NewDesktop v0.1.7: settings grouped by area, a new first-run guide, mu-agent 0.1.8 inside
Documentation Documentation

Start here

Getting started The desktop app The command line

Using mu

Judges Permissions and safety Goal mode and finishing Context Lessons The plain-language board Sub-agents and the hive

Reference

Configuration Features and options Troubleshooting Privacy

Reference

Features and options

Every feature of the judgment kernel, whether it is on by default, its decision points and each option with its default and range.

Each feature is configured under features.<name> in ~/.mu/agent/mu.json. false turns a feature off, true turns it on with its defaults, and an object overrides single options:

{
  "features": {
    "injection": { "tools": ["web_fetch", "mcp__*"] },
    "board": { "defaultOn": true },
    "ttsr": false
  }
}

The desktop app's settings write the same file, with the same names and descriptions as this page. Both come from one manifest in the repository.

Message preflight preflight

On by defaultDecision points input.preflight

Judges a message before work starts and shows the verdict in the conversation.

OptionDefaultMeaning
thinkingfalseSet the thinking level from the verdict (a switch loses the cache)
hintstrueGive the model a one-line hint
showtrueShow the wait and the verdict
waitMs4000 msWait at most. After this the turn starts without the verdict. Range 500 to 30000.

Mid-run messages interjection

On by defaultDecision points input.interjection

Handles messages sent while the agent is working.

OptionDefaultMeaning
waitMs1500 msWait at most. Range 200 to 10000.

Skill disclosure skills

On by defaultDecision points skills.disclosure

Chooses which skill descriptions a session carries.

OptionDefaultMeaning
minSkills4Do not filter below this many skills. Range 1 to 100.
waitMs4000 msWait at most. Range 500 to 30000.

Capability catalog catalog

On by defaultDecision points capability.disclosure

Install a lot, expose little: packs and MCP servers stay hidden and open per task.

OptionDefaultMeaning
waitMs4000 msWait at most. Range 500 to 30000.

Task frame and to-do list frame

On by defaultDecision points task.frame

Keeps what you actually want: the goal, your hard constraints (your own words, with their source), the current subgoal and the acceptance items. Those items are the to-do list the model ticks with the todo tool. Every goal-relevance judgment reads it, and it rewinds with the session.

OptionDefaultMeaning
waitMs3000 msA turn waits for its frame at most. Counted from the arrival of the message. A late update is not dropped: the turn starts on the previous version plus the raw message, and the update lands when it is ready. Range 0 to 30000.
writerTimeoutMs20000 msTime limit for writing a frame. On a timeout or a malformed reply the last version stays and is marked stale, goal-based filtering holds back, and the next message retries. Range 1000 to 120000.
showtrueShow frame updates in the chat

Lessons memory

On by defaultDecision points memory.recall memory.capture memory.outcome memory.worth memory.merge memory.applied

Learns from your corrections, from the agent getting itself unstuck, and from what the model and sub-agents found; merges each lesson with the kept ones before storing it, brings the relevant ones along next time, and retires those nobody follows. /lessons shows them, /forget retires one.

OptionDefaultMeaning
pathemptyLessons file. Empty uses the default location.
maxCandidates24Judge at most. The most followed, then the most recently stored or confirmed, come first. Range 1 to 200.
maxInjected5Bring in at most. Range 0 to 20.
waitMs4000 msWait for the recall at most. Counted from the arrival of the message; picking lessons for sub-agents waits as long. Range 0 to 30000.
retireAfter8Retire after this many recalls never followed. 0 never retires a lesson by itself. Range 0 to 100.
mergeNeighbours6Compare with this many similar lessons. Picked by shared words, asked in one request; 0 stores without merging. Range 0 to 16.
outcometrueLearn from the agent getting unstuck. Needs the writer model or the conversation's model to put the lesson into words.
appliedtrueCheck at the end of a turn whether lessons were followed

Risky command guard guard

On by defaultDecision points tool.risk

Confirms dangerous commands before they run.

No options.

