Proof you can check.

Murage is open source under AGPL-3.0. The code, every installer’s checksum, the team library and the skill library are public, and you can build the app yourself. Here’s where to look first.

Free and open source. macOS, Windows and Ubuntu.

Read these five files first.

They decide what a bot may do, how your AI is run and where your data goes.

  1. 1server/stop-line.tsThe approval code: the few outside actions a bot stops for on Full access, and what each engine asks it about.
  2. 2server/auto-approve.tsPermission levels, and the key guard: the patterns Auto mode never approves on its own, such as reading SSH keys or moving an API key.
  3. 3server/drivers/claude.tsHow Claude Code is run, including the sign-in check. It asks Claude Code whether you’re signed in and never inspects where the login is stored.
  4. 4server/coordination-budget.tsThe runaway limits: 16 hand-offs per turn, 32 per task and 4 at once. They stop loops; they aren’t spending caps.
  5. 5server/memory/Where memory lives and how it’s written, recalled and forgotten, in files on your computer.

Check it yourself.

Verify a download

Run shasum -a 256 on the installer (sha256sum on Linux, Get-FileHash on Windows) and match it against the checksum below or on the download page.

Read the license

AGPL-3.0, in LICENSE. Anyone can read, run and change Murage. If you distribute a changed version, or let other people use it over a network, you share those changes.

Build it yourself

Follow CONTRIBUTING.md. You need Node 24 or later and pnpm.

git clone https://github.com/FerroxLabs/murage
cd murage
pnpm install
pnpm typecheck && pnpm test
pnpm package:mac   # or package:linux

This release’s checksums.

Each installer’s SHA-256 is on the download page and on the GitHub release.

What’s open.

The app

Murage itself, under AGPL-3.0. Anyone can read, run and change it; changes you distribute stay open.

FerroxLabs/murage

68 teams

Every ready-made team, with its roles and instructions, as plain files.

library/packages

2,237 skills

The skill library, each one scanned by Skill Guard for risky instructions, with its verdict published.

skills-library

How often it ships.

Every release has notes. Read the changelog

The public main branch has about 3,100 commits (checked September 27, 2026). Read the history

Questions people ask before they read the code.

AGPL scares my company. Should it?

Running Murage unmodified inside your company doesn’t require you to publish anything, and the license covers Murage’s code, not the work your bots produce. AGPL’s source-sharing duty applies if you change Murage and distribute it, or let other people use your changed version over a network: then you share those changes. It also means nobody, including us, can take the code closed later. This isn’t legal advice; have your counsel read the license.

What happens if Ferrox Labs stops?

If Ferrox Labs stopped tomorrow, the code, the team library and the skill library stay public, and you can build the app from source. Your team’s memory and files are already on your computer.

How do I report a security problem?

Email security@ferroxlabs.com, or use GitHub’s private vulnerability reporting on the source repository. Please don’t open a public issue. The policy is in SECURITY.md.

SECURITY.mdPrivacy and securitySecurity overview for reviewers

Give your first job to Murage.

Download the free app, connect the AI you already pay for, and tell your Chief of Staff what needs doing. Plan on about ten minutes from install to a working team.

No account needed · Runs on the AI plan you already pay for