Added
- Subagent conversation history is readable through the owning parent session
- Configurable live subagent status and read-only transcript switching from the interactive prompt
--experimental-harnesssessions can track todos, shown as a pinned line under the input and in full on/todo, and keep a per-session scratchpad whose notes are re-stated to the agent after the conversation is summarised.- Turn an installed skill on or off from the
/skillsbrowser without removing it. - Skill authors can mark skills as explicit-only, keeping slash invocation available while preventing model-initiated loading.
vibe mcp add --allow-insecure-httpand/mcp add --allow-insecure-httpopt into plaintext http:// MCP servers on non-localhost hosts, such as a server on the LAN.- Tool telemetry events now carry approval_source (config/smart/user/bypass/never) to distinguish how a tool call was authorized.
- Press
rin the MCP servers & connectors panel to refresh the list on demand. - Connectors view now links to Studio to add more connectors, pre-scoped to your org and workspace.
- Local app-server sessions now persist and expose their latest accepted user interaction timestamp for downstream session resources.
- Unified Harness app-server sessions can now be pinned, and remember it across restarts.
- Scheduled loops (/loop) are now available in the Vibe VS Code extension with a panel UI for creating, listing, editing, and canceling recurring prompts.
- Vulnerability disclosure guidance and private reporting instructions in SECURITY.md.
- /teleport now works under --experimental-harness
Changed
- The Unified Harness is no longer labeled "experimental";
--legacy-harnessis the documented escape hatch back to the legacy Python harness. - Sessions with OAuth MCP servers configured start faster: fewer and overlapping keychain reads.
- Approving a shell command with a variable expansion now covers the next call that differs only in the expansion.
- Switched the audio engine to miniaudio to improve stability and performance of voice recording and playback
- Connectors are listed and titled by their display name, falling back to the connector name.
- Removed the local Cargo build job cap that limited editable builds to 2 jobs, restoring full parallelism for local harness builds.
- Admin-managed config now enforces the individual keys it sets inside
session_logging,project_contextandexperiments, rather than the whole group. Keys an admin does not set are taken from the user's own config instead of being reset to defaults. - A model change requested while a turn is running is now accepted and applied at the next turn boundary, instead of being rejected.
- The Vibe CLI now sends a dedicated
MistralAI-VibeCLI/<version>User-Agent header on MCP HTTP requests, letting the connectors gateway distinguish Vibe CLI tool calls from other MCP clients.
Fixed
- Images attached to text-only models now fall back to file links instead of failing the turn.
- Worktree sessions now tell the agent about the worktree working directory instead of the original checkout.
- Subagents no longer prompt for tool permission when the parent session is in auto-approve mode under the Unified Harness
- Workspace trust decisions over ACP now require a session and can only target its working directory.
- The experimental unified harness can now record the IDE's workspace trust decision.
- Keep skills with invalid invocation policy metadata explicit-only instead of exposing them to the model.
- Creating or cleaning up a worktree no longer runs the repository's own git hooks (such as post-checkout) or its fsmonitor command.
- Show retrying status during transient provider failures.
- Cancelling a turn no longer hangs when the interrupt wedges server-side, and an interrupt that is taking unusually long now warns with the force-quit hint instead of leaving you staring at a silent "Interrupting" spinner.
- Message sending after resuming pre-existing sessions that use connectors
- Attaching an image from outside the workspace (e.g. ~/Downloads) in a fresh session no longer fails with 'Image file is outside the workspace or session attachments'.
- Existing session logs are restricted to owner-only permissions when Vibe starts.
- Vibe's home directory and the logs inside it are now accessible only to the current user.
- Tool telemetry events now carry the actual approval decision (execute/skip) and approval type (always/never/ask) instead of always None.
- MCP and connector tool calls now respect the permission system: they honor each tool's configured permission, ask before running by default, and remember your approval for later calls.
- The enabled_tools and disabled_tools config globs now apply to MCP tools, not just connector tools.
session_logging.enabled = falseis honoured again on the Unified Harness: the conversation and its attachments no longer land in the session save directory, the session log summary reports that logging is off, and--continue/--resumeare refused with the same message the legacy backend gives.- Hooks now run inside subagents on the experimental harness, instead of being silently skipped.
pre_toolandpost_toolhooks now run for theskilltool, which previously took no hooks at all.- Hook commands using pipes,
&&, redirects, globs or$VARnow run through the shell. - A hook's
matchnow matches the tool the model actually calls, includingeditand MCP tools. - Unified Harness now injects the current git branch, status, and recent commits into the system instructions, matching the legacy backend
- Shell approvals no longer widen to cover a different program, subcommand, custom shell, or environment.
- Shell approvals no longer cover side-effecting options that the command's guardrails gate.
- Approving a guardrailed command whose argument the shell could not read no longer approves the same command with a different one.