Ask mode by default
Every new bot starts here and asks before each action it tells Murage about. Answer with Allow once, Allow for this task, Always allow, or Deny.
Murage keeps your conversations, files and memory in its own folder on your computer, not on our servers. The AI, apps and services you connect receive what they need for the jobs you give them, and you choose each one.
Free and open source. macOS, Windows and Ubuntu.
Nothing in this list happens until you set it up, apart from the update check and the optional email at setup.
You decide what each bot does alone and what waits for you, one bot at a time.
Every new bot starts here and asks before each action it tells Murage about. Answer with Allow once, Allow for this task, Always allow, or Deny.
New bots start on Ask. On Full access, a bot stops before messaging anyone new, posting publicly, paying, or deleting outside its folder, unless you have allowed it for that task. Replies in an existing conversation go ahead on Auto and Full access. No limits turns the stop line off. On Hermes and other ACP engines, Ask and the stop line cover only what the engine asks Murage about: shell commands and file edits.
In the app, from the menu bar, in the phone web app, in Telegram, or out loud on a call.
Write how your bots should work once. The defaults include never promising prices or deals in your name, and treating emails and web pages as information, not orders.
Skill Guard scans every skill before a bot can use it. Risky ones need your OK; dangerous ones are blocked.
Open exactly what a bot reads, in order, and switch off what you added.
Read the code on GitHub · Checksums on the download page · Read server/stop-line.ts · See the test cases · How we test the stop line
No SOC 2, HIPAA or outside security audit.
The stop line is a check on each action a bot tries to take, not a sandbox. A bot on Auto or Full access runs with your user’s permissions. Keep a bot on Ask for anything where a mistake would be expensive.
The stop line judges what Murage is asked about, so how much it covers depends on the engine. On Claude Code and Codex, the stop line also covers tools from MCP servers you add. On Hermes and other ACP engines, Ask and the stop line cover only what the engine asks Murage about: Hermes asks before shell commands and file edits, but not before MCP or connected-app tools.
No central settings lock. Each person controls their own copy of Murage. The security overview lists the rest.
Found a security problem in Murage? Please report it privately, not in a public issue.
Email security@ferroxlabs.com or open a private report on GitHub. Please don’t file it as a public issue. The security policy says what we treat as in scope.
A one-page overview of where data lives, where it goes, the access levels and the license. Machine-readable contact details are at /.well-known/security.txt.
Only if you connect your mailbox, and only while you leave it connected. Agents read what their job needs. A new bot starts on Ask, so it asks before sending anything; on Full access it can reply in a thread you already have going, but still stops before writing to anyone new. On Hermes and other ACP engines, Ask and the stop line cover only what the engine asks Murage about: shell commands and file edits.
New bots start on Ask. On Full access, a bot stops before messaging anyone new, posting publicly, paying, or deleting outside its folder, unless you have allowed it for that task. On Hermes and other ACP engines, Ask and the stop line cover only what the engine asks Murage about: shell commands and file edits. Replies in an existing conversation go ahead on Auto and Full access. No limits turns the stop line off; it’s a desktop-only level you switch on yourself, after a warning. You can give a trusted bot more room one bot at a time, and take it back.
No. There’s no SOC 2, HIPAA or outside security audit yet. What exists: the full source under AGPL-3.0, signed installers with published checksums, and a one-page overview for security reviews.
Not yet. Each person controls their own copy of Murage, so any user can choose No limits for their own bots. Imported teams arrive on Ask with nothing switched on.
Murage doesn’t train models. What your AI provider does with prompts is set by their terms and your plan with them.
Every file on the download page lists its SHA-256 checksum so you can check it. The source code is public.
Yes. Your data is a folder on your computer. Delete memories one by one in the app, or remove the folder.
Download the free app, connect the AI you already pay for, and tell your Chief of Staff what needs doing. Plan on about ten minutes from install to a working team.
No account needed · Runs on the AI plan you already pay for