This release gives every bot a workspace you can see and edit beside the chat, lets a bot ask you a real question and get a real answer, brings local models into the product as a first-class setup, moves connected apps onto your FluxRouter account, and adds inline images, audio and video that never leave your machine unverified, including saved-file cards that show the file right in the chat. Underneath it, the engine runtime, the desktop process, the companion, the installer and the hosted broker each close a set of audited gaps, Stop means stop on every engine, and all seven language packs are complete.
Added
A workspace pane beside the chat. A resizable Workspace rail on the right of the conversation (chat keeps at least 360 px, rail at least 320 px, width remembered), a covering overlay with Back to chat on narrow screens, and an Expand mode. The rail lists the selected conversation's files, opens them in tabs named by scope and relative path, and previews Markdown (rendered or Source), protected HTML in a sandboxed frame, plain text, images, and a truthful open/download fallback for everything else. A single click reuses one clean preview tab; Keep open and Edit make a tab persistent; a dirty tab is never replaced and asks before it closes. Actions: Save, Save a copy, Save this version, Download, Open in app, Show in folder, Open in Files.
A Markdown editor that only writes on Save. Rich editing runs on Tiptap 3.31.3 and opens a file in rich mode only when the pinned parser is proven to round-trip that file byte for byte; anything else opens in Source mode on the exact text. Reloads never become edits. Saves are conditioned on the revision you opened: a file a bot changed underneath you becomes a conflict that shows both texts with Use the disk version / Keep my version, and a save while a bot turn holds that folder is refused with a plain message and nothing written. The revision you replace is kept as a saved version in Files first, so nothing is overwritten unless it was retained. Unsaved typing survives a crash: drafts live in the renderer (50 drafts, 10 MiB), are labeled separately from "File saved", and a recovered draft found after you started typing is held until you choose.
Files shows the workspace, not only saved copies. Files now carries both halves: the conversation's working folder as it is on disk right now (lazy folders, breadcrumbs, name search with an honest "incomplete" state, 200 entries per page) and the saved versions that never change. Every row is labeled "Workspace file" or "Saved copy". Legacy conversations pinned to no workspace and remote runs say exactly that instead of listing your home folder. Open in app and Show in folder hand one live file to the OS through an owner-bound, extension-allowlisted bridge that re-checks the file's identity immediately before the call.
Bot outputs are saved automatically. A file a bot writes into the managed outputs/ folder of its task workspace during a turn (regular files up to 25 MiB, at most 20 per turn) becomes a verified saved version in Files with producer and run provenance and one host-authored card in the chat, with no register_artifact call. A failed or canceled turn leaves the receipts retained and registers nothing. Generated images are receipted before they are attached, so an interrupted publication resumes on restart from the retained bytes with zero provider calls and no duplicate message.
Saved-file cards show the file itself. Every "Saved file" card in the chat previews inline instead of sending you to Files: images render in place and open the lightbox; audio and video embed the same player card (no autoplay, one at a time); Markdown, text and code show a bounded slice (2 KB, Show more up to 256 KB) rendered like the transcript; HTML renders in the same protected sandboxed frame Files uses; PDF and binaries keep their buttons. Open here still opens the working file in the workspace pane. Source and configuration files a bot writes (.py, .ts, .sh, .yaml, .toml, .sql, .go, .rs and the rest) are now saved as text so they preview too; .svg, .env, .pem, .key, archives and binaries stay download-only. The card never builds a raw bytes URL and refuses any resolver answer without a capability.
A question card, end to end. When Claude Code, Codex, Fuigo, an ACP agent or Pi asks you a question (AskUserQuestion, requestUserInput, ask_user_question, elicitation, select/input/editor), Murage now shows a card with the questions, options, descriptions, multi-select, Other and free text, fully keyboard-driven (1-9, Tab, Enter, Esc), and sends the engine exactly the answer shape it documents. A question is never auto-approved, never remembered as "Always allow" and never auto-reviewed; skipping it is delivered at once instead of leaving the engine waiting. The engine waits 30 minutes; after that the card stays as Expired with "Send as a message" so a late answer still reaches the bot. Cards persist across restarts. A URL elicitation is shown as a link you open; Murage never fetches it for you. The card reads like the other transcript cards: each question is a recessed sub-card, options are separate pills with an accent edge when picked, the key map lives in the Send button's tooltip, and an answered, sent or skipped card keeps its picks and settles into an "Answered · time" footer.
Questions on Telegram. The same card reaches the paired Telegram owner as its own message per question: numbered options with one inline button each, multi-select toggles with Submit, "Reply with text" for a free-text answer, and Skip. Answers go through the same validation as the desktop card; a stale, forged, foreign or expired tap does nothing. Secret questions stay in-app.
Local models, as a real setup. Settings → Models gains a permanent Local models section that says which addresses automatic detection checked (Ollama, LM Studio, llama.cpp, vLLM, SGLang), lets you add, edit and remove your own servers (loopback, home network or tailnet over plain http; https otherwise; key write-only), and runs a seven-check tool-calling test per model with a one-sentence outcome ("Tools work, ready for agents", "Context too small for agents") and the checks behind a disclosure. Loaded context is read from the server; Ollama gets a "create a 64K copy" action. Fuigo, Pi, OpenCode, Qwen Code, Hermes, Droid and Kimi are wired to a tested model; Codex and Claude Code rows appear only after their own surface test passes. The picker's Local rail shows "model · server" and marks a model whose tool test failed. Live proof against a llama.cpp Qwen3.8-27B host: four engines completed real tool-using turns.