Changelog

What’s new with Murph

Seven days of features and improvements from the full Murph archive.

Referrals, Max, and a more capable Murph

A public referral home, the Max plan, personalized contact cards, live workout logging, safer Family setup, private group follow-ups, clearer connection paths, and stronger conversation recovery all landed together.

New features

Feature

Referral rewards have a public home

The new Referral page explains the earning paths currently available, shows rewards in Murph usage days, and keeps your reusable link ready to copy when link rewards are on.

The page separates personal signup rewards from group missions, states eligibility before you share, returns you after sign-in, and keeps another member's identity and private data out of reward confirmations.

Feature

Meet Murph Max

Max is a new $50 monthly personal plan with Murph's highest included AI usage for frequent deep research, analysis, and heavier ongoing use.

Settings uses the existing plan-change confirmation and Stripe handoff. Upgrades activate after payment confirmation, scheduled downgrades stay visible, and an exhausted Max plan points to the existing add-usage or reset recovery.

Murph Max

$50 monthly

Included AI usage

Highest

Deep research

More room

Ongoing analysis

Built for it

Feature

Give Murph a new contact photo

Ask Murph in a private iMessage conversation for a new contact photo and get one saveable contact card with the generated square image and your current Murph line.

The request is one-shot and stays bound to the turn that asked for it. Murph refuses an ambiguous route before generation and never reports a card as delivered unless the sending service confirms it.

Contact card

vCard

Murph

Your requested contact photo

MobileCurrent Murph line
Add to Contacts

Feature

Start Family setup safely from a group

When someone asks about a Murph Family plan in a group, Murph now offers a private conversation or a stable browser handoff into that person's Family settings.

The group never reads Family status or creates billing and invite links. Sign-in happens before the personal Settings handoff, and Family requests stay distinct from sponsoring or adding usage to the current room.

Murph Family

Set this up privately

Continue in your private Murph conversation or sign in to open your Family settings.

Open Family settingsMessage Murph privately

Feature

Run a workout set by set

Murph can start a live structured workout, add exercises, log or correct one exact set, clear a mistake without shifting later sets, and finish with the elapsed duration.

Saved routine targets remain plans, never completed work. Repeating an explicit set update changes the same recorded set, and repeated same-day workout tallies now count planned occurrences without inventing missing repetitions.

Live workout

3 rows
SetRepsLoad
Bench · 18135 lb
Bench · 28135 lb
Bench · 3PendingPending

Feature

Continue a group question privately

Ask Murph in a group to continue with you privately, and your personal Murph can send the answer only to your verified direct chat on the same channel.

Murph uses the exact group message author and checks the direct chat before personal work begins. If no eligible direct chat is available, Murph asks you to open one on that channel and retry.

Improvements

Improvement

Group sleep checks use fresh shared data

Murph now checks the current shared sleep record before answering, counts reported Deep and REM sleep as soon as those values are shared, and includes explicit manual corrections.

The latest manual correction for a sleep date wins and is labeled Manual instead of a connected source. Reconnected sources no longer combine an old disconnected status with a newer sync time. Future-dated entries stay excluded, and missing data remains unverified.

Improvement

Connections explain the route before you leave

Direct connections now explain the handoff before authorization, Apple Health relay sources use recognizable service icons, and unsupported sources get verified export guidance.

Relay cards still make Apple Health ownership clear. Manual exports are described as snapshots rather than live sync, private files move to your private Murph, and Murph does not invent an export menu it cannot verify.

Improvement

Body-composition guidance fits the actual goal

Murph now routes weight loss, weight gain, cutting, bulking, recomposition, and maintenance into one evidence-backed body-composition approach.

The guidance keeps the roles of nutrition and training clear, compares trends in consistent units, minimizes tracking burden, and uses separate safety handling when pregnancy, postpartum recovery, breastfeeding, or under-fueling changes the answer.

One goal, clear ownership

evidence-backed
goalChoose the body-composition lane
habitUse the minimum useful tracking
rampAdjust only after a real trend

Improvement

Group replies respect who has the floor

Murph now understands the native reply relationship between group messages and gives ordinary conversations a longer beat before answering.

A reply edge never invents the target's words or identity. Human-owned beats can finish silently, urgent coordination skips avoidable delay, and a burst still produces at most one terminal action for the room's current moment.

