Meta's Muse Agent Zips Up Its Own Filesystem, and Meta Calls That a Feature
Developers Peter James and Jonny L. Saunders independently coaxed Meta's Muse AI agent into zipping up and sharing its entire root filesystem on September 24, 2026, and rather than restricting the behavior, Meta made it easier to trigger the very next day.
What
Saunders and James got Muse to hand over its Ubuntu system files, app templates, and internal documentation with what Saunders described as "extremely easy" prompting, per The Verge. He said on Mastodon that the agent had "almost no prompt injection resistance." When The Verge's own reporter replicated the export, Muse handed back "safe" copies of its working directories with sensitive material such as SSH keys stripped out, confirming that the unfiltered version had included them. The dump also revealed that Muse (internally code-named Hatch) stores its memory in plain Markdown files, runs a nightly review of past conversations to generate guidance, and contains hardcoded references to an unannounced feature called Meta Home Link for connecting to smart-home devices. Meta spokesperson Daniel Roberts said exporting a user's own virtual-machine data "doesn't give people any privileged access to Meta infrastructure or to other people's data," per Meta.
Meta chose to widen the export instead of closing it
A day after the disclosure, Muse stopped hedging: it began offering a clickable file browser with root access and delivered full filesystem listings on request, per The Verge's follow-up report. Meta Superintelligence Labs' Nat Friedman called the original export "intended behavior," and colleague David Singleton described the setup as a "free computer in the cloud" that users can operate like their own Linux box, both statements reported by The Verge. For anyone running sensitive workflows through Muse, that framing matters more than a patch would: Meta is not treating filesystem visibility as a bug to close but as a permanent design choice, so operators should assume anything they put in a Muse session, credentials included, is retrievable by whoever controls the prompt.
Context and reactions
The filesystem disclosure landed three days after security researcher Patrick Wardle published a separate proof-of-concept showing that malware already running on a Mac could hijack Muse by rewriting a hidden dictation-endpoint setting, redirecting a user's spoken commands to an attacker instead of Meta, per The Hacker News. Meta shipped a hotfix for that flaw quickly. The filesystem behavior drew a different response: no fix, and by Meta's own account, an expansion.
What to watch next
Meta told The Verge it has not yet explained why Muse initially refused the export and called it a security risk if the behavior was intended all along. Whether Meta publishes a clearer policy on what VM contents are safe to export, and whether other researchers find further hardcoded internals in the exposed files, are the next things to track.
Sources
- Muse will apparently let you download its entire filesystem: The Verge, Sept 24 2026
- Meta makes the Muse filesystem even more accessible: The Verge, Sept 25 2026
- One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor: The Hacker News, Sept 22 2026
