Release notes
The agent can watch a video
The agent can now look at a video: it samples frames from a clip into one contact sheet it can see, so it can check a demo it just recorded or analyse a screen recording you drop in the workspace. This build also hardens the run, provider, filesystem, and MCP paths.
New
read_videosamples frames from a clip and returns them as one contact-sheet image the agent can see. Use it to verify a clip recorded withrecord_browser_video, or to analyse a video file in the workspace. By default it samples the clip's own markers; otherwise it spreads frames evenly across the duration. The result lists each tile's timestamp, so the agent can map a tile to its moment. macOS only, and local to this Mac.
Fixed
- The tab-drop preview on a split edge is no longer clipped behind the pane's content. It now paints above the pane's own layers, including the plan card, and still below an open modal or palette.
- A run's saved state is written in order and coalesced, so a burst of updates cannot land out of order or lose the newest one. A run that ends twice keeps its first terminal outcome, and a resumed run cleans up only its own state.
- The verification requirements a run was given survive the display cap and a restored checkpoint, so a resumed run is still held to the same bar.
- Recovery stops asking for an action it cannot take: an unavailable action is not consumed, and exhaustion is measured against progress rather than attempts.
- Streaming responses are bounded. A single SSE frame and an error body are capped, so a malformed or hostile provider response cannot grow without limit. Legacy line-delimited and EOF-terminated gateways still work, and partial usage is still recorded, including for a failed or cancelled review.
- Provider routing is scoped to the provider, so a model-name prefix no longer vetoes a route. Saved legacy base URLs are preserved, and transport URLs are redacted from diagnostics.
- Filesystem writes stage atomically and exclusively, preserve permissions, refuse a copy onto itself or into its own subtree, and read only up to the requested limit. Existing symlink behaviour is unchanged.
- Login and PATH bootstrap is bounded, and a cancelled command is not spawned.
- MCP sessions are scoped to the workspace, config, and account, with generation fencing, atomic private config writes, and bounded idle retention. A mutation is never replayed ambiguously, and the desktop and the host agree on a missing session and an explicit 404.