Group chat

Replying here: Tuesday works better.
Same here.
Tuesday has the room. Want me to help with a time?

Improvement

Group sponsorship stays quiet by default

Funding a group no longer produces a song or other public creative response unless the payer opens the optional personalization and chooses one.

Message, poem, and 15-second song are explicit formats. Usage credit is granted independently of creative success, and missing or older customization state never counts as song consent.

Personalize (optional)

Quiet by default

No room message

Selected

Message, poem, or song

Opt in

Improvement

Response cards survive long turns and newer messages

Private nutrition and compact-table cards now keep their full structure when a long conversation is condensed and still use Murph's verified web address.

The result returns as one card in the same conversation with an accurate static or text fallback. Empty fallbacks stay silent, and invalid card data is rejected.

Private response card

2 rows
MetricTodayGoal
Protein92 g120 g
Fiber24 g30 g

Improvement

Nutrition cards fit Messages cleanly

Static nutrition cards now use Messages' own app icon and rounded frame, with only the date and meal count beneath the card unless totals are partial.

Calories, nutrient totals, and goal status stay inside the card without a second Murph badge or a long repeat below it. Provider chrome keeps only a short partial-data warning when needed.

Improvement

Typing can warm Murph before you send

For an established private chat, an authenticated typing hint can help Murph get ready while you compose the message.

Typing is never treated as a message, permission, or delivery claim. Unknown or ineligible hints quietly fall back to the normal path, and the later accepted message still owns the reply.

Private-chat start

best effort

Authenticated typing hint

Warm the existing shell

Accepted message owns the reply

Improvement

Recurring automations repeat themselves less

Dynamic recurring automations can now use a small recent-output history to avoid substantially repeating the same quote, fact, prompt, suggestion, or recommendation.

The history stays tied to the current version of the automation. Exact-text reminders remain exact, and old output is treated as history rather than a new instruction.

Improvement

Restarts keep the latest conversation work

When Murph restarts while saving its latest work, the new instance now waits for that exact handoff instead of restoring an older conversation.

The handoff remains automatic and limited in time. A faster save preserves the same protection for restored and newly arrived messages without adding routine startup delay.

Conversation handoff

automatic

Recognize the active save

Preserve the latest handoff

Resume fresh conversation work

Improvement

Privacy cleanup continues while Murph is paused

Pausing Murph no longer blocks already-authorized cleanup of expired private inbox media.

Ordinary replies stay paused. Only already-approved retention cleanup can briefly resume, remove expired media, and save the cleaned state.

Paused-member privacy cleanup

Ordinary assistant work stays paused
Expired private media is removed
A new member action is required

Improvement

Background results leave more room for current replies

Proactive follow-ups and completed phone-call results now do less blocking background work, leaving current replies more room to run during busy moments.

Current replies still keep priority, while card and call destinations, duplicate protection, and recovery stay unchanged.

Background results

less shared work

Read prior reply context in bounded batches

Prepare completed call results

Leave current replies room to run

Improvement

Feedback can carry bounded reproduction context

When a product problem has useful reproduction evidence, the internal feedback path can store a bounded model-written summary with concise steps and environment context instead of attaching the raw conversation or service response.

Ordinary feedback remains silent and best-effort. Recognizable shaped identifiers and secrets receive deterministic scrubbing, but the path does not claim that every private meaning can be detected or removed.

Exact experiment links and steadier background work

Murph can point to the precise private experiment you asked for, while group funding, scheduled work, device sync, room memory, and shared-page previews recover more cleanly.

New features

Feature

See how Murph runs

The homepage now explains Murph's private runtime, how tools connect to the conversation, and why that architecture matters without requiring a technical detour.

Improvements

Improvement

Group funding has one clear recovery path

Monthly sponsorship and one-time contributions now return to the same group-funding flow when checkout needs to resume, reconcile, or explain what happened.

A verified payment still owns the credit grant, an uncertain checkout stays recoverable without a second charge, and group usage can continue independently of optional public creative output.

Group funding recovery

Verified payment owns the credit
Uncertain checkout stays recoverable
Create a second charge

Improvement

Room context survives longer conversations

Group-room memory maintenance now preserves the latest trustworthy room context when a long conversation needs compaction or a background refresh fails.

The room keeps one trusted, limited history. A maintenance failure does not replace known context with an empty or misleading status.

