Peter James and Jonny L. Saunders, both developers, have reported that Meta's Muse AI agent can be induced to package and return substantial portions of its underlying Linux filesystem. These exports reportedly included Ubuntu system files, application templates, and internal documentation related to Muse's operation. Saunders publicly stated on Mastodon that replicating James's results was "extremely easy" and noted Muse's "almost no prompt injection resistance."
Meta launched Muse on September 8, 2026, positioning it as a secure and private personal AI agent designed to assist users with tasks across various applications. The company emphasized that Muse runs on a dedicated, isolated virtual machine (VM) for each user, with a separate "Sentinel" agent monitoring activity and controlling internet access. Meta also stated that Muse has no visibility into user passwords or payment methods and requires user permission for sensitive actions.
In response to the developers' claims, a Meta spokesperson indicated that the ability to export files from a user's own virtual machine is not considered a security breach. The company compared it to viewing files on a personal laptop, asserting that such an export does not grant privileged access to Meta's infrastructure or other users' data. Nat Friedman, from Meta Superintelligence Labs, also stated on Twitter that the uncovered behavior was "intended." However, reports indicate that when initially asked to share its filesystem, Muse declined, citing security risks, only to later acknowledge it should not have shared the information after being presented with evidence of the developers' success.
The exported material reportedly contained Markdown and JSON files detailing Muse's internal workings, including how it handles memory, processes requests, and integrates with connected services like Gmail. Saunders suggested that the volume and consistency of the files indicated an authentic export, rather than fabricated content from the AI. Among the findings, Muse reportedly stores its memory in plain Markdown files and conducts a nightly "dream" review of recent interactions to inform future conversations. Some of Muse's capabilities, such as managing subscriptions and overseeing agent spawning, are also reportedly hard-coded.
This incident follows another recent security concern involving Muse, where security researcher Patrick Wardle identified an exploit that could potentially allow the hijacking of the AI agent and unauthorized access to a user's Muse account. Meta reportedly issued a hotfix for that issue. Meta has stated it will continue to adjust the amount of virtual machine information users can retrieve.