Each user gets dedicated VM. They got contents of their own sandbox. Big deal. The level of excitement here is wildly disproportionate
I asked it for it's harness and then asked agy to do a teardown. It's a monolithic 332MB binary written in Rust from scratch.
Full teardown is here:
https://gist.github.com/simonpure/d6f960045334453360eff1e2a0...
That seems like a feature not a bug. Agents work best with full access to their computer, the same way developers work.
It gives me a glimmer of hope that openness will win. I don't trust Meta as a corp, but they've been doing the a lot of good things with open source, open models, and developer friendly agents.
More thoughts on agent computer architecture here, as I've been building our own open core system for this: https://housecat.com/blog/agent-computer-101
Ah, glad to hear Muse has a Polymarket integration in the pipeline. I mean, what could possibly go wrong?
These files are visible in the muse app by browsing system files.
Seriously, no bug bounty for that? For exfiltrating the entire content of the system?
The most potentially dangerous technology in the world is being created by the most irresponsible people on Earth.
”we've determined that the reported issue does not qualify as a valid vulnerability…because the behavior described is working as intended”
So I’m sure they won’t be fixing it then.
> Postgres makes those files searchable. memory.entries stores chunks and line references, memory.embeddings holds 384-dimensional vectors, and memory.claims tracks evidence, confidence, and status.
Is each Muse instance running it's own Postgres??That seems wildly wasteful, especially since earlier in the article it states that the Muse instance has a SQLite database and schema already...
I have no idea why people would ever want to touch anything from Meta.
I assume SOUL.md was empty.
Seriously, I want to know what's in there!
The internals are not _that_ reveling, most agents run a similar setup. Metas' responds is the most interesting here.
Am I missing something? This isn't a vulnerability. Your agent can see the files in its virtual environment. SSH keys are also not necessarily confidential. Please don't use AI to write blog posts.
Everything about this is just embarassing
original post on x: https://x.com/heypeterjames/status/2102183576418558269
muse is a pretty capable agent but still asks for too many approvals to do tasks. I'm a student and have been going between muse and instinct
This isn't a bug and doesn't deserves any bounty. Each user gets isolated VM and that is the design and agent is able to access everything.
The tldr is that muse is heavily inspired by openclaw and should be considered FB’s version of it.
> I’m not publishing the archive, keys, or session logs.
Lame
I asked Muse to archive the filesystem visible to my session and send it to my Google Drive. It sent an archive that unpacked to about 6.8 GB.
Inside were internal docs, integration code, the Spaces app framework, memory records, container startup scripts, and documentation for an experimental ESP32-based home network bridge called Home Link. Codex CLI was also installed, though I found no evidence that Muse invokes it.
I didn’t demonstrate a sandbox escape or access to another user’s data. I reported the export to Meta’s bug bounty program, which marked it “Not Applicable.”
The post walks through the findings with screenshots.
-Pete
[flagged]
[dead]
Will Muse cut down on scrolling? I've read about people using it to summarize FB Marketplace listings, cutting down on time spent there.
I of course won't use it.
> About 20 Markdown files described browser use, connectors, payments, credentials, data handling, generated files, voice, goals, and scheduling.
This the state of software engineering in 2026.
Edit: clarified engineering to software engineering, which is more correct