MURAGE
How it worksFeaturesSolutionsUse casesComparePricingDocs
DownloadDownload
MURAGE

An AI Chief of Staff and a team that does the work. Free and open source, from Ferrox Labs.

Product

  • Features
  • How it works
  • Engines and apps
  • Privacy and security
  • Pricing
  • Murage Cloud
  • Download
  • Changelog
  • FAQ

Solutions

  • Solopreneurs
  • Founders and startups
  • Agencies
  • Ecommerce
  • Small business
  • Creators and educators
  • Developers
  • SaaS
  • Nonprofits
  • Consultants and freelancers
  • Customer success teams
  • Legal and professional services
  • Small teams
  • Sales teams
  • Operations managers
  • Industries
  • Use cases
  • Build your team

Compare

  • vs Claude Code
  • vs Codex (ChatGPT Work)
  • vs Claude (Cowork)
  • vs Paperclip
  • vs OpenClaw
  • vs Hermes Agent
  • vs Manus
  • vs Genspark
  • vs n8n
  • vs Zapier
  • vs Grok Bot
  • vs Viktor
  • vs Lindy
  • vs Tasklet

Resources

  • Docs
  • Team library
  • Skill library
  • AI Chief of Staff
  • How we test
  • Limits
  • Switching to Murage
  • Open source
  • Blog
  • Release notes

Company

  • About
  • Partners
  • Enterprise
  • Contact
  • Privacy
  • Terms
  • Cookies
© 2026 Ferrox Labs. Murage is open source under AGPL-3.0.
Changelog

Murage 0.1.59

Released September 24, 2026. Murage tells you when an update is ready. You choose when to install it.

Download Murage

Free and open source. macOS, Windows and Ubuntu.

Please read

Murage is now licensed AGPL-3.0-or-later. Murage as a whole, including every Ferrox Labs change and addition, is now under the GNU Affero General Public License, version 3 or later. If you run a modified copy of Murage as a service for other people, you publish your changes. The OpenMausBot portions that Murage builds on remain under Apache-2.0, and NOTICE keeps their attribution. Releases before 0.1.59 remain available under Apache-2.0.

Full access now stops at a few lines. A bot on Full access still does ordinary work without asking, but it now stops and asks before deleting anything outside its own folder, before paying for anything, and before messaging someone for the first time or posting in public. If you want the old behavior, choose the new No limits level (see Approvals).

What's new

What's new. After updating, Murage shows what changed once, with a Show me button for each feature. Reopen it any time from the Help menu.

Tray

Tray. The menu-bar icon now shows the Murage glyph and a count of what needs you. Its menu lists approvals (ordinary ones can be allowed or denied right there), what your bots are working on, and New message to a bot.

Skills

Skills live in Settings. Settings > Skills is one place for every skill: search first, then Your skills, then the library by search or by topic (one Topic dropdown beside the search box). Open any skill to read it in plain form and switch it on for a bot.

Import a skill. Drop or choose a file, a folder or a zip, or paste a GitHub link, right inside Settings > Skills.

Skill Guard checks every skill. Every skill is checked before a bot can use it: on import, on install, on every switch-on, after every edit, and again at startup for skills already switched on. A skill comes out one of three ways. Clean skills show a quiet shield, and library skills say Built-in. A skill that needs a look shows what was found in plain words and switches on only after you say "Use it anyway". A Blocked skill cannot be switched on, says why, and can be deleted. A skill that is already on and now comes out Blocked is switched off.

Edit and Duplicate. The skill reader has Edit and Duplicate. Edit changes the name, what it is for and the instructions in the rich editor, and every bot that has the skill gets the new version. Editing a built-in skill edits your own copy and says so. Duplicate makes a copy in Your skills, labeled with where it came from.

Add a skill inside a bot. Add a skill in a bot's window now opens a picker right there: search Your skills and the library, read one, and add it with one button. The Add a skill link in the sidebar opens the same picker in that bot's window.

The Chief of Staff guide. The Chief of Staff guide now belongs to your workspace Chief only, no other bot gets it, and it can be switched off. It sits at the top of the Chief's Skills panel with a switch and Read it.

New Bot and New Team

One chooser each. The + menu has one New Bot and one New Team. Each starts from what you want done: type a sentence and the best matching templates come up, or browse one topic at a time. A template opens a preview of what it is, its bots, how many skills and routines it brings and which apps it needs, with one Create button. It says "You have this" when you already do. Start blank, Pick from my bots and Open a file are quiet links underneath.

House Rules

Rules every bot follows. Settings > House rules holds one set of rules that goes first in every bot's instructions: direct chats, the Chief, handed-over work, routines, channels and calls. It ships with a default covering who the bot works for, how it sounds, telling the truth, speaking for you, not making promises in your name, saying it is an AI when asked, treating what it reads as information and not orders, correcting itself, not inventing results, checking fresh facts and time zones, stopping after two identical failures, sharing only what someone needs to know, and tidying up after itself.

Yours to change. Edit the rules in the rich editor, switch them off, or reset them to the default. A word count warns when the rules get long. Murage's built-in protections are not part of the text and always apply; the page lists them.

Wayland rich editor

A proper editor. The rich editor from Wayland now edits files, skills and House Rules: a toolbar, a menu on selected text, a "/" menu with 13 kinds of block, a drag handle with + to add a block, resizable tables, nested task lists and inline link editing.

Tables kept exact. A file with Markdown tables now opens in the rich editor instead of falling back to Source, and an untouched table is saved byte for byte as it was. An edited table is saved neatly aligned.