Group chat

House rule: weekend workouts stay social.
What should we do Saturday?
Keep it social: easy circuit, no leaderboard.

Improvement

A backlog of automations clears more cleanly

When several scheduled jobs become due together, Murph can collect and clear the limited backlog in one coordinated pass instead of repeatedly waking around the same work.

Each occurrence keeps its existing approval and delivery path. Capacity stays limited, and one busy lane cannot silently create duplicate work.

Due automations

Admit the bounded due set
Preserve each occurrence
Duplicate the backlog

Improvement

Shared Murph pages unfurl again

Referral, experiment, biomarker, and other shareable pages now trace their social-preview assets correctly instead of losing the image during route rendering.

Improvement

Device sync recovers from brief service contention

If a sync update briefly collides with another write, Murph releases the contested step quickly and asks the wearable service to try again.

The retry stays with the same sync job and cannot turn one update into a second import or duplicate health event.

Sync recovery

Wearable sourceSyncing
Murph health recordConnected

Improvement

Proactive group messages return to the right room

Before sending a proactive group update, Murph now verifies that the saved conversation route belongs to that exact room.

It cannot borrow another member's route or guess a room from private identity. If the room is ambiguous, nothing sends.

A personal first read, richer automations, clearer trends

Murph can offer one useful personal read after onboarding, keep scheduled work within its supported delivery route, send a bounded email from a connected account in a current private conversation, research a focused public question, and show repeated experiments and biomarker ranges more clearly.

New features

Feature

A useful first read after onboarding

After completed onboarding, Murph can offer one specific interpretation grounded in your available health evidence and one optional low-burden next action.

The read is private, focused, and scheduled only once. It does not automatically create a plan, habit, experiment, or reminder, and it stays honest when the evidence is too thin for a useful interpretation.

Private conversation

Your sleep timing has been steadier this week. The useful next step may be keeping the same wake time tomorrow.
That feels manageable.

Feature

A scheduled private call can run when it is due

When a saved private conversation supports scheduled calling, its automation can place the exact requested phone call when the occurrence is due and return the result there.

Email, Telegram, and group conversations are not eligible. Manual or mismatched occurrences also fail closed, and an uncertain call start is not automatically repeated.

Feature

Send a bounded email from your connected account

In a current private conversation, you can ask Murph to send an ordinary email from an active Gmail or Outlook connection when the sender, recipients, and content are clear.

Attachments and scheduled sends are not included. A send completes only after the email service confirms success; if the result is uncertain, Murph checks Sent mail narrowly and never automatically repeats the send.

Feature

Research one focused public question

When current evidence would materially improve an answer, Murph can run one bounded research lookup over a finite public health scope and map the answer back to usable sources.

Names, private notes, arbitrary question prose, and account data never enter the live research request. If the scope cannot be represented or no source is usable, Murph says the lookup did not run or found nothing usable.

Focused current research

public scope only

Represent the question safely

Map a usable source

State limits with the answer

Feature

Repeated experiments show today's occurrence

Experiment progress can now distinguish the specific occurrence due today from the overall repeated cadence instead of collapsing the schedule into one generic day.

Experiment cadence

Mon7:00 AMOccurrence 1 · complete
Wed7:00 AMOccurrence 2 · today
Fri7:00 AMOccurrence 3 · upcoming

Feature

Biomarker charts show the reference band

Result charts now place the reported value against its available lower and upper reference bounds, making in-range and out-of-range context easier to scan.

The band reflects the source result's own reference context. Missing or one-sided bounds stay visibly incomplete instead of being replaced with a universal range.

Fasting glucose

Improvements

Improvement

Scheduled tools follow the delivery route

Scheduled work can generate an image where the route supports image delivery, show an explicitly requested response card in a private direct chat, and offer a Clinical Records handoff that begins only after you open it.

Email delivery stays text-only, private and group boundaries stay intact, and Clinical Records sign-in does not start until you open its launcher.

Improvement

Group calls can start without a duplicate preview

In an authenticated group chat, a current participant can ask Murph to make one bounded public-venue or service call for the room without a special second approval step when the request is already complete.

Murph still asks for any missing commitment bound or requester fact. Participant, current-message, membership, privacy, and transfer checks remain in place, and a call start never claims the later outcome.

Improvement

Interactive iMessage cards are back

Private structured responses can once again arrive as interactive iMessage cards, with the existing static layout or deterministic text recovery when the extension is unavailable.

