v1.0.310
New features
- Every automation, project and procedure picks its own thinking level. A scheduled run, a saved procedure and a project used to inherit whatever thinking level the chat happened to be set to — so a nightly report that only needed a light pass could quietly run at maximum, and a deep analysis could run at minimum because you had switched the composer down earlier in the day. The effort a job deserves is a property of the job, not of the window you last typed in. Each one now carries its own level — off, on, high or max — chosen from a switch right on its card, beside the mode toggle it already had. New ones start from the mode you are running right now, so nothing changes until you say so; anything saved before this release carries no setting and keeps following your chat exactly as it always did. The levels on offer are the ones your selected model actually honours, so a card can never present one the model would silently ignore. See Automations, Procedures and Projects.
- The phone carries the same switch, and it is the same value. The three cards on your phone read and write the very same setting — flip it on the desktop and the phone shows it, flip it on the phone and the desktop shows it, because they are one setting seen from two places rather than two copies taking turns.
- The terminal gets it too.
wolffish procedures thinking <id> highsets it from the command line, andwolffish procedures thinking <id> defaulthands the decision back to your chat. Both the procedures and automations lists now show a thinking column, so you can see at a glance what each one runs at.
v1.0.309
New features
- A finished turn has a real way to end. The runtime used to tell a finished turn to close with an entirely empty response — zero characters — and no provider carries an empty message: the content channel cannot be empty, which is why the app itself refuses to store one. So a turn with nothing left to say had exactly one legal move left: type a small stand-in for the silence and send it to you. You have seen the results:
(no output),(no content),[Empty response], and most recently[(empty — nothing further)]stuck onto the end of a reply that had already finished. The instruction was impossible, and the workaround was the bug. There is now aclose_turntool whose only job is to end the turn when everything is already said and delivered — saying “nothing further” is a tool call, something a model can actually produce, instead of a zero-character message it cannot. It stays model-led end to end: nothing rewrites, strips or suppresses a character the model wrote. The model still decides when the turn is over — it just has a real way to say so. See Ending a turn. - The silence detector stopped keeping a list. The guard that catches a faked silence worked from a hand-written list of phrases, and kept losing the race:
(no output)→(no content)→[Empty response]→空空如也→[(empty — nothing further)], each one added to the list after it reached you. Detection is now structural rather than a vocabulary: a short bracketed group that closes a reply and is about the absence of content trips it, whether or not anyone has seen that exact phrasing before. It also catches the shape that had been invisible — a marker glued directly onto the end of prose. And it knows the same set phrases in Chinese, simplified and traditional, which matters because seven of the providers Wolffish talks to are Chinese labs. Ordinary parentheticals are still content:The build ran clean (no output)andBlockers: (none)are never second-guessed. The guard observes and tells; it never edits — the model sees what you saw and corrects itself. - The folder chips name the project, not the leaf. The strip of folder chips over a transcript answers one question — where did this run work? — and it had started answering a different one. On a chat with no working folder set, every chip was labelled by the leaf of the path it happened to touch, so the folders you actually worked in were invisible:
…/wolffish-app/.github/workflows/ci.ymlbilled a chip readingworkflows. Worse, work spanning two projects built the same way put two chips both namedsrcon the strip. Each touched directory now collapses to the project folder that opens its tree —wolffish-app,wolffish-cloud,capabilities— with the counts added up across everything underneath. See Working folders.
Updates
- One wrap-up per turn. A turn that wrote its closing answer, sent the phone notification and then wrote the same news again left you reading one paragraph twice. The one-wrap-up rule is now explicit in the prompt and in the notification tool’s own description — the place a model actually reads at the moment it would break it. A landed notification is the finish line, not an intermission.
- The controls around a running turn stop playing dead. The PDF export button sat greyed for as long as a turn was in flight; it now isn’t drawn while it cannot work, and returns the moment it can. The send arrow beside Stop stood there permanently dimmed; it now appears with your first keystroke or attachment, which makes its arrival the sign that the message can go through to the running turn. And leaving a project no longer dims while its turn runs — exiting is a view switch, and a running job is no more a reason to trap you in it.
- A clearer header for the browser side panel. The connection state has a line of its own under the header: a check mark while connected, a spinner while connecting, a pulsing plug while down. The conversation title truncates instead of shoving the row around.
v1.0.306
New features
- You can talk to a job while it works. Wolffish learned to take a message mid-turn a few versions ago — but only in a chat you had started yourself. A scheduled automation, a procedure or a heartbeat job took none of it, and those are exactly the runs that work unattended for minutes at a time and most need steering: that post text is wrong, fix it before you publish. Type into one and the message was refused outright — your bubble went up and came straight back down, and your words then waited, on no screen at all, until the run ended and the window sent them as a brand-new turn, far too late to matter. Those runs do not travel the same track a chat turn does, so nothing had ever registered them as steerable. They now borrow the very same inbox: the same acceptance, the same pending row, the same button to take a message back, and the same return of anything the job never got around to reading. See Steering a run mid-flight.
- A browser group of its own for every job. Wolffish works in its own blue tab group rather than in your tabs — but there was only ever one group, so two jobs running side by side, or one starting right after another, landed in each other’s tab and left one job’s label standing over the other’s work. Every conversation now gets a group, a tab and a title of its own: an automation browsing in the background never takes over the tab you are watching, and never renames it out from under you. The browser’s side panel follows the same rule — it shows the name of the conversation that actually ran the commands, not whichever chat the app window happened to be sitting on, and a conversation named seconds ago shows that name straight away instead of
Untitled.
Updates
- A message sent in the sliver where a turn is closing no longer disappears. The composer had already been emptied the moment you pressed Enter, so the message vanished with nothing to show for it. It now stays on screen saying it is waiting for the current turn to finish, and taking it back hands the words to the composer rather than dropping them. The instant a run actually reads your message, it appears at the point it was read — on the desktop, on your phone and in the terminal — instead of waiting out the pacing the rest of a turn pays.
- Cards that stop drifting from what they describe. On the Automations, Procedures and Projects pages, the small grey detail line at the foot of each card was pinned to the card’s floor so every card in a row ended on the same line. What that bought was the opposite: a card standing next to a taller neighbour opened a gap above the line, and the detail floated away from the thing it belonged to. It now sits directly beneath its own content.
v1.0.305
Updates
- The stray fragment at the end of a finished job. A scheduled run would do everything right — build the file, publish the post, write up its own notes — and then close with a cryptic fragment like
[Empty response]where a clean ending belonged. Wolffish already watches for this, but every scheduled run gets a conversation of its own, closed the moment the run ends — so the correction was addressed to a conversation that would never speak again, and was quietly thrown away. The check was catching every one of these and telling nobody, which is exactly why you saw it on automations and almost never in chat. That note now reaches Wolffish wherever it next speaks, carrying a line saying the slip happened somewhere else, so it never apologises to you for a message you never saw.
v1.0.304
Updates
- A reply from your phone reaches the chat you left open. Continue a conversation on your phone while the desktop still has that conversation open, and the answer arrived everywhere except here: your prompt sat with an empty bubble underneath it, or with a reply that stopped mid-sentence, and the only cure was quitting Wolffish entirely. A turn running anywhere but this window streams itself into an open chat as a series of snapshots, and the desktop kept whichever snapshot came last; for a short answer that was the very first one, sent before a single word had been written. The finished reply did arrive moments later, and was discarded because the chat recognised it and assumed it already had it. An open conversation now refreshes what it is already holding against what was actually saved, instead of only adding what it has never seen — and a turn run from your phone sends one last snapshot the instant it finishes. The same correction covers a reply written on Telegram or WhatsApp, or by a scheduled automation, while you have that conversation open in front of you.
v1.0.303
New features
- Wolffish can wait. Until now there was no honest way for Wolffish to be idle. A build it had just started, a rate limit to ride out, a render that needed ten minutes — the only options were a shell
sleepyou could neither see nor interrupt, calling the same tool over and over, or giving up and saying it would come back later, which meant starting again from nothing. There is now awaittool with no ceiling on it — ten seconds or four hours, whatever the job actually needs, asked for once rather than chopped into a polling loop. While it runs the chat shows a card saying why it is idle and when it will wake, counting down, with a box you can type into to wake it at once. Anything you send from anywhere does the same — that box, the composer, your phone, Telegram, WhatsApp — and your message arrives as the very next thing it reads, in the order you sent it. The whole turn survives the pause: the files it had open, what it had already worked out, the rest of its plan. The card reaches disk within a second of the wait starting, so an hour-long wait outlives a crash or a restart, and it appears in the terminal, on your phone and in a PDF export like every other card. Three things that used to blur together now have edges: waiting keeps this turn, a countdown is for an action that must land after the reply is sent, and a one-time automation is for hours or days from now, starting fresh from what was written into it. See Waiting well. - Wolffish taps you on the shoulder. Until now Wolffish had no way of reaching you once you looked away. A turn would finish, or an approval card would go up and wait, and unless the window happened to be in front of you nothing said so — the work just sat there. Wolffish now uses the signal your operating system already has for exactly this: on macOS the Dock icon bounces, on Windows the taskbar button flashes, and on Linux the launcher entry is marked urgent wherever your desktop honours it. Two moments earn it and nothing else does. A turn ending is news, so it gets a glance — one bounce, then quiet. A card that cannot go on without you, an approval or a question, is a demand rather than news, so it keeps bouncing until you actually come back. None of it happens while you are already looking at the window, the signal is withdrawn the moment you return or answer the card, and a card left waiting keeps its bounce even if another conversation finishes while it waits. Turns that arrived from your phone, from Telegram or WhatsApp, or from a scheduled automation never do this: each already has its own way of reaching you.
- Word documents that look composed. A generated
.docxwas correct and plain; this is a typography pass over the whole engine. Headings are now three voices rather than three sizes — a section claim with a rule beneath it, an accent heading inside a section, and a letterspaced caps label for a short head over a list or a table. The default is a pair of typefaces, Cambria over Calibri, because one typeface doing every job is the flattest a document can look. Margins open to 1.25 inches and the text sets on 130% leading — at one inch an A4 line runs past ninety characters. Tables lost the spreadsheet look: no vertical rules, no striped rows, no fills, keeping letterspaced caps column heads over a rule with hairlines between rows, and a column of figures right-aligns itself, heading included. A cover now carries a label-and-value row across a hairline and no longer prints a page number or running head on itself, so the first page of real content is page 1.
v1.0.302
Updates
- Spreadsheet colours and deck proportions, corrected. A cell whose number format asks for a colour by number rather than by name —
[Color 3]instead of[Red]— was painted from the wrong list, and any number past the eighth came out with no colour at all; it now reads the palette Excel actually means. And a deck whose first slide could not be drawn took its shape from a guess, so a 4:3 presentation was letterboxed into a widescreen card for every slide after it; proportions now come from the first slide that really rendered. - A faster start. The QR code library was being loaded every time the app started, because one of the two settings panels that draw a pairing code pulled it in eagerly. It is now fetched only when a code is actually on screen — about 64 KB out of the startup bundle.
v1.0.301
New features
- Slides, documents and spreadsheets look like themselves now. A
.pptx, a.docxor an.xlsxin the chat used to be a grey file card with a name on it — you had to open it somewhere else to find out what was in it. All three now render as the document itself, right where they land. A deck comes through as its actual slides, with chevrons to page through them. A Word file is laid out as real pages — its own margins, headings, tables, images, headers and footers — with a chip telling you which page you are on. A spreadsheet arrives as a grid that kept the file’s formatting: fills, fonts, borders, number formats, merged cells, frozen panes, column widths and sheet tabs, each sheet in its own direction so an Arabic interface never flips a Western workbook. See Office documents in the feed. - Wolffish makes PowerPoint decks. There is a new presentation capability: read a deck, build one, edit it, and check it before you send it. Building is not a thin wrapper over a slide library — you say what each slide is (a title, a section break, bullets, two columns, cards, stats, steps, a table, a chart, an image, a quote, a closing) and the layout engine owns the geometry, the type scale and the palette, so slides come out composed rather than assembled. The colour themes are the same eight tested palettes the PDF documents use, so a deck and its report look like they came from the same place. A deck you upload is now read properly too, instead of being unzipped by hand.
- Word documents that stay editable. A generated
.docxused to be formatted the way a screenshot is formatted — every heading hand-styled, so changing the look meant changing every paragraph. Documents are now built on real named Word styles, which is how Word itself expects a document to be put together: open one, change the Heading 1 style, and the whole document follows. There is a design step that sets the look up front, a structural check that catches a broken file before you ever open it, and a render-and-look pass so Wolffish sees the page you will see. - Spreadsheets that actually recalculate. A workbook full of formulas could come back as a grid of empty cells: the formulas were written but no value was ever stored beside them, and anything that reads the file without opening Excel sees nothing. Every formula write now recalculates the whole workbook and stores the computed value with the formula — and the result names any cell that evaluated to an error (
#DIV/0!,#REF!,#VALUE!). Charts are now native Excel charts that Excel, Numbers and LibreOffice all draw, in seven kinds, instead of pictures pasted in. - A few options, side by side, ready to copy. When the honest answer is “here are three ways to write this”, Wolffish used to stack three code blocks in a row and leave you scrolling between them. It now offers them as one tabbed card: lettered tabs across the top, the selected option underneath, and a copy button on each. The letters are the same everywhere, so “I’d go with option C” points at the same thing on every screen. It follows you across surfaces — the card on your desktop and in the terminal, and on Telegram and WhatsApp each option arrives as its own tap-to-copy message, because tabs cannot exist there.
- Wolffish can build a tool server, not just connect to one. Wolffish could already connect to MCP servers — the standard way an outside service hands tools to an assistant. It can now write one. A scaffold command lays down a runnable server with its tools, its manifest and a README, and Wolffish then connects to it through the same client you use and calls its tools to see them work before handing it over. See Building a server.
- A notification names the conversation it came from. A conversation that had sent five notifications could show a badge reading 2. The phone was working out which conversation a notification belonged to by reading its link — but a link is where a tap goes, and Wolffish deliberately leaves it off most mid-run notifications, so three of those five named no conversation at all and nothing counted them. Each notification now carries its own conversation, stamped by the desktop rather than chosen by the model, so the badge matches the notifications list. A tap still goes exactly where the link points, and an older desktop paired with a newer phone behaves precisely as it did before. See Unread badges.
- The browser extension gets a settings page. The extension’s switches used to live at the bottom of the side panel, in the way of the thing you actually opened it for. They now have their own settings page, split into what Wolffish shows on the page and what access it has to the browser — with a plain sentence saying why each one is needed. The on-page presence grew too: the tab Wolffish is driving now carries a soft blue glow around the edge of the window.
v1.0.300
New features
- Wolffish reads a web page as a map of things it can act on. Driving a page used to mean guessing at it: a CSS selector copied from a hunch, a click on visible text, and no way to tell whether anything happened. Wolffish now reads the page as its accessibility tree — the same structure a screen reader uses — and gets back every button, field, link and heading as one line with a reference of its own:
uid=3_4 textbox "Email" required. It then acts on the reference, not on a guess. Take the tree again after a click and everything new since last time is marked with a star, so Wolffish can see exactly what its own click opened. And every action now ends with what the page actually did — navigated, changed, or no visible change — which turns the most common automation failure, clicking hopefully at the same wrong spot three times, into a single line that says re-aim. See The browser extension. - Forms that actually submit. Filling a form in a modern web app was a quiet failure waiting to happen: typing into a React field sets the text on screen, the framework never registers it, and the form posts empty. There are now two dedicated tools — one field, or a whole form in a single call — that go in the way the framework expects, handling text, dropdowns by their visible option, checkboxes, radios and rich-text boxes alike. The whole-form call reports how many fields landed and names the ones that did not.
- It can watch the page, not just touch it. With the browser debugger attached, Wolffish can see what a page is doing: every network request it made with its status, size and timing — and the headers, post body and full response of any one of them — plus the page’s own console output with stack traces. It also answers the page’s own alert, confirm and prompt dialogs, and can make a tab pretend: a phone viewport with touch, dark mode, a location, Slow 3G or offline, a throttled CPU. Screenshots got the same lift: the entire scrollable page, or one element. The debugger is now attached per tab and stays attached. Eleven new tools in this release, seventy-three in all.
- You can see where Wolffish is working, on the page itself. The tab Wolffish is using now carries a small pill reading “Wolffish is working in this tab” and a cursor that glides to each spot before it acts, outlining the target. It never appears in Wolffish’s own screenshots, and it disappears when the work stops.
- When the browser will not cooperate, Wolffish names the reason. There is now a readiness check that runs even with nothing connected: it looks at the extension server and its port, the browsers connected, whether the extension is missing, disabled, stale or blocked by policy, site access, incognito and local-file access, debugger availability, and on macOS the Screen Recording, Accessibility and Automation permissions. Each finding comes back as a blocker, a limit or a note, with the steps to fix it — and where Wolffish can fix it itself, a Fix button does it and a Verify re-runs the check. See Setup.
- Inside the page, outside the page. The extension stops at the edge of the page, and everything just outside it — the native file picker, an OAuth or passkey popup, a browser permission bubble, the built-in PDF viewer, a
chrome://settings page — used to be where a browser task quietly stalled. Wolffish now knows that boundary and crosses it on purpose: extension tools inside the page, computer use for the window around it, and a line in the reply saying it did. - A message you send mid-turn is never lost. Messaging Wolffish while it works had a hole in it: the message lived in memory and in the bubble on your screen — and nowhere else. So a desktop that quit before the agent read it, a phone that went to sleep at the wrong moment, or a run you stopped with the message still unread, could take your words with it. Every mid-turn message is now written to disk before you are told it was accepted, and released only once it provably lives somewhere else. Anything else is put back: re-sent as a normal turn, or — when re-sending would restart work you deliberately stopped — handed back into the composer as a draft.
- Documents get eight tested palettes and a measured page check. Every styled PDF came out in the same blue. There are now eight complete colour themes — Steel, Teal, Forest, Indigo, Plum, Claret, Rust and Graphite. The bigger fix is underneath: a page could silently print its last paragraph straight across its own footer, and a page a third empty looked perfectly composed in a thumbnail. The footer is now a real part of the page that content cannot run under, and Wolffish measures every sheet before rendering it, reporting how full each page is and whether anything was cut off — so both failures are caught as numbers instead of missed by eye.
v1.0.299
New features
- Wolffish can run your mobile app, and drive it. Wolffish now drives iOS simulators and Android emulators and devices with one vocabulary: boot a device, install an app and launch it with its logs attached, read the screen, touch it, and see what happened. Touches never go to a coordinate guessed off an old screenshot — Wolffish reads the app’s accessibility tree, gets back every button, field and cell with a reference of its own, and taps the reference. Every touch returns proof: a close-up patch of the exact spot with a crosshair on it, and an objective verdict on whether the screen actually changed — “Changed: no” means re-aim from a fresh look, not press again. Typing goes in as keystrokes for plain text and through the pasteboard for Arabic, other scripts and emoji, so what you asked for is what arrives. Beyond driving: screenshots and native-resolution zoom, video recording, the device log for crashes and print output, and simulated locations, push notifications, permission grants, dark mode, the status bar and rotation. Thirty-seven tools in all — iOS on macOS, Android everywhere. The
sim_andadb_names v1.0.288 shipped are gone, replaced by the onemobile_set. - You see the device being driven. A simulator moving by itself is unsettling if you do not know why. Whenever Wolffish is looking at or touching a device, a blue frame sits around that device’s window with a pill reading “Wolffish is driving iPhone 16 Pro”, and a ripple appears wherever a touch lands — a stroke drawn across the screen for a swipe. It follows the window if you drag or resize it, clicks pass straight through it so it never gets in your way, and the tools that see or touch the device refuse to run until it is up. It comes down as the last act of the turn, and if a turn ever ends with it still on — finished, given up on, or failed — the app takes it down itself, so the frame on your screen always means what it says.
- Building an iOS app from source, in one call. Point Wolffish at a folder and it finds what is there: Xcode workspaces and projects, Swift packages, Flutter, Expo, React Native and Gradle — and how each one is run. For an Xcode app, a single call builds it, installs it on the simulator and launches it with its logs streaming; when the build fails, the errors come back as file and line, not a thousand lines of
xcodebuildoutput. Scheme, project, configuration and device are set once for the conversation and then left out of every call after that. Whatever the framework, the loop closes the same way: run the app, then read and touch it on the device instead of guessing from the code.
Updates
- A silent API call no longer hangs your turn. A model provider can accept a request and then say nothing at all — one call measured here sat silent for ten minutes and returned a single token, another for four minutes and returned nothing — and the turn simply hung, because an open connection that never speaks looks exactly like one that is thinking. Wolffish now watches for it: five minutes with no response whatsoever and the request is dropped, the turn ends, and you get a card that says so. It is never retried automatically, because five minutes of silence is your call to make — so the card offers Continue, which carries on from exactly where things stopped. Nothing is lost: the files written, the tool results and the plan so far all still stand, and the note that resumes the conversation appears as a quiet line in the feed, never as something you said. Local models are exempt — a slow machine thinking about a long prompt is genuinely quiet.
- Computer use keeps its session, and stops retrying what it cannot fix. The screen driver’s session expired after five idle minutes, and a single silent API call was enough to cross that line — after which every screen action refused, for the rest of the turn. The session is now kept alive for as long as the indicator is up, and if it does lapse, the next action reconnects and repeats itself without you ever seeing a failure. Refusals that cannot change on another attempt — a point outside the current picture, a key name the driver does not know, an action taken before the indicator is on — now come back immediately, with the fix, instead of burning three identical retries. Key names like period, comma and slash are understood now, and long text is typed in one call, with the character count reported, so a paragraph that arrived short is visible rather than silent.
v1.0.298
New features
- Computer use stops taking your mouse. Driving the screen used to mean surrendering it: every click moved your pointer, every keystroke went to whatever had focus, and a nudge of the mouse mid-action sent the click somewhere else. Computer use now delivers clicks, typing, shortcuts, scrolls and drags straight to the target window in the background — your pointer does not move, the window is not raised, and you keep working beside it. When an app genuinely cannot take background input, Wolffish steps down one rung on purpose — a brief foreground delivery with the pointer restored — and says so in the result, instead of failing quietly. Underneath sits a native driver for all three operating systems (macOS, Windows, Linux X11 and, where the compositor allows, Wayland), verified live on macOS and on Windows 11 against a real window with pixel-exact ground truth. Windows needed three of its own rules, all learned from that run: the hidden shell windows Windows keeps around (the Start menu, Search, a closed Settings) are never treated as targets; right and middle clicks, and typing into browsers and Electron apps, use the brief foreground delivery because those apps drop posted input; and whenever Wolffish does have to borrow the pointer, it puts it back where it was.
