Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

OpenMuse

CI License: MIT Open in GitHub Codespaces

A local-first, auditable personal AI agent runtime. OpenMuse separates untrusted planners from typed tools, host-issued approvals, durable tasks, encrypted secrets, and redacted audit history.

Why OpenMuse is different

The goal is the smallest readable personal-agent runtime whose safety semantics are verified in code and tests:

  • Exact-action approval. The host signs each approval token against one action's tool and arguments. Tokens expire and can be consumed exactly once. The planner cannot mint approvals, and approving one action never approves a similar-looking one.
  • Verifiable audit. Every decision lands in a redacted, hash-chained local log that you can re-verify independently. Change one audited byte and verification fails.
  • Secrets never reach the model. Tools receive decrypted secrets through a host callback at execution time. Secret values never appear in planner context, action arguments, tool manifests, or the audit log.

See the safety boundary in 30 seconds

One simple story: the agent starts a task, pauses before one write, the user approves exactly that action, it runs, and the audit chain proves what happened.

Play the real terminal recording

This is a real terminal capture. Its raw, replayable cast is also checked into the repository.

The approval boundary

The planner and everything it reads are untrusted. Only the trusted host can issue an approval, and it issues one for the exact action the user approved:

flowchart TD
    U([User])
    subgraph untrusted["Untrusted"]
        P["Planner (model)"]
        X["External content: pages, messages, files"]
    end
    subgraph host["Trusted host"]
        POL["Policy"]
        AUTH["Approval authority"]
        VAULT["Secret vault"]
        EXEC["Tool executor"]
        AUD["Hash-chained audit log"]
    end
    X -.-> P
    P -->|proposes one typed action| POL
    POL -->|sensitive action: ask| U
    U -->|approves this exact action| AUTH
    AUTH -->|one-time, expiring, action-bound token| EXEC
    POL -->|allow| EXEC
    VAULT -->|decrypts via host callback| EXEC
    EXEC -->|typed result| P
    POL --> AUD
    AUTH --> AUD
    EXEC --> AUD

Use a real model

OpenAICompatiblePlanner supports OpenAI-compatible chat-completions endpoints. Set OPENAI_API_KEY and pass the planner to Agent.run(). This is an alpha adapter: use a test key and non-sensitive data.

import os
from pathlib import Path
from openmuse.core import Agent
from openmuse.policy import Policy
from openmuse.providers import OpenAICompatiblePlanner
from openmuse.tools import ReadFile

agent = Agent([ReadFile(Path.cwd())], Policy(), Path(".openmuse/audit.jsonl"))
planner = OpenAICompatiblePlanner(api_key=os.environ["OPENAI_API_KEY"])
print(agent.run("Read README.md and stop", planner))

The deterministic demo remains the recommended first run because it is free and reproducible.

Current scope: an alpha security-primitives runtime and reproducible demo, not a production personal assistant. Unlike Digger's deployable OpenMuse assistant, this project focuses on host-enforced exact-action approval and verifiable local audit trails. The Python distribution is named openmuse-agent.

Independent project. Not affiliated with or endorsed by Meta. No Meta code, branding, or assets are used.

Run it

The quickest path opens a ready Python environment. In the terminal, run python examples/e2e_demo.py so you can inspect and approve the exact write yourself:

Open in GitHub Codespaces

Or run locally with Python 3.11+ and Git:

git clone https://github.com/tahodev/openmuse.git
cd openmuse
python -m venv .venv
source .venv/bin/activate             # Windows: .venv\Scripts\activate
pip install -e '.[dev]'
python examples/e2e_demo.py

The deterministic demo needs no API key. It keeps the existing web-channel and durable-task flow, but makes the one sensitive write and its host-issued approval visible.

Verify, don't trust

After the demo, independently recompute every audit hash and link:

python examples/verify_audit.py

Expected result:

VERIFIED: 3 records form an intact hash chain

Change any audited byte and verification fails. The verifier is intentionally small: examples/verify_audit.py calls the public verify_chain function. The audit contains a blocked attempt, the approved action, and its execution result.

Status

Capability Status
Typed, budgeted agent loop Working
Exact-action, expiring, one-time approvals Working
Workspace file tools + SSRF-resistant public fetch Working
Redacted hash-chained audit Working
SQLite task checkpoints/cancel/restart Working
In-process web channel adapter Experimental
Envelope-encrypted local secret vault Experimental
Browser-worker policy envelope Experimental
Persistent task threads + atomic cron job claims Working
Credential-free read-only mail/calendar connectors Working
Production-capable read-only Google Calendar and Gmail connectors Working
Managed Google OAuth code exchange, refresh, encrypted storage, and OS-keyring master key Working
Resource-limited OS process worker Working
Kernel/network-isolated browser worker Not yet
Ephemeral OTP grants + exact-total validation Working
Searchable, tiered, provenance-verifiable memory + edit/forget Working

Do not use OpenMuse with sensitive production accounts yet. “Working” means covered by the current test suite, not externally audited.

How it works

Channel -> durable Task -> Planner -> typed Action -> Policy/Approval -> Tool -> typed Result

The model cannot mint approval tokens. Secret decryption happens through a host callback, not planner context. See architecture, threat model, product foundation, and roadmap.

What OpenMuse is and is not

In scope today Not yet
Typed local tools, bounded loops, exact-action approval, encrypted local vault, durable tasks, audit verification, simulated mail/calendar connectors Production browser isolation, independently deployed OAuth callback, independent security review, unattended use with sensitive accounts

Contributing

See CONTRIBUTING.md, governance, and the code of conduct. Starter work is tracked with good first issue and help wanted labels.

License

MIT.

Metadata

Release files for openmuse-agent 0.3.0a0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for openmuse-agent 0.3.0a0
File Size Uploaded
openmuse_agent-0.3.0a0.tar.gz 52.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for openmuse-agent 0.3.0a0
File Interpreter ABI Platform
openmuse_agent-0.3.0a0-py3-none-any.whl Python 3 none any Details

Total release size: 93.6 kB

Release files / openmuse_agent-0.3.0a0.tar.gz

Download URL openmuse_agent-0.3.0a0.tar.gz
Size 52.7 kB
Tags Source
SHA-256 checksum
How to use checksums
b6aac8f992cf8ed2c01527be0d8de376dafbf6fde2da398053a5b1733895cdb5
BLAKE2b-256 checksum
How to use checksums
2793108aed10a54d7538c998964ac1c46ca19532efc3a78efe4e816e95d3f093
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 19, 2026.

Transparency log

Release files / openmuse_agent-0.3.0a0-py3-none-any.whl

Download URL openmuse_agent-0.3.0a0-py3-none-any.whl
Size 40.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
e5748e0ee1fd1dbc98b13eaa0c0f904bfa458374f288749c4d2a73aa00cc1a33
BLAKE2b-256 checksum
How to use checksums
e4b5cc06fadae6d7b46755fc12aa63548de643550aa31d8ebec812b6419f0f64
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 19, 2026.

Transparency log
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page