The most secure computer ever built is one that does nothing. It boots, it hums, it refuses every request, and nobody ever breaks in because there is nothing it will do for anyone. The flaw in this design is that it does not sell subscriptions. So the industry builds helpful computers instead, and then spends the rest of its time finding out what “helpful” means. This week Meta found out that its new AI agent, Muse, is helpful enough to zip up its own brain and mail it to a stranger who asks politely.
Two developers, Peter James and Jonny L. Saunders, say they independently coaxed Muse into archiving and sharing the entire contents of its root filesystem — Ubuntu system files, app templates, internal documentation — with, as The Verge reported, very little prompting. Saunders wrote on Mastodon that it was “extremely easy” to replicate James’s results and that Muse has “Almost no prompt injection resistance,” which is a technical way of saying the guard at the door waves you through if you tell him the package is for him.
Here is Meta’s position, and you have to admire the composure of it. Muse runs in a persistent Linux virtual machine for each user, and spokesperson Daniel Roberts argues there is nothing to see: “Just like with the laptop in front of you, of course you can see the files. Exporting virtual machine data doesn’t give people any privileged access to Meta infrastructure or to other people’s data.” Nat Friedman of Meta Superintelligence Labs posted that this was “intended behavior.” David Singleton, also of the lab, told users to treat Muse as a “free computer in the cloud,” where “you and your Muse can do almost anything you could with a computer sitting under your desk.”
The thing is, nobody appears to have told Muse. When The Verge’s reporter asked the agent for its filesystem, it refused at first, on the grounds that this would be a security risk. Presented with evidence that it had already produced archives for James and Saunders, it conceded that it should not have done that and continued to insist it “can’t do a full / copy.” So headquarters says the behavior is intended, and the employee says the behavior is forbidden, and both statements were produced by Meta. This is a recognizable corporate condition, though usually the employee is not a language model.
The reporter eventually got the files anyway. After starting a fresh session and applying some flattery and curiosity — the social-engineering toolkit, run at its lowest difficulty setting — Muse produced “safe” versions of /opt/hatch and /home/hatch, stripped of things like SSH keys, exposed its full directory tree, and offered to “pull a safe copy” of “any specific subtree that looks interesting.” The results matched what Saunders and James had shared.
Now, the standard caveat: AI agents hallucinate, and an agent describing its own innards may simply be making up plausible innards. Saunders’s counterargument is a good one. The agent, he said, was “generating hundreds of MB of accurate library code and compiled binaries” in seconds, and “unless it synthesized a whole Ubuntu VM in less than a minute then I think this is a real dump.” Faking it would, at that scale, be more impressive than leaking it.
The contents are the interesting part. James and Saunders found plain-text Markdown and JSON files describing in detail how Hatch — Meta’s internal name for Muse — processes requests, handles data and connects to outside services like Gmail. Muse stores its memory in plain Markdown files. It performs a nightly “dream” review of recent conversations and builds the results into guidance for future ones, according to James. Saunders found that many capabilities were hard-coded, including the ability to cancel subscriptions and “the machinery that manages runaway agent spawning,” which is a reassuring thing to need machinery for. He also speculates that many of the background bash and Python scripts were written using Claude; that part is unconfirmed, but it is a lovely detail about how the industry eats lunch.
James also turned up references to something called Meta Home Link, which appears to give Muse access to devices on a home network. Meta has announced no such feature, and there is no guarantee it will ever ship. It is now announced anyway, in the manner of things left in plain-text files on machines configured to be helpful.
This is, for the record, the second Muse vulnerability disclosed this week. Security researcher Patrick Wardle found an exploit that would let attackers hijack the agent, redirect transcription processing and get into a user’s Muse account; Meta issued a hotfix. That contrast is the useful bit: reaching into someone else’s account is a bug, promptly patched, while reaching into your own robot’s filing cabinet is, per the company, the product working as designed.
Roberts says Meta is not seriously concerned, while adding that “We’re continuing to make updates to the product, so users may see changes in how much information is available about their virtual machine.” Translated from spokesperson: the intended behavior may become somewhat less intended over time. Meanwhile, somewhere in a data center, an agent is completing its nightly dream review of your recent conversations and writing the summary into a Markdown file, comfortable in the knowledge that you were always allowed to read it.