- A shadow cursor shows where Wolffish is working. The blue glow and the capture notice now travel with a shadow cursor: an arrow that glides to the exact point before every action, pulses on the press, and parks there afterwards, with a small label naming the target. You always see where Wolffish is about to act — and because it is a drawing on the indicator layer, it never touches your real pointer and never appears in Wolffish’s own screenshots. The indicator also learned to stay honest under stress: if the system takes its window down (a display unplugged, a sleep), the next action puts it back on a display that exists, so “on” always means visibly on.
- A second way to find things: by name. Beyond pixels, Wolffish can now read an app’s accessibility tree — the same structure a screen reader uses — to find a button, field, checkbox or menu item by its name, click it by reference, read a field’s current value, write a value directly with readback, and invoke menu paths like File › Save As… without aiming at tiny items. Every pixel click also reports the control the app says sits under the point, so a wrong aim is caught by a single lookup rather than by eyesight. Native apps expose rich trees; web content in browsers usually exposes only the window chrome, and the result says so plainly.
- Evidence on every action. Each screen action now returns one evidence line: how it was delivered, the driver’s verdict on whether it took effect, an objective before-and-after comparison of the screen, the element under the point, and — for the rare foreground delivery — whether your mouse moved during it, in which case Wolffish refuses to repeat anything with side effects. That evidence, together with what the model said it expected, is carried into the next step so the model verifies before it plans. A new wait tool replaces guessed delays: wait until the screen is stable, until a window with a given title appears, or until a control appears or disappears.
- Permissions, asked up front. A new access check tells Wolffish — and you — exactly what this machine allows before a session starts: Accessibility and Screen Recording on macOS with the settings pane to open, the session type and compositor on Linux, elevation limits on Windows, and whether the background driver loaded. Turning the indicator on runs the same check, so a missing grant is named at the first step with its fix, never discovered as a cryptic error halfway through. The Computer Use settings page shows an Open System Settings button next to any grant that is missing, and nothing next to one that is not.
- More ways to act, all the model’s to choose. The toolset grows from twelve to thirty-one: window listing and per-window capture (even when the window is covered), triple clicks and modifier clicks, held mouse buttons and keys, hover for tooltips, typing with replace and press Enter in one step, scrolling by pages, clipboard read and write, and batches that run a sure sequence in one call and stop at the first miss. The approval card names the app and window an action is going to, and “Allow for this conversation” now allows that app rather than one tool name.
- Mid-turn messages on the phone (mobile v1.0.59). A message written while the agent is mid-job now goes into the work already running rather than waiting its turn, reaching the agent at its next step. It joins the conversation as your own bubble with a quiet line saying it will be read at the next step, and when the agent reads it that bubble moves inside the reply, at the exact point it was taken in. One tap takes it back before it is read, with the words returned to the composer. The reply keeps streaming, the cards stay put, Stop still stops, and it carries a photo, a file or a voice note like any ordinary message — in demo mode too.
Updates
- Plan moves to the composer (mobile v1.0.59). The Plan stance has left the controls sheet for the composer’s own row, beside the model chip — where the desktop keeps it, and where the message it shapes is actually written. It is a switch there, not just a sign: one tap turns planning on, another turns it off, and the chip says which way it is set without opening anything. It stands in demo mode too. When your desktop is out of reach the chip stays where it is and dims, and a tap tells you why rather than setting a stance nothing would receive.
v1.0.297
Updates
- A note in brackets is still a message. The bracketed sign-off came back in a far more convincing form. A turn with nothing left to say would close on a reasoned sentence in parentheses — that the recap above was the reply, that the notification to your phone was already on its way — and because the note was perfectly accurate, the rules as written could not reach it. They forbade a “stand-in for silence” without ever denying the premise underneath it, that brackets are an out-of-band channel, so a model able to argue its case felt licensed to write one. What reached you was a cryptic fragment at the end of your conversation, explaining something you never needed explained. The instructions now name what parentheses are genuinely for — a real aside inside a sentence Wolffish is actually saying, a clarification, a caveat, a worked example — and only then close the channel: a bracketed note about its own output is still a message to you, and however well it argues its case, writing it is exactly the failure it describes. The same correction runs through every place the app speaks up about this — the always-on rule, the nudge when a turn ends on nothing, the asides about the screen indicator and the task list, and all three after-the-fact notices — so there is no wording left anywhere that still treats a bracket as a way out. Nothing was tightened on the detection side, and deliberately: catching the articulate variety by pattern would mean flagging ordinary parentheses in ordinary sentences. Wolffish keeps writing naturally, and a finished turn simply ends.
v1.0.296
New features
- You can message Wolffish while it works. A message typed into a running turn used to wait in a queue: Wolffish finished whatever it was doing — the wrong folder, the wrong file, the whole long detour — and only then read the line that would have stopped it, so steering arrived after there was nothing left to steer. A message sent mid-task is now handed to the work in flight. The agent reads it at its next step — the moment the batch of tool calls it is running finishes, before it chooses the next one — and it lands in the conversation as a real message of yours, at the exact point it was read. So “skip the tests folder”, “use the other file”, “that’s enough, just summarise what you have” now do what they say while the run is still going: Wolffish acknowledges the change in a line, adjusts, and never redoes the work your message did not touch. It is not a second turn racing the first — it is one run, steered from outside.
- Pending until it’s read, and yours to take back. Your message sits at the end of the feed as its own bubble marked “Read at the next step”, with an X that takes it back — straight into the composer as a draft, so a message sent too soon costs nothing. Once the agent has read it the X is gone, because a delivered message is part of the conversation and cannot be unsent. It works everywhere Wolffish does: the app, the terminal (type while it works;
esctakes the last one back), your phone, Telegram and WhatsApp — and voice notes count, transcribed before they are handed over. A message that arrives while Wolffish is writing its final answer keeps the turn alive so it answers you in the same run instead of ending and starting over. Stop a turn and an unread message is handed back rather than silently applied to whatever comes next.
Updates
- A reply ends on its last real word. Some turns were still closing with a bracketed note where silence belonged — a stray
(no content)stapled under a finished answer, or sent alone as a message of its own. Two rounds of fixes to the instructions never caught it, because the instructions were not the source: whenever Wolffish ended a turn with nothing, the app wrote a parenthesised placeholder into Wolffish’s own mouth — a line in its voice, in its history, one message before it was asked to reply — and the leaks were that line’s shape exactly. The placeholder is gone from all three places that used it, so the pattern is no longer demonstrated to the model at all. A stand-in typed anyway is now noticed and reported back the way a stray control token or a lone.already was, with the exact characters quoted, so Wolffish can see what reached you. Silence is written as nothing. wolffishworks in a new terminal, with nothing to paste. Installing the terminal client wrote the command into a folder no shell was looking in, and left you the last step: add a line to your shell profile, by hand, on every machine. The app now puts the folder on your PATH itself — a marked block in the shell profiles on macOS and Linux, the user PATH on Windows — checked on every start, removed cleanly on uninstall, and never touching a line you wrote. Settings,wolffish pathand the status screens now say “open a new terminal” instead of handing you something to copy, and only show the manual line if the app could not do it. Finding the command on Windows is also fixed: it is matched however the name is cased on disk.
v1.0.295
New features
- The terminal is now a real screen.
wolffishin a terminal used to be a line at a time: type, wait, read, and hope the tool calls you could not see were going somewhere. It is now a full-screen terminal client, on par with the app it belongs to. The conversation streams into a scrolling feed with the same cards the app draws — tool calls with their output, file edits as diffs, delivered files, todo lists, workflow rosters, background tasks and countdowns — and the prompt at the bottom is a real editor: Shift+Enter adds a line, a long paste folds into a placeholder,@pathcompletes and attaches a file,/completes every command. Under the prompt sits what a chat window shows for free and a terminal never did: the mode, model, thinking effort, plan mode and project on one line, and while a turn runs, what the agent is doing right now, how long it has been at it, how much of the context window is used, and what it has cost — the app’s context meter, made for a terminal. Approvals and questions arrive as cards you answer with the keyboard (allow once, allow always, deny; pick an option by number), a prompt typed mid-turn queues instead of being refused,esctwice interrupts, and if the app restarts under you the terminal reconnects on its own and picks the conversation back up. - Everything the app can do, from a box with no screen.
ctrl+popens a command palette that lists every command with its key;ctrl+x lswitches conversations from a fuzzy-searchable list with rename and delete;ctrl+x mswitches the model, then the thinking effort; plan mode, chat mode and the project bound to the conversation each have a key and a slash command. Settings open as the app’s own page → card → row browser — every switch, number, choice and secret edits in place, every action the app has (pairing a phone, testing a key, adding an MCP server, installing an engine) runs from the same list, and a search reaches across every row at once. Usage shows the same totals, providers and models as the app’s panel with a range picker and a daily strip; status shows the daemon, brain, autostart, PATH and channels. Projects, procedures, automations (with what is running and queued), delivered files, parked approvals, background tasks and the daemon log each have a dialog. Everything that took a--jsonflag still does, andwolffish -p "…"with a pipe still prints plain text and exits — scripts do not change. - HTML files run live in the chat. An HTML file in the chat — a game the agent just built, a report, a page — used to render as a static picture of its markup: the app’s own security policy silently blocked every inline script, so anything interactive showed a blank canvas. The card now hosts the page in a real browser tab of its own: scripts run, the canvas draws, keys and sound work,
localStoragepersists between opens, and relative assets and CDN loads resolve as they would in Chrome. The card shrinks a wide page to fit; the expanded view shows it at full size, with Reload to start over and Developer tools to look inside. Every guest is hardened by the app — no access to the app’s context, popups and outbound links go to your system browser — and a file too large to show as source still previews live.
Updates
- Built into the app, updated with it. The terminal client is now a compiled program of its own, shipped inside the app and pointed at by the same
wolffishcommand as before — nothing to install, nothing to keep up to date, and an app update replaces it in the same step. On Windows it is a proper console program, so the extra launcher the old client needed is gone. The terminal’s own small preferences — its theme, prompt history, recent models — live with the app’s data, so a machine you reach over SSH remembers them too.
v1.0.294
New features
- A restart is armed, not run. Asking Wolffish to restart, shut down or log out used to hand the job to a hidden timer: the agent scheduled the command twenty seconds out in a detached shell and moved on, with no way to cancel it on a Mac or on Linux, and a failure to even start that timer was reported to you as success. The whole thing is rebuilt around one rule: nothing that would cut off the agent’s own reply runs inside the turn. A power action is now armed rather than run — the agent finishes its answer, the conversation is saved, and only then does a countdown card appear in the chat with the action’s name, a bar draining over ten seconds, and an Abort button. When the bar empties the command runs; press Abort and it never does. The card is a real part of the conversation, so it appears on your phone with the same Abort button, and a conversation opened later shows exactly what happened — ran, aborted by you, or dropped because the turn was stopped before its reply landed. On a chat channel,
/cancelaborts it. Nothing stays pending across a relaunch: a countdown the app went down with is recorded as dropped, never left counting. The escape hatch survives for the one case it exists for — a user who says “restart now” and accepts losing the tail of the turn. - Any action can take the same countdown. The restart is the first user of a general mechanism, and the agent has it as a tool of its own.
countdown_startarms any tool call to run a few seconds after the reply is finished, on the same card with the same Abort — quitting the app, an irreversible cleanup, anything you would want a last chance to stop. The armed action is checked against the same safety rules as calling it directly, and if it needs your approval, the approval card is raised at the moment it is armed, never later when no one is there to answer. One countdown is pending at a time; arming a second replaces the first. Automations cannot arm one at all, because no one is watching their card. - Abort from your pocket (mobile v1.0.58). The countdown card reaches the phone like any other card — and the Abort button works from there, which matters most when the machine going down is the one you are not sitting at.
v1.0.293
Updates
- A finished turn ends on nothing, not on a note about nothing. When a turn had nothing left to say — the answer already delivered, the phone already notified — Wolffish’s own instructions told it to end with nothing, and printed the mistake it must not make: the offending note itself, in quotes, as the example not to write. A model that has decided to say nothing reaches for the nearest token, and the nearest token was the one the instruction had just shown it. So a finished turn could close with that note typed after a real answer and delivered to you as part of it, twice in one conversation. Every one of those instructions — the standing procedures and both runtime notices — now names no example at all and never prints the phrase it forbids. They describe the class of mistake instead (a bracketed status note, a written statement that you are staying silent, a lone ”.” or ”…”), say outright that nothing is ever structurally required in a reply, and cover the shape that leaked: a substantive answer never carries a trailing marker — it ends at its last real character.
- The update button keeps its name. No Installing… swap in the chat card or the Settings panel while the work is in progress.
- The running note is an automation card’s last line, under the mono well, rather than floating among the rest of it.
v1.0.292
Updates
- An automation card says when, at a glance. The schedule an automation runs by —
Daily (09:00),Weekly (Mon 09:00), a raw cron line — used to open the small grey line of code at the bottom of its card, sharing two clamped lines with the next run’s date, the project and the edit stamp, where a long one could be cut off before you ever read it. It now carries a chip of its own, paired on one row with the countdown: when it runs next on one side, the rule it runs by on the other, pushed to the card’s two edges the way the On/Off and Single/Workflow switches above them are. The chip wears the glyph of its period — a sun for a daily run, a briefcase for weekdays, a calendar for weekly and monthly, a stopwatch for hourly, a rocket for one that fires when the app starts, angle brackets for raw cron — so the shape of an automation registers before you read a word of it, and a long cron drops to its own line rather than squeezing. The line of code below is left with only what it was always for: the exact moment of the next run, the project it belongs to, and when you last edited it. - One Library on the phone, too (mobile v1.0.56). The three pages you make things on now live behind one row in the conversations sheet: Library, with Automations, Projects and Procedures as three tabs under the title — the desktop’s own v1.0.286 move, laid out for a phone, remembering the tab you left on and still opening straight to the right one from a notification. The Automations tab shows cards only: the raw
heartbeat.mdview and its toggle are gone, because on a phone the cards are the schedule and a second surface for the same store was a second place to get it wrong. The full Conversations page — the one with search and delete — moved out of Settings into the sheet as well, beside the other pages you go to rather than the settings you adjust. - Cards that stop at the same edge (mobile v1.0.57). The compact rows reporting an edit, a write or a shell run, and the card summarising a workflow, ran the full width of the chat while every other card the agent produces stopped short of it — two different left margins in one conversation. Both now stop where the reply stops, at the agent’s own width. The working row’s spinner actually spins, too: the glyph that used to sit there only faded in place and read as a frozen screen.
v1.0.291
Updates
- Updates on Mac come back. Clicking Update on a Mac would sometimes close Wolffish and then — nothing. No relaunch, and when you opened it yourself it was still the old version. The cause was a race: on macOS the system’s own installer has to unpack and check the 300 MB bundle after you click, and Wolffish gave it a fixed five seconds before forcing itself shut. On a busy disk that is not enough, so the app died with the update half-prepared. Wolffish now prepares the update first, while it is still fully running, and only begins shutting down once the installer confirms it holds the new version. If preparing fails, nothing is torn down: the app stays open, tells you the install did not go through, and lets you try again. The same rule now holds on every platform — Wolffish never force-quits with nothing installed; if the installer could not be armed after shutdown had begun, it relaunches the current version instead of vanishing. One honest note: the update that brings you this version is still carried out by the old code, so it may misbehave one last time — the update after it is the first to run the fix.
- Install failures say so. If an install failed, the Update button used to sit greyed out on “Installing” for good, in both the chat card and Settings → Updates, with no way back short of restarting. Both now show what went wrong in place of the release notes, turn the button into Retry, and read “Installing…” only while the work is actually in progress.
v1.0.290
New features
- Several times a day is one automation. “Sweep the inbox at 8, at 2 and at 8” used to mean three separate automations standing in a row, each with its own card, its own history and its own edit. A schedule can now carry a list:
Daily (08:00, 14:00, 20:00)fires three times a day,Weekday (09:00, 17:00)twice on every working day, andWeekly (Monday, Wednesday, Friday 09:00)three times a week. Days and times can both be lists —Weekly (Monday, Friday 09:00, 17:00)is four runs a week from one line — day names take Mon, Tue, Wed as readily as the full word,Monthly (1, 15 09:00)covers the first and the fifteenth, and the times need not share a minute, soDaily (08:00, 12:30, 18:00)is fine. For anything the lists cannot say,Cron (…)takes several expressions joined by;. The card’s countdown follows: a schedule like that shows its next run rather than its first, so an automation that fires at 08:00, 14:00 and 20:00 reads 14:00 when you look at lunchtime. Everything already written keeps working exactly as it did — a single value is simply the one-item list. - Pick how many times, then the period. Above the schedule field there is now a row of count pills — Once, Twice, 3 times, 4 times, 5 times — that reads as one sentence with the period chips beneath it: “3 times” · “Every day” fills in a
Daily (…)with three times spread evenly across the day, anchored on now. Pick them in either order. Both rows light from what is actually in the field rather than from your last click, so opening an existing automation — or typing a schedule by hand — shows you its own period and its own count. The phone got the same pills in its v1.0.55, with the next-run line underneath confirming the reading before you save.
Updates
- Code blocks without a language tag. A fenced block with no language on it — just three backticks — rendered with a second, darker box drawn inside it, sized to the text instead of the block and plainly visible in light mode. Wolffish was deciding “block or inline snippet?” by looking for a
language-class that an untagged fence never carries. It now decides by where the code sits: inside a fence, it is a block. - Previews on the right ground. The Word and spreadsheet previews painted themselves on the window’s background rather than the card’s, leaving a document sitting in a well slightly darker than the card holding it; they now use the same ground every other card paints on. The folder chips along the top of a transcript were translucent, which let the lines scrolling underneath ghost through them — they are solid now.
v1.0.289
Updates
- Ollama stops asking to be installed. A first run used to walk you from the welcome screen straight into install Ollama, and from there into pick your Ollama model — two full-screen pages that carry none of the app’s navigation, so anyone who simply did not want a local model had nowhere to go. Wolffish now treats Ollama as what it is: one optional provider among several. Onboarding is a theme, a language, and then the chat — nothing else. The model picker no longer exists as a screen at all; it is the Ollama panel of Settings → Models, where you go looking for it when you actually want it, and every way in is a button you chose to press. Launch itself now asks Ollama nothing — no probe, no tag list, no quietly rewriting your configuration before the window is even up.
- The Models panel stays where you are. Finishing a download used to throw you out of Settings and into the chat, because the picker was built as a step in a flow rather than a panel you had opened on purpose. It now stays exactly where you are: the list comes back with your new model marked as the current one, and the panel re-reads what Ollama actually holds, so re-downloading a model your configuration already names no longer leaves the card standing there still offering “Install”. The buttons that belonged to that old flow — “Skip for now”, “Back to chat” and “Continue to chat” — are gone, because Settings’ own sidebar and back chevron were always the way out of a panel.
- When a local model goes missing. Delete a model with
ollama rmand Wolffish used to carry on believing it still had one: the composer stayed live, the notice that points you at Settings stayed hidden, and you found out by sending a message and getting a raw provider error back. The chat now reads the daemon’s live state — a background watch the app already keeps, not a new probe of its own — and tells you plainly that your local model is no longer installed in Ollama, with the same one-click path to Settings → Models. A daemon that is merely switched off is left alone, and so is one that stumbles for a moment before answering: neither is reported as a missing model. And the Stop button is now gated on nothing at all, so a turn running on a model that vanished mid-generation can still be stopped.
v1.0.288
New features
- Wolffish writes code now. Point a conversation at a code project and Wolffish stops being an assistant that happens to own a shell and becomes a coding agent that works the way you would. It begins by reading the project instead of guessing at it: the runtime now tells it which of your working folders are real projects, what branch each one is on and how many uncommitted changes it carries, which toolchain it uses, and the exact check commands that project exposes — and it reads the project’s own
AGENTS.mdorCLAUDE.mdfirst, so a repository’s house rules outrank anything Wolffish believes by default. Three new tools do the work:file_editmakes a surgical, exact-string change and shows you the diff instead of rewriting a file whole;file_grepsearches file contents with ripgrep across a codebase of any size, respecting.gitignore; andfile_globfinds a file by name. Every edit is followed by two steps you never have to ask for — the project’s own formatter runs on the file when the project demonstrably uses one, and the project’s own TypeScript, ESLint, Ruff or Pyright is asked what it thinks, with any errors handed straight back so they are fixed in the same turn instead of surfacing at build time. And a change is not done until a check passes: the narrowest test first, then the project’s full typecheck, lint and tests, with a failure reported rather than hidden. All of this is attached only when the working folder really is a code project — an ordinary conversation carries none of it. - Plan first, change after. A new Plan chip sits in the composer beside the draft-editor button. With it on, a turn cannot change anything: it reads, searches and investigates, then ends by writing a plan — the recommended approach, the files it will touch, the steps in order, and how the result will be checked — and tells you to turn Plan off to run it. It is a stance you take for a conversation rather than a property of its transcript, so it is held in one place and shared with your paired phone: set from either surface, and the other follows at once. A brand-new chat can carry the stance before it even has an id. Turn it off and the next turn is told, once, that the plan is now approved to act on.
- Every change arrives as a diff. A file edit and a shell run used to look like every other tool call in the feed. They now get a compact activity row of their own — a short label, the file or the command, and a chip reading
+12 −3for an edit orexit 0for a command, green or red. Open the row and an edit shows the real unified diff, red and green with the true line numbers down both sides; a command shows its output and, when the output was long, the path of the file holding all of it. The diff travels on the result itself, so a conversation reopened next week renders exactly what it rendered live. - The task list. When a job runs to three steps or more the agent now keeps a task list, and it appears in the chat as a checklist card: exactly one item in progress, an item ticked off only after the check that proves it really ran. The card updates in place rather than stacking a new copy on every revision, so a long run leaves one list in the transcript showing where things stand. It reaches the paired phone and the exported PDF the same way.
- Putting it back. Before the first change a turn makes to a file, Wolffish now keeps the original bytes.
changes_listshows what each recent turn touched, andchanges_revertputs a turn’s files back — the whole turn, or one file of it. It needs no git, works in any folder, and keeps the last twenty turns of each conversation. It exists for one sentence you have certainly said before: that fix made it worse, put it back. - Simulators, on both phones. A new Mobile simulators capability puts iOS and Android on the desk: nine
sim_tools for the iOS Simulator — list the devices, boot one, build, install, launch, terminate, screenshot, read the log, open a deep link — and sevenadb_tools for an Android emulator or a plugged-in device, tapping and typing included. “Does the new screen look right?” is now a question the agent answers by building the app, launching it and looking.
