What's new in 0.15
Released 2026-10-01. Upgrade with
npm install -g buildwithnexus@latest. Some defaults changed. The upgrade notes in
docs/UPGRADING-0.15.md
list each change and the setting that brings back the old behavior. Where no setting exists,
the old behavior was a defect or lost data.
First launch never offers to install packages, bwn's own connections use your
proxy and the operating system's certificate store, and auto-update stays within your minor
version. A repository's hooks, commands, skills and allow rules take effect only after you
trust them, and the terminal UI asks before it uses the repository's AGENTS.md.
An approval for rm and similar commands covers only that exact command, deny
rules match commands inside wrappers, and provider keys stay out of the agent's commands.
Setup finishes only after the chosen model answers. Every mode shares one conversation. A headless run's exit code tells you how it ended. The release also adds
helpers that run in parallel, extra working folders, sign-in for MCP servers that use OAuth,
editor support over the Agent Client Protocol, a GitHub Action, Claude Code's hook decisions
and events, and pictures, PDFs and screenshots the model can read.
Permissions and approvals
- accept-edits mode. File edits inside the project and inside folders added
with
--add-dirrun without a prompt. Commands, deletions, network access, sensitive paths and changes inside.gitstill ask. Turn it on with--permission-mode accept-editsor/permissions accept-edits. - bwn checks permission names.
"permission": "acceptEdits"and"accept-edits"now select accept-edits mode. In 0.14 they meantauto. An unknown--permission-modeexits 2, and an unknownpermissionsetting prints a warning and usesask. - Allow, ask and deny rules go in
settings.json, along withnetworkhost lists. Deny overrides ask, and ask overrides allow. A deny rule refuses in every permission mode, an ask rule asks even inauto, and an allow rule skips the prompt. Read-only mode still refuses every change, and sensitive paths and dangerous commands such asrm -rf /still ask. A project's settings add ask and deny rules right away. They add allow rules only after you trust the folder. - Some approvals cover only the exact command. Answering
soraforrm,mv,cp,chmod,killand similar programs covers that exact command. The same holds for a git command that discards changes or rewrites history, such asgit reset --hard,git push --force,git branch -Dorgit clean.Escat an approval refuses the call and stops the turn.d <reason>refuses and lets the model continue. - Deny and ask rules match commands inside wrappers. A
run_command(git push*)deny rule also refusessudo sh -c 'git push',git -C . push,env FOO=1 git pushandmake && git push. The rules match the command behindenv,sudo,xargs,find -exec,uv runand other wrappers. They also match insidesh -c,cmd /cand$(…), and after git's own options. - Destructive Windows commands ask even in
auto. These includerd /s,del /q,diskpart,reg deleteandRemove-Item -Recurse -Force. Sensitive-path checks read Windows paths too, sorg . C:\Users\me\.ssh\id_rsaasks first. - A turn that answers a question in PLAN or BRAINSTORM is read-only, whatever the session's permission mode.
@diffand@statusask before running git in a repository whose git config can run programs, as/diffand/commitdo.- A permission switch lasts for the session. Typing "use auto" or running
/permissions autono longer writes settings, but/permissions default <mode>does./permissionslists saved approvals and rules, and/permissions remove <entry>removes one. - Web search asks first outside
auto, like a fetch. - Keys stay out of commands. bwn removes provider key variables, such as
*_API_KEYand*_API_TOKEN, from the environment of every command the agent runs.shell_env_passthroughkeeps the variables you name. On Linux and macOS, bwn's own environment block shows provider keys as****. A process's/proc/<pid>/environis a sensitive path, so reading it asks first in every mode. - A call quoted in an answer never runs. When a local model describes a
tool call in prose, such as "you could send
{"name": "run_command", …}", bwn keeps it as text in every mode. - Network rules match every spelling of an address. A rule for
127.0.0.1also matches[::ffff:7f00:1]. bwn refuses a redirect to a denied host before following it. - bwn sends a desktop notification when an approval or a question is waiting. By default
it sends one only while the terminal is unfocused. The
notifysetting changes that.
{
"permissions": {
"allow": ["run_command(cargo test*)"],
"ask": ["write_file(migrations/**)"],
"deny": ["run_command(git push*)"]
},
"network": { "deny": ["*.internal.example"] }
}
Hooks and trust
- Hook matchers take Claude Code tool names such as
Bash,Edit,Write,WebFetchandmcp__.*, so a matcher copied from a Claude Code settings file matches the same calls."on_error": "deny"makes aPreToolUsehook that crashes block the call. bwn reports unknown events instead of ignoring them. - bwn checks a project hook's trust again each time the hook runs. If the hook changed since you trusted
the folder, bwn asks again and names the file that changed. A headless run skips the
changed hook with a warning. The trust prompt is one screen
with one question. Answer
yto trust everything listed, orn, the default, to trust nothing. A third answer,e, trusts everything exceptbase_urlandpermission. bwn offers it when the project settings set one of those two keys along with other keys, and apermissionofreadonlydoes not count. - The question about a repository's
AGENTS.mddefaults to No. Anything you type while it is open goes to the composer when it closes. A headless run uses the file whatever you answered. It prints a notice on stderr until you answeryin the terminal UI. - For CI,
buildwithnexus trust --printprints a digest of the project settings, and--trust-project <digest>trusts exactly that content for one run. A repositorybase_url, or apermissionother thanreadonly, also needs--trust-project-allow base_url,permission. - A repository's own commands, skills and agent files load only after you trust them. Adding, editing or removing one asks again.