Permission modes permissions

On by defaultDecision points tool.approval

Full access, Jev approves, or minimal permissions, switched any time with /permissions. When a step needs your permission the status bar asks; allow it once or for the whole conversation. While it is on, it also handles the risky command guard.

OptionDefaultMeaning
modejevMode of a new conversation. Once you pick one with /permissions, your last pick is used.full Full access · jev Jev approves · ask Minimal permissions

Hard constraint gate constraints

On by defaultDecision points tool.constraint

Checks a change or a command against your hard constraints first; sub-agents work under them too.

OptionDefaultMeaning
maxConstraints6Constraints checked per call at most. The newest ones are used. Range 1 to 20.
waitMs5000 msWait at most. Range 500 to 30000.

Injection screening injection

On by defaultDecision points tool.injection

Withholds instructions aimed at an AI before the model reads web pages, search results and MCP answers.

OptionDefaultMeaning
toolsweb_fetch, web_search, browse, mcp__*Tools screened. Tool names, or a prefix ending in *; mcp__* is every MCP server.
waitMs6000 msWait at most. After this only plain injection phrases are withheld, by rule; the verdict is still recorded. Range 500 to 30000.

Tool output admission admission

On by defaultDecision points tool.admission tool.admission.test-log

Controls how long tool output enters the context.

OptionDefaultMeaning
minChars4000 charsOnly filter output longer than. Range 500 to 200000.
chunkChars1200 charsChunk size. Range 200 to 20000.
maxChunks48Judge at most this many chunks. Range 4 to 400.
batchChunks16Chunks per request. A hosted judge takes many chunks in one request, the state billed once; the local judge takes one at a time. Range 1 to 32.
waitMs4000 msWait at most. After this the output goes in whole; the verdict is only recorded. Range 500 to 30000.
passThroughread, edit, writeNever filter these tools
testLogoffTest log trimmingoff Off · rules Drop exact repeats only (lossless) · jev Also let the judge select from the rest
agentEnvtrueTell test runners an agent is reading. Vitest and others then print failures and the summary only.

Forgetting stale results forgetting

On by defaultDecision points context.forget

Replaces stale results with tombstones when the context gets tight.

OptionDefaultMeaning
thresholds50, 70, 85Trigger thresholds (context use %)
minChars6000 charsOnly results longer than. Range 500 to 200000.
minAgeTurns2At least this many turns old. Range 0 to 50.
maxPerBatch12Judge at most per batch. Range 1 to 100.
waitMs4000 msWait at most. This request waits this long; verdicts that come later apply at the next request. Range 500 to 30000.

Summary-free compaction compaction

Off by defaultExperimentDecision points context.compact

Compaction that keeps original passages instead of a summary.

OptionDefaultMeaning
keepThreshold0.5Keep threshold. Range 0 to 1.
minChars600 charsKeep anything shorter than. Range 100 to 20000.
headChars300 charsHead kept when pruning. Range 0 to 5000.
targetRatio0.5Target share of the original. Range 0.05 to 1.
maxWindowShare0.25At most this share of the window. Range 0.05 to 0.9.
freeChars24000 charsHistories this small are not squeezed. Range 0 to 500000.
maxJudged120Judge at most this many passages. Range 10 to 1000.

Checkpoints and rewind checkpoint

On by defaultDecision points turn.rewind

Before the first change of every turn that edits files, snapshots the working tree into mu's own shadow git directory, never touching your repository. /rewind takes files and conversation back, /rewind undo takes the rewind back.

OptionDefaultMeaning
diremptyWhere snapshots are kept. Empty means mu/checkpoints in the mu home, one shadow repository per project.
keep50Snapshots kept per project. Range 1 to 1000.
maxAgeDays14 daysDays a snapshot is kept. Range 1 to 365.
maxFileMb5 MBLargest file in a snapshot. Larger files stay out of snapshots, and a rewind never touches them. Range 1 to 1024.
maxFiles5000 filesMost files a snapshot takes in. With more files to take in, the session goes without checkpoints and says so once. Your home folder and mu's own folders are never snapshotted. Range 100 to 1000000.
maxTotalMb200 MBMost a snapshot takes in, in all. With more to take in, the session goes without checkpoints and says so once. Range 1 to 100000.
ignoreemptyExtra paths to ignore. gitignore patterns, one per line. The project's own .gitignore and the built-in list (node_modules, build outputs and so on) always apply.
timeoutMs30000 msLongest a snapshot may take. Past this the turn goes without a checkpoint; the tool call still runs. Range 1000 to 600000.
proposetruePropose a rewind at a dead end
confirmSeconds120 sHow long a proposal waits for you. Unanswered, the run carries on. 0 waits forever. Range 0 to 3600.