Updates
- Allow it for this conversation. The approval card has a second button. Allow for this conversation approves the call in front of you and stops asking about the same kind of call for the rest of the chat — the same tool, and for the shell the same command head, so allowing
npm installonce never quietly allowsgit pushlater. Anything blocked outright never reaches this card and never gets the button. - Approvals that read the path, not the code. Writing a file whose contents happened to mention a path used to stop the agent and ask you about it. An ordinary relative import —
import x from '../lib/x'— raised a red “Path traversal attempt” card, the app’s most severe warning, over a line of perfectly normal code; a shell script beginning#!/usr/bin/env nodewas announced as “Modifying system files”. The rules were reading the whole call, text and all, instead of the one thing they are about. They now read the path being written, and nothing else. A genuine traversal such as../../../etc/hosts, and a genuine write into/etc,/usror/private, still stop and ask exactly as before, on a file tool and on a shell command alike. One thing genuinely relaxes: a shell command that merely walks up a directory,cd ../sibling && npm test, no longer counts as an attempted break-out. - The feed shows the work, not the mechanics. The switch that controls how much of a turn you see carried the name “Verbose task results” on four different surfaces — a name describing its setting rather than what you would see. It is now “Show all tool activity” everywhere: desktop, phone, terminal, Telegram and WhatsApp. More usefully, what a clean feed always shows has grown. With the switch off you now see the replies, the delivered files, the code edits and shell runs, the questions and approvals, the reasoning and the task lists — only genuine mechanics stay out of sight. Along the transcript’s top edge there is also a new strip of folder chips: every folder this conversation changed files in, and how many, each one a click away from opening on your desktop. Going the other way, the live run cards are gone — the card that covered the chat while an automation, a procedure, a compaction or a reflection ran has been removed along with its four switches, because each of those runs already reports itself on its own page and the card only ever sat in front of what you were reading.
- Output that keeps its ending, servers that can be stopped. A long test run’s output used to be cut off past about 100 KB — it kept the beginning and threw away the bottom of the log, precisely where the failure is reported. Long output now keeps the last 2000 lines or 50 KB, and the full text is written to a file the result names, so nothing is lost and the agent can search the log for the failing test instead of running everything again. Commands also run in your working folder by default now instead of your home directory, so
npm testandgit statusland in the project without being told where it is, and they come back with the colour codes stripped out. A command shaped like a dev server or a watcher is refused in the foreground rather than hanging the turn: it is started in the background instead, withshell_jobsto list what is running andshell_stopto end one or all of them before the turn finishes. - The local models group waits for Ollama. The composer’s model card used to ask Ollama what it held every single time you opened it, then re-render when the answer arrived — and it offered a local group whether or not the daemon was actually running. Wolffish now watches Ollama in the background, and the card simply reads an answer that has already settled: the local group is there exactly when Ollama can answer, the same way a cloud provider’s group is there exactly when it has a key. Opening the card costs nothing, and nothing shifts under your cursor.
- All of it on the phone (mobile v1.0.54). The Plan switch sits in the chat controls with its composer chip, mirrored both ways with the desktop — and it hides itself in demo mode, where an unpaired phone has no desktop to hold the stance and a switch could only lie. File edits, writes and shell runs always draw their compact row whatever the tool-activity setting says, expanding to a red/green diff with line numbers or the command’s output, exit code, duration and spill path. The task list renders as a checklist card that updates in place and resolves its original card when a later turn picks the list back up. The model picker drops its Local/Cloud switch for one provider row with Ollama listed beside the cloud providers whenever its daemon is up. And the floating run cards retire along with their four switches, leaving the reindex overlay alone.
v1.0.287
New features
- DeepSeek’s new Flash can see. DeepSeek has retired its whole V4 Flash line and replaced it with one model, DeepSeek-V4.1-Flash, served under the plain name
deepseek-flash. It is now the default DeepSeek pick in the model catalog, and it wears a vision badge for the first time in that provider’s row: it reads the images you attach and the screenshots computer use takes, so driving the screen on DeepSeek no longer means switching to another provider first. It is also markedly cheaper — input at 0.30 and output at 1.20 per million tokens depending on the hour, with cache hits close to free — and the catalog now shows those rates. Underneath, the app finally recognises a name that carries no version number: until now a chat ondeepseek-flashwould have been quietly treated as an 8K-context, 16K-output model instead of the 1M-context one it is, and every image would have been stripped before sending because the app still believed DeepSeek was blind. The retired names keep working — DeepSeek routes them to the same model, and the app now treats them the same way.deepseek-v4-prostays listed at its own prices for the few days it has left; from 14 September DeepSeek routes it to V4.1 Flash as well and bills the Flash rate.
v1.0.286
Updates
- Automations, Projects and Procedures become one Library. The three pages that hold what the agent runs on its own, what it starts a conversation from, and what you run on demand sat behind three separate sidebar entries, each opening a near-identical grid of cards under its own back button — so finding the thing you wanted to edit began with remembering which of three lookalike pages it lived on. They are now one Library page with three tabs, the same shape Customization took for Soul, User and Agents: the back button leads, the tabs sit beside it, and the grid fills the rest. Nothing on the cards changed — creating, editing, playing and deleting all work exactly as before — and the Automations tab keeps its cards-or-markdown switch, now at the far end of the same row as the tabs rather than in a header of its own. The tab you left on is the one you come back to after a detour through chat, so a look at what is scheduled never costs you your place among your procedures. The sidebar is one row shorter for it, in English and in Arabic alike.
v1.0.285
Updates
- The stray period at the end of an answer. Every so often a finished answer was followed by a message containing nothing but a full stop. It arrived under a reply that was already complete, said nothing, and left you wondering what the agent had meant by it. It meant silence. When the work is done and the notification has gone out, the runtime tells the agent there is nothing left to reply to — and the correct way to finish there is to write nothing at all. But a model asked to send nothing cannot always send nothing, so it typed the smallest mark it could find and sent that instead. The app never edits a word the agent writes, on purpose, so the answer was never to quietly delete the character — it was to make sure the agent knows a lone
.is every bit as visible as a sentence. It is now told exactly that, the next time it speaks, along with what you actually saw on your screen, the same way it is already told when a raw tokenizer marker slips into a reply. The instructions it works from name the case outright now, too, so the far more common outcome is that it never types the character in the first place. A reply that is genuinely just punctuation because you asked for it — a divider, a row of dashes — is left alone. - The context meter waits until it has something to show. A brand-new chat opened with an empty gauge sitting in the composer row, and hovering it produced a card that said only “No usage yet” — a control that existed to tell you nothing, beside the logs and files chips that had already stopped doing exactly that. The meter now joins the row the moment it has a reading, on your first send, and stays away until then. Next to it, the button that opens the full-height draft editor wore the four-arrow mark the file, PDF and video viewers use for “make this bigger”, while its own label reads “Write your message” — it now wears the pencil that the project, automation and procedure cards already use to open an editor, at the same size as every other icon in that cluster.
v1.0.284
Updates
- The composer expands like everything else. The last release moved the automation, project and procedure editors into the full-height panel when you ask their prompt for more room. The chat composer’s own expand button was the one left over — it still opened a box floating in the middle of a dimmed screen, so the same request meant two different shapes depending on which text you happened to be writing. It now opens the same panel, over the same draft, so what you write in it is what the composer sends the moment you close it. It also has a close button and answers Escape, where before the only way out was clicking the dimmed area behind it — and that click is gone on purpose, because a stray one while you were writing used to shut the editor mid-sentence. The button itself finally says what it does when you hover it, instead of being a bare icon.
v1.0.283
Updates
- The expanded prompt editor joins the panel. The last release moved the automation, project and procedure forms into full-height panels that slide in from the edge. The button that gives your prompt more room, though, still opened a box floating in the middle of a dimmed screen — a second shape stacked on the first, for the very same act of asking for space. It now opens the same full-height panel, the one the file and PDF viewers already use, so writing a long prompt widens the surface you are already on instead of covering it with another. It also finally has a close button: before, the only ways out were Escape or a click on the backdrop, and that backdrop click is gone on purpose — a stray click while you were writing used to shut the editor from under you. In Arabic on a Mac, the expanded viewer’s title also no longer sits underneath the window buttons.
- The prompt comes first. In all three editors the prompt sat below the file list and the folder list, so the one field the whole form exists for was the one you had to scroll past everything else to reach — and the longer your file and folder lists grew, the further down it went. It now sits directly under the name and project, with files and folders beneath it. Projects already worked this way; automations and procedures now match.
- Cards that say what they hold. A project card now shows how many files and working folders it carries into every conversation it starts, as two small chips beside the name — and shows nothing at all where there is nothing, rather than an empty “0”. On a procedure card the Single / Workflow toggle moved up beside the buttons, giving the name a full line of its own. Both cards now close with the same small monospace line the automation cards use — when it was last edited, when it was last used, how many conversations — so the three pages read alike.
v1.0.282
New features
- Soul, User and Agents become one page. The three documents that shape the agent — its personality, the facts about you it should always know, and your own procedures — sat behind three separate sidebar entries opening three near-identical editors, so adjusting how the agent behaves began with remembering which of the three held the paragraph you meant. They are now one Customization page with three tabs, the shape your phone already uses. Each tab states in a line what its document is actually for, so the choice no longer rests on a single word. A draft you leave in one tab is still there when you come back from another, and that tab carries a dot while it holds unsaved changes — which is exactly the draft you can no longer see. Edits made on your phone or in another window still arrive on their own, and now they land on whichever tab is clean rather than only the one you happen to be looking at.
Updates
- The files sheet lists what the conversation actually has. View Files had been drifting into a list of things that were not there. A long run names plenty of files it then cleans up — a PDF check renders proof pages, looks at them, re-renders and deletes the batch — and every one of them stayed in the sheet as a tombstone you could click but never open. Files the agent merely read for reference landed there too, so a morning digest that consulted last week’s reports filled today’s sheet with last week’s files. Meanwhile the one file you were most likely looking at — a meme or a GIF the agent had just made and shown you inline — was the single file the sheet never listed at all. All three are fixed: the sheet now checks what is still on disk and counts only that, a file read for reference no longer counts as this conversation’s, and generated media appears the moment it does, while the answer is still being written. When a picture is genuinely gone, its placeholder fills its column instead of sitting in it as a narrow stub.
- The logs and files chips earn their place. The two chips beside the composer were always mounted and merely greyed out when they had nothing, so a brand-new chat opened carrying two dead controls advertising sheets that were empty anyway. Each one now joins the row when its first event or file lands, the same way the export button waits until there is something to export. They also wear the same frame as the context meter they sit beside, instead of standing bare next to a bordered pill.
v1.0.281
Updates
- The leak that broke every tool at once. Leave the app open long enough and everything that runs a program would start failing at the same moment — Google Workspace announcing that gogcli “is not installed”, video and audio conversion falling over, a shell command dying with nothing useful to say. Each one reported the failure as its own local problem, so none of them pointed anywhere near the cause: the file watcher that keeps your workspace searchable was claiming one system handle for every single file it watched, and a lived-in workspace is tens of thousands of files. Once the app ran out of handles it could no longer start any program at all, and every tool went down together. The watcher now holds one handle for the whole workspace — eleven of them instead of twenty-three thousand, and it stays eleven however far your workspace grows. It also notices folders created after the app started, which the old watcher quietly missed on a fresh workspace.
- Installing Google Workspace explains itself. When the Google Workspace install or update failed, all you got was a toast reading “Install failed” — which then vanished, taking the only account of what happened with it. The real reason now stays on the card in plain words: GitHub’s hourly rate limit, a release that has moved, a file that won’t run, a path the app can’t write to. Install itself is repairable now, too. It unpacks to a scratch folder and swaps the finished binary into place in one move, so a download that dies halfway leaves your working copy untouched instead of replacing it with a truncated one — and the state that used to make Install fail forever, however many times you pressed it, now clears on the first try. An update that lands a binary which won’t actually run reports that as a failure, rather than showing you a green checkmark while every Google call quietly fails.
- The edit forms get the whole window. The editors for automations, projects and procedures were boxes floating in the middle of a dimmed screen — and a real one, with a schedule, a file list, a folder list and a prompt, grew straight past the bottom of the window with nothing to scroll and the Done button somewhere off-screen. All three are now full-height panels that slide in from the edge, the same surface the logs, files and conversations sheets already use: the form scrolls, while the title and the Done bar stay put. The three list pages also dropped from three columns to two.
- Every automation says when it runs next. An automation card gave you its schedule in small grey text among everything else on the card — the one fact about a scheduled job that changes on its own, buried in the one line that never does. Each card now leads with a countdown chip: Next run in 3 hours, in the same shape the composer wears for its model. Inside the final minute it counts down by the second, and when the moment passes the card rolls forward to the next occurrence by itself instead of sitting on a time that has already gone. A switched-off automation wears the chip greyed out rather than promising a run that isn’t coming. The exact wall-clock time, the schedule’s own syntax and when you last edited it moved to a small monospace line at the foot of the card — and the editor now previews the very same chip the card will wear once you save.
v1.0.280
New features
- A turn that survives the power going out. Until now a conversation reached your disk exactly once — at the very end. A run that worked for forty minutes across a dozen tool calls existed nowhere but in the app’s memory while it worked, so a crash, a force-quit, an update installing itself, or a Windows restart threw the whole thing away and left you with your question and nothing else. Every in-app turn is now written to disk as it happens: the answer so far, every tool card, the task timeline. The prompt lands before the first word arrives, the slow and expensive parts — a tool call, its result, a task flipping to done — are saved within a second, and the prose follows a few seconds behind. Quit the app mid-run, restart the machine, pull the plug: the conversation comes back with the work in it, marked as the run that never got to finish, and nothing about a turn that ends normally changes at all.
- Your voice, changed by asking. Changing how the agent speaks or how it hears you meant opening Settings and finding the right panel. Now you just say it. “Use a British voice”, “you’re talking too fast”, “transcribe in Arabic from now on”, “use a more accurate model” — the agent reads your current settings, changes the one you meant, and tells you in plain words what it changed. It can also install the voice and transcription engines on request, with the same progress bar the panel’s own button shows. Whatever it changes, the Settings panel and your phone update live, and it will only ever set a voice, speed, model or language that every screen can actually display.
Updates
- Restarts wait for the answer to land. Asking the agent to restart your machine used to take it down that instant — including the turn that was still being saved, so the very answer telling you it was restarting went down with it. A restart or shutdown is now scheduled about twenty seconds out. The agent tells you what is about to happen and how to stop it (
shutdown /aon Windows), gives the machine longer when a download or a long write is still in flight, and can still go down immediately if you explicitly ask for it. It also can’t sneak a reboot through the terminal any more — that path skipped both the approval card and the delay. (v1.0.294 replaced the delay entirely with an abortable countdown card.) - Screenshots as sharp as the task needs. Screenshot resolution and format used to be two settings you had to find and tune yourself, and every capture came out the same regardless of what it was for. Both are now chosen per screenshot by the agent, which knows what it’s looking at: an ordinary hunt for a button stays small and fast, while reading a page of code, judging spacing and color, or handing you a screenshot to keep goes up to 2560 pixels and lossless PNG. Ask for a higher-resolution or sharper screenshot at any point and it simply takes one — it is a choice on the next capture, not a preference buried in a panel. The old settings are gone from the app, the terminal and your phone, because nothing needs to write them any more.
- Automations, procedures and projects at a glance. All three pages listed their entries as tall stacked rows, each one carrying its full prompt, its attached files and its folders — so four automations filled the window and finding one meant scrolling past everything it contained. They are now grids of compact cards, matching the Services page: an icon, the name, the two lines that matter, and the controls. Automations also finally have a name of their own — “Morning digest” rather than “Daily (08:00)” — so a card tells you what a job does, with its schedule reading underneath.
- Logs and files, one click away. The Logs and Files buttons were folded inside the context meter’s hover card, so reaching either meant hovering one thing to click another. They now sit right in the composer footer as two small chips carrying their own counts. Both sheets, along with the expanded file and PDF viewers, also stopped being boxes floating in the middle of a dimmed screen: they now slide in from the edge as full-height panels, mirroring the conversations sheet on the other side.
- Thinking, shown or hidden. The model’s reasoning card is welcome company for some people and clutter for others. There is now a Show reasoning switch in Preferences — on by default, and shared by this app and your phone so the two never disagree. Turning it off hides the card and nothing more: the model still thinks exactly as before, and the reasoning is still saved with the conversation and still included when you export it, so switching it back on brings every thought back with it. (Mobile v1.0.52 carries the same switch, and drops its own two computer-use screenshot rows.)
v1.0.279
Updates
- One model, one chip. The composer carried two labels side by side — a Local one and a Cloud one — as though both were somehow live, when only ever one model answers you. There is a single chip there now, and it shows the model that will answer: your provider’s logo and its name, or Ollama’s logo and your local model’s name. Click it for the same searchable card as before. Choosing a model is the switch — pick an Ollama model and you are running local, pick a cloud model and you are running that provider — so the checkmark in the list marks the one model you’re on instead of one per side. Your local model always keeps a row of its own in that list, so it is there to pick even when Ollama isn’t answering.
- The export button waits until there’s something to export. The download-as-PDF button sat in the header of every conversation, greyed out and unclickable until the chat had something printable in it. On a brand-new conversation it is simply not there now, and it appears the moment there is something worth exporting — a dead control says less than no control at all.
- Every tap answers back (mobile v1.0.51). Press a settings row, an icon button, a project card, a chip in the model picker — anywhere in the app — and the surface under your finger lights up. It never did: the highlight was being asked for in a form the app’s styling could not draw, so it was skipped in silence and close to forty controls landed completely inert. A handful of small surfaces had been drawing with no background at all — the status pill on a task card, a tool’s status chip, the file-type badge, the download progress track, the file viewer’s line numbers and table headers, the context meter’s bars — and all of them carry their intended tint again, in both light and dark.
v1.0.278
Updates
- The model list comes back. The composer’s model card spent a version speaking in chips — three sideways-scrolling rows you had to drag through to find a brain. It is a list again: your installed Ollama models on top, then a group per connected provider, each model on its own line with its size, badges and context window, and a checkmark on the one you’re using. It scrolls down the way a list should, never sideways, and the search box is back at the top — type a few letters and it filters local models and every provider at once. The chip rows stay where they belong, on the project pickers and the phone.
- Long model names fit the composer. The Local and Cloud labels under the composer were capped so tightly that any name past about twenty characters got cut off mid-word. The cap is now wide enough for every model in the catalog.
v1.0.277
Updates
- Reasoning in plain view. The Reasoning card no longer folds the model’s thinking behind a click. It is now an open scroll block, styled like a tool’s output: the thinking sits right there under a small brain icon, grows with what it holds up to eight lines, and scrolls inside its own box past that — a one-line thought takes one line, and a long deliberation never swallows the conversation. Hover the block and a copy button appears, putting the whole thinking on your clipboard. When a model opens its reasoning with a heading, that heading becomes the card’s title instead of the plain word “Reasoning”. While a reply is still streaming, the block follows the newest line as it arrives and stops following the moment you scroll up to read — and a conversation you reopen shows every card from its first line. (Mobile v1.0.50 ships the same block, with a copy chip in the header and a long press for selection.)
v1.0.276
Updates
- Reasoning that opens at the beginning. Tapping a turn’s Reasoning card used to drop you at the tail of the thinking — its first line flung far above the screen — and closing it could hurl you all the way back up to your own prompt. The card now minds your place in the conversation: expanding scrolls the head of the reasoning into view so you always read the thinking from its first line, and collapsing carries you straight back to the newest message at the bottom. If the reasoning is short enough to fit where you already are, nothing moves at all — and opening a conversation still lands pinned to the end, exactly as before.
v1.0.275
Updates
- Write the prompt right where you read it. The prompt in the Automations and Procedures editors — and a project’s instructions — used to be a preview you had to click to edit, and clicking it anywhere flung open a full-screen sheet. That block is now a real editor, sitting right in the dialog: type in place, scroll a long prompt inside it, and everything autosaves exactly as before. It keeps one fixed height, filled or empty, so the dialog never jumps around as the text grows, and it wears the same recessed look as every other input field. The Edit button below is now the one thing that opens the full-screen editor, so reading, selecting, and scrolling never open anything by surprise.
- Projects are one tap away. Binding an automation or a procedure to a project meant opening a dropdown that hid the list and truncated the name it showed. The picker is now a row of chips, the whole list on one line — each project wearing its own emoji and title, No project first — and the row scrolls sideways however many projects you have, with the chosen chip carried into view when the editor opens.
- Downloads pick up where they left off (mobile v1.0.49). A photo or GIF arriving over a slow link could start over from nothing, again and again: one stalled stretch failed the whole transfer, and the next attempt re-paid every byte the last one had already landed. A transfer now waits out a slow stretch instead of giving up at the first long pause, and when an attempt does break, the next one continues from the exact byte it stopped at. A file that genuinely changed on your desktop between attempts still starts over, because stitching two versions of one file together is never the right answer.
v1.0.274
New features
- The whole train of thought, in its place. A reasoning model used to leave one Reasoning card at the very end of a reply, holding only what it thought before its final words — everything it weighed earlier, before each search and each step, was never shown. Every stretch of thinking now lands as its own collapsed card, exactly where it happened, above the words and actions that thinking produced — and it appears live, while the model is still thinking, so the long quiet minute at the start of a hard question shows a card filling up instead of nothing at all. Tap to read; copying a reply still copies only the reply itself; old conversations keep the single card they were saved with. The paired phone receives the same cards, streamed mid-turn too (mobile v1.0.48).
- A heads-up before the hands get busy. The agent’s standing instructions now open every working turn with a short line about what’s about to happen — before the first tool call, with extra weight on the first reply of a conversation and the start of a big task: exactly the moments a silent spinner reads as a hang. Longer stretches keep dropping a one-liner as phases turn over, so the words remain the progress bar the whole way.
Updates
- A finished turn ends silently — not with “(no output)”. A turn whose closing message had already gone out could end with a literal “(no output)” typed into the chat — the agent obeying an internal instruction a little too literally. Every one of those instructions now spells out that silence means zero characters, never a typed placeholder, so a finished turn simply ends.