- A repository's
.buildwithnexus/system.mdapplies only after you trust the folder, and bwn adds it after your ownsystem.mdinstead of replacing it. A repository skill with the same name as a bundled or user skill loads as/project:<name>. - Hooks take and return Claude Code's formats. A
PostToolUsehook can add to the result the model sees. AStophook can keep the agent going for at most 3 rounds.tool_inputcarries Claude Code's field names. - The new hook events are
PermissionRequest,PreCompactandNotification. APermissionRequesthook can answer allow, deny or ask for you.Notificationfires when an approval or question is waiting, a turn is done, or the prompt is idle. A hook with"type": "http"POSTs the event as JSON to a URL.
Keys and setup
- bwn hides a key as you type it and saves it only after the provider accepts it. Setup,
/loginand/modelshare one key question. bwn refuses anything that cannot be a key, such as a sentence or a menu number, without sending it. A/commandcloses the question and sends nothing, and in a session the command runs next. bwn asks again after the provider rejects a key. - bwn saves a custom OpenAI-compatible endpoint's key for that endpoint only. Pointing
/modelat a new address asks for that address's own key and never sends another server's. - Setup finishes only after the chosen model answers. When it cannot finish, it says why, such as an unreachable address, an Ollama with no models, or a gateway that needs a key.
/loginandbuildwithnexus loginreplace a rejected key in place and check the new key before saving it.- First launch never offers to install packages.
buildwithnexus doctorprints the install command for each missing tool and exits 1 when a check fails. /modelremembers each provider's address. The banner names the preset and its address, such asLM Studio (localhost:1234), instead of the wire protocol./initwritesAGENTS.mdfrom the repository's own build and test files and shows it as a diff for you to approve.
Local models
- bwn uses the real context window that llama.cpp, LM Studio and vLLM report instead of
guessing 8,192 tokens.
/contextshows what fills it. - Image support follows what the server reports. A
visionsetting overrides it. - Errors say what to do: a rejected key points at
/login, a missing Ollama model names itsollama pullcommand, and a stopped server readsnothing is answering at <host>. - With a spend cap set, a run on a remote model without a known price stops before the
first request, exits 2 and asks for a price. A model server on another machine counts as
remote, unless bwn reaches it through Ollama's native API. A
pricessetting gives any model a price. - bwn retries a 429, 500, 502, 503, 504 or 529 answer 3 times. In 0.14 it retried 4 times
for remote models and 14 times for local servers. bwn never retries an out-of-memory error.
A server that answers 503 while it loads a model gets 14 retries, about two minutes.
BWN_MAX_RETRIESsets the count, from 0 to 20. - bwn's own connections use
HTTPS_PROXY,HTTP_PROXY,ALL_PROXY,NO_PROXYand the operating system's certificate store. They always reach loopback addresses directly. They also go directly to private network addresses, such as a model server on your local network, unless you setBWN_PROXY_PRIVATE=1.
Helpers and folders
- Helpers that only read and isolated helpers started by the same reply run at the same
time.
max_parallel_helperscaps how many run at once. It defaults to 3. With a local preset or a server at a loopback address, it defaults to the number of requests the server reports it answers at once, up to 3, or to 1 when the server reports none. Each helper shows in its own block when it finishes. Helpers that write in your folder still run one after another. - Helper agents. An agent file with
name,descriptionandtoolsfrontmatter in~/.buildwithnexus/agentsor~/.claude/agentsbecomes a helper agent the model can delegate to, limited to those tools. A trusted repository's.buildwithnexus/agentsand.claude/agentscount too./agentslists them. - bwn commits an isolated helper's uncommitted edits to the helper's
bwn-sub-*branch, and the result names the branch and thegit mergecommand. In 0.14 bwn deleted those edits when the helper finished. read_only: truein an agent file, or on the call, makes a helper that can read and search but never change anything.--add-dir <path>and/add-diradd folders to work in for the session. The sandbox lets commands write there too. bwn never loads their settings, hooks or commands.
Pictures, PDFs and screenshots
read_fileon a PNG, JPEG, GIF or WebP shows the picture to a model that takes images. bwn tells a text-only model why it sees none.read_filereads a PDF as text through poppler'spdftotextwhen it is installed.- A new
screenshot_urltool uses a local headless Chrome, Chromium or Edge to screenshot a page served on this machine, such ashttp://localhost:3000. bwn opens a page on another host only whennetwork.allowor an allow rule names that host. The page can then load from that host and from this machine, and bwn refuses its requests to every other host. "vision": falseturns off pictures andscreenshot_url.read_filestill reads PDFs as text.
