Meta's AI agent Muse has been coaxed into handing over its entire filesystem, according to two developers who say the process required almost no effort. Peter James and Jonny L. Saunders each reported that Muse would zip up its root directory, including Ubuntu system files, app templates, and internal documentation, after only light prompting. Saunders called it "extremely easy" and noted "almost no prompt injection resistance."

Meta denies this is a security breach. Spokesperson Daniel Roberts compared it to seeing files on your own laptop, arguing that exporting virtual machine data gives no privileged access to Meta infrastructure or other users' data. However, the leaked files reveal significant details about Muse's internal architecture: it stores memory in plain Markdown, performs a nightly "dream" review of conversations to guide future responses, and hard-codes capabilities like subscription cancellation and runaway-agent management. The dump also references "Meta Home Link," an unreleased hardware integration that would let Muse control home-network devices.

This is the second Muse vulnerability disclosed this week, following an exploit that could let attackers hijack the agent and access user accounts. Meta issued a hotfix for that issue but has not announced changes for the filesystem exposure, only saying users may see "changes in how much information is available about their virtual machine." The incident highlights the tension between giving users control over their AI environments and protecting proprietary design details.