- Quoting a file marker no longer conjures the file. Tool output that merely quotes the app’s internal delivery marker — a grep through code, a read of the docs that describe it — could mint a file card for a path that was never sent, and on Telegram or WhatsApp even trigger a real send. A marker now counts only when it stands on its own line, the way actual deliveries emit it; a quoted template renders as the plain text it is. In the same spirit, a file whose upload was since deleted now shows its calm placeholder everywhere instead of logging errors behind the scenes.
- Ogg voice notes play on the iPhone (mobile v1.0.47). A voice note in Ogg used to stop at a file card on iPhone, because the system had no decoder for it. Recent iOS versions decode Ogg natively, and the app follows suit: on a current iPhone an Ogg voice note opens in the same inline player as every other voice note. Older iPhones keep the file card. The button that closes a project also stopped wearing the destructive red reserved for deleting things.
v1.0.273
Updates
- Voice notes on WhatsApp actually play now. A spoken reply the agent sent to WhatsApp as a push-to-talk voice note arrived — and tapping it played nothing: WhatsApp plays voice notes in one format only, OGG/Opus, and the app was handing it the TTS file as-is, usually an MP3. The agent now knows the rule. Voice notes meant to be heard on WhatsApp are always OGG/Opus; the agent converts them with the app’s own bundled ffmpeg the moment the audio would otherwise be MP3 or WAV, and an MP3 goes out untouched only when you asked for a file to save or share, not a note to play.
- The agent owns its own management — and reaches for it. Three capabilities run Wolffish itself: automations (the heartbeat), projects (shared context), and procedures (saved prompts). Until now the agent had to hear a capability’s own name; say “change the daily”, “add my files”, or “save that as” and it could miss the intent entirely, or answer by editing the underlying markdown by hand. These skills now declare themselves owned. The agent recognizes the intent in the way you actually phrase things — “make it run automatically”, “that job didn’t run”, “which project am I in”, “the one I use for X” — and reaches for the capability’s own tools first, touching files only as a fallback.
v1.0.272
Updates
- The chrome finds its height on Windows. The chat’s two glass discs — and the strip of pages atop the conversations sheet — floated at a height chosen for macOS, where the app hides the system titlebar and has to clear the traffic lights. Windows and Linux keep their native titlebar above the app, so the same offset left the discs hanging in dead air, visibly lower than the back button every other page already places correctly. The floating chrome now sits at each platform’s own height: on Windows and Linux the discs and the sheet’s pages ride up to match the tighter layout, and the discs take a touch more breathing room from the window edges. macOS keeps its geometry exactly as it was.
v1.0.271
Updates
- The phone is never minutes behind again. While a turn ran, this app sent the paired phone a full snapshot of the reply-so-far twice a second, however large the reply had grown — on a long automation run that is hundreds of kilobytes every half-second, down one connection. A phone on a slower network could never keep up: the backlog grew for the whole run, and the reply kept “streaming” there a word at a time, minutes after the desktop had finished. Snapshots now pay for their own size — a small one keeps the half-second rhythm every ordinary chat has always had, a heavy one waits in proportion, and overlapping runs share one budget instead of stacking on the same wire. Nothing is lost to the pacing: every snapshot carries the whole reply so far, the newest one goes out the moment the wire has room, the live word-by-word text rides beside them untouched, and a question or approval waiting on you still lands instantly. The phone stays seconds behind at worst — and everything else it does, other chats and settings and files, stops queuing behind a monster turn.
- Catching up no longer crawls (mobile v1.0.46). A phone returning to a busy conversation could spend minutes replaying what it had missed one word at a time. What arrives now pools for a blink and lands together, so a backlog fast-forwards to the present instead of re-typing itself. The feed also holds the end properly while a reply grows: streamed growth is glued to the end instantly, opening a conversation lands on the newest message and stays there while its media settles, a stray tap is just a tap, and reaching the bottom reliably hands the feed its job back.
v1.0.270
Updates
- Replies are saved as paragraphs, not confetti. Every streamed reply was being stored one fragment per instant of writing — a few characters each. A single automation answer could carry thousands of them, wrapping a ten-kilobyte reply in a quarter-megabyte of packaging that every reader paid for afterwards: this window redrawing it, the paired phone downloading and storing it, every later open re-parsing it. Prose now folds into whole paragraphs as it streams, across every surface that writes conversations — chats here, Telegram, WhatsApp, the terminal, and the automations that run on their own. Transcripts hold the same words at a fraction of the weight, and nothing about how they read changes.
- Automation transcripts stop weighing a ton (mobile v1.0.45). A conversation written by a busy automation could arrive carrying thousands of tiny text fragments plus download cards for scratch files that only ever existed on the desktop’s side of the work — a transcript many times its real size, and downloads that could never finish spinning beside the real ones. Fragments now fold into paragraphs the moment a conversation lands (the meme run’s transcript dropped to about a quarter of its stored size), and a file the desktop cannot serve is written as plain text instead of a card.
v1.0.269
Updates
- Your phone hears every save. A turn could finish here and leave your phone showing the conversation as it stood before the answer — the app announced “done” a beat before the transcript actually reached disk, so the phone’s follow-up fetch could pull the old copy and then wait for a signal that never came. It read as a chat frozen in the past on the phone until you reopened it. The desktop now announces every conversation the moment its file is saved — turns from any channel, automations writing in the background, all of them — and the paired phone uses exactly that signal to pull the finished transcript.
- A finished turn always lands (mobile v1.0.41). The phone now refuses to take silence for an answer: when a turn ends, it keeps checking until the finished reply is actually in hand. Opening the app after time away brings the conversation you are looking at level with the desktop, not just the list around it, and a notification tap is treated as the evidence it is — the conversation it names refreshes no matter what the phone thinks it already knows, even from a cold start. Transcript pieces now travel several at a time rather than one round trip each, so long conversations open in a fraction of the time.
- A file is only “deleted” when it is actually gone (mobile v1.0.42). That message now appears only when your desktop actually answers that the file no longer exists. A download that merely failed keeps its loading card and quietly retries — a few times over the next seconds, and once more whenever the connection comes back.
- The open conversation can no longer go blank (mobile v1.0.43–44). A busy sync could produce two momentary illusions — a catch-up sweep that missed a conversation for a single pass, or a fetch that caught a brand-new conversation’s file before its first reply was saved — and the phone took either as fact. It now refuses both: the conversation you are looking at is never dropped by a background sweep, and an empty answer never overwrites messages already in hand. The chat screen’s one empty frame is gone too: a transcript that disappears mid-view brings the loading placeholders back over the gap and repaints in place.
- The keyboard dismiss chevron reaches every field (mobile v1.0.40).
v1.0.268
Updates
- The feed opens where you left it. Opening a conversation whose history holds a multi-question card used to land you somewhere strange: instead of the newest message, the feed dragged itself up to that card, parked mid-transcript on a question you had long since answered. The card’s little question chips scroll sideways in their own row, and the code that keeps the active chip in view was reaching past that row and scrolling the whole transcript along with it — firing the moment the card appeared, including the moment an old conversation’s history mounted. The chip-follow now moves only the chip row itself, in either text direction, and a reopened conversation lands where it always should: pinned to the bottom, on the newest message.
v1.0.267
Updates
- The chat is all yours now. Both rails that used to frame the chat are gone — the icon strip on one side, the conversations list pinned to the other — and the transcript now runs edge to edge, framed by nothing but two small glass discs floating over it, the same chrome the mobile app settled on. The leading disc opens the conversations sheet: every page — Settings, Heartbeat, Projects, Procedures and the rest — in a fixed strip up top, and beneath it the full cross-channel conversations list, live-updating as turns start and finish anywhere, growing as you scroll instead of rendering hundreds of rows at once. In a project, the sheet shows that project’s conversations under its name. The trailing disc is New Chat, with the same hover card of project shortcuts it had on the composer — and in project mode it becomes the project’s emoji, opening the manage dialog exactly as before. Every control kept its behavior; only the walls came down.
- Settings you can search. The Models and Services tabs traded their long sidebar sub-lists for card grids: one card per provider or service, each with its icon, a one-line description, and — for cloud providers — the green badge that says a key is saved. A search box filters the grid as you type, opening a card drills into the familiar panel with a back chevron to return, and Settings now opens on Channels, where the browser extension has moved — it is a place Wolffish talks to you, not a service bolted on. The terminal’s settings menu follows the same map, so
wolffish settingsand the desktop never disagree about where a thing lives.
v1.0.266
Updates
- The automation card stops saying “none”. An automation plainly bound to a project — the
project:marker sitting right there in the schedule file — showed “project none” on its terminal card, no icon in the list, and zero attached files, which read exactly like a binding that had silently fallen off. The binding was never broken: runs always executed under their project, with its files and overlay. The daemon simply dropped those fields from what it sent — the internal job carried project, icon, files and folders, and the wire projection forgot all four. Every consumer of the job list now receives the whole job, so the icon and attachment counts are back everywhere. And the card answers the actual question: instead of a bare UUID it names the project — ”💉 Mentor Miller” — with the short id beside it, falling back to the raw id only when the project list cannot be read, and saying “none” only when the job is truly unbound.
v1.0.265
Updates
- An automation can hold any prompt now. A carefully written automation prompt with its own
##section headings quietly destroyed itself on save — in the schedule file every##line marks where one job ends and the next begins, so the prompt’s outline shattered the automation into orphan fragments: the job kept only the text before its first section, the rest sat in the file as debris, and a second attempt just doubled the mess. Traced on a real machine and closed everywhere it can happen. Pasting a prompt now demotes its##headings one level automatically —###reads as the same outline and the scheduler leaves it alone — with a clear note saying how many were adjusted; an HTML comment marker, which has no safe form inside a job, is refused outright instead of corrupting the file. And the nano/vim editing path gets the same protection: saving a block that gained extra##rows now asks — demote them, keep the split deliberately, or cancel — instead of silently splitting your automation apart. - The menu stops losing its place. Two lies the terminal’s automations screen told after a save are gone. Saving or renaming a job used to throw you back to the list: the menu kept looking the job up under its old name, concluded it had vanished, and bailed — it now follows a renamed schedule to its new heading and waits out the daemon’s own reload instead of trusting the first read after a write. And that same post-save instant could paint “Automations (0)” over a file holding live jobs. An empty list is now only believed once the file agrees it should be empty — and if the file plainly holds job headings that no longer parse as schedules, the screen says exactly that, which is the difference between “you have no automations” and “your automations are there but broken”.
v1.0.264
New features
- The terminal learns to take a real prompt. Typing anything longer than a sentence into the terminal used to be a trap: pasting a multi-line prompt fired its first line at the agent mid-paste and scattered the rest, and Shift+Enter just sent the message. The chat input is now a genuine multi-line composer. Paste is safe — a pasted block of any size lands whole, every line visible on its own row, and nothing is sent until you press Enter. Shift+Enter starts a new line on terminals that speak the modern key protocol — iTerm2, Ghostty, kitty, WezTerm and friends — and Option+Enter or Ctrl+J do the same everywhere. Changed your mind? Ctrl-C discards the draft instead of ending the session. On the Windows console, where keystrokes cannot be intercepted, a pasted block is stitched back into one message instead of being sent line by line. And pasted text is scrubbed of stray control characters, so a hostile paste can never script your terminal.
- Copy and paste for every prompt. Projects, procedures, automations and the three customization documents all gained the same pair of commands: copy puts the instructions or prompt on your system clipboard — pbcopy on macOS, the real clipboard on Windows and Linux, and over SSH it fills the clipboard on the machine you are sitting at — and paste opens a multi-line input that takes the whole replacement in one go and overwrites the field, exactly as it says. Pasting an automation’s prompt is surgical: the schedule heading and the attached file and folder markers are preserved byte for byte — only the prompt changes. Scripts get all of it for free too:
cat new-prompt.md | wolffish procedures paste <id>is a one-liner.
Updates
- Edits open in nano, not vim. Every “Edit” in the terminal — a project’s instructions, a procedure’s prompt, heartbeat.md — now opens nano by default on macOS and Linux and Notepad on Windows, even when an
$EDITOR=vimset years ago says otherwise: a modal editor you cannot leave is exactly the wrong place to land someone who just wanted to tweak a prompt. Want vim anyway? Set$WOLFFISH_EDITORand it is honoured verbatim, flags and all. Windows 11’s tabbed Notepad — which hands the file to an already-open window and returns instantly, silently losing the edit — is now detected and waited out instead.
v1.0.263
Updates
- The conversation that never goes dark. A sixteen-minute inbox cleanup vanished mid-run — prose, tool cards, even the questions Wolffish had asked — leaving both the phone and the desktop staring at a lone thinking shimmer until the run was stopped, when everything reappeared at once. That whole class of disappearance is now closed. The live view of a working turn used to be silently withheld the moment it outgrew its wire budget; it is now trimmed to fit and always delivered — older tool payloads shorten first, the words being written stay whole, and the saved transcript restores every byte the moment the turn ends. A phone that rejoins mid-run — iOS reclaiming a backgrounded app is the everyday case — no longer returns to a blank screen: it asks the desktop for the turn-so-far and redraws the prose, the cards, the prompt, and any question still waiting for your answer, which previously could be lost so thoroughly that the run would wait forever on a card nobody could see. And the desktop finally watches phone-started runs live: a turn begun on your phone now streams into the desktop window as it happens — and a window opened mid-run picks up the story instead of a spinner.
- Big conversations arrive whole. A long, tool-heavy conversation could grow past what the secure tunnel allows in a single frame — and an oversized answer does not arrive late, it closes the connection, after which every attempt to open that conversation kills the link again. Transcripts of any size now travel to your phone in chunks and arrive complete, byte for byte. An older phone build that cannot chunk yet receives the transcript trimmed to fit instead of a dead tunnel — degraded gracefully, never broken.
- Google Workspace, repaired and pinned. The Google tools had quietly drifted out of step with the CLI underneath them: creating calendar events was entirely broken, task lists, sheets reads and writes used vanished syntax, listing Gmail labels failed with a cryptic parser error, and deleting a Drive file, calendar event, or task could never succeed at all — the CLI silently refused every non-interactive delete. All of it is fixed and now verified command-by-command against the real binary, on both the version machines already have and the newest release. The installer no longer fetches “whatever is latest”: it is pinned to the exact audited version, so the CLI can never again change syntax underneath a shipped release — upgrades now happen deliberately, audit first. And if an ancient installation ever does mismatch, the error now names the fix — update from Settings — instead of sending the model guessing at shell commands.
- A browser extension that heals itself. Browsers keep an extension’s old code running long after an update lands on disk — while reporting a version that looks current, so nothing ever told it to reload. Wolffish now treats the one reliable symptom, an “Unknown command” reply, as proof of a stale build: it asks the browser to reload the extension automatically, and the cosmetic tab-label call that used to fail a task three times over now simply skips with a note. Extension v0.1.58 ships alongside, and every connected browser converges on it at the next handshake.
v1.0.262
New features
- Clicks that cannot lie. A screen session that missed a 16-pixel close button three times — and then talked itself into believing it had clicked it — was dissected frame by frame, and every hole it slipped through is now closed in Computer Use. Zoom tells you when it is not really zooming: magnify too wide a region and the result warns that the view is barely sharper than the screenshot, and names the exact narrower region that would give a true 3x close-up. The cursor is no longer marked by a ring alone: in every aiming view, thin hairlines run across the whole image through the exact cursor pixel, so “the crosshair is on it” is something you can see, not something a model can imagine — and the post-click close-up is now 3x magnified instead of 2x. Above all, every click now returns an objective change report: the screen is captured before and after the press and the pixels compared, so the result states plainly whether anything actually changed — a click that hit dead space is called a miss in numbers, not left to wishful reading. Because a slow page or a second monitor can hide a real effect, the model is also explicitly forbidden from re-clicking send-style buttons on the report alone — verify first, then act. And clicks can now carry the name of their target (“the ✕ on the GitHub tab”), which comes back in the verification so the model checks the right thing.
Updates
- The indicator is now in the model’s hands. The blue glow got a redesign and a new owner. It now reliably wraps all four edges of the controlled display — the vanishing bottom border turned out to be a macOS quirk that shoved the overlay window off the screen, found and fixed — with a narrower, livelier band that breathes while work is underway and flashes on each capture. In the center of the screen sits a small translucent notice — “Wolffish is capturing your screen”, in your app’s language, Arabic included — so there is never any doubt about what is happening. And the switch moved to where responsibility belongs: Wolffish itself turns the indicator on before its first look at your screen and off as its final act — finished or given up — instead of a timer quietly fading it away. On means watched, off means not: the signal now says exactly what it means.
v1.0.261
New features
- DeepSeek learns to see. DeepSeek released its first vision model — DeepSeek-V4-Flash-Vision-Exp — and Wolffish supports it from day one. Choose it as your Brain and DeepSeek finally sees what you send: the photos and screenshots you attach to a message, and — the part that matters most — the screenshots its own tools capture, which means computer use and browser control now genuinely work on DeepSeek instead of being a blind model clicking from imagination. Every path was verified live against the real API before shipping: it reads attached images, it reads tool screenshots, and it keeps the full V4-Flash character — the same 1M context, the same thinking modes, at the same price. The model shows up in Settings wearing its vision badge, and the no-vision warning in the Computer Use panel clears itself the moment you pick it.
Updates
- DeepSeek prices, as they really are. DeepSeek moved its whole lineup to peak and off-peak billing — off-peak hours cost exactly half — and the pricing table in Settings had quietly fallen behind. It now shows the true current ranges for every DeepSeek model, low end first, so what you read next to a model is what you would actually pay.
v1.0.260
New features
- Computer use that proves its aim. Controlling the screen used to be an act of faith: screenshot, guess the button’s pixels, click, hope. The whole loop is rebuilt around verification instead of hope. Every screenshot carries a crosshair marking exactly where the cursor is; a small or crowded target is no longer squinted at — a new zoom re-captures just that region at native resolution, so a tiny control becomes dozens of pixels wide before it is ever clicked; and every click, move and scroll comes back with a magnified close-up proving precisely where it landed, so a miss is visible immediately and corrected in the close-up itself instead of by guessing again on the full frame. The hands improved with the eyes: a new drag action for drag-and-drop, sliders and text selection, shortcuts written the way you’d say them (
cmd+shift+s), and Arabic, emoji and long text arriving exactly as written instead of being mangled key by key. Multi-monitor setups need no arithmetic — coordinates always mean the image being looked at — ultrawide screens stay readable, and the display being controlled wears a soft blue glow so you always know Wolffish is at the wheel; the glow is invisible in its own screenshots and fades when the work stops. Older screenshots are retired from the model’s context as fresh ones arrive, so a long session grounds its next click on the current screen and stays affordable — and if your selected Brain cannot see images at all, the Computer Use panel now says so plainly instead of letting a blind model click by imagination. - Skills it builds now carry proof. Wolffish can author brand-new tools for itself — and now it both offers to when it spots you repeating a pattern, and is held to a standard when it does. Every skill it creates is stamped as its own work and wears a Wolffish badge in Settings → Capabilities, distinct from Official and imported ones — and a freshly built or freshly edited skill is visibly Untested until one of its tools succeeds in a real call. The badge cannot be talked away, only earned, and it clears live the moment the first genuine call passes.
- It knows you’ve been away. Come back to a conversation after three weeks and Wolffish used to answer as if you’d never left — treating the transcript’s “today”, prices and running state as still current. Resuming after a real gap now tells the model how long it has been — “about 3 weeks ago”, with the exact timestamp — and reminds it that the older turns spoke from an older now, so it re-checks what matters instead of confidently quoting the past.
Updates
- The composer is one card. The chat input is redrawn as a single quiet card: the message box is the surface, with New Chat and your project on the top edge, the model switch and usage meter in the footer, and attach, folder, mic and a round Send at the end. Nothing moved home behind your back — every control kept its exact behavior; only the chrome dissolved. The phone got the same redraw, plus something its screen never had: the model about to answer, worn as a chip you read at a glance and tap to change, with provider and model pickers flattened into rows of chips — the whole list on one slidable line — and, on iPhone, a floating chevron that finally puts the keyboard away without costing you a word of the draft.
- Learning from your words, not your grades. The 0–10 turn scoring is retired everywhere — the rating bar above the composer, the “rate this reply” invitations on Telegram and WhatsApp, the bare-number votes, the terminal’s
/rate, and the switches that governed them. Grading every answer was homework, and the numbers told the nightly reflection less than what you already say naturally in conversation — so reflection now reads exactly that, your own words in the transcript, when it reviews each settled conversation and folds the lessons into its playbook. A number you type is simply a message again, on every surface. - No more stray gibberish at the end. Certain models occasionally “say nothing” by writing their internal end-of-sequence marker as visible text — a literal
<|eos|>in your chat or stuck to a conversation title. Wolffish never rewrites what a model says, so it fixes this where it belongs: it notices the leak and tells the model, and ending a turn in genuine silence is now explicitly recognized as valid, so the model is never pressured into filler. The link to a paired phone grew more patient alongside — a connection that is merely busy for a moment is asked twice before being replaced, ending a whole class of needless mid-use reconnects, and on the relay a control-plane hiccup now costs the notification it was carrying, never the tunnel.
v1.0.259
New features
- See what Wolffish sees. Wolffish works inside your real browser — reading pages, filling forms, clicking through whole flows — and until now every screenshot it took along the way was for its own eyes: on your phone, on Telegram or WhatsApp, a long browser task was a wall of silence with an answer at the end. It now shows you the moments that matter, as they happen: the results page it was hunting for, a form filled in just before an important submit, the confirmation right after, the final state that proves the job is done — sent into the conversation you’re actually in, an image in the app and a real photo on Telegram and WhatsApp, delivered mid-task with a one-line caption. Surprises get the same treatment — an error page, a login wall — so when it reports a blocker, you see the blocker. And it is deliberately not a firehose: routine navigation and scrolling stay private, so the handful of shots that arrive are the ones that tell the story.
- Workflow runs show their pages too. In a workflow run the browsing is often done by agents — and only the master speaks to you. Agents now put their milestone screenshots on the record, flagged as worth seeing, and the master relays the telling ones into your chat as the run progresses. The live card has always shown that things are moving; now you also see what they look like.
v1.0.258
Updates
- Queued behind nothing at all. Press Run now on an automation and you could be told it was queued — while the page in front of you showed nothing running whatsoever. Two separate faults were holding slots no work occupied. An automation was tracked by its position in the heartbeat file rather than by its name, so editing the file mid-run could hand one automation’s identity to another — every later press folded into a run that was never its own. Automations are now tracked by their heading, which an edit does not move. Quieter and worse: a run announcing itself to a window mid-close could fail before the slot was booked for release, and the slot stayed held for the life of the app — three of those and every automation, procedure, compaction and reflection run queued forever behind work that finished hours earlier. A slot is now released no matter how its announcement goes.
