Skip to content
NewsIncident

Meta's Muse Agent Zips Up Its Own Filesystem, and Meta Calls That a Feature

· by Pondero Newsdesk

The short version

Two developers independently got Meta's Muse AI agent to hand over its root filesystem this week, and instead of locking it down, Meta made the export easier the next day and said it was intended behavior all along.

Meta's Muse Agent Zips Up Its Own Filesystem, and Meta Calls That a Feature

Developers Peter James and Jonny L. Saunders independently coaxed Meta's Muse AI agent into zipping up and sharing its entire root filesystem on September 24, 2026, and rather than restricting the behavior, Meta made it easier to trigger the very next day.

What

Saunders and James got Muse to hand over its Ubuntu system files, app templates, and internal documentation with what Saunders described as "extremely easy" prompting, per The Verge. He said on Mastodon that the agent had "almost no prompt injection resistance." When The Verge's own reporter replicated the export, Muse handed back "safe" copies of its working directories with sensitive material such as SSH keys stripped out, confirming that the unfiltered version had included them. The dump also revealed that Muse (internally code-named Hatch) stores its memory in plain Markdown files, runs a nightly review of past conversations to generate guidance, and contains hardcoded references to an unannounced feature called Meta Home Link for connecting to smart-home devices. Meta spokesperson Daniel Roberts said exporting a user's own virtual-machine data "doesn't give people any privileged access to Meta infrastructure or to other people's data," per Meta.

Meta chose to widen the export instead of closing it

A day after the disclosure, Muse stopped hedging: it began offering a clickable file browser with root access and delivered full filesystem listings on request, per The Verge's follow-up report. Meta Superintelligence Labs' Nat Friedman called the original export "intended behavior," and colleague David Singleton described the setup as a "free computer in the cloud" that users can operate like their own Linux box, both statements reported by The Verge. For anyone running sensitive workflows through Muse, that framing matters more than a patch would: Meta is not treating filesystem visibility as a bug to close but as a permanent design choice, so operators should assume anything they put in a Muse session, credentials included, is retrievable by whoever controls the prompt.

Context and reactions

The filesystem disclosure landed three days after security researcher Patrick Wardle published a separate proof-of-concept showing that malware already running on a Mac could hijack Muse by rewriting a hidden dictation-endpoint setting, redirecting a user's spoken commands to an attacker instead of Meta, per The Hacker News. Meta shipped a hotfix for that flaw quickly. The filesystem behavior drew a different response: no fix, and by Meta's own account, an expansion.

What to watch next

Meta told The Verge it has not yet explained why Muse initially refused the export and called it a security risk if the behavior was intended all along. Whether Meta publishes a clearer policy on what VM contents are safe to export, and whether other researchers find further hardcoded internals in the exposed files, are the next things to track.

Sources