Dev Log #1: Why I had to build msh (and shipping the v1.6.0 update today) ๐
If youโve ever watched an autonomous AI agent (like Claude Code, Devin, or custom CrewAI swarms) run commands in your terminal, youโve probably experienced this:
โข It runs an interactive [y/N] prompt and hangs forever.
โข It dumps a 20,000-line stack trace that destroys your LLM token budget.
โข It prints an active API key or AWS token directly into stdout.
โข Or worse: it hallucinates bad code, corrupts 15 files, and you have to manually clean up git state.
Most agents today execute raw bash on bare metal with zero safety net.
What is msh?
I built msh as a deterministic runtime and flight recorder that sits directly between the AI agent and the operating system (think sudo for AI agents).
It intercepts execution to provide:
โข Atomic Workspace Rollbacks (msh undo): Surgically reverts file diffs if an agent breaks a build.
โข In-Memory Secret Redaction: Masks environment variables and bearer tokens before stdout reaches prompt history.
โข Semantic Error Extraction: Extracts root-cause compiler errors so agents fix bugs on attempt #1.
โข Live Fleet Control Hub: A browser dashboard (msh fleet) to monitor and broadcast commands to agent swarms.
โโโโโโโโโโโโโโโโโโโ
What just dropped in v1.6.0:
Today, I just tagged and shipped our biggest architectural milestone yet: Speculative Execution & Shadow Worktrees (msh branch).
When an agent wants to test 3 different refactoring strategies, doing it on the main working tree causes index lockups and poisoned context.
With v1.6.0:
โข msh branch create <name> provisions an isolated shadow git worktree in ~40ms.
โข The agent trials hypotheses in complete isolation.
โข If it fails, msh branch abort cleanly discards the files AND emits a context synchronization payload instructing the LLM: "Prune conversation turns #12-#17; that attempt was discarded."
Just pushed the update to GitHub and refreshed the embedded Fleet UI to ~ swarm 1.6 ~ (attached screenshot above!).
๐ฆ Open source on GitHub:
https://t.co/8APDIuXIwq
Would love to hear your thoughts. If you're building or running local agents, what's currently the most frustrating part of terminal execution?
Someone copies a real webhook and sends it again next week. Does your system believe it?
SafePay webhooks now carry a unique event ID, an event type, and a timestamp inside the signature. An old copy is rejected, and a changed body fails too.
Day 9/60 Building SafePay
#60Days