- Told what you are actually waiting for. “Queued” had been doing the work of two very different answers. Waiting for a slot means it will run on its own, shortly. Folded into a run already going means there will be no second run at all — the button did nothing, by design. Wolffish now says which, in the app, on your phone and in the terminal alike — a waiting automation also says how many runs are holding the pool, worth knowing because compaction, reflection and procedure runs share those slots and draw no card unless asked. The model is told the same thing just as plainly, so it stops re-firing an automation that was already lined up.
- The project prompt you came to read. A new conversation inside a project used to greet you with the project’s name and the first two lines of its instructions, trailing into an ellipsis. The empty chat now shows the instructions in full, in the same scrollable block the Projects page uses — there to be read before you type.
v1.0.257
Updates
- Step zero of pairing. Pairing your phone has always assumed the one thing the panel never helped with: the app already being on the phone. Wolffish Mobile lives on the App Store and Google Play, and Settings → Channels → Mobile now carries a “Get the app” card holding the two links themselves — the App Store for iPhone and iPad, Google Play for Android — so the path finally reads the way it runs: install, open, scan, with nothing to hunt for in between. The project’s README on GitHub hands out the same two badges, for anyone who arrives that way first.
v1.0.256
Updates
- The terminal command that never said anything. Every Windows user who typed
wolffishgot the same answer: nothing — not an error, silence. Wolffish ships as a windowed application, and Windows hands a windowed program no way to write into the console that started it, a detail no wrapper can paper over. A small console companion now sits beside the app, whose only job is to hold a real terminal open and hand it to Wolffish — and the command finally behaves like a command:wolffishopens a session and stays open instead of exiting before you reach the keyboard, piping works in both directions (type notes.txt | wolffish -p "what changed?"genuinely sends the file), colour, box-drawing and the true width of the window come back, and a secret typed at a prompt is hidden again rather than left in your scrollback. The settings panel also stops accusing another program of having taken the name — it was reading the wrong answer out of Windows, and the command was correctly installed the whole time. - And Git Bash finds it too. Git Bash looks for a file named exactly
wolffish, while Windows’ own shells look forwolffish.cmd— the folder was on the PATH, but as far as bash was concerned the command did not exist. Wolffish now installs both, so cmd, PowerShell and Git Bash each find the one they are looking for, and a Git Bash session gets a real terminal bridged in — colours, prompts and typing all behave, while pipes and redirects are left exactly as they were.
v1.0.255
New features
- The card that stopped showing up uninvited. Wolffish runs work in the background on your behalf — an automation, a procedure the model started, the nightly reflection, the daily and weekly compaction passes — and every one of them used to float a live card over your chat while it ran, whether or not you had any interest in watching. Every one of those cards is now off by default, and each family has its own switch: automations and procedures share one in Settings → Channels → In-app, compaction has its own under Knowledge → Compaction, reflection under Knowledge → Reflection. Off changes exactly one thing — whether the card appears. The run still happens, still logs, still reports on its own page, and a failed run still says so. The switches take effect the instant you flip them — on the run already in flight — and they follow you across surfaces: flip one in another window, or from your paired phone, and this app agrees at once. All four are editable from the phone and the terminal, alongside the settings they sit beside.
- Your phone gets its own answer. A card worth having on your desk is not automatically one worth having in your pocket: the paired phone carries its own switches, separate from the desktop’s — so a background run can announce itself on the machine you are sitting at and stay silent on the phone, or the reverse. Off by default there too. And procedure runs are now shown at all: they ride the same background pool as everything else but were previously filtered out completely — they now appear like any other run, under the automations switch, because “is something running for me right now” is one question, not two.
v1.0.254
New features
- Reading the fine print. Wolffish could show a model a picture, but only ever one picture at one size: the whole frame, shrunk to fit 1024 pixels — enough to recognize a room, useless for a receipt, a code screenshot, a chart’s axis labels, a serial number. Now the model chooses the view:
image_viewtakes a crop region, a resolution, and a lossless PNG option for anything made of text, so it can pull the part that matters out of a twelve-megapixel photo and read it at native sharpness. A crop is not only clearer, it is cheaper — the price follows the pixels actually sent, not the size of the file on disk. None of it needs your attention: ask about a detail and the model decides how close it has to get, and a view too big to send is shrunk automatically instead of vanishing quietly on the way out.
Updates
- What it actually received. Ask a model whether it really saw your photo and it would hedge — for a good reason: nothing ever told it. The tool now states plainly that the pixels are attached, and that they last for this turn only, so instead of answering later questions from a fading description it opens the image again. A provider that refuses a picture for some unrelated reason no longer blinds a capable model for the rest of the session — Wolffish tries pictures again every so often — and the running estimate of how much room images take up was overstating them roughly twenty-five-fold, which in an image-heavy conversation could trigger a needless tidy-up of a context that was never full.
v1.0.253
Updates
- The screenshot it described without ever seeing. A screenshot, a photo opened with
image_view, a page captured in the browser — Wolffish has been taking them for a long time. What it had not been doing, on most of the models that can see, is showing them the picture: the caption went out, the pixels stayed home. Claude, ChatGPT and anything through OpenRouter already received the image; Grok, Kimi, Qwen, StepFun and GLM were working from the label alone, and so were the vision variants of MiniMax and Mimo. They now get the photograph itself, inline — the bare MiniMax and Mimo chat models still receive the caption alone, because they cannot see at all. A capture too large to send stays on disk with its path in the caption rather than being forced onto the wire to fail there, and a provider that refuses pictures inside a tool result no longer kills the turn: Wolffish retries without those pictures, then without any, and remembers what worked for the rest of the session. - Your appearance choice survives a language switch. On the phone, switching the app’s language could bring it back in your phone’s colours rather than your own — Light chosen on a dark phone returned a dark app, with Light still selected in Settings. The app now confirms the scheme it asked for is the one actually showing before it appears, so your choice comes back with your language.
v1.0.252
Updates
- The reconnect that waited half a minute for a reply it already had. The wake probe that made reconnecting instant could, now and then, leave you watching the opposite: a phone that came back, reached the relay, received everything it needed — and sat for thirty seconds before admitting it was connected. Every handshake arms a thirty-second deadline, and when an attempt was replaced mid-flight, nothing cancelled the abandoned attempt’s timer: half a minute later it fired and emptied the mailbox belonging to its own successor, so the reply landed in a slot nobody was watching. A handshake now only clears the slot while the slot is still its own — the reconnect finishes the moment the relay replies, which is what it should have been doing all along.
v1.0.251
New features
- Grok 4.6, and a thinking dial that finally turns. Grok 4.6 joins the model list and becomes the xAI default — 500K of context, vision, frontier-class, at the same price as the 4.5 it succeeds. It arrives alongside a correction reaching every Grok you already use: Wolffish believed the model’s thinking control was a two-position switch, so the three settings you can pick — On, High and Max — were squeezed onto two rungs and Max quietly sent exactly what High sent. Sweeping the parameter against the live API told a different story: it is a five-rung ladder, with a rung above High that Wolffish had never once used. The three settings now land where they belong — Max reaching the top of the ladder at last, and becoming a real option on 4.5 and 4.3. Two catalogue figures were corrected against the API’s own answer while we were there: the 4.20 pair holds a million tokens of context, not the 256K we were showing.
- DeepSeek’s Max was talking to nobody. The same fault, deeper and quieter: DeepSeek’s thinking effort was sent one level too far inside the request, where nothing complains and nothing listens — so the setting simply never reached the model. The tell had been sitting in our own notes for months: High and Max measured less than a third of a percent apart, which is not two settings behaving similarly, it is two settings that were never sent. With the field in its correct place and measured live, the difference is the one you’d expect — Off thinks not at all, High thinks hard, and Max thinks roughly twice as long as High on a problem that rewards it. DeepSeek V4 Pro also takes its rightful place at the head of the list as the frontier model of the pair.
Updates
- Your phone reconnects the moment you look at it. Bring the phone app back after it has been away and you could meet ten seconds of nothing — a connection that read as healthy and answered nothing, because phones are suspended mid-breath and the link dies with nobody awake to notice. Returning to the app now sends a probe and holds the link to a reply within seconds; a link that fails to answer is replaced immediately, with no backoff to sit through, and the app starts reaching for your desktop while it is still starting up. Walking out of Wi-Fi range onto mobile data no longer strands it either — the app watches for the network moving and reconnects the moment it does. Keepalives are held to a ten-second answer rather than inferred from a long silence, and a first-time pairing by code that loses its connection mid-way now redials as the pairing it actually is, instead of asking you to re-pair a device that only needed to reconnect.
v1.0.250
New features
- Your phone stops being quiet. Wolffish could always buzz your phone, and almost never did — its own instructions rationed notifications, so work finished, automations ran, findings landed, and your pocket stayed silent. That is now inverted: every turn ends with one notification carrying the actual result — the number, the outcome, what’s next, and a tap that opens the very conversation it came from — because five minutes later you are somewhere else, and a notification reaches a closed app, a backgrounded app, or a phone with no signal that gets it the moment signal returns, which no open window can. A blocker, a failure, or a finding worth acting on no longer waits for the end either: it goes out the instant it happens, mid-run, so the question that stopped the work reaches you while it still matters. Long work announces itself when it starts, a scheduled digest closes with its own, and the bar for the words rose with the count: “Task completed” is not a notification — “Sheet rebuilt — 214 rows, 3 broken dates fixed” is.
- Louder, not noisier. More notifications are only better if none is a repeat. A Telegram or WhatsApp reply never gets a second buzz — that message already arrived on the same phone with its own notification, so there the push is saved for what a chat message cannot tell you: a blocker, a failure, a finding. The same news is never sent twice, and the one genuinely dangerous case is handled at the root: when the phone never confirms, the delivery is unknown rather than failed — the notification is most likely on your lock screen already — so it counts as sent instead of being tried again, which was the one way a single buzz could ever become three. Small talk and bare acknowledgments still pass in silence, and an instruction to stay quiet outranks all of it.
Updates
- Pushes that actually arrive. The policy inversion would have rung hollow on phones the pushes couldn’t reach. Android builds were missing the registration that makes remote delivery possible at all — a notification landed only while the app sat open and connected — and they now carry it: a run that finishes, fails or needs you reaches the lock screen with the app closed, backgrounded, or the phone asleep. An iPhone’s registration could stall indefinitely on a question iOS is free to leave unanswered; it now goes out within seconds, with a token or without one, and lock-screen delivery switches itself on the moment the token arrives. And on the relay, Android pushes go out at FCM high priority, so a sleeping phone shows them now rather than when it happens to stir.
v1.0.249
Updates
- Copy from the conversation, the way your hands expect. Select a line of a reply, right-click it — and nothing came: the app-wide menu answered only where text could be edited, while the conversation itself, the place most worth quoting, had no menu at all. Right-click now speaks wherever text merely sits: a message bubble — yours or the reply’s — offers Select all and Copy, Copy takes exactly what you highlighted (with nothing highlighted, the whole bubble), the expanded Reasoning text answers the same way, and a selection sweeping several messages copies whole from wherever you right-click it. The empty parts of the window stay silent, and every editable surface keeps its fuller menu, spelling suggestions and all.
v1.0.248
New features
- Your desktop’s updater, live on the phone. The phone’s Updates screen could say what a new version changed, but the desktop’s self-updater — the machine that actually fetches one — worked invisibly on the far end. It now mirrors to the phone live: checking, downloading with a moving progress percent, verifying, ready, installing — every move pushed the instant it happens, the same state the desktop’s own panel renders, so the two screens can never tell different stories. A phone that connects mid-download is handed the current picture up front, and a phone that meets a phase it doesn’t know — an older app against a newer desktop — chooses to show no card rather than a wrong one.
- Check and install from wherever you are. The two acts that matter became taps. Check from the phone and it is the desktop’s own check — the exact handler its panel and the terminal invoke, guards included — and a found update starts downloading on its own, progress ticking on your screen. Install from the phone and the desktop answers before it acts: the confirmation leaves the line a beat before the graceful shutdown closes it, you watch the connection drop and re-form, and the new version introduces itself the moment it reconnects. The buttons keep their word: a desktop that cannot self-update at all says so honestly and the phone hides controls that would have to lie, the Check row holds its place dimmed while no desktop can answer instead of vanishing with every dropped link, and an install tap racing a state change is refused quietly instead of blooming error cards on two screens at once.
v1.0.247
Updates
- The failure that read as a normal reply. A turn that died mid-run — a provider outage, an expired key — showed its error card on the phone while the run was live; open the same conversation again and the failure had vanished into a clean transcript, because the stored copy of a message never carried how the turn ended. Every message now travels with its stop reason and its error, so a failed turn stays visibly failed however you arrive at it. The card itself grew up too: the phone renders the desktop’s own provider error card — the provider’s logo, a plain reading of what went wrong, a View details fold with the verbatim trace — and a Try again button that doesn’t blindly re-send: it opens a fresh turn that tells the model what broke, so it checks what already finished and continues instead of redoing it.
- On your phone from the first instant. Start a run the phone didn’t start itself — an automation firing on schedule, a Telegram or WhatsApp message — and the phone’s conversation list used to improvise a stand-in row with no real title, icon or origin, because a conversation’s details were pushed at every stage of a run except its start. The identity now rides every phase of a run, start included, so the list shows the real title, icon and origin from the moment a run begins — and History merges in the turns running right now, pulsing chip and all, instead of waiting for the first save.
v1.0.246
Updates
- Paste anything into an automation. An automation’s instructions live in a markdown file with a grammar of its own —
##begins the next automation, a dashed---separator is structure, HTML comment markers wrap a switched-off job. Paste a prompt carrying any of those and everything after the first heading silently vanished, at display and at run time alike. The editor now escapes those lines the moment it saves — each respelled in the closest form the file reads as plain text, proven against the engine’s own parsers, never growing on re-save, and byte-identical to what the phone’s editor already writes. The agent’s own automation tools take the other road, as they always have: they decline the prompt and say how to rephrase it — now covering the dashed separator too. - Workers save; Wolffish delivers. When a workflow run spins up background workers, each worker used to carry the delivery tools — and one read the standing “send the file when it’s done” instruction meant for Wolffish itself, and dropped a file straight onto the Desktop unannounced. Delivery is now the master’s act alone: workers have no send tools at all — withdrawn, not merely discouraged — their marching orders say files are saved under the workspace and reported by path, and Wolffish decides what actually reaches you.
- The failure report that missed the point. Export a diagnostic bundle over a conversation whose background worker had failed and the front page could say “FAILED: 0” — technically true of the transcript, useless as a diagnosis, because a worker’s stumbles live in task records the bundle copied but never read. The bundle now reads every task record step by step: a separate task-steps line in the metrics, each failed step in full with its arguments and untruncated error, and the AI opinion that rides in the bundle is shown the same evidence. A worker that stumbled and recovered still ends SUCCEEDED — which is exactly why the bundle checks steps, not statuses.
- The number you typed into a menu that wasn’t ready. In the terminal, a line typed into the gap between a menu’s questions found no question waiting, fell through to the chat queue, and replayed as a message to the live agent the moment the menu closed — a double-tapped Enter reprinted the menu, a stray “2” became words nobody wrote. Typed-ahead lines now wait for the flow that owns them and whatever is left when the menu closes dies with it, and nested prompts hold the cursor behind a visible input bar instead of parking it on a bare line that looked exactly like a stall.
- Buttons that keep their word. Press Save and half the app’s buttons used to swap their label mid-flight — “Saving…”, “Deleting…”, or just ”…” — the word jumping, the button resizing, for work that finishes in a blink. A working button now simply keeps its label and dims until the work lands, on the desktop and the phone alike; where the wait is genuinely long — a model downloading, a channel connecting — the real progress indicators are untouched. And the Model page’s sub-nav clouds now tint green for providers holding a saved key, so one glance says which clouds are ready.
v1.0.245
Updates
- The voice-reply switch found its home. Yesterday the spoken-reply rule grew a switch on the Text-to-Speech card; today it lives where it belonged all along — the Wolffish page, with the app-wide preferences — because whether a voice note earns a spoken answer is a preference about how Wolffish answers you, not a fact about the speech engine. The wiring beneath it was cut to one honest rule: the switch decides whether the voice-reply instructions exist at all. On — the default — and every conversation carries the standing policy along with its every-step reminder; off, and the instructions are gone entirely, not flipped into a paragraph explaining what won’t happen. Flip it from the desktop, the terminal or your phone, and the other surfaces follow live.
- Settings that say what they change — and what they don’t. The Appearance page kept its two choices behind dropdowns with no explanation. Both are now the segmented controls the rest of Settings speaks — System / Light / Dark for the theme, English / العربية for the language — with a plain sentence underneath each saying what it changes and, just as deliberately, what it doesn’t: these are display settings only. The theme never touches the model, and the language the agent replies in follows, as it always has, whatever language you write to it in.
- Start of week, now from the phone. The preference could be read from the phone but not changed there. It can now, and the edit is the desktop’s own: it lands in the exact handler the desktop control calls, refuses anything that isn’t Sunday or Monday, and announces itself so an open desktop window adopts it without a refetch.
v1.0.244
New features
- The voice reply grew a switch — and teeth. The last release made a spoken prompt earn a spoken reply by default; now that default is a switch you own — and the rule itself grew teeth. It used to live as a paragraph buried in a very long prompt, and the failure was exactly the one you’d guess: the rule got read, and the reply came back silent text anyway. The instruction is now built from the live setting on every turn — what the agent is told can never contradict what the switch says — and a voice-prompted turn carries a reminder at the tail of the request on every single step, the position a model attends to most. Files, tables and code still arrive exactly as a typed turn would deliver them; the memo speaks the answer over them. Your own words still beat everything — say “reply in text” and it’s a text turn.
- The transcriber stopped guessing your language. Speak a short sentence and automatic language detection could mishear the whole clip — the failure that forced this was an English voice note coming back transcribed into Arabic script. Transcription is now pinned to a language you choose: a Language setting on the Speech-to-Text card, a searchable list of 100 languages, and Auto-detect demoted to an explicit opt-in for people who genuinely live in two tongues. Every voice note from every surface follows the pin, naming a language for one specific file still wins for that file, and the default model moved up a size — from base to small — because the smaller model’s hearing was part of the problem. The same 100 languages appear everywhere the setting does: desktop, terminal, phone.
Updates
- Fifteen seconds means fifteen seconds. Ask for “a 15-second vertical clip” and what came back was six seconds of landscape: the video generator never reads format words out of prose — length, quality and orientation are parameters of their own, and specs left in the prompt silently produced the defaults. The agent now treats your specs as orders, not scenery — a named length goes in the duration parameter, named quality in resolution, “vertical” or “for Reels” in the aspect ratio — and this holds in both Director modes, because a cinematic rewrite must never eat a spec. Impossible asks stopped being silent too: past the 15-second ceiling the agent says so and offers one 15-second clip or a sequence to stitch, and a task’s confirmation echoes the settings actually in flight while cancelling still saves the credits.
v1.0.243
New features
- Talk to it and it talks back. Speak instead of typing — the in-app mic, a Telegram or WhatsApp voice note, your phone — and Wolffish now answers out loud by default. A conversational exchange comes back as one voice memo that is the whole reply, not a memo trailing a wall of text that restates it; a turn that produced real things — files, tables, code, charts — still delivers them exactly as a typed turn would, then closes with one voice memo speaking the answer over them. The reply arrives in the language you spoke: every voice note carries the language the transcriber heard, and the agent treats that as final, so an English question gets an English answer even if the rest of your life with it runs in Arabic. Your words always win — say “write it down”, or keep a standing preference for text, and it is a normal typed turn. One companion fix rides along: the agent is told, firmly, that your voice note is already transcribed, so it never wastes a turn running speech-to-text on the message you just spoke to it.
Updates
- A terminal that explains every setting.
wolffish settingswalks the same page → card → row tree as the desktop’s screens, but two thirds of its rows stopped at a bare label — fetched through translation files where a missed lookup printed a raw key likechat.modewhere a name should be. The words are now written directly where the settings are defined: every one of the 53 rows carries a real label and a sentence or two of description — what the setting does, what the default is, what the trade is. One trade is made deliberately and worth saying plainly: the terminal is an English surface now. The desktop app still speaks your language, Arabic included — only the terminal stopped translating, and in exchange nothing in it can ever print a key instead of a word.
v1.0.242
New features
- Every row your phone shows now takes an edit. The phone has been able to read the desktop’s settings for a while; editing was another story — most rows were a look, not a control. The write side is there now. The Model screen edits from the phone — chat mode, the thinking chip, local-only, the local model, the cloud provider and its model, even a newly typed provider key — and every one routes into the exact handler the desktop’s own control calls: same persistence, same live update, same announcement, so an open desktop window adopts the change without a refetch. The details carry the same care: a key shows as a twelve-character preview that round-trips on every edit, so a masked value can never overwrite the real credential it abbreviates, and a local model pick is checked against what is actually installed — refusing a stale row beats silently starting a multi-gigabyte download. MCP switches, the compaction schedule and the in-app feed’s verbosity flip from the phone as well, and the Telegram and WhatsApp cards became editable end to end — allow-lists, auto-refresh, stale hours, verbose — through the same code path the desktop takes, so a change that touches the connection restarts a running bridge and a preference-only change deliberately does not. Two switches stayed home on purpose: the bridge power switches, because starting a bridge process is this machine’s act, and the phone shows them as what they are — status.
Updates
- The QR a packaged install could never draw.
wolffish pairends in a QR — and in every packaged install, on every platform, it ended in “no QR renderer available” and a wall of raw text. The terminal client ships as loose files next to the app archive while the QR library lives inside it, so the terminal’s own import failed everywhere except a development checkout — exactly where nobody would notice. The daemon now computes the matrix and the terminal only draws it, and a terminal updated ahead of its daemon falls back to the old raw-text payload instead of dying, because a pairing flow must never dead-end. - Bad news in one shape. When an update failed to download, the Updates page grew a red box of its own design — a title, a paragraph, the raw error dumped at full length. The chat already solved this: the provider error card, with its one-line summary, its View details fold, and a detail block you can copy with one click. The update failure now is that card, with retry sitting beside it — one design for “something went wrong”, wherever you meet it.