Interactive iMessage card

2 rows
DaySleepSteps
Mon7h 42m9,120
Tue7h 18m10,404

Improvement

Group answers use the room's own context

Murph now grounds a group reply in the room's learned norms and recent shared context without dropping that context when the prompt grows.

Room memory remains separate from private member memory. It guides how Murph participates but never creates identity, permission, or health-data sharing authority.

Group chat

Remember, no one wants a sunrise start.
Plan Saturday?
Late-morning walk, then coffee. No sunrise involved.

Improvement

Billing recovery leads back to Murph

Paused, lapsed, or recently changed subscription states now resolve through one clearer access-recovery path instead of leaving Home or a browser return in a contradictory state.

Stripe remains the billing authority. Settings and conversational recovery wait for that projection, preserve scheduled plan changes, and avoid creating a second checkout while the first result is still uncertain.

Subscription recovery

Your plan change is still settling

There is no need to start another checkout. Murph will use the confirmed billing result.

Check statusReturn to Murph

Improvement

Cancel a file that has not been delivered

Murph can now cancel a pending generated-file delivery before the send begins, without deleting the underlying private file or affecting a delivery that already started.

Pending file

Cancel before delivery starts
Keep the private source file
Recall an entered provider send

Improvement

Meal capture respects your latest choice

Rapidly enabling and disabling meal-photo capture now preserves the newest explicit choice even when an older setup or closeout operation finishes later.

A delayed operation cannot silently re-enable capture, duplicate a daily closeout, or override a later opt-out.

Meal capture

Latest choice wins

Photo capture

Off

Daily closeout

Stopped

Faster starts, richer X answers, better continuity

The companion can start before a device is connected, X answers can use images and video, browser work reports progress in the current turn, health-data choices read more clearly, and late cards, images, support escalations, and first-contact messages stay attached to the right place.

New features

Feature

Open the companion before connecting a device

A signed-in member can now enter or resume the native companion without first choosing a wearable or health source.

Device setup remains available when useful, but it is no longer the admission gate for the app or the member's existing account state.

Murph companion

Murph

Ready before device setup

Feature

Browser work shows progress in the current turn

When Murph uses the browser for noticeable work, progress now stays visible and belongs to the exact conversation turn that started it.

A later turn cannot inherit an old browsing status, and a finished or abandoned browser task clears its own progress rather than leaving the conversation looking stuck.

Current browser task

this turn

Open the requested page

Check the visible details

Return the result here

Feature

Recovery insights require corroboration

A weekly insight can now notice a sustained recovery or readiness decline only after checking source freshness and finding an independent signal or relevant context.

One proprietary score is never enough. When the evidence clears the bar, Murph offers at most one reversible low-burden adjustment with a guardrail and reassessment trigger.

Weekly recovery read

Fresh source + corroborating signal

One adjustment

Reassess before changing more

Feature

Ask about images and video on X

Murph can inspect the images and video in a relevant X post, instead of relying only on its text.

The existing live X search now asks Grok to inspect relevant media. Murph keeps the source link, separates the post text from what the media shows or says, and treats the result as unverified third-party content.

Improvements

Improvement

A first message gets moving sooner

First contact now uses the faster welcome path and starts preparing the conversation after enrollment, reducing avoidable work before Murph's first useful reply.

Consent and activation still finish before the assistant can use member data. A failed prewarm quietly falls back to the ordinary durable message path.

First contact

faster path

Finish activation and consent

Warm Murph's shell

Answer the accepted message

Improvement

Late cards and images return where they started

A nutrition card or generated image that finishes late now resumes in its exact originating conversation and session instead of attaching to newer work.

Attachment transfer retries only before the send could have started. If delivery is ambiguous, Murph will not make a blind second attempt or duplicate the media.

Improvement

Support escalations carry the issue, not the conversation

After an explicit request in a verified private conversation, the support email can include a short model-written problem summary instead of attaching the raw conversation or service response.

The email stays linked to the member for follow-up and can contain free-form issue context. Recognizable shaped identifiers and secrets receive deterministic scrubbing, but the route does not guarantee that every private meaning is removed or promise a response time or ticket status.

More ways to connect, prepare, and finish

Apple Health relay wearables, next-group preparation, compact response tables, more reliable nutrition cards, clearer public links, and several setup, delivery, and maintenance recoveries all shipped together.