Drift monitor monitor

On by defaultDecision points turn.drift

Notices drift from the goal and going in circles.

OptionDefaultMeaning
every6Check every this many tool calls. Range 1 to 100.
repeats3Repeats that count as a loop. Range 2 to 20.
window8Window. Range 2 to 100.

Language server diagnostics lsp

On by defaultDecision points diagnostics.delivery

Uses the language servers already installed here (installs none), keeps only what an edit newly introduced, and lets the judge pick the moment to tell the model.

OptionDefaultMeaning
builtintrueUse the built-in table of well-known servers. Well-known servers for TypeScript, Python, Go, Rust and C/C++, looked up on PATH only. Your own go under features.lsp.servers in mu.json.
editToolsedit, writeTools that count as editing a file
subAgentsfalseSub-agents start language servers too. Off by default: one set of servers per sub-agent is heavy on the machine.
settleMs1500 msWait for the server after an edit, at most. Past this nothing waits: late diagnostics are handled at the next edit or when the turn ends. Range 0 to 10000.
turnEndSettleMs3000 msWait at the end of a turn, at most. Range 0 to 30000.
quietMs250 msSilence that counts as the server being done. Range 20 to 5000.
baselineMs5000 msWait for the pre-edit diagnostics, at most. Waited for in the background, never blocking a tool. Past it, the first report is not called new. Range 100 to 60000.
maxItems10Diagnostics told at once, at most. Range 1 to 100.
maxServers4Servers running at once, at most. Range 1 to 16.
waitMs4000 msWait for the judge, at most. Range 500 to 30000.

Mid-stream correction (experiment) ttsr

Off by defaultDecision points output.drift

Semantic TTSR: the judge, not a regular expression, notices the output going astray, cuts it, shows the rule and lets the model carry on. Off by default; when on, every stretch of output costs one more judge call.

OptionDefaultMeaning
rulesemptyRules to hold at all times. One per line, in plain words, e.g. “Answer in Chinese”, “No placeholder implementations”. Your hard constraints from the task frame are added automatically.
segmentChars600Characters of output per check. Range 200 to 5000.
maxRules4Rules checked per call at most. When there are more, the ones you said last stay. Range 1 to 12.
maxInterrupts2Cuts at most between two of your messages. Range 1 to 10.

Goal mode goal

On by defaultDecision points goal.met

After /goal <condition> the agent keeps working until the condition holds (/goal alone asks for it). Each time it wants to stop, a model reads the evidence: met, or the next step. It stops by itself when you interrupt, a model call fails, it idles or goes in circles, or its allowance runs out; your next message picks it up again.

OptionDefaultMeaning
checkermodelWho checks whether the goal holds. A model reads the goal, what the run did, the last test run and the closing message, and gives a verdict and the next step; Jev only when it gives no answer. Either way an open acceptance item or an unverified edit means not yet.model A model (recommended) · jev The Jev judge
checkModelemptyModel for the check. As provider/model. Empty: the session's current model.
checkThinkingoffThinking level of the checkoff Off · minimal Minimal · low Low · medium Medium · high High
checkTimeoutMs90000 msLongest wait for the check. After that, Jev decides, and failing that the facts alone. Range 5000 to 600000.
stallLimit2Runs without progress before it stops. The check found the agent repeating itself. The first time it is told to change course; at this count the goal pauses for you. Range 1 to 10.
maxContinuations20Continuations at most. Counted from your last message. Range 1 to 200.
maxMinutes180 minLongest automatic run. Counted from your last message. Range 5 to 1440.
idleLimit2Idle runs before it stops. Runs in a row that ended without a single tool call: the agent is going nowhere. Range 1 to 10.