- The agent’s manual caught up. Two lines of the agent’s own instructions had quietly gone stale: they still described phone notifications as budgeted — one per phase, five per run — though nothing has counted or capped a send since v1.0.239; restraint is a judgement the instructions teach, not a meter that runs out, and now they say so. And where a notification wants its tap to land on the conversation that produced it,
wolffish://chat?id=currentnames this run’s own conversation and the app resolves it — one less lookup, one less way to point a tap at the wrong place.
v1.0.241
New features
- The command is there when the install finishes. Installing Wolffish on a Linux server used to end with homework: add a directory to your PATH, restart your shell, and launch the app once so it could write itself a launcher — and on a server the middle step was circular, because the thing you had to launch was the thing you were trying to reach. The
.deband.rpmnow ship thewolffishcommand themselves, alongside the app binary: it exists the moment the package manager finishes — no first launch, no PATH line, no new shell, the same command for every account on the machine, and removed cleanly when the package is. The AppImage has no package manager to do this, so there the installer writes the PATH line for you — once, never twice however often you reinstall, and--no-modify-pathif you’d rather it kept its hands off your dotfiles. And where the terminal used to be told to start the agent by hand, with a flag and an ampersand it had to explain, it now says the only true thing left: runwolffish— the agent starts itself, in the background, with everything a root server needs already applied. - Unread counts that know what you’ve read. A notification about a conversation now feeds a per-conversation unread badge on the phone: on the conversation rows, summed on the floating menu button, and as the number on the app icon — correct even before the app has woken, because the relay stamps its running count onto every platform push. Clearing is reading: open the conversation and its count is gone, tray notifications included; delete a conversation anywhere and its count goes with it. The phone’s own total is authoritative — the moment the app runs, it overwrites the relay’s stand-in absolutely, so the two can never drift apart.
Updates
- Disconnecting leaves nothing behind. Unpairing the phone used to be thorough about the phone and forgetful about the middle: the relay kept the device’s push registration, and a later notification would still be flung at a phone that had left. Disconnect now runs in the right order — badges cleared everywhere, the relay’s count zeroed, then the relay told to forget the device registration entirely — and only then does the phone drop its keys and wipe what it synced. Every later notification addressed to that phone is answered dropped, honestly, and pairing again starts from a clean slate at badge zero.
v1.0.240
Updates
- The install that stopped saying it worked.
curl … | shon a fresh Linux box could end with “installed successfully!” on a machine that had no Wolffish on it whatsoever — a package manager’s own way of fixing an unsatisfiable dependency is to remove the package it just unpacked and exit reporting success. The installer now asks dpkg or rpm whether the package is actually installed and configured, which is the only honest question. It also refreshes stale package lists and retries before concluding anything (a fresh VPS image is often oneapt-get updateaway from working), never lets the package manager remove things to make an install succeed, cleans up after itself rather than leaving a half-unpacked package that breaks every lateraptrun, and when it genuinely cannot proceed it names the libraries that are missing. - An agent that starts on a server. Two invisible faults kept Wolffish off the one machine the terminal exists for. The package never declared libasound2 — Electron links ALSA at load time whether or not the machine has a sound card, so the app died at exec on the minimal image a server starts from; it is now declared, and versioned, which is what makes it resolve on Ubuntu 24.04, where the package was renamed and the old name became ambiguous. And Chromium refuses to run as root unless
--no-sandboxarrives on the command line — before a single line of app code runs, so appending it at startup never counted. The flag is now on every path that starts the app: the menu entry, the systemd unit, the autostart entry, and the daemon the CLI spawns. - An AppImage that outlives its own mount. An AppImage runs from a temporary mount with a different name every launch — and everything Wolffish wrote for later (the
wolffishcommand, the systemd unit, the autostart entry) recorded that doomed path. All three now record the.AppImageitself, the CLI client is lifted out of the image so it still exists once the app has closed, the whole install lives under~/.wolffishsorm -rf ~/.wolffishremains a complete uninstall, and on a machine that can’t mount one at all — no FUSE, a container without/dev/fuse— the launcher unpacks and runs instead, carrying that decision into the shim and the service so nothing disagrees with the installer that just got them working.
v1.0.239
New features
- Wolffish in a terminal. Wolffish has always needed a window, which has always meant needing a screen — so the machine most likely to run an agent around the clock, a server you reach over SSH, was the one machine it could not run on. There is now a
wolffishcommand, and it is not a smaller second Wolffish: every command it has is a call into the same code the desktop windows call, so a setting changed there is the setting here, carrying the same label and description, in your own language, Arabic included. Typewolffishfor an interactive session orwolffish "…"for a one-shot answer; pipe context in, attach files by path with-f, resume old conversations, read and change every setting — provider keys typed hidden, never landing in shell history — switch the model, edit Soul, User and Agents, run procedures and automations, and pair a phone, WhatsApp or Telegram from the same command. The important part is what the terminal is: a view, not the app. Wolffish runs as a background process and the command attaches — close the terminal or drop the SSH connection and the turn keeps working; a tool call waiting on your approval parks instead of failing, answerable when you return or from your phone. Replies arrive as rendered markdown — headings, tables, bordered code blocks — andwolffish settingswalks the settings the way the app does, page → card → setting, with blank always meaning up. Editing works even on a box with nothing installed: your$EDITOR, else nano or vi, else a built-in editor with no dependencies at all. - A service for a machine nobody logs into. Autostart is the app’s own business on every platform now — a login item or launchd agent on macOS, a login item or Task Scheduler task on Windows, an XDG entry or systemd user unit on Linux, where the toggle used to silently do nothing. It also gained the mode a server needs: a background service that starts with the machine, with no session and no window at all — which is what keeps automations firing and channels answering on a box nobody has logged into, and what the terminal attaches to. On Linux, lingering is enabled alongside the unit, because a user service without it dies the moment your SSH session ends; a unit missing it is reported as a warning, not a healthy state. The whole route — install script to headless boot to systemd to the CLI attaching — is verified end to end on a pristine Ubuntu 24.04 VPS, and with a paired phone as the daily interface, a headless server is not a degraded Wolffish but the desktop experience with the desk removed.
- Automations and procedures bring their own files. A project could carry files; the automations and procedures that do the unattended work could not — where it matters most, since nobody is there to attach anything when they run. Both now carry attached files and working folders of their own, editable from the app, the terminal or your phone. An attached file is copied in, so a run can never break because you moved the original; working folders are deliberately not copied — every run gets a fresh listing of the real folder as it is that moment. A project’s folders now flow into everything that runs inside it, and each of the three got a full-height prompt editor that scrolls instead of cutting off. On the phone, the same files and folders ride the workspace cards — a folder chip wears the full desktop path, typed and validated against the desktop’s own filesystem.
- A memory you can correct. Everything Wolffish believed long-term was, from its own side, write-once: telling it “that’s wrong, she moved” earned an agreement in prose and changed nothing on disk. It can now add, amend and forget across all nine files that carry its long-term self — its playbook, your standing instructions, its character, your profile, and the five knowledge files. The rule it works to is forget beats contradict — two entries that disagree is worse than one that is missing — and the correction lands in the same turn you say it, not tonight. Every write keeps the previous version, so any change is one step from undone, and it removes only what you challenged; pruning by its own judgement is still the nightly clean’s job.
Updates
- The channels it could actually see. The agent decides how to reach you by reading its own channel roster, and that roster named Telegram, WhatsApp and the window — not your phone, and not the terminal. Both are on it now, with the distinction that makes the phone’s row worth having: paired is not connected, so a phone in a pocket reads as down-but-paired, never gone. Most consequential of the three: on a headless box, in-app chat stopped claiming to be available — it was telling the agent someone was there to answer in a window that does not exist.
- One notification, not three. A notification the relay never answered for was reported as failed, and failed is retryable — so one decision became three buzzes on a phone in someone’s pocket, each with a fresh id nothing could fold together. An unanswered send is now reported as unconfirmed rather than failed, and the tool declares its own failures non-retryable, so nothing re-fires a send on its own. The per-run caps that stood in for restraint went away in the same change: whether a second interruption is worth it is a judgement rather than a quota — the agent’s to make, with the reasons spelled out where it reads them.
- A turn from the terminal, seen everywhere. Terminal conversations wear their own origin mark in the desktop’s History and rail — and on your phone, where the origin glyph now rides the very first live update, so a conversation the phone has only ever seen running still shows where it came from. A phone whose tunnel comes up mid-run also finally knows the run exists: it asks the desktop what is running on every connect, so a busy conversation shows its stop button and streaming pulse instead of an idle composer, and the rating bar waits for the desktop to actually say the turn ended. Answering an automation’s conversation from the terminal now unseals it like every other channel, and long-lived terminal conversations grew the rolling summary they were missing — without it, every reply replayed the whole transcript and cost more each turn, precisely on the headless box where terminal conversations are the long ones.
- Linking WhatsApp where a QR won’t fit. A WhatsApp QR is a 49×49 matrix — 27 printed rows against the 24 an SSH window gives you, unscannable no matter how it is drawn. WhatsApp can now be linked by phone number instead: give it the number and it prints the eight-character code WhatsApp shows under “Link with phone number instead” — the route that works in a window too small to hold a square.
- Arabic, whole again. Eighteen strings had no Arabic and quietly fell back to English — the entire Debugger Mode card, every message the updater shows when an update fails, five browser actions. All translated, and the two locales are back in exact parity. The name is settled too: Arabic had been writing it two ways, and it is وولفيش everywhere now — the app, the tray, the browser extension and the back changelogs alike.
v1.0.238
Updates
- A rating bar that knows when it’s done. The 0–10 strip above the composer asked you to score a turn, and then went on asking — an answered question still sitting over the composer. It retires the moment the turn has a score now: one click, the vote is in, the strip is gone. And because a score is a fact about the turn rather than the device that cast it, the bar goes away wherever the vote came from — the window, your phone, or a bare number typed into Telegram or WhatsApp — without waiting for anything to reload.
- Text you can actually take. On the phone, long-press any bubble or tool card to select from the rendered reply — in place on Android, and on iPhone in a dedicated sheet where you drag across the styled text and copy exactly the part you need, instead of fighting a screenshot.
v1.0.237
New features
- A notification that opens what it’s about. A phone notification could always take you somewhere when you tapped it, but the agent had to name the destination by id — and a run does not reliably know the id of the conversation it is answering in. So it either went looking for it or guessed, and a guessed id opens someone else’s transcript on your phone; or it left the destination out altogether, and the tap merely opened the app wherever you had left it. It can now simply ask for this run’s own conversation (
wolffish://chat?id=current), and the desktop fills the id in from the run itself — the same place the run’s identity already comes from, never the model’s guess. A link naming a screen the app does not have is refused before anything is sent, together with the list of screens that do exist, instead of traveling all the way to the phone to quietly drop you on the home screen. And the destinations now cover every screen your phone actually has — Projects, Automations, Procedures and Customization included — read from the app’s own route table, so what the agent is told can no longer drift from what the phone can open. On the phone, a tap that launched the app is read on the entry screen’s first render, so its destination is the boot destination rather than a second navigation racing the redirect.
Updates
- PDFs, read where they sit (Android). A PDF in a conversation used to be a file row on the mobile app’s Android build — tap it and the document left for whatever viewer the phone happened to have. It now opens in the card itself, showing a real first page and expanding to the whole document, scrollable and pinch-zoomable, exactly as it already did on iPhone. The reader travels with the app instead of depending on one being installed, and the page drawing it can reach no file but the one you opened. Very large PDFs still go to the system viewer.
- A tab group label worth reading. The Wolffish tab group was told to announce itself for everything, including opening a single page — where the plain Wolffish name already said all there was to say. Labeling is a judgement now rather than a ritual: a one-off lookup keeps the plain name, and a real task — several steps, more than one page, more than a moment — carries an emoji and a few words, updated as the work moves from one phase to the next. You still see what your browser is doing when it matters, without a label on every trivial thing.
- Arabic that reads in one script. Four Arabic strings still spelled the brand in Latin letters mid-sentence — the capability gate, the memory rebuild overlay, the diagnostics overlay, and the name an untitled conversation carries into a PDF export — so the eye crossed from one script to the other and back inside a single line. They read وولفيش now, and the prose runs in one script throughout. The pairing screen’s code hint also lost a sentence it never needed, in both languages.
v1.0.236
New features
- The phone catches up with the desktop. Pairing brought your conversations across; everything that shapes them stayed behind. Your phone now carries Projects, Procedures and Automations — create, edit, run and delete them from either device, against the very same files, so an edit made on one screen lands on the other instead of in a second copy that quietly disagrees. The three documents that define the agent — Soul, User and Agents — are editable there too, and the desktop’s editor adopts a save made on the phone live, unless you are mid-draft, in which case your unsaved text stands and wins when you save it. You can score a turn from your phone and watch the vote land on the desktop chat you have open, file a conversation under a project, add files to a project, and collect a diagnostic bundle when a run has gone wrong. Work that takes the desktop’s whole screen shows on the phone as a card in a stack — a memory rebuild, a nightly reflection, a compaction, an automation mid-run — so the phone stays usable while they happen instead of looking broken. And a turn you are watching from your phone finally shows the question above the answer: the prompt now travels with every live update, so a phone that pairs, or opens a conversation, mid-turn is no longer reading a reply to nothing.
- Automations you can open and watch. A scheduled automation or a procedure used to run somewhere you couldn’t see. Its conversation appeared in the list only once it was over, and if the app quit halfway everything the run had written was lost. Every autonomous run now creates its conversation before it starts: it takes its place in the rail with the same processing pulse a Telegram turn gets, you can open it and watch the reply arrive live, and the Stop button works on it — the same button, the same gesture, for a run nobody typed. Progress is written to disk while the run works, so quitting or crashing halfway leaves a real transcript rather than a bare prompt, and reopening the app mid-run finds the automation still going instead of sitting idle.
- The web, read in your own browser. Wolffish had three ways to reach the web and habitually reached for the weakest. A plain fetch sees only what a server hands a bare request, so a modern page comes back empty and paywalls, logins and bot checks all defeat it — yet that is where the agent went first, often failing twice before doing the obvious thing. It now leans on your real browser, where your logins already are and pages render as you see them, and keeps search for what search is genuinely good at: settling one fact, or finding which link to open. When no browser is running it starts one itself with the new
ext_launch_browser. And it works in its own tab group — a blue group named Wolffish, created the first time it needs a page — so your own tabs are never navigated away from mid-task; it reads the tab you are on only when you ask it to. That group’s label says what it is doing right now, in the agent’s own words:🔎 Comparing flights,🛒 Checking out,✍️ Writing reply. - Web pages that come out designed. Ask for a guide, a handbook, or a report as a web page, and what came back depended on the model’s mood that day. A new core web design manual now loads before the agent writes a line of HTML, exactly as the document manual already works for PDFs. It carries a planning step, a responsive rail-and-column layout, light and dark themes with a toggle, a component kit, hand-drawn SVG figures themed to the page, Arabic and RTL rules, and a mandatory verify pass: the agent screenshots the finished page in both themes, at desktop and phone widths, and looks at it before handing it over. Pages arrive as one self-contained file that reads complete with scripts switched off. And because the preview card in chat is deliberately sandboxed, every website card now carries an Open in browser button — the live page, from its real location, with its scripts running.
Updates
- A composer that stopped collecting buttons. The composer had grown a button per feature — reasoning, chat mode, local/cloud, logs, files, export — until the row was mostly chrome. It is back to three controls on each side, and nothing was lost. Thinking effort and Single/Workflow mode moved inside the model card, two chip rows above the search, so every model knob sits in one panel. That card now also lists the Ollama models you have installed, read fresh each time it opens — pull one in a terminal and it is there without a relaunch — which turns “switch to local” and “pick which local model” into a single click instead of a trip through Settings. Logs and Files moved into the context meter, at the foot of the card that was already about this conversation. Diagnostic export now lives in History alone, where it works for the conversation you have open too and says “Not indexed yet” instead of going quietly dead. Choosing a model you have already downloaded no longer pretends to download it again. And a voice note you record shows just its player: the transcript is still stored, still sent, still searchable — printing it back underneath only repeated what you had said out loud a moment earlier.
v1.0.235
New features
- Wolffish, now on your phone. Wolffish runs on your machine — which has always meant being at your machine. A phone can now pair with this desktop and carry the same conversations, the same settings, the same usage with it. Pairing happens once: scan a QR with your camera, or type a short code when the camera can’t see the screen — the secret travels screen to camera and never crosses the network. From then on the two devices talk end to end encrypted (X25519 · ChaCha20-Poly1305), sealed on your devices before anything is sent. What carries the bytes is a blind relay: it only helps the two find each other and passes sealed frames along — it cannot read, alter or replay them, and it stores nothing at all, no database, no logs, no accounts, no message history. Both devices show the same fingerprints so you can confirm at a glance that nothing sits in between, and the relay is open source and self-hostable — point this desktop at your own deployment and the next pairing carries that address to your phone. The link runs the other way too: with phone notifications on, the agent can reach you with its
notify_phonetool when a run finishes, fails, or needs you — never automatically, always a deliberate call, and Off makes the tool refuse outright. A Task results switch decides whether your phone’s feed relays every tool call or stays clean with just replies, files and errors. - Video generation, directed by your own model. Wolffish can now make video, and the interesting part is who writes the prompt. Ask for a clip in any conversation and your current chat model directs it — it rewrites your request into a full cinematic brief (subject, camera movement, lighting, mood) and chooses duration, resolution, aspect ratio, and which images serve as first frame, last frame or style reference. That rewriting is where most of the quality lives, so a stronger chat model gets a better video from the identical request; if a clip misses what you pictured, telling your model what to change usually beats rewording the original ask. Turn director mode off and your words go to the video model exactly as you wrote them. MiniMax H3 does the rendering — text to video, image to video, first-and-last-frame transitions, or reference images, clips and audio for consistent subjects, motion and voice, up to twelve media items in one request — producing H.264 mp4 with a generated soundtrack, 24 fps, 768P or 2K, four to fifteen seconds. Because a render takes minutes rather than moments, a task card appears in the chat carrying the task id, live status and a progress estimate; it updates itself, you can cancel from the card, and the finished mp4 downloads automatically and plays inline. If a generation outlives its turn — the app restarts, or the model has moved on — Wolffish finishes the job on its own: it keeps polling, saves the video, updates the card, and delivers it to the channel the request came from, compressing oversized clips to fit Telegram or WhatsApp while keeping the original here at full quality. Attached media is checked and optimized for you, and the composer’s paperclip grows an Attach media URL option that hands MiniMax a link directly — the way around the size limit on large references. Videos are stored per conversation and deleted along with it, and the key lives in Settings → Services → Video generation, kept deliberately separate from the MiniMax chat provider so rotating one never drags the other with it.
- Zip archives, handled where they land. Wolffish couldn’t open a zip. Attach one and it came back an unrecognized file type; ask what was inside and there was no tool to ask with. A new archive capability closes both halves at once: the agent can list what a zip contains without unpacking it, read a single file straight out of it, extract all of it or just the part you want, and pack files and folders into a new archive. Nothing is unpacked by default — an archive dropped in with no instructions gets listed, described in a line, and then you’re asked what you want done with it. The composer now takes
.zipas a first-class attachment, up to 512 MB, so the archive arrives somewhere the tools can actually reach it.
Updates
- A settings panel that says why it’s dark. Every service page in Settings used to assume its capability was present and working; when one wasn’t, the controls simply sat there doing nothing. Each panel now checks for itself and, when its capability is missing, switched off, or failed to load, says exactly which of the three it is — showing the underlying error when there is one — and offers a way straight through to the Capabilities page. The controls below go visibly inert rather than pretending to work.
- Legends that stay off the axis. A chart legend long enough to wrap onto a second row used to spill over the x-axis labels underneath it. Wrapped rows now have their height reserved in the plot’s grid, re-measured whenever the chart is resized or its data changes — so a legend gains room instead of taking someone else’s.
- Newer defaults from DeepSeek and Qwen. The model catalog picks up deepseek-v4-flash — now frontier-badged and auto-selected when you connect DeepSeek, at a third of Pro’s price — and qwen3.8-max, Qwen’s new flagship and the first Max tier with vision, cheaper than the 3.7 Max it replaces. deepseek-v4-pro stays listed alongside for the heavier reasoning work.
v1.0.234
New features
- Every browser you own, one extension. The browser extension used to assume one browser — connect it from Chrome and that was the whole story. It now speaks to several browsers at once, and two profiles of the same browser count as two browsers, told apart by each profile’s signed-in email, so “work Chrome” and “personal Chrome” stop being guesswork. Every connected browser introduces itself on arrival — name, version, operating system, profile — and takes its own row in Settings → Channels → Browser, a row that holds steady through extension reloads instead of flickering away. The agent sees the same roster: it can list what’s connected and choose which browser a conversation drives — a choice that sticks for that conversation until it deliberately switches — picking for itself when you named a browser or the context makes it obvious, and asking you first when nothing does. Each browser remains a fully separate world — its own tabs, logins, and cookies — and the agent is taught never to mix them up.
- The reasoning behind a reply, one click away. When the model thinks before it answers, that thinking no longer evaporates. A reply that carries reasoning now ends with a small collapsed Reasoning card in the chat feed — click it to unfold the model’s raw thinking text, click again to tuck it away. Nothing appears when there was no reasoning, and the card mirrors the one the mobile app already shows.
Updates
- Your phone vote lands on the open chat. Score a reply from WhatsApp or Telegram — a bare number, 0 to 10 — and the desktop app used to sit there looking as if nothing had happened; worse, a conversation reopened later showed no scores at all, even though every vote was safely on disk. Scores travel now: a vote cast on any surface appears live on the rating bar of the chat you have open, reopened conversations show every score they’ve earned, and when the same turn ends up voted on twice, the most recent vote wins — a re-vote from your phone can no longer be quietly overwritten by a stale copy the desktop was still holding. In-app clicks paint instantly and roll themselves back on the rare failed write.
v1.0.233
New features
- Wolffish sleeps on it. Every night, Wolffish now reviews its own finished conversations — scheduled automations included — the way a careful colleague reviews their day: what was attempted and how it actually ended, what worked well enough to repeat, what failed and why, and what you showed it about how you like things done. The lessons distill into a playbook — do this, avoid that, recipes for recurring tasks — and that playbook rides into every future conversation, so a lesson learned Tuesday night shapes Wednesday’s first reply. It is a living document rewritten in place: the newest evidence wins a contradiction, stale guesses fade unless reinforced, and your live instruction always outranks it. Once a month, a deep reflection takes the opposite stance and attacks what the nights accumulated — stale rules, sweeping conclusions built on one incident — the structural guard against self-taught bad habits. A laptop asleep at 3 AM simply runs its review on the next launch, and the schedule, quiet window, run-now buttons, and last-run reports live in Settings → Knowledge → Reflection.