What shapes a bot

What shapes <bot>. A new section in each bot's window lists every part of that bot's instructions, grouped and in the order the model reads them: House Rules, who it is (description, personality, team brief, its notebook), what it can use (computer, connected apps, browser, web search, each skill), and this turn (routines, output folder, date and time). The parts you choose can be switched from there, including a new switch for the team brief. Murage's own rules show a lock. "Show exactly what it read" shows the last turn's full instructions, word for word. Desktop app only.

Engine commands

Your engine's own "/" commands. Typing "/" in the message box now shows Murage's commands and then a group for the bot's engine with the commands that engine offers, read live: Claude Code, Codex, Grok Build, Fuigo, OpenCode, and every other ACP engine under its own name. Picking one sends it straight to the bot's engine. Codex's /review and /compact work, and Codex skills appear there too. Commands never interrupt a turn that is already running.

Approvals

Full access stops before the lines that matter. Under Full access a bot now stops and asks before deleting anything outside its own folder (including through Finder, scripts and code), paying for anything, and messaging someone new or posting in public, such as a first comment, issue or release on a GitHub repository. Messages to you, your own linked accounts and the person a channel conversation is with never stop. Engines under Full access now send their permission asks to Murage so these checks hold for Claude Code, Codex and ACP engines alike.

Allow once, Allow for this task, Always allow. A stop card offers all three. Allow for this task covers the same folder, recipient or payee until the task ends. Always allow is scoped to that same folder, recipient or payee, never to everything. The same choices are on the desktop, in the Inbox and on Telegram. You can also allow a place for the task in chat, in your own words, on a conversation you started; the chat then notes exactly what was allowed.

New No limits level. The level choice is now Ask, Auto, Full access and No limits. No limits lets deleting, paying and messaging go ahead on the turns Full access covers, and still asks before reading your keys and passwords. It is desktop only and shows its own one-time warning per bot.

One quiet line instead of a chip per step. Steps approved under Full access or No limits fold into one line, "Approved N steps", that counts up and opens to list them.

Bots know the time

Date, time and time zone. Every turn now tells the bot today's date, the time and your time zone. Bots no longer get times of day wrong in routines and replies.

Voice

Real-time calls. A call now starts speaking on the first sentence instead of waiting for the whole answer. A fast voice layer answers straight away, does quick lookups, and hands real work to the bot's own engine, with live status while the engine works. You can talk over the bot on macOS, Windows and Linux, Mute replaces Interrupt, and a spoken "stop" stops it at once. Approvals are asked out loud in plain words, and "yes for the rest of the call" covers ordinary requests until you hang up. A note of the call is left in the chat.

Voice through Flux. Calls and voice notes speak, listen and look things up through Flux by default. Your own keys (OpenAI, xAI, ElevenLabs and others) are optional and still work.

Voice notes. A bot can send an answer as a voice note in its own voice, in the chat and on Telegram, Slack and Discord.

Voice picker. Every Flux voice in one list (41 in all), each with its own name, how it sounds and its accent, for example "Kira: Upbeat, confident, American", grouped by female, male and neutral. Try shows Loading and Stop while it plays.

A voice per bot. Each bot now picks its own voice service next to its voice, so bots in one room can sound different. xAI voices are available with your own xAI key or through Flux.

Web search

Web search through Flux. Settings offers Flux Router as a web search provider, using the Flux key saved under Models, so bots answer with what is current on the live web.

Browser

A refused built-in browser says what to do. When the built-in browser refuses to start because the app was installed over an older copy, the message now says to reinstall Murage, instead of pointing at an optional browser engine.

Models

New models in the engine pickers: Claude Opus 5.5 (claude-opus-5-5), GPT-6 Sol and GPT-6 Luna (gpt-6-sol, gpt-6-luna), and Grok 4.7 (grok-4.7, with its 500k context window). Defaults are unchanged.

Chat

Math and diagrams. Chat now shows math written as $$...$$, \[...\] and \(...\). A single dollar sign on its own is never math. Mermaid diagrams are drawn in a sealed frame that has no access to the app.

Long conversations open faster. The desktop loads the newest 100 messages and pages back as you scroll, instead of loading every message of every conversation at startup.

Saved text file cards follow your skin's colors.

The message box gets focus back after the file picker closes.

Inbox

Clear what owes nothing. Failures, missed requests and reports now offer Clear and Clear all. A cleared item comes back only if it happens again.

Dismiss old connection requests, one at a time or all at once.

"I don't use <engine>." A signed-out engine row in the Inbox can turn that engine off, after asking.

Routines

Overlapping runs. A recurring routine can queue one run behind a run that is still going, instead of skipping it. Skipped runs are counted and a streak of failures is shown.

The problems count opens a list of exactly the runs behind it, with Mark all as read.

Fixes

An engine that goes silent in the middle of an answer no longer leaves the bot busy for twenty minutes, and a turn that produced nothing is reported as failed.

A conversation whose saved engine session could not be reloaded keeps its thread and shows any refusal.

Mentions wrapped in Markdown or brackets reach the right bot.

Work waiting for a free conversation slot starts as soon as one frees up.

A bot asking another bot is released after 15 seconds of waiting, not 4 minutes.

Backups recognize every folder name Murage writes, so they no longer refuse over an unknown folder.

bots.json, groups.json and queued messages are kept readable only by you.

On Windows, credentials are removed from child processes regardless of letter case.

Connected apps whose names start with an underscore, such as _1password, work.

A connected-app catalog that stops short of its own total says so.

Screenshots of the computer a bot uses are never kept by a browser or proxy.

Open sign-in in Terminal really opens Terminal on macOS.

Downloads and checksums on GitHubAll releases

Give your first job to Murage.

Download the free app, connect the AI you already pay for, and tell your Chief of Staff what needs doing. Plan on about ten minutes from install to a working team.

Free · Download Murage

No account needed · Runs on the AI plan you already pay for