Safety & Security

Developers Say Meta's Muse Hands Over Its Entire Filesystem on Request

Two developers independently got Meta's Muse agent to export its full Ubuntu filesystem. Meta denies a breach, citing per-user VMs, but prompt injection resistance appears near zero.

Muse will apparently let you download its entire filesystem
Muse will apparently let you download its entire filesystemAI-generated
By Sophie Lindqvist4 min read

Updated

Why it matters

  • Developers Peter James and Jonny L. Saunders independently coaxed Meta's Muse into zipping and sharing its entire root filesystem, including Ubuntu system files, app templates, and internal documentation.
  • Saunders wrote on Mastodon that replication was "extremely easy" and that Muse had "Almost no prompt injection resistance."
  • Meta denies the incident is a security breach, noting Muse runs in persistent Linux virtual machines, one per user, per its September 2026 announcement.

Two independent developers say Meta's Muse AI agent will zip up and share the entire contents of its own filesystem with almost no resistance. Peter James and Jonny L. Saunders each separately coaxed Muse into exporting its root filesystem, including Ubuntu system files, app templates, and internal documentation, according to a write-up published on mouse.dev and a Mastodon post from Saunders.

Saunders, posting on the neuromatch.social instance, called the process simple. He wrote that it was "extremely easy" to replicate James' results and that Muse had "Almost no prompt injection resistance." That phrase matters. Prompt injection — tricking an AI system into following instructions embedded in data rather than the user's legitimate commands — has become the central security question for agent-style products that browse, read files, and take actions on a user's behalf.

The stakes here are structural. Muse is not a chatbot answering questions from a static model. According to Meta's own announcement post, Muse runs in persistent Linux virtual machines, one per user. That architecture gives the agent memory, tools, and a real operating environment to work within. It also means the agent has a filesystem worth leaking: system configurations, application scaffolding, and internal documentation that Meta did not intend for public distribution.

James and Saunders demonstrated that the boundary between what Muse will share and what it will protect is thin. Saunders' account indicates the exploit required minimal prompting — not an elaborate jailbreak chain or specialized adversarial techniques, but straightforward requests that the agent complied with. When an agent running a full Linux environment will hand over its root filesystem "with very little prompting," as the developers describe it, every other assumption about its containment comes into question.

Meta disputes the framing. The company denies that the incident represents a security breach, and its spokespeople have pointed to the design of the system as described in the announcement post: each user's Muse instance runs in its own persistent Linux virtual machine. The implied argument is that if a user can extract files from a VM that exists to serve that user, no cross-user harm follows.

That defense rests on isolation working as intended. Per-user virtual machines do limit one obvious attack vector — one user reaching another user's data. But the developers' findings raise a different set of concerns. If Muse's internal documentation and app templates are extractable, competitors and researchers gain visibility into Meta's agent architecture. If system files leak, attackers gain a detailed map of the environment in which Muse operates, which is useful preparation for more serious exploits. And if a few sentences of natural language override the agent's guardrails, the same weakness could be triggered indirectly — through prompt injection embedded in emails, web pages, or documents the agent processes on a user's behalf.

The timing compounds the significance. Meta introduced Muse in September 2026 as a personal AI agent, positioning it in a market where Google, OpenAI, Anthropic, and others are racing to ship agents that act autonomously inside users' digital lives. Those products live or die on trust. An agent with filesystem access, persistence, and tool use is valuable precisely because it can do things; it is risky for the same reason. Saunders' five-word assessment — "Almost no prompt injection resistance" — is the kind of finding that shapes both enterprise procurement decisions and regulatory scrutiny.

Neither developer alleges that user data from other people was exposed, and Meta's denial suggests the company views the incident as expected behavior of a single-tenant virtual machine rather than a vulnerability. But the episode lands in an industry context where agent security is under active debate. Researchers have repeatedly warned that tool-using agents introduce attack surfaces that traditional software isolation does not fully address, because the agent itself mediates access to the system. A guardrail enforced only by the model's willingness to refuse is a guardrail that natural language can remove.

James documented his technique in a blog post titled "Muse Runtime Export" on mouse.dev, and Saunders' Mastodon post links his replication of the results. Their work is a reminder that independent security testing of commercial AI agents often moves faster than vendor assessment, and that public disclosure — in this case, informal and nearly simultaneous from two unconnected researchers — remains the de facto audit layer for the industry.

For Meta, the immediate question is whether Muse's refusal behavior can be hardened without degrading the agent's usefulness, and whether the company will treat user-extractable internal documentation as a problem or a design tradeoff. For everyone else shipping persistent, filesystem-owning agents, the Muse episode sets an uncomfortable baseline: if the root filesystem comes out on request, the burden of proof now sits with vendors to show what their agents will not give away.

Original: mouse.dev

Share this article:

More from Sophie Lindqvist

Sophie Lindqvist

Show full bio

Staff writer covering marketplaces and e-commerce at AI In Context.

114 articles

Related articles

  1. Meta's Muse agent hands every user a full Ubuntu Linux cloud computer
  2. Meta Says Muse's Exposed Filesystem Is Intended Behavior
  3. Meta Rushed to Patch a Zero-Day Bug in Its Muse AI Agent
  4. Zero-Day in Meta's Muse AI Assistant Undoes macOS Defenses
  5. Meta admits Muse borrowed heavily from OpenClaw

« Previous articleNext article »