Plain-language board board

On by defaultDecision points board.read

Tells you in plain words how far the work is, what is happening now and what waits on you, and keeps a running account: a line for every step as it happens, and what the agent says or finds retold at once by a plain-speaking model, with Jev deciding what is worth telling; a finished run is summed up once more, with the account kept. For you only, never in the model's context. Switched per project (/board on, /board off); the first time, you pick the model that writes it (/board model changes it).

OptionDefaultMeaning
defaultOnfalseOn for projects not switched yet. Off by default: each update of the board costs a model call.
modelemptyModel that writes the board. As provider/model; set here, nobody is asked. Empty: you pick one the first time the board is switched on (Claude Opus 4.6 recommended, then Gemini 3.8 Flash), kept in mu/board.json; none picked: the writer model, else the session's.
languageautoLanguage of the boardauto The one you write in · zh Chinese · en English
everyTools5Tool calls between two looks. Range 1 to 100.
minIntervalMs20000 msShortest gap between two looks while it works. When the agent stops it always looks, whatever this says. Range 0 to 600000.
maxSteps10Latest tool calls read each time. Range 3 to 50.
narrateTimeoutMs60000 msLongest wait for the writer. After that, fixed sentences are used. Range 5000 to 300000.

Completion check completion

On by defaultDecision points turn.completion

Checks that something verified the work before it is called done.

OptionDefaultMeaning
waitMs3000 msWait at most. After this there is no nudge; the verdict is only recorded. Range 500 to 30000.

Carry on after stopping short continuation

On by defaultDecision points turn.continue

Sends a run that stopped short of what it said it would do back to it.

OptionDefaultMeaning
maxNudges2Most nudges per message. Range 1 to 5.
waitMs3000 msWait at most. After this there is no nudge; the verdict is only recorded. Range 500 to 30000.

Notification routing notify

On by defaultDecision points notify.routing

Decides when events are told to the model.

OptionDefaultMeaning
budgetThresholds70, 85Context budget notices (%)

Cache warming warming

On by defaultDecision points cache.warming

Refreshes the prompt cache before it expires when that pays off.

No options.

Judge connection warm-up warmup

On by default

While the session is in use, one tiny question keeps the judge's connection warm: the questions before a turn skip 1-3 s of connecting.

OptionDefaultMeaning
intervalMs50000 msEvery. The server drops a connection idle for about 90 s; stay under that. Range 10000 to 85000.
idleMs900000 msStop after this much quiet. Range 60000 to 7200000.

Sub-agents swarm

On by defaultDecision points swarm.routing swarm.patch

Delegates tasks to sub-agents with roles.

OptionDefaultMeaning
modelsemptyModel ladder (cheapest to strongest). Empty means every sub-agent uses the session's model.
maxTasks6Tasks per call at most. Range 1 to 32.
concurrency3Running at once. Range 1 to 16.
defaultAgentworkerDefault role
agentsDiremptyFolder with your own roles. Empty uses <agent dir>/agents.
isolationworktreeSub-agents that edit files. Isolated changes come back as a patch that the main agent applies with apply_patch_from, or not. Outside a git repository it falls back to editing in place.worktree Edit in a git worktree of its own · none Edit in place
carryUncommittedtrueCarry uncommitted changes over. The sub-agent starts from the files as the main agent sees them, not from the last commit.
patchPreviewLines30Lines of patch preview. The beginning of the patch shown with the sub-agent's report. Range 0 to 400.

Hive hive

On by defaultDecision points hive.publish hive.deliver hive.relate

Several bees work one hard task in parallel; the judge gates what passes between them. /hive <question> starts one yourself; the agent also starts one when a problem resists a direct attempt.

