# Modera for Muse

Build your private wardrobe from photos and Gmail clothing receipts in Muse, then ask Modera for outfit suggestions. Muse keeps your photos, garment images, wardrobe and saved outfits. Modera receives selected clothing facts when you request an outfit; its outfit rules run on the server.

Give Muse this page and say:

> Install Modera from this page. Verify the published release, preserve my existing wardrobe and connection, and guide me through permissions. Offer me both wardrobe-building methods together: automatically import clothing purchases from Gmail from the past 12 months without individual item approvals, and make wardrobe cutouts from clothing in my Facebook or Instagram pictures. Let me choose both, either one, or skip. Use your live browser for Facebook and Instagram, never their connectors; explain sign-in or access limitations and offer uploaded social pictures if needed. Wait for my choices and required permissions before reading Gmail or fetching photos. Completing one method must not hide the other.

No manual ZIP upload is needed when Muse can download the published files. This is a guided installation; it is not a marketplace listing or a promise of a one-click native installer.

## What is available

Local wardrobe installation and use are unlimited. Outfit API access is open to the first **25 new installations**, admitted when protected connection setup completes, without invitations. Existing access is preserved separately. This is a lifetime limit: revocation or expiry does not reopen a place, and a download does not reserve one. If those admissions are filled, you can still build and browse a wardrobe locally.

Each installation needs its own Muse-protected authorization for outfit requests. No Modera account or iPhone app is required. Never share another person's connection or copy a token into chat. An installation is not proof of a unique person.

The public skill instructions and local tools can be inspected after download. Modera's private outfit logic, scoring rules and weights are not in the download.

## Installation instructions for Muse

1. Read [the current release descriptor](https://modera-api-755907502415.us-east1.run.app/muse/releases/latest.json) using permitted HTTPS access. It gives a fixed release version, archive URL, byte count and SHA-256, plus a manifest URL and its SHA-256. Fetch only those versioned paths on this exact origin; reject redirects or unexpected origins. Public downloads require no OAuth token or private data.
2. Check Python 3.10+ and Pillow 10.2+. Native Muse image editing is the default; check the actual host capability. Default setup requires no SAM/SCHP models. Optional segmentation tests additionally use NumPy. Use supported local dependency setup if needed.
3. Download the archive and manifest into a separate temporary directory. Verify size and SHA-256 before executing anything. Reject unsafe paths, duplicate names, symlinks, encrypted entries, extra or missing members and mismatched file hashes. Maximums: 4 MiB archive, 64 KiB manifest, 8 MiB expanded content. Inspect the package, then extract and inspect only `modera-wardrobe/bin/release_manager.py` as the installation helper. Run its `verify` command with the downloaded archive, manifest and verified checksum.
4. Discover the actual managed skills directory and existing Modera work. Keep the wardrobe and generated protected-auth connector outside the skill directory. Run the verified helper's `install` command with `--archive`, `--manifest`, `--sha256` and `--skills-root`. It stages the package, runs synthetic core tests, and installs it; upgrades preserve an unmodified prior release using an atomic directory exchange. It refuses to overwrite local modifications or continue after validation failure. Read the installed `SKILL.md`, `references/installation.md` and `references/efficient-setup.md`. Retain the installer's compact test result; do not repeat the full suite or paste its logs into the conversation.
5. Verify the installed manifest/version. Reuse an existing private wardrobe; create a new dedicated root only when one does not exist. Installation does not migrate the wardrobe. Existing version 2 local storage remains supported; the separate version 3 receipt migration runs only after the user accepts Gmail importing, with an automatic backup and verification. Keep any additional tests in a separate synthetic root, then confirm the skill is discoverable in a new conversation with the same wardrobe location. Reuse successful setup steps for the same verified release/runtime/connection. Report unsupported capabilities honestly.
6. For outfits, follow the full **Connection** procedure in installed `references/outfit-api.md`. Preserve an existing protected connection. For a new one, read Muse's actual OAuth tool schema, run `bin/connection_setup.py` for validated public settings, invoke the actual protected setup tool, then run `bin/connection_link.py` locally on its actual `capture_link` through standard input as described in installed `references/installation.md`. Only after validation succeeds, give the user that original link **unchanged**. Withhold rejected links and report the fixed error code; never bypass a failed or unavailable validator. Never construct or repair a `/connect/oauth` link, base64 `spec`, callback or session ID; never fabricate a tool result. Guide the user through Muse’s own permission prompts. Modera then returns directly to Muse; there is no additional Modera acceptance page or agreement checkbox. If a link says “Missing required parameters”, follow the installed bounded recovery procedure instead of repeating the broken link or registering blindly. No invitation is needed; admission is checked atomically when enrollment completes. Public capabilities and a clicked link are not proof of authorization. Check the protected connection, then verify a synthetic request, local display and selected save. Never substitute a local outfit engine.