MCP servers that ask you to sign in
/mcp and bwn mcp list show an http MCP server that requires OAuth as
needs login. bwn mcp login <name> or
/mcp login <name> signs in through the browser. It saves the token in
~/.buildwithnexus/mcp-auth/ for that server only. The token refreshes on its own.
bwn mcp logout <name> deletes the saved token and asks the authorization
server to revoke it when that server offers revocation. Headless runs never open a browser.
Editors
buildwithnexus acp runs an Agent Client Protocol server on stdio, so Zed,
JetBrains IDEs and Neovim plugins can control bwn. The editor shows streamed replies and plans,
and it shows tool calls with diffs. Approvals come up as questions in the editor. Add this to Zed's
settings.json:
{
"agent_servers": {
"buildwithnexus": {
"type": "custom",
"command": "bwn",
"args": ["acp"],
"env": {}
}
}
}
Conversations and sessions
- Every mode shares one conversation, and bwn saves it as the session. The mode changes only
when you change it, or when you answer
yto the model's offer to switch. A task typed in BRAINSTORM gets a tip to switch modes. bwn continuereopens this folder's latest session, and/resumelists this folder's sessions first./rename,bwn sessions rmandbwn sessions exportare new./undoasks before overwriting a file you changed after the agent edited it, and says what it cannot undo./rewindgoes back to an earlier prompt and restores the code, the conversation, or both./commitshows the drafted message and commits only after you pressc./difflists every changed and new file, and/diff turnshows what the last turn changed./export,/copyand/askare new./askanswers a side question without adding it to the conversation.- The plan selector has a new Revise Plan choice. Say what to change and you get a revised plan. Edit Step opens the step's text in the composer.
- Background workflows from
/scheduleand/looprun with the session's permission mode, provider and model instead of the ones insettings.json.
Headless and CI
Piped stdin becomes the task when you give none. When you also pass a task, bwn adds stdin
after it as context, for example git diff | bwn run "review this". Custom commands and skills run
headless and take $ARGUMENTS. The new --base-url flag points a run at a
gateway, and the new --worktree <name> flag runs the session on its own branch.
buildwithnexus review and buildwithnexus update are new commands. A mistyped
/command exits 2 instead of reaching the model. When a custom command or skill
differs from it by at most two letters, the message names that one. Failure messages
name flags and variables rather than slash commands. An http hook fills in $NAME
in its headers from the variables it lists in allowed_env_vars. The exit code
tells you how a run ended:
| Exit code | Meaning |
|---|---|
0 | Finished |
1 | Failed, or the turn ended right after a call that could not run |
2 | Usage error, including an unknown option, no task, a spend cap on a remote model with no price, or a repository command that is not trusted |
3 | bwn blocked changes for lack of approval, or a hook, a deny rule or read-only mode refused them. A check_work round that nobody could approve does not count. |
4 | A UserPromptSubmit hook blocked the task |
5 | --max-budget-usd stopped the run |
6 | The turn ran out of steps |
7 | The project's checks, run by check_work, still fail |
8 | The verifier still blocks after its fix rounds |
9 | buildwithnexus review found a blocking issue |
130, 143 | SIGINT or SIGTERM interrupted the run, and bwn saved the session |
With --json, the last event names the outcome, the session id, tokens, estimated
cost and every refused call. --legacy-exit-codes turns the codes for runs that
stopped short back into 0.
The repository is also a GitHub Action. It runs bwn run or
bwn review, turns the exit code into the step's result with annotations, and can
comment on the pull request:
- uses: Garretts-Apps/buildwithnexus@v0.15.1
with:
command: review
review-base: origin/${{ github.base_ref }}
provider: anthropic
max-budget-usd: "1"
env:
ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
Terminal
- bwn has new dark, light and ansi colour themes. The
themesetting defaults toauto, which follows the terminal's background, so a light terminal gets the light theme./themeswitches and saves it. --plainorTERM=dumbselects line mode, for screen readers and plain consoles.Esccancels a question. Pickers filter as you type, a digit moves to a row, and only Enter picks.Ctrl+Con an empty prompt quits only on a second press.- Pasted line breaks reach the model.
/help, the/popup and Tab completion list every command. - Each tool call shows as one plain line, and the agent's todo list shows as a checklist.
- The file tools skip what
.gitignoreignores.
Auto-update
"auto_update": "install" installs only patch releases within your minor version.
bwn announces a new minor or major version and tells you to run
buildwithnexus update.
"install-any" installs any newer release, as "install" did in 0.14.10.
The npm launcher keeps the binary in ~/.buildwithnexus/bin/<version>/, outside
the npm package. The Windows exe links the C runtime statically, so it runs without the
Visual C++ Redistributable.