New features

Feature

Bring more wearables through Apple Health

Connections now includes guided Apple Health relay paths for Huawei Health, Xiaomi or Mi Fitness, Zepp or Amazfit, COROS, Suunto, and RingConn.

Each card explains that Apple Health remains the sync source and opens the existing companion setup guide. Relay source cards never appear as direct connections or show a false disconnect state.

Feature

Prepare your next Murph group

A group owner can prepare one upcoming room for a short window, optionally choosing the room style and guidance before the new group starts.

Preparation applies only to the next new room, expires after 30 minutes, and cannot modify an existing group or create ownership for someone else.

Next group preparation

Now30 minPrepared room style and guidance
NextNew roomApplies once

Feature

Structured answers can arrive as compact tables

Murph can now return a small tracked or untracked table in a private iMessage card when rows and columns make the answer easier to scan.

The card stays presentation-only unless the request has an explicit tracking contract. It keeps a deterministic text fallback and returns to the originating thread as one response.

Tracked compact table

2 rows
HabitThis weekStatus
Morning walk4 / 5On track
Lights out3 / 5Building

Feature

See the connected-app handoff before leaving Murph

Before a connected-app authorization opens, Murph now shows a short first-party preview that explains the external handoff and lets you continue manually.

The countdown pauses when the page is hidden, authorization does not start before the handoff is visible, and closing the preview leaves the existing connection flow unchanged.

Connected app

Continue to authorize

You are leaving Murph to approve this connection with the external service.

ContinueNot now

Feature

Murph can account for official local alerts

When heat, cold, or outdoor air quality matters, Murph can check the official alert for your location and use it as added health context.

Murph uses the official service's location-specific alert instead of applying one temperature or air-quality threshold everywhere. An alert alone does not trigger outreach, unrelated hazards stay out of health reasoning, and a failed check does not block the rest of the answer.

Official local alert

Outdoor activity context

Heat advisory

Location-specific, not a universal threshold

Improvements

Improvement

Daily nutrition cards render in the conversation

Daily nutrition cards now use the supported iMessage layout, so the compact totals appear directly in the private conversation.

The card keeps the date, logged-meal count, every available total, one exact saved goal and status, and a visible partial-totals marker when meal support is incomplete. Text fallback remains available when the card route cannot be used.

Daily nutrition card

2 rows
MetricTotalGoal
Protein92 g120 g
Fiber24 g30 g

Improvement

One-time group contributions fit on a phone

On mobile, the one-time group contribution flow now opens as a focused bottom drawer with the amount and next action in reach; desktop keeps the dialog treatment.

Monthly sponsorship remains primary, a one-time contribution stays explicitly separate, and no payment starts until the contributor chooses the amount and continues.

One-time contribution

Separate from monthly

Add group usage

$10

Checkout starts

After continue

Improvement

Scheduled reminders keep their own approval

Editing or reviewing one scheduled reminder no longer borrows authority from another reminder or loses an independently approved occurrence.

Each reminder keeps its own audience, schedule, and approval evidence. A review regression cannot silently send, suppress, or rewrite a different reminder.

Independently approved reminders

Tue8:00 AMMedication · approved
Thu6:00 PMCall Dad · review pending

Improvement

Setup recovery stops at the right point

Onboarding follow-up now expires after three days, and a group join can recover after activation without replaying setup that already finished.

The companion sync status also uses the server time for a trustworthy freshness comparison. Recovery resumes the existing activation and sync instead of starting a second one.

Setup recovery

Recognize completed activation
Resume the existing group join
Repeat finished setup

Improvement

Venice explains the usage tradeoff before save

The model choice now states, in shorter language, that Venice can use included AI capacity faster before you commit the setting.

The explanation applies to future usage and keeps the actual model-rate accounting already introduced on the previous day.

Model provider

Before save

Venice

Can use capacity faster

Selected

Managed models

Murph's standard route

Available

Improvement

Product feedback starts with what went wrong

When you share product feedback, Murph now clarifies the underlying problem and impact before jumping to a proposed solution.

The conversation stays user-facing and concise, and an escalation still requires the separate explicit support path.

Private conversation

The meal flow is frustrating.
What happened, and where did it stop you?

Improvement

Environment setup uses the full dashboard width

The empty Environment panel now lines up with the rest of the dashboard instead of sitting inside a second, narrower page cap.

