crash on non-UTF-8 command-line arguments
- Partial model responses cut off mid-stream are kept and marked incomplete instead of lost
- Model calls fail fast with a clear status when the network is down, instead of hanging through silent retries
- The working indicator and retry countdown stay visible when a response drops mid-stream
- Streamed answer text no longer appears in the wrong place before the response type is known
- HTTP and HTTPS proxy environment variables are respected for all network traffic
- Keystrokes are no longer lost while an approval decision is submitting
- Multi-line pasted text stays together, including in terminals without bracketed-paste support
- Fixed shifted keys being misread in older VS Code terminals
- Prompts typed in quick succession while a run starts are accepted instead of dropped
- Prompts appear in the transcript as soon as you submit them, even while the run is still starting
- Ctrl-C withdraws queued messages that hadn't started yet
- A steering message you already sent is no longer lost when you retract the turn
- Retracting a turn just after a steering message went through no longer freezes the interface
- Prompts entered when forking a session run in the forked session, not the original
- Esc interrupts the end-of-turn reminder wait instead of appearing to hang
- Tools no longer time out while waiting for you to answer an approval prompt
- Resume restores permission prompts that were still awaiting an answer
- Resumed sessions keep the approval mode you chose
- Permission prompts stay visible when the side panel refreshes
- Denying a network permission request now tells the agent and shows in the transcript
- The automatic permission reviewer is more predictable, with consistent verdicts, retry caps, and timeouts
/compactcompacts the session's real working set, including after forks and side chats/compactruns in the background instead of blocking the session- Branching into a side chat after a restart no longer breaks conversation history
- Resume replays subagent activity recorded in the parent session log, with the original identity
- Resumed sessions keep subagent lifecycle events in their original order
- Output from background subagents started before a resume is replayed instead of disappearing
- Subagent results that finished before you pressed Esc are preserved instead of disappearing with the cancelled turn
- Long-running background subagents reliably deliver their final answer
- Input submitted just before the app stops is no longer stranded on resume
- Resume no longer writes checkpoints from a half-replayed log, or breaks on expected gaps in the checkpoint log
- Resume no longer risks adopting the wrong
/compactresult during recovery - Manual
/compactruns are recorded durably and survive restarts - A log truncated mid-write no longer restores a partially written permission record
- Session goals are restored with working controls after a kill and resume, and usage totals stay correct when a goal is replaced
- Resumed session goals restore their usage totals instead of failing to resume
- Session goals pause when successive turns stop making progress, instead of looping indefinitely
- Exported sessions keep the full record of permission prompts and decisions
- Sessions get a proper end record on normal exit, keeping history and resume listings accurate
- Closing or losing your terminal is no longer misreported as a crash
- Starting two sessions at the same moment no longer fails to open the local session store on a first run
- Starting from a missing or unreadable folder fails immediately with a clear error
- A prompt passed at startup is no longer occasionally captured as blank
- Fixed a race at run start that could leave the session in a confused launch state
- Headless runs pass your prompt text through unmodified by default
- A
!shell command whose process dies unexpectedly settles cleanly instead of leaving the session stuck - Background processes are cleaned up more reliably when a session exits
- The agent gets correct guidance for backgrounding commands from the shell tool on macOS
- Stopping a background task no longer hangs when two stop requests race
- Background reminder checks are tied to their own run, so no activity lingers after it ends
- Headless runs no longer hang after finishing because an older reminder task is still open
- Background command and task ids are globally unique and time-ordered
- Scheduled tasks with a timezone problem warn once instead of every tick
- A corrupt scheduled-task database now warns at startup and identifies where the quarantined data was retained
- A failed subagent launch no longer permanently consumes a capacity slot
- Subagents that finish without a result show a proper final state
- Notes typed in a subagent's view reach the running subagent
- Subagent worktrees whose ownership can't be proven after a crash are quarantined instead of wrongly cleaned up
- Status lines for cancelled and waiting agents show the agent name instead of a raw UUID
- Messages with pasted images sent while the agent is busy arrive in order
- Pasting an image alongside a pending rewind routes correctly
- Hook output starting with a UTF-8 BOM has its allow or deny decision honored
- Project hooks take effect as soon as you trust a folder, without a restart
- Hooks triggered by
!shell commands are durably recorded and survive resume and export - Structured JSON output from file hooks is preserved instead of flattened
- Rejected hook output produces a bounded, readable diagnostic
- Shell approval prompts keep the command's original line breaks
- Invalid todo-list tool arguments produce a proper structured error
- A malformed skill on or off value in settings is ignored gracefully instead of breaking loading
- Prompt hints only suggest commands that exist in your session
- A symlinked user config directory no longer breaks loading of project and built-in agent definitions
- Fixed a settings file lock held longer than needed, which could block later writes
- Ctrl-L clears the screen without redraw artifacts
/helpshows the full shortcut list in an 80×24 terminal- Fixed a wildly wrong elapsed time in the activity row after reattaching to a session
- The task panel no longer glitches while old checkpoints are retired
- The Ultra reasoning-effort display and activation animation no longer pop, flicker, or dim
- On Linux, the command sandbox is selected once at startup so behavior stays consistent for the session
- The built-in doctor skill's session-evidence collection and redaction work correctly again
Performance
- Faster startup with a large skill catalog, and an accurate count of skills dropped from the catalog
- Git operations for isolated subagent worktrees no longer block the agent runtime
0.1.x
Also delivered in 0.1.x patches: attaching the session recording when reporting a bug as well as a bad result; correct truecolor detection for Ghostty over SSH; reliable replay of terminal command output in long sessions; subagent results shown once with the correct outcome; and a rollback of a built-in instruction change that had regressed answer quality.
0.1.0
- Launch version