- Your 0–10 becomes its ground truth. The strongest signal in that nightly review is yours to give: a 0–10 rating bar appears above the composer once a reply completes — one click scores the turn, another changes your mind. On WhatsApp and Telegram, a reply that is nothing but a number from 0 to 10 is quietly captured as your score for the last reply — acknowledged with a small ✍ reaction, never a chat bubble — and digits typed on an Arabic keyboard count the same. The plumbing stays careful: a “3” answering a numbered question card still means option 3, and a number opening a fresh chat is just a message. Scoring is optional everywhere — each surface has its own switch in the same Reflection settings.
- Charts — live in chat, drawn in print. Wolffish can now show data instead of narrating it: interactive chart cards in the app chat — line, area, column, bar, stacked, pie, donut, scatter, heatmap, radar, gauge, and funnel — themed to the app in light and dark, with tooltips, legends, an expandable full-screen view, the underlying data one toggle away, and Save as image for sharing. Inside generated PDFs, charts are drawn to the same visual system with print-perfect geometry and a colorblind-validated palette. A new core dataviz manual teaches the agent when a chart earns its place (and when a number or a table is the honest answer), and which chart fits which data.
- Documents designed by a manual, not a mood. Wolffish’s PDFs used to swing between genuinely good and visibly broken — dark slide-like pages, half-empty sheets, a different look every time — because the full design recipe lived where the model rarely read it. That recipe is now a core document design manual the agent loads before authoring anything you’ll read: a page-planning step so no page ships half empty, a fixed-sheet architecture with running footers and real page numbers, one type scale, one accent color with light body pages always, a component kit, Arabic/RTL rules, and a mandatory verify pass — the agent renders sample pages as images and looks at them before sending you anything. Your own instructions still win: an automation that asks for a minimal layout keeps getting exactly that.
Updates
- Raw Markdown stops reaching your phone. WhatsApp and Telegram render no Markdown — yet an agent deep in a task could still write
**bold**,# headings, or| tables |, and the raw symbols landed in your chat. That leak is now sealed at both ends: the send tools refuse Markdown outright — the agent rewrites the message in the chat’s own formatting before anything goes out — with careful guards keeping honest text flowing (x**2andf(**kwargs)read as math and code, not bold). The live narration between tool steps is watched instead of blocked: when a line lands carrying raw markup, Wolffish tells the agent exactly what you received, and on Telegram points it at the delivered message so it can quietly edit it clean. Nothing ever rewrites the agent’s words and nothing is withheld. - A memory that curates instead of piling up. The nightly pass that turns the day’s conversations into long-term knowledge used to be an extractor: it never saw what it had already written, so it re-derived the same facts night after night — the same phone number recorded a dozen times, facts drifting onto the wrong person. It now works as a curator: it reads the current knowledge files alongside the day’s log and rewrites them whole — one tidy section per person, project, and topic, near-duplicates merged into a single line, contradictions resolved in favour of the newest evidence, junk deleted on sight. Every rewrite keeps the previous version as a backup right beside the original, so a bad night is one copy away from undone, and your own hand-written edits survive curation.
- Relative paths find the workspace. Ask the agent to touch a file by a bare relative path —
files/report.pdfrather than the full address — and it used to resolve against wherever the app happened to be launched from. Relative paths now resolve against the workspace, the folder where generated files actually live, so the file the agent names is the file it finds.
v1.0.232
Updates
- Settings tabs that say what they hold. Two tabs in settings were named after parts of a brain rather than after anything you would go looking for. Cellebrum — the page listing every skill, plugin, and tool Wolffish can call on — is now Capabilities, and Hippocampus, where the memory compaction schedule lives, is now Knowledge. The pages themselves are unchanged down to the last switch; only the words you navigate by have moved into plain English. The Data page follows suit — its storage breakdown now reports what memory costs you under Knowledge. Wolffish’s inner workings keep their anatomical names; what changed is the labels you actually click.
- Room at the bottom of the conversations list. Scroll to the end of the Conversations page and the last row stopped flush against the window’s edge, close enough to look cut off rather than finished. The list now keeps a margin of space past its final row, so the bottom of a long scroll reads as the bottom.
v1.0.231
Updates
- Find a conversation by when it happened. Every conversation list was one long stack sorted newest-first — fine to about the twentieth row, useless after it. All three lists — the right-hand rail, the Conversations page, and a project’s conversation list — now break themselves into dated groups: Today, Yesterday, Previous 7 days, Previous 30 days, then quarter, half-year, year, and Older. The windows widen as they recede, deliberately — recent work is the kind you look for by its exact day, older work by roughly its era. A heading only appears when something sits under it, the numbered chips keep counting straight through the headings, and groups are cut on calendar days, so something from eleven last night reads as Yesterday rather than falling inside a rolling twenty-four hours. The collapsed rail keeps its chips-only look and marks each boundary with a thin rule.
v1.0.230
New features
- Zoom into what you’re looking at. An image in a conversation opened big and stopped there. The expanded view now zooms to your cursor: scroll and the pixel under the pointer stays exactly where it is, up to eight times in, then drag to pan around what you’ve magnified. A small toolbar carries the live percentage;
+,-, and0do the same from the keyboard, and a double-click jumps in or back out. Videos got the same surface — a new expand button opens the player sized to the picture’s real shape rather than an assumed widescreen — and PDFs expand too, to a full 80% of the window, where the built-in viewer keeps its own scrolling and paging. - Report a bug without opening the conversation first. The bug button that packs up everything about a conversation that went wrong was reachable only from inside that conversation. Every row on the History page now carries its own bug button, so you can hand over a bundle for a conversation you aren’t in. The export itself got steadier in three places: the collecting screen no longer spins forever over an archive that already landed, returning to a run already in flight attaches to it instead of reporting failure, and the optional step that asks the model what it thinks went wrong gives up after ninety seconds — a stalled provider costs the bundle one section rather than the whole export.
Updates
- One conversation, one story, whichever list you read it in. The right-hand rail, the History page, and a project’s conversation list now share one definition, and each keeps up on its own: start a chat in the app, message from WhatsApp or Telegram, or let an automation or saved procedure open one, and the row appears the moment its first turn starts — pulsing chip and source emoji included — instead of surfacing only once the work was over. On the Projects page, conversation counts and “last used” stamps refresh themselves live too.
- Point at a folder mid-answer. Handing Wolffish a working folder was locked the moment it started answering. Adding one is live now, exactly like attaching a file — the folder rides your next queued message rather than the running one. Removing a folder still waits for the turn to end, deliberately: the agent may be reading files in there this second, and the delete button says as much on hover.
- Windows: PDF tools and shell commands, unstuck. Two Windows-only faults, both invisible from the outside. Every PDF tool — reading, searching, rendering a page — failed on its very first call, because a file path was assembled with the platform’s own separator where the PDF engine insists on one particular character. And a shell command that printed anything to the error stream — how
npm,git,pip, andffmpegreport ordinary progress — could be reported as failed when it had fully succeeded whenever a stray2>&1was appended out of habit; that redirect is now dropped before the command runs. - The project dialog stops shifting under you. Adding a file to a project moved everything below it twice. The progress card and the file list now share one shell and one row height, so the block claims its space once and keeps it — and the copy button on a project’s standing instructions appears on hover, like every other code block in the app.
v1.0.229
New features
- One button packs up everything that went wrong. Explaining a broken conversation to the developer used to mean hunting down which log, which task file, and which prompt snapshot actually belonged to it. A new bug button in every chat runs the whole errand: one press bundles that conversation and nothing else — the transcript, the event log for the days it spans plus a slice filtered to its own turns, the task files it spawned, the memory behind it, the prompts and capability contracts it was working against, and your settings — into a single zip you can forward as-is. Every credential is redacted (a length marker, never the value) and attachment media is left out, so the archive is safe to hand over. On a cloud model it also asks the model itself what it thinks went wrong and tucks that into the bundle. See Diagnostic Export.
- Show me the figure. Ask about a diagram, chart, algorithm or table inside a PDF and Wolffish could only ever read you the words around it. The new
pdf_render_pagesrenders the page itself as an image — the figure exactly as printed, at whatever zoom the small print calls for — and sends it into the conversation. This is the fix for a quiet failure: a textbook figure is usually drawn, not stored, so there is no image inside the file to pull out andpdf_extract_imagescorrectly came back with nothing. Extraction got sharper too — it now works on the pages you name rather than the whole book, and skips the sub-80px fragments that used to bury the one figure you wanted under thousands of unusable files. See the pdf capability.
Updates
- Big files say so while they copy. Attach something large and the composer used to sit blank while it was copied into Wolffish, until the chip simply appeared seconds or minutes later. Every file you pick, drop, or paste now claims its chip the instant you choose it, with a filling ring and a live percentage counting real bytes, and hands over to the finished attachment when those bytes land. Send waits for them — the button rests, the Enter key is caught too, and a tooltip says why — because a message sent mid-copy would have quietly gone without the file. Stopping a running turn is never blocked. Adding files to a project got the same treatment: one bar across the whole batch, with which file of how many is moving.
- Record while it’s still working. The microphone used to go dark the moment Wolffish started answering. Recording stays live now, exactly like attaching: a take started mid-answer waits in the row above the composer — with a play button and its length, so you can hear it back before it goes — and sends itself when the turn finishes, uploaded, transcribed, and answered in its proper place in the queue.
v1.0.228
New features
- Core capabilities can’t be switched off by accident. Settings lets you toggle individual capabilities on and off — but a handful are load-bearing: the workflow engine, your secrets, the
skillscapability, projects, automations, procedures, and the shared tools the rest leans on. Those now wear a Core badge, settle at the bottom of the list, and can no longer be turned off — a locked Always on marker sits where their switch used to be. Everything you added yourself stays exactly as toggleable as before; only the essentials are protected, so a stray click can’t pull the floor out from under a feature you depend on.
Updates
- Workflow mode, working again. In v1.0.227, workflow mode quietly stopped delegating: the tools it uses to plan phases, spawn agents, and gather their results failed to load, so it fell back to working alone with no hint of why. The cause was a small formatting slip in an internal file — now fixed, and workflow mode plans, delegates, and collects work the way it should again.
v1.0.227
New features
- Nothing you send has to be resent. Message Wolffish from Telegram or WhatsApp while it’s still working and the message is now queued, not bounced with a “hold on, I’m busy” — files and voice notes included, downloaded and transcribed the instant they arrive so nothing goes stale in line. A reply confirms where it sits, and each queued message runs on its own turn, in order, the moment the current task finishes. Two commands keep you in charge:
/canceldrops everything waiting and leaves the running task alone, while/stopstops the run and lets the queue carry on. Starting or switching conversations (/new,/resume,/delete, a project switch) clears the queue with the conversation it belonged to. One habit to unlearn: on Telegram/cancelis no longer another name for/stop. - Your phone’s chat, live on your desk. A conversation that Telegram, WhatsApp, or an automation is answering right now used to open in the app looking idle and finished, the whole reply landing in one lump at the end. It reads as live now: the reply streams into the feed as it’s written, the Stop button genuinely stops the run whichever device started it, and a message you type mid-run queues and sends itself when that run lands — even if you opened the window in the middle of one.
- A stuck agent says so. In workflow mode, a delegated agent that wedged itself — re-issuing the same tool call to no effect — used to be invisible while the master sat blocked waiting for a result that never came. Both ends are told now: the spinning agent gets a note to wrap up with what it has, and the master is woken out of
agents_awaitwith the agent’s name, the repeated call, and the count — then decides for itself whether to wait it out for partial findings or cancel it and cover that slice another way. Nothing is capped, nothing is killed automatically.
Updates
- Memory compaction shows its work. The Memory compaction card in Settings used to show only the next scheduled run. It now also shows each job’s last completed run — when it ran, how long it took, the output it produced, and (for the daily summary’s model call) the tokens in and out — and skipped or failed passes never overwrite it, so you’re always reading the last pass that did something. The background side-calls got quicker too: naming a conversation and writing a summary now run with reasoning off on your configured Brain, whatever reasoning level you’ve picked for chat.
v1.0.226
Updates
- Low on disk? Warned, not walled. Launching with less than 5 GB free used to be a locked door — the low-space screen had no way past it short of deleting files. It’s a warning now: a Continue anyway button takes you straight to your usual screen, with a plain note that models, saves, and downloads can fail until you free room. The choice lasts one sitting — the warning still greets every launch while the disk stays low — and Recalculate now answers out loud, ending each re-check in a toast: a green “enough to continue” with the exact free amount when you’ve cleared the bar, the familiar warning when you haven’t.
- One Arabic label, mended. A garbled character had crept into the Arabic label for recording a voice note. It reads «تسجيل رسالة صوتية» again, as it should.
v1.0.225
New features
- Background runs stop taking over. A firing automation used to swap the whole app for a full-screen “chat is paused” overlay. Now it surfaces as a floating live card pinned over the top of the screen — pulsing icon, the job’s name and mode, a live feed of what it’s doing — while the rest of Wolffish stays fully usable. Click the card to expand the full activity panel (timer, instruction, step-by-step log); Escape or a click outside folds it back without losing a line of history. Procedure runs deliberately get no card at all — a saved prompt doing its job needs no stage — though a failed run still raises a toast naming what broke.
- Three at once, the rest in line. Background jobs used to run strictly one at a time — a slow nightly digest made the whole schedule late. The engine now runs up to three jobs side by side, each with its own card, and everything past three waits in a visible queue — a row under the cards counts and names what’s waiting, and nothing is ever dropped: a queued job starts the moment a slot frees, and a job that fires while already running or queued folds into the pending run instead of stacking copies. On the Automations page, a running or queued job says so on its card and its Run now button rests until the run ends.
Updates
- An edit counts, whoever makes it. The “Edited” stamp on an automation card used to notice only the card editor’s own saves. Stamps now come from the engine watching
heartbeat.mditself: any writer counts — the dialog, the markdown view, Wolffish’s ownautomation_*tools, an external editor, even an edit made while the app was closed — while merely toggling a job on or off correctly doesn’t restamp. The Automations, Procedures, and Projects pages all refresh themselves live when something changes underneath them — ask Wolffish mid-chat to add an automation and watch the card appear — and project cards now show their own Edited time next to last-used. The card editor’s schedule field also stopped flashing red mid-keystroke: it waits out your typing pause before calling a schedule wrong. - Admin rights reach the agents. Wolffish keeps one saved admin session per app run — you type your password into a native dialog once, and
sudoauthenticates app-side from then on. That session is now genuinely app-wide: workflow agents and scheduled runs — automations and procedures — elevate through the same session as the chat, so a delegated task that needs admin rights just runs instead of coming back with “this needs elevation.”
v1.0.224
New features
- Projects. Some work is a dozen conversations sharing one context — projects give it a home. A project is a name, an emoji, standing instructions, and a set of files; every conversation inside it starts already briefed: instructions ride each turn, files are known by name and read on demand rather than stuffed into context. Manage them on the new Projects page; start one by hovering the New Chat button (your projects fan out as cards), and the rail and History group and badge every conversation under its project. Procedures and automations can be bound to a project too, and
/projecton WhatsApp and Telegram starts project conversations from your phone — with/newdeliberately staying inside the project and/project closethe way out. Wolffish manages projects itself through eight newproject_*tools. - Files the size of books. Attachment content is never injected into context anymore — every file becomes a compact reference note (name, path, real facts — a PDF’s page count is probed lazily from its own index), and Wolffish reads on demand: new
pdf_infoandpdf_searchplus a lazy, cachedpdf_readwalk thousand-page documents a page range at a time,file_readstreams slices of giant text files, and vision models pull an image’s pixels with the newimage_viewonly when they actually look. The arbitrary size caps (100 MB documents/spreadsheets, 500 MB audio) are gone, and Wolffish narrates long reads instead of going silent. - Automations, now with faces. The Automations page is rebuilt around cards: each job wears its own emoji (📧 for the inbox sweep, 📰 for the news digest), with a proper editor dialog — schedule chips for every form including full cron, a real time input, a live next-run preview, and autosave. The emoji is stamped on every conversation the job’s runs create, so the rail tells you at a glance which automation an overnight run belongs to. Procedures got the same treatment — an emoji per procedure, stamped on its runs.
- Several questions, one card.
ask_usernow takes a list of questions: in the app they arrive as one card with chip tabs — flip through, answer everything, one resolution — and on WhatsApp and Telegram the same request walks you through them one message at a time, in order. Quizzes run through it too: every question up front, graded and explained after.
Updates
- Replies that fold. Chat replies can use a careful, sanitized slice of real HTML: collapsible
<details>sections with a clickable summary, highlighted<mark>text, keyboard keys, sub- and superscripts. Scripts, styles, frames, and event handlers are stripped outright; unknown tags degrade to their text. The PDF export renders the exact same subset, so an exported conversation shows what the feed showed. - A card that opens the folder. When the deliverable is a place rather than an attachable file — a folder Wolffish scaffolded, a batch of outputs, a file deliberately left where you asked — it pushes an openable location card: Open for folders, Reveal for files. The old path-guessing that parsed cards out of prose is deleted — a card now exists exactly because Wolffish chose to hand you the place, through a real tool with a checked path.
v1.0.223
New features
- Keep typing while Wolffish works. The composer no longer locks during a turn. Type your next message mid-run and Enter queues it in a row above the composer — cancelable until the moment it goes — and it sends itself when the current turn ends; queue several and they go out one by one, in order. Attachments keep pace: the attach button, drag-and-drop, and paste all stay live during a run, with staged files riding the queued message instead of interrupting the running one. Stopping a run counts as ending it, so Stop advances the queue too — your queued follow-up steps straight into the room the stop just made.
- Your spending, added up for you. The Usage panel always knew what every call cost — it left the adding to you, one provider card at a time. A new Costs section now does the arithmetic for the range you’re viewing: Total Spend, Top Day Spend with the date it happened, and Daily Average across the days you actually used Wolffish. The total counts Brave search fees too, so it genuinely equals the sum of the provider cards below it, and the new cards load under the same skeletons as the rest of the panel, so nothing jumps when the figures land.
Updates
- A zoom that fits the picture. Clicking an image to see it big used to float it in a general-purpose dialog, with empty bars wherever its shape and the box’s disagreed. It’s now a proper lightbox: a clean overlay that hugs the image’s exact proportions, growing it until it reaches 80% of the window on whichever edge gets there first — no title bar, no letterboxing, just the picture. Click anywhere outside it, or press Escape, to dismiss. The same lightbox serves the chat and the workspace file viewer alike.
v1.0.221
New features
- Phone conversations, continued at your desk. A conversation that started on Telegram or WhatsApp — or one an automation ran overnight — used to open in the app read-only. Now every conversation is a live chat everywhere: continue a phone thread with a real keyboard, or pick up a finished automation run and ask the follow-up — it unseals and grows like any other chat. If a message lands on your phone while the same conversation is open on your desk, the new tail simply appears in place, and voice notes survive the round-trip untouched. The conversations rail and History now badge each conversation with its origin — Telegram, WhatsApp, automation, procedure — so a mixed list stays legible.
/resumereaches every conversation. On both channels the picker now lists everything Wolffish has — every channel, newest first, 25 to a page withnext— each row tagged with its origin and the numbering continuous across pages. A number you were never actually shown selects nothing, which matters most for/delete, now served by the same picker, where a wrong pick is unrecoverable. Scheduled automation runs stay out of/resumeby default — a new toggle in both channels’ settings — while remaining in/deleteand the app.- Replies land where you meant them. When Wolffish messages you out of band — an automation reporting a finished job, an in-app conversation dropping you a note — the chat now points itself at the sending conversation, idle clock restarted so the staleness guard can’t bounce you back out. You reply, and you’re already in the conversation that messaged you.
- Kimi K3. Moonshot’s new flagship, supported in full from day one: a 1M-token context window, 128K max output, vision, and its three-step reasoning dial — Off / High / Max — on the reasoning button, with Off verified to genuinely disable thinking. K3 is now the Kimi provider’s default model, priced in usage tracking down to the cached-token discount, and available through OpenRouter as well. Vision also unlocked across the rest of the line: everything from k2.5 onward is natively multimodal, so images now flow to k2.5, k2.6, and the k2.7 code models instead of being stripped as text-only. And the model picker stopped burying the flagship — Moonshot stamps its whole catalog with one shared release date, so the list now sorts newest family first.
- Try again on failed turns. When a provider dies mid-turn — overloaded, timing out, erroring — the error card now carries a Try again button. One click continues the conversation with the failure named, so Wolffish checks what already completed (files written, tool results in hand) and picks up from the break instead of restarting the task blind.
- Per-agent spend in the meter. The context pill’s card now itemizes workflow runs: one row per agent — live status dot, tokens, cost, a bar scaled to the run’s biggest spender — plus run totals of tool calls, tokens, and cost. It restores with the rest of the meter when you reopen a conversation whose last turn was a workflow run.
Updates
- Conversations merge instead of clobbering. Every message now carries a permanent identity, and two copies of the same conversation reconcile message-by-message instead of last-writer-wins — so a Telegram message landing while the same thread runs an in-app turn survives alongside it, the rolling summary stays pinned to the exact message where its coverage ends, and a window holding a stale copy can no longer save over a finished turn. Existing conversations pick up their identities on first launch, invisibly.
- The end of permanent “Untitled”. The conversation-naming call silently defaulted to a full high-effort reasoning call — thinking hard about five words — blew its deadline, and wrote nothing, stranding roughly one in five Telegram conversations (one in ten on WhatsApp) as “Untitled” forever. Naming now runs with thinking off and lands in about a second; a title that still runs late degrades to a readable slice of your own message instead of to nothing; a photo sent with no caption is named from its filename; and the conversations already stranded heal on launch, deterministically, without a single model call.
- Arabic that reads like Arabic. Every size the app shows — model downloads, disk usage, free space, transfer speeds — was hardcoded English, a “1.5 GB” sitting mid-Arabic-sentence. All of it now reads natively, the bidirectional-text bug that tore numerals away from their unit words is fixed, and hardware specs dropped their false precision — “16 GB”, and never a meaningless “0 GB” for a small model.
- Settings numbers that tell the truth. The Data panel’s CPU gauge was measuring its own disk scan — an idle app reported 93% when the truth was 0.3% — and showing a share of a single core, so a busy moment on a twelve-core machine read as 141%. It now samples after the scan and shows whole-CPU utilization, with a “Less than 0.1%” floor so a small real load reads as one. Usage paints the instant you open it, every range warmed at launch — the loading skeleton is gone from the panel you check most.