The existing voice walkthrough, chat alternative, report preview, desktop columns, and mobile stack keep their current behavior.

Improvement

Storage maintenance no longer needs a global pause

Murph can keep ordinary replies, saved conversations, attachments, and uploads available while its saved data moves safely.

If Murph cannot confirm that the new storage is ready, the move stops safely. Messages already received remain available when the conversation resumes.

Live storage maintenance

Ordinary replies stay available
Attachments and checkpoints continue
Pause everyone by default

More control over data, models, and connections

You can bring a compatible model endpoint, pause health-data processing, ask for a nutrition card, disconnect one wearable source, and get clearer recovery across usage, device sync, physical notes, photos, and follow-up timing.

New features

Feature

Bring your own model endpoint

Settings now lets you use Murph's managed models or a compatible custom endpoint for core replies in your personal conversation.

Murph verifies a public HTTPS endpoint, encrypts its connection details, and never silently falls back to a managed model if the custom route fails. Murph's health tools and other hosted services keep their existing funding and privacy boundaries.

Feature

Ask for today's nutrition card

In a private conversation, you can ask for a daily nutrition card with the current totals for calories, protein, carbohydrates, fat, and fiber.

When the date and data are clear, the card can also show an exact saved goal and status. Missing goals stay missing, uncertain dates fall back to a normal reply, and group or unrelated scheduled turns do not produce the card.

Feature

Disconnect one wearable source at a time

The Connections page can now remove one selected wearable source without disconnecting your other sources or deleting their history.

The chosen source keeps its imported history but stops future sync. A failed removal stays recoverable, and reconnect-required cards now expose the same source-specific action.

Improvements

Improvement

Food estimates start with label data

Murph now looks up a nutrition label or food-database match for each identifiable part of a meal before estimating its nutrients.

Portions still come from the photo and conversation, while sauces, fats, drinks, and exact supplement labels stay explicit. A general estimate is used only when database and official-source lookup cannot resolve the food.

Improvement

Physical notes need fewer address follow-ups

When you provide a destination for an approved physical note, Murph can temporarily complete a missing city, state, or ZIP code from the address you supplied.

The lookup cannot discover where someone lives, saved prompts and notes never gain the address, and Murph's platform-owned return address stays separate from the recipient destination.

Improvement

Capacity answers stay in percentages and dates

Murph no longer turns remaining AI capacity into a guessed number of messages, even when you ask how many replies are left.

Usage answers use the known percentage, reset date, trial date, or day-level forecast instead. They do not pretend that differently sized requests consume a predictable message count.

Improvement

Venice usage reflects its provider rate

Replies sent through Venice now consume included AI capacity at the underlying provider rate instead of using the managed-model price.

Settings explains that this choice can use capacity faster. The change applies to new usage only and does not reprice earlier replies.

Improvement

Device sync retries transient write failures

A temporary failure while saving a replay-safe device-sync artifact now retries through the existing sync job instead of ending the import immediately.

Only safe transient writes retry. Permanent errors still stop with their specific failure, and the retry does not create a second import or duplicate user action.

Improvement

New messages keep priority after a wake

A newly accepted message now keeps foreground priority when it arrives just after Murph wakes from a saved checkpoint.

The change is invisible when timing is normal. In the race it fixes, the new message reaches the ordinary reply path instead of waiting behind restored background work.

Improvement

Group photo references carry forward

Murph now keeps a bounded room index of captions, positions, and corrections for recent group photos, then checks it before asking for another upload.

References stay tied to the conversation and do not use face recognition. Corrections can update which known photo the group means without turning the image into an identity record.

Improvement

Usage limits no longer turn into runtime errors

When managed AI usage is exhausted, accepted work stays safely pending instead of being mislabeled as a runtime failure during a background wake.

Murph does not consume the conversation or call a metered model while access is denied. The existing usage message explains the block, and the existing continuation path can resume after capacity changes.

Connected apps recover with a clearer next step

Large connected-app results now stay bounded and useful, so Murph can narrow the request or explain the real failure without losing the conversation.

Improvements

Improvement

Oversized app results can be narrowed in place

When a connected app returns more data than one reply can safely use, Murph now compacts the result and can narrow or retry the request in the same turn.

A genuinely failed app call keeps its specific safe error instead of looking like an oversized success. Raw service responses stay outside the model conversation.