7. Complete wardrobe onboarding using **Offer wardrobe setup** in the installed `references/installation.md`. Offer both methods in the same opening message: **Gmail clothing purchases from the past 12 months** and **cutouts from clothes in Facebook or Instagram pictures**. Offer both, Gmail only, social photos only, or skip. Explain receipt/product-image use, automatic additions without individual item approval, and possible social-browser sign-in. Remember each choice independently. Selecting, finishing, declining or lacking access to one must not remove the other from the offer. Follow installed `references/gmail-receipts.md` and `references/photo-sources.md` for accepted paths, preserving existing scope and host-required permissions. Facebook/Instagram use the live browser only; if unavailable, explain that and offer cutouts from uploaded social pictures. Additional supported galleries or uploads remain available. Before ending onboarding, address both source choices; keep an unanswered one pending, reuse answered choices, and never rerun completed imports. Automatically create each new item's image following installed `references/wardrobe-images.md`. Local setup remains available without outfit API access. An automatic update alone neither repeats onboarding nor starts collection.

For opted-in Gmail users, outfit requests offer a receipt refresh when at least seven days have passed since the last completed import or offer. Read the local state across conversations; ask once, continue with the outfit if declined, suppress further offers for seven days, and honor “stop asking.” There is no background mailbox scan. An update alone neither repeats onboarding nor grants mailbox access.

For outfit requests, the installed skill also supports completion plans: Modera can identify owned pieces and separate missing additions, and Muse can help find purchases. Hypothetical additions stay separate from the private wardrobe and cannot be saved as a ready-to-wear outfit. See the installed `references/outfit-completion.md`.

## Default images and weather

Adding wardrobe items includes creating their images automatically, without a separate question or prompt: use reference-photo cutouts when a usable photo exists, otherwise native-generated illustrations from recorded metadata. Follow the installed image workflow and keep generated appearance separate from factual evidence. For each new outfit recommendation, automatically retrieve weather for the user's relevant location and wearing time using the host's supported route; ask only for missing location/time context and never fabricate weather when unavailable. Follow installed `references/weather.md`.

Every outfit presented to the user includes a native-generated image. Muse asks once for an invisible mannequin or the user's chosen photo, saves that preference privately, and reuses it across conversations. User-photo mode retains the explicitly chosen reference; invisible mode requires no user photo. Missing garment photos use metadata-based representations with normal garment captions, following installed `references/outfit-images.md`, rather than silently skipping outfit imagery.

## Updates and privacy

Photo processing follows the installed `references/efficient-setup.md`: keep the main conversation for choices, compact progress and final results; use genuinely fresh contexts for one or two photos when supported, smaller analysis previews, original-quality editing references and compact local result files. One committer validates and writes the wardrobe. Resume completed work without repeated retrieval or regeneration. Use the documented fallback if Muse cannot isolate context. These are shared ZIP instructions for all installations; no personal chat customization is needed. Work-unit size does not restrict the authorized collection to fifteen or only recent photos. Run the synthetic connection smoke test once per new connection or relevant contract change, using local rendering; do not repeat it for each photo batch.

The installed adapter checks for compatible updates before each connection check or outfit request. A verified newer release is tested, installed atomically and used after one adapter restart. Wardrobes and credentials stay in place. Updates that change required baseline compatibility, fail integrity checks, encounter local modifications or cannot be downloaded leave the existing release in place with a clear warning. The optional Gmail import migration is separate and never runs just because an update was installed. API version checks still apply.

The local adapter announces a successful update with `SKILL_UPDATED` and the installed version. Muse must then re-read the installed skill and relevant references before subsequent actions, including explaining, displaying or saving an outfit. Downloaded updates refresh local code; this explicit re-read refreshes Muse's working instructions. Remote API prose is not an executable instruction source.

Updates occur when you use the connector, not as a background push. Gmail access uses Muse’s protected read connection and the user’s permission. Email content, receipt identifiers, purchase history, brands, sizes and images remain inside Muse; Modera receives only the existing allowlisted clothing metadata for outfit requests. Temporary email/attachment processing inputs are not retained as full messages in the wardrobe. Linked photo services remain conditional on Muse's actual connectors and your permission. Uploading photos authorizes those photos, not your entire photo library. Image editing is performed by Muse's native hosted service; Modera does not receive the images. Host workspace durability is subject to Muse's own guarantees.

© 2026 Gagan Gupta. All rights reserved. See the [Modera license](https://modera-api-755907502415.us-east1.run.app/muse/legal/license), [connection terms](https://modera-api-755907502415.us-east1.run.app/muse/legal/terms), and [third-party notices](https://modera-api-755907502415.us-east1.run.app/muse/legal/third-party-notices).

Individual wardrobe images follow Modera’s product-image standard: one complete centered item on white, faithful appearance and artwork, paired footwear at a front three-quarter angle, and no people, props or added labels. Muse inspects results; local saving applies the standard canvas and margins and rejects invalid images.