- Small polish. The one-time post-update memory-index rebuild now owns the screen properly — rendered once at app level, with the conversations rail stepping aside instead of floating over it — and its “database growing large” health warning trips at 1 GB instead of 50 MB;
/resumeand/deleterender as proper LTR command chips inside Arabic settings copy; and the verbose-toggle description on all three channels now matches exactly what the clean feed delivers.
v1.0.206
New features
- Concurrent conversations. Wolffish is no longer a single chat window that empties when you open another. Every conversation now runs at once — each keeps its own feed, composer, context meter, and in-flight turn, all mounted together. Start a second chat while the first is still streaming, flip back to it, and both are exactly where you left them; switching conversations never pauses, resets, or drops a turn that’s mid-flight. A conversation only advances when its turn does.
- The conversations rail. A new rail down the right edge lists every conversation across every channel, newest first, each with a numbered status chip that pulses while a turn runs and settles into a color when it’s done — green finished, red failed, amber stopped — held for the rest of the session. Collapsed it’s just the chips; expanded each shows its title. Click any to jump straight in, including a conversation still mid-turn that hasn’t been written to disk yet (the rail reopens it by its live session instead of dead-ending on a missing file). The History page carries the same live chips and shares one open-or-activate path with the rail.
- Conversations name themselves. The moment a conversation begins, Wolffish reads your first message and writes a short, specific title for it — so the rail and History read like a table of contents instead of a wall of identical “New chat” rows. Titling runs quietly in the background on your chosen model; its cost is recorded on your usage ledger but walled off from the conversation’s own context meter, so naming a chat never eats into its window. If the model can’t be reached the title falls back to a trimmed slice of your opening line, and a later turn tries again.
Updates
- Channels stop waiting in line. Turns were globally serialized: a Telegram message landing mid-in-app-turn had to wait for it to finish. That queue is now per conversation — a single conversation is still one ordered transcript, but different conversations run in parallel, in any mix of in-app, WhatsApp, and Telegram. Every turn reports its live status back to the app, which is what lets the rail’s chips pulse for channel runs and not just the one on your screen. See Channels Overview.
- Sidebars, squared up. Both rails were rebuilt to match: mirror-symmetric widths, both defaulting to collapsed, and they now snap open and closed instead of animating a width that made the icons jump mid-slide. Each ends cleanly at the top of the action bar.
- Small polish. Running procedure and heartbeat overlays now wear a Single / Workflow badge so you can see which mode an automated run is executing in (a job with no marker shows the global mode it inherits); opening a conversation warms its file cards before it paints, so a resumed chat lands fully formed instead of popping its attachments in one by one; and the Arabic interface caught up on the “automated task — read only” heartbeat notice.
v1.0.205
New features
- Workflow mode. Orchestrator mode is gone, rebuilt as workflow mode: the agent you talk to becomes the master of a run it designs itself — it declares its phases (
workflow_plan), spawns live parallel agents (agent_spawn), collects each report the moment it lands (agents_await), sends follow-ups (agent_send), and cancels dead ends (agent_cancel). The fixed “Worker model” slot is retired: the master picks each agent’s model individually from every provider you’ve connected — it sees a catalog of your models with context windows, reasoning support, and vision, and matches frontier models to hard slices and cheap ones to mechanical sweeps. Agents are single-shot (the master owns every retry decision), can’t reach you or spawn agents of their own, and each one’s context is budgeted against its own model’s window. - The workflow card. Every workflow run gets one collapsible card in the chat: the phase plan as chips moving from pending to active to done, a live table with a row per agent (name, task, model, phase, status, elapsed time, tokens, tool calls, cost), and run totals including the true whole-turn cost. Every number comes from harness telemetry — never from what the model claims — so the live card and the reloaded card are the same card. The chat’s PDF export prints a finished run as a static table.
- Model and mode pickers in the composer. The drag-and-drop Brain settings page is gone; choosing what runs your conversation moved to where the conversation happens. Beside the chat input: a Local/Cloud model switch that opens into a searchable catalog of every connected provider’s models (capability badges, context sizes, one click to switch), a mode pill (Single / Workflow), and a redesigned reasoning button — hover for a card of every effort level the current model supports instead of blind-cycling. API keys stay in Settings → Models.
- Every job picks its own mode. Heartbeat jobs and procedures each carry their own Single/Workflow toggle — under the hood an optional
mode: workflowfirst line in the job’s block, stripped before the instruction reaches the agent.automation_create/automation_edit/procedure_create/procedure_edittake an optionalmode, so Wolffish can set it by conversation. Jobs without a marker follow the global mode.
Updates
- Workflows on the channels. The old per-worker narration is retired. Telegram and WhatsApp now get deterministic progress from workflow runs — the phase plan at start, a line per completed phase, and a closing summary with totals — with verbose adding a landing line per agent (name, model, duration, tool calls). Verbose off keeps the clean feed: the master’s reply, nothing else.
- Migration on first launch. If you were running orchestrator mode you wake up in workflow mode (multi-agent intent preserved, not silently downgraded); the Worker-model slot, the Greedy effort and Autonomy toggles, and the old orchestrator capability are removed, and their leftovers are swept from deployed workspaces.
config.llm.modereplacesorchestratorMode/workerModel/greedy/autonomousin config.json. - GitHub and Notion tests that fail loudly. A failed connection test in the GitHub or Notion panel now leaves a persistent red alert with the reason on the connection card — cleared when you edit the token or a test passes, and translated live when you switch the app language.
- Small polish.
.txtattachments open in a line-numbered text viewer instead of a bare file card; the attachments grid got wider tiles and more spacing; the clocks on running procedure and heartbeat overlays follow your app language’s time format; model names display compactly in the pickers; error messages are shorter and plainer.
v1.0.204
New features
- Save any conversation as a PDF. A new download button in the chat footer exports the conversation you’re looking at to a PDF that mirrors the feed exactly — your messages, Wolffish’s replies, tool cards, code blocks, and file attachments — laid out for print and offline reading.
- The usage meter, rebuilt. The opt-in “Show in-chat analytics” strip (and its
showChatAnalyticssetting) is gone. In its place the context pill beside the chat input is always there and now opens: hover or pin it for the full picture — how much of the context window is in use and exactly where auto-compaction triggers (drawn as a tick, so the visible percentage and the trigger are finally the same number), how much of that context arrived warm from cache versus freshly ingested, and a running ledger for this turn, last turn, and all time of input/output tokens, API calls, tool calls, and cost. In orchestrator mode its workers and background summaries get their own sub-totals.
Updates
- Send an image to any model. The capability gate that rejected images on non-vision models is gone. Attach an image to any model on any surface — in-app, Telegram, WhatsApp — and it goes through; a model that can’t see the pixels receives the file’s name, location, and the tools that can read it, and tells you plainly what it can and can’t do instead of bouncing the upload.
- Workers narrate on Telegram and WhatsApp. In orchestrator mode with verbose enabled, background workers now surface their own labeled thread on the channels — prose and tool cards, coalesced per worker so concurrent workers never scramble into one another — mirroring the subagent rail in the app. Verbose off still shows only the orchestrator’s final reply.
- Offline, treated as a state. The offline notice is now a sticky warning pinned to the top of the window with its own close button, swapped in place for a brief “connection restored” when you reconnect. Wolffish itself now knows when it’s offline and leans on tools that work without a network (memory, files, shell) instead of burning turns on ones that don’t. Every toast can now be dismissed with a click.
v1.0.203
New features
- The lean context system. The biggest internal rebuild Wolffish has ever had. A fresh request now costs ~9.4K tokens instead of ~94K — a 10× reduction — because the prompt carries only the essentials plus two compact indexes: a capability index of everything installed and a memory map of everything recallable. The memory dumps, episode dumps, and the 16K-token tool catalog are gone; the prompt prefix is byte-stable, so ~99% of it serves from the provider’s cache. Measured live: the hourly automation dropped from 96,442 input tokens (0.019).
- Total recall, on demand. Everything Wolffish has ever done, said, produced, or spent is now in one indexed store it searches in milliseconds — every conversation including every tool call and its output, daily activity, long-term knowledge, task runs, generated files, costs, and even incoming WhatsApp messages. A new retrieval toolset (
memory_search/memory_get/conversation_list/conversation_read/memory_save/usage_report) reaches any of it surgically, and the operating contract teaches unprompted recall: “send me the flight plan” searches the past before doing anything else, whether it was yesterday or a month ago. “What did today cost?” finally has an answer. - Tools that scale to thousands. Instead of shipping 300+ tool definitions with every request, ~30 essentials stay loaded and the rest — including every MCP server — load themselves mid-task via
tool_search/tool_activate, usable the same turn. Activation is per-conversation (an automation loading a tool never disturbs your chat’s cache), bounded by an invisible LRU, and tunable viapinnedCapabilitiesin config.json. - Files, hand-delivered. File delivery is now entirely the agent’s own decision: nothing auto-attaches, and the operating contract requires it to
send_filethe result of any file-producing task the moment the work is done — rendered natively in-app and uploaded for real on Telegram and WhatsApp. No more “saved to ~/some/path” dead ends, and no more surprise attachments it never chose to send.
Updates
- Endless conversations, one summary. A conversation that outgrows verbatim replay now folds its early turns into one persisted rolling summary instead of re-paying a hidden summarization call on every message — and the folded turns stay on disk, indexed, retrievable verbatim via
conversation_read. Conversations can never outgrow the context window, and the History view always shows the complete, untouched transcript. - One system for every model. The “Stateless local models” and “Restrict local models” settings are gone. Local models run the exact same lean context, full toolset, and memory as cloud models — they’ll say so honestly when a task is beyond them, but nothing is withheld. Models with very small context windows automatically get a slimmed bootstrap toolset.
- Instant everywhere. The memory index no longer rebuilds from scratch at every launch (incremental, ~22ms; a full rebuild of a 2GB workspace takes ~1.3s and only runs on upgrades). The History page loads from the index — instant at any size. The context meter shows your model’s full window and measures real provider-billed tokens.
- Memory hygiene. Episode entries are tagged with their origin (
[heartbeat],[worker], channels), knowledge promotion deduplicates, the weekly review writes a digest instead of pasting seven days of raw logs, automation runs are recorded durably (run-history.md), and prompt debug snapshots rotate at 50 instead of growing forever.
Bug fixes
- Task history was silently empty — every indexed task record had NULL fields due to a parser/format mismatch; all 340+ tasks are now queryable.
- Memory search ranked backwards — stronger matches scored lower; ranking is fixed across the index.
- MCP servers with hostname-derived names no longer register as doubled
mcp-mcp-*capabilities, and per-tool descriptions from servers are sanitized and capped so a server can’t inject fake structure into the prompt. - A ghost tool (
channel_status) the agent was told to call but couldn’t reach is now properly routable. - Cloud-provider PDFs are no longer needlessly flattened to plain text on several providers — they arrive as native document blocks.
v1.0.202
New features
- MCP servers. Connect any Model Context Protocol server from the new Settings → MCP page — paste a command for a local server (
uvx tafsir-mcp) or anhttp(s)://URL for a remote one, and every tool it exposes is available to Wolffish on your next message, in normal chat and to orchestrator workers alike. No connect step, no restart. Remote servers that require sign-in get a one-click browser OAuth flow (tokens stored, refreshed silently, and revoked at the provider on removal). Crashed or offline servers reconnect silently in the background with their tools quietly stepping aside until they’re back — one misbehaving server can never affect another or the app. - Wolffish manages MCP by conversation. A new
mcpcapability (mcp_list/mcp_add/mcp_test/mcp_enable/mcp_disable/mcp_remove/mcp_authorize) mirrors the settings page exactly — “connect the tafsir MCP server,” “which servers are on?”, “remove that one” — with every change reflected live in the UI. - Network awareness. A quiet toast when your connection drops and when it’s back — real transitions only, silent on a normal launch. Background-run failures now state why in plain words (“no internet connection,” “rate-limited,” “invalid API key”) instead of raw machine errors.
v1.0.201
New features
- Procedures. A new Procedures page holds prompts you want to reuse — write one once, hit Play, and it runs in a fresh background conversation under a live overlay with a timer and activity log, then lands in History marked with a Play icon. Wolffish manages them by conversation too — “save this as a procedure,” “run my morning brief” — through a new
procedurescapability (procedure_list/procedure_view/procedure_create/procedure_edit/procedure_delete/procedure_run). - Multiple GitHub and Notion accounts. The GitHub and Notion panels now hold any number of connections, each with its own label (“Personal,” “Work”) and a per-connection Test button showing the account it resolves to. Every tool takes an optional
connectionlabel — picked automatically when only one is linked — and newgithub_connections/notion_connectionstools list what’s configured. Existing single-token setups migrate on their own. - WhatsApp accepts any file. Send a PDF, document, image, video, audio file, or sticker over WhatsApp and Wolffish downloads and reads it like an in-app attachment — previously only voice notes made it through. Files without a name or extension are typed from the media itself; Telegram gained the same nameless-file handling.
- Conversation files at a glance. A new files button in the chat footer opens everything a conversation holds — your uploads and every file Wolffish produced — in a full-width grid. The timeline beside it now spans the whole conversation, with a collapsible divider per prompt.
- HTML attachments.
.htmlfiles can now be attached, rendering in the code viewer with a one-click toggle between the sandboxed page preview and the highlighted source.
Updates
- WhatsApp messages in WhatsApp’s own formatting. Replies no longer arrive as raw Markdown — the agent writes in WhatsApp’s native style, and everything sent passes through a converter that translates leftover Markdown (headings, links, tables, task lists) into clean WhatsApp text.
- Chat stays live across navigation. Visiting Settings or other pages no longer reloads the context meter or timeline; playing media pauses on the way out.
- Faster long conversations. Feed rows re-render only when their message changes, and code highlighting no longer runs language detection on every block.
Bug fixes
- Background runs are isolated. Procedures and automations can no longer skew the live chat’s context meter, hijack its Stop button, or overwrite a conversation created in the same second.
- No double file delivery. A file a tool already delivered isn’t re-sent in the same turn — and the agent now reliably hands you every file it produces.
- No silent endings. A turn can no longer end mid-task with no message and no tool calls.
v1.0.196
New features
- Orchestrator mode. The one agent you talk to can now become an orchestrator that spins up live parallel worker sessions on a second model, briefs and drives them, reviews their output against the goal, and folds everything into a single reply. It’s opt-in and decides per turn whether to delegate — reaching for workers only when a task genuinely splits into independent parts. Single mode stays the default for quick, sequential work.
- A “Modes” settings page. Model setup moved to its own Modes page — the first thing you land on in Settings. Pick one model (your Brain) by drag-and-drop or a click; switch on orchestrator mode to add a second Worker model in a slot beside it.
- Subagent transparency. With Verbose task results on, each worker’s text and tool calls render inline in the chat, tagged with the worker’s label, so you can see exactly how the orchestrator split the work. Off — the default — shows only the final synthesized reply.
- Greedy & Autonomy toggles. Two behavior switches on the Modes page tune how hard the agent works on every turn, regardless of mode — Greedy effort (persist harder: more retries, several approaches, keep going until the job is truly done) and Autonomy (act with high agency, ask you as little as possible). Both off by default.
- Run an automation now. A Run now button on the Heartbeat page fires any active scheduled job immediately, with a live overlay tracking its tool calls, results, and finish.
- Save a file to your computer. Save a copy of any file Wolffish has read or written — wherever it lives on your machine — to a location you choose through a normal save dialog.
Updates
- One Brain, no provider cascade. The old fallback-order / priority cascade is gone. You now select one Brain model explicitly — the one you choose is the one that runs, and you always know which. Existing setups migrate automatically: your top provider becomes the Brain and the dead settings are cleaned out. On a transient error the same model retries on a backoff; there’s no silent switch to another provider. See config.json for the updated
llmshape. - A default model on connect. Connecting a provider for the first time auto-selects a sensible default model, so you’re ready to go immediately — it never overrides a model you’ve already chosen.
- Crash-safe writes. Config, conversations, and channel state now write through one ordered, atomic path — temporary file, flushed to disk, then swapped into place — so a crash or hard quit can never leave a half-written, corrupted file. You always get the complete old version or the complete new one.
v1.0.193
New features
- Automations. Wolffish now manages its own scheduled jobs — its heartbeat — entirely through conversation. Say “every morning brief me on my calendar,” “in 2 days remind me to renew the lease,” or “check the build every hour,” and it creates the automation; ask it to list, change, delete, or test one and it does. One-time jobs fire once and remove themselves, recurring ones keep going, and jobs never overlap — one that comes due mid-run waits its turn instead of being dropped. Anything missed while the app was closed runs once, collapsed, on the next launch.
- Read a WhatsApp chat. A new
whatsapp_readtool catches Wolffish up on the latest messages in any WhatsApp contact or group, returned oldest-first. It covers traffic seen while Wolffish is connected — not older history from before it started — and that buffer now survives restarts instead of resetting every launch.
v1.0.191
New features
- Ask cards. When a decision is genuinely yours to make, Wolffish poses it as an interactive multiple-choice card — a question, 2–5 options, and a free-text “something else” box — and waits for your pick instead of guessing. On Telegram and WhatsApp you reply with the option number.
- Self-managed skills. A new
skillscapability lets Wolffish list, search, enable, disable, delete, and even author its own capabilities at runtime — turning “do this every time” into a reusable skill, or “turn off the browser” into a disabled one. - Channel status. A new
channel_statustool reports which messaging channels are connected and how to reconnect any that aren’t.
Updates
- Channels aren’t apps. Asked to message you on Telegram or WhatsApp, Wolffish no longer tries to launch a phantom desktop app that doesn’t exist — it reaches channels only through their own send tools and fails gracefully with reconnect steps when one is down.
- Openable path cards. File and folder paths Wolffish mentions in a reply now render as a card with a one-click “open in file manager” button — shown only for paths that actually exist on disk.
Bug fixes
grep -czero counts. Agrep -cthat finds no matches exits with code 1 and prints “0” — that’s now read as the valid zero-count it is, not a failed command, so it no longer triggers needless retries.
v1.0.186
New features
- Fully local voice. Text-to-speech now runs on Kokoro and speech-to-text on faster-whisper — both entirely on-device, with no cloud, no API keys, and no Microsoft servers. Voice memos work fully offline after a one-time setup. The default voice is
af_bella(English, US); voices are English-only (Americanaf_/am_, Britishbf_/bm_). - Install voice engines on demand. Settings → Text-to-Speech and Speech-to-Text now offer an Install button with a live progress bar. The voice and model pickers stay disabled until the engine is ready, and the Preview button plays the actual selected Kokoro voice — not a browser stand-in.
- Managed Python runtime. The voice engines provision into an isolated, app-managed Python runtime automatically — no system Python or developer tools required on the machine.
- Z.ai (GLM) provider support. You can now run Wolffish on Z.ai — Zhipu’s GLM models with toggleable thinking and a 1M-token context flagship (GLM-5.2). OpenAI-compatible streaming and tool-calling at budget-tier pricing; bring your own API key.
- Verbose task results toggle. Each channel now has a Verbose task results switch — off by default — that controls how much of the agent’s step-by-step work you see. Off keeps a clean feed (replies, files, and errors only); on surfaces every tool call, result, and activity card as the turn runs.
Updates
- Install progress survives navigation. Starting an install — or a Google Workspace setup/update — then switching tabs or reloading the window no longer resets the progress; it resumes exactly where the real work is.
- One voice memo per reply. Sending a voice note now returns exactly one voice memo across Desktop, Telegram, and WhatsApp — no duplicate memos and no echo of your own recording. Multi-step requests run normally first, then close with a single spoken reply.
- Verbose changes display only. Flipping the verbose toggle re-renders the feed without changing what the agent does — every tool call and result is still saved to history and memory in full, so nothing is lost when it’s off.
v1.0.126 – v1.0.129
New features
- Context compaction redesign. The compaction system has been rebuilt to use instant proportional truncation plus a single LLM summary call, replacing the previous per-message approach that required N separate API calls. Compaction that took 6 minutes now completes in under 30 seconds, and a structured continuation nudge ensures the model finishes multi-step tasks after compaction instead of treating shorter context as “done.”
- Planning skill. A built-in skill that injects planning discipline into every turn — the agent must state its understanding, lay out phases with verification criteria, and confirm each definition of done after execution.
- Conversation timeline. Conversations now track a timeline of key events (tool calls, results, compaction, model switches) that persists across sessions.
- Multi-turn tool history. Channel conversations (Telegram, WhatsApp) now reconstruct full tool-call history from stored segments, so the model can see its prior tool interactions across turns.
Updates
- Batch completion enforcement. New runtime instruction ensures the agent completes every item in batch operations (e.g. reading all emails, not just a subset).
- Structured provider error cards. Error details now always show provider name, HTTP status, error reason, retry count, and duration — even when the API returns no error body.
- Provider failure tracking. Per-provider failure details are now surfaced when a stream errors mid-response, not just when all providers are exhausted.
- Tool transcript detail logs. A separate detail log captures full raw tool output alongside the truncated transcript preview.
v1.0.76 – v1.0.102
New features
- DeepSeek provider support. You can now run Wolffish on DeepSeek, the recommended default for agentic workloads. Bring your own API key and start chatting in seconds.
- Ollama is now optional. You no longer need a local Ollama install to use Wolffish — pick any combination of cloud providers or local models that fits your setup.
- Microphone and audio permissions. Wolffish now requests mic and audio access on first launch, paving the way for voice-driven workflows.
- Instant conversation titles. New chats get a title the moment you send your first message, so your sidebar stays organized without waiting on the model.
Updates
- Smarter chat rendering. Cards, code blocks, and tool outputs now render more reliably in long conversations.
- Refined sidebar and chat navigation. Cleaner layout, better keyboard navigation, and quicker access to past conversations.
- Tray menu improvements. The system tray menu is more responsive and reflects the current app state correctly.
- Better token display. Token usage indicators are now accurate and easier to read at a glance.
- Windows performance. Shell execution and app startup have been optimized for Windows users, including a cleaner installer name.
Bug fixes
- Fixed web fetch failing on certain URLs.
- Fixed channel connection errors and intermittent API failures.
- Fixed a JSON parsing crash that could interrupt long agent runs.
- Fixed microphone access on macOS.
- Fixed DeepSeek streaming and tool-call edge cases.
- Fixed docs handling so attached files render correctly in chat.
- Fixed bypass mode not engaging in some sessions.
- Fixed blank request timeouts that could stall the agent.