OptionDefaultMeaning
maxNotesPerBee12Notes per bee at most. Range 1 to 100.
maxDeliveriesPerBee10Deliveries per bee at most. Range 1 to 100.
checkpointEvery4Ask for findings after this many silent tool calls. 0 turns this off. Range 0 to 50.
lastCalltrueOne last hearing while writing the report
maxRelatedPerNote6Earlier findings a new one is held against, at most. Only those sharing words with it. 0 turns corrections off. Range 0 to 30.
verifyConflicts1Verifier bees for unsettled disputes, at most. 0 adds none; both sides stay in the report. Range 0 to 3.
verifyAfterSeconds60Seconds a dispute may stand before a verifier is added. Range 0 to 600.

File location locate

On by defaultDecision points files.locate

The locate tool: find files by description.

OptionDefaultMeaning
candidates40Candidates judged. Range 5 to 400.
results12Results returned. Range 1 to 100.

Bulk judging tool judgeItems

On by defaultDecision points judge.items

The judge_items tool: one yes/no question, a probability for each of many items.

OptionDefaultMeaning
maxItems500Most items per call. Range 10 to 5000.

Built-in browser browser

On by defaultDecision points browser.step

A judge-driven browser with its own profile; it never touches yours.

OptionDefaultMeaning
headlesstrueRun headless
maxSteps40Steps per run at most. Range 1 to 200.
textChars4000 charsPage text read per step. Range 500 to 50000.
embeddedtrueUse the desktop app's browser panel when it is running. Every step is then visible and can be paused, stopped or taken over; without the app mu's own browser is used.
profileDiremptyBrowser profile folder. Empty uses mu's own folder.

Background commands background

On by default

bg_start / bg_output / bg_stop: dev servers and long builds without blocking the turn. Whether the end of a job interrupts is decided by notification routing; every job stops with the session.

OptionDefaultMeaning
maxJobs8Jobs running at the same time. Range 1 to 32.
bufferChars262144 charsOutput kept in memory per job. The newest is kept; the log file has everything.
maxOutputChars20000 charsMost that one bg_output returns
killGraceMs3000 msWait before a job is killed by force. SIGTERM first (taskkill without /F on Windows), force after this long.
logDiremptyLog directory. Empty means ~/.mu/jobs/<session id>, cleared after 7 days.
inheritShelltrueUse the foreground shell settings. Reads shellPath and shellCommandPrefix from settings.json, like the bash tool.
wakeWhenIdlefalseA finished job may wake an idle agent. Only a verdict of "now" starts a turn; when off the notice is only appended.

Web reading and search web

On by default

web_fetch reads a page as text (time and size limits, internal addresses refused, page text labelled untrusted); web_search uses a source that answers from mainland China without a key.

OptionDefaultMeaning
searchsoSearch source. so (360), sogou, bing-cn, searxng:<base url>, or a URL with {query} in it.
searchFallbacktrueTry the other built-in sources on failure. Applies to a verification page, no results, or results unrelated to the query.
maxChars20000 charsMost that one web_fetch returns
timeoutMs20000 msTime limit of one request
maxBytes2000000 bytesDownload limit
maxRedirects5Redirects followed. Range 0 to 20.
allowLoopbacktrueAllow this machine's dev servers. Only when the URL itself says localhost or 127.0.0.1; a redirect from the web is always refused.
allowPrivatefalseAllow private network addresses. 10/8, 172.16/12, 192.168/16, link-local and the like. Refused by default so a page cannot steer the reader into the local network.

Welcome screen welcome

On by default

The welcome box in the terminal and the identity note.

No options.

Inherit existing setup inherit

On by default

Uses the rules, skills and MCP servers you already set up for Claude Code, Cursor and Codex, read-only. Always-on rules join the prompt; a rule scoped to file patterns is handed over once, with the result of the first tool that touches a matching file; the rest are listed by description. Project content is only used for a trusted project.

OptionDefaultMeaning
claudetrueFrom Claude Code
cursortrueFrom Cursor
codextrueFrom Codex
rulestrueInherit rules
skillstrueInherit skills
mcptrueInherit MCP servers. When off, only the servers under mcp.servers in mu.json are used.
maxRuleChars4000 charsMost of one file-scoped rule handed over. The rest stays in the file for the model to read. Range 500 to 20000.
maxAlwaysChars16000 charsBudget for always-on rules. Always-on rules that do not fit are listed by description instead, so rules cannot bloat the prompt. Range 0 to 100000.

MCP servers mcp

On by default

MCP servers are connected by pi's own client (stdio and Streamable HTTP, OAuth sign-in, managed with /mcp). Each server mu takes over from Claude Code, Cursor, Codex and mu.json is a catalog entry that stays hidden: it starts and its tools are handed to the model only when the judge finds the task needs it or the model asks through find_capability. Tool lists are cached, so the judge has a description before a server ever ran. A server defined by a project asks before its first start, and again when its definition changes. "exposure": "always" under mcp.servers in mu.json keeps a server open. Servers added with mu mcp add are pi's: they connect with the session, and tool_search loads their tools when needed.

OptionDefaultMeaning
startTimeoutMs45000 msStart timeout. An npx-style server downloads itself first. Range 1000 to 300000.
requestTimeoutMs120000 msCall timeout. Range 1000 to 3600000.

Capability packs packs

On by defaultDecision points review.triage

Tool packs that ship with mu and stay hidden until a task needs them; a missing program gives an install hint.

OptionDefaultMeaning
astGreptrueast-grep structural search and rewrite. Finds and changes code by syntax, not text. Needs ast-grep on this machine.
maxResults50Matches one search returns. Range 1 to 500.
maxDiffChars12000 charsMost diff one result carries. Range 1000 to 200000.
astGrepCommandemptyPath of ast-grep. Empty: ast-grep, then sg, from PATH.
githubtrueGitHub through gh. No tools, one skill that teaches gh for PRs, issues, checks and releases. Needs gh on this machine.
ghCommandemptyPath of gh. Empty: gh from PATH.
committrue/commit: split the change into commits. A model proposes the groups and the messages; commits are made only after you confirm the plan, all or none. Never pushes.
maxPlanChars60000Characters of the change the model reads. Range 5000 to 400000.
reviewtrue/review, with findings sorted P0 to P3
conflictstrueConflict resolution. When a merge, rebase or cherry-pick stops on conflicts: both sides and their base per file, the resolution written block by block and the file marked resolved. Never commits, never runs --continue.
maxSideLines80Lines shown per side of a conflict block. Range 10 to 1000.
maxConflictChars20000Characters of one file's conflicts shown. Range 2000 to 200000.
maxFindings40Findings sorted per triage at most. The rest are still reported, just not sorted. Range 5 to 200.
debuggertrueDebugger: breakpoints, stepping, variables. Runs a program under a debugger, stopped at breakpoints or an uncaught exception, with the call stack and variables. debugpy for Python, delve for Go, lldb-dap for compiled programs, each if installed; add your own under debugAdapters in mu.json. One run at a time, ended with the session.
maxFrames20Frames shown at a stop. Range 1 to 200.
maxVariables50Variables listed per scope. Range 5 to 1000.
debugOutputChars4000 charsProgram output one result carries. Only the tail is kept when there is more. Range 500 to 100000.
debugWaitMs30000 msLongest wait for the program to stop. If it has neither stopped nor ended by then, the model is told it still runs, and can pause it to see where, or wait more. Range 1000 to 600000.

Sign in with Google (experimental) googleLogin

On by defaultExperiment

Adds two entries to /login: Gemini CLI's sign-in for the Gemini models, and Antigravity's for Gemini, Claude and GPT-OSS. These are Google's logins for its own tools; another program using them may break Google's terms and get the account limited or suspended, so the sign-in states the risk first and goes on only if you agree. The official routes need none of this: a Gemini API key (provider google) and Vertex AI (provider google-vertex, signed in with gcloud).

OptionDefaultMeaning
geminiClitrueGemini CLI sign-in. The Gemini models, on the free tier for a personal account or on a Code Assist licence.
antigravitytrueAntigravity sign-in. Gemini, Claude and GPT-OSS; once signed in, the list follows what the account can use.

If mu is useful to you, star it on GitHub

A star helps more people find it. The code, the discussions and every release live in the repository.

Star on GitHub464