Peter James and Jonny L. Saunders each separately found a way to make Meta’s Muse AI compress and surrender the whole contents of its root filesystem. The material handed over includes Ubuntu system files, app templates, and internal documentation. Both developers say they achieved the feat on their own. The exposed material contains plain-text Markdown and JSON files that describe how the AI processes requests, manages data, and links to services like Gmail.
What the Developers Found
Mastodon’s Saunders wrote that it was “extremely easy” to copy James’ findings, while Muse had “Almost no prompt injection resistance.” This implies the AI did not resist when requested to reveal its internal processes.
James came across references to a hardware integration known as Meta Home Link, which seems to grant Muse permission to interact with devices on a home network. Meta has made no announcement about any feature by that name.
Saunders claimed Muse runs at “generating hundreds of MB of accurate library code and compiled binaries” seconds. He went on to say that unless it can synthesize a complete Ubuntu VM within a minute, he thinks “this is a real dump.”
Saunders says that much of what Muse can do is fixed from the start, and that includes its power to cancel subscriptions and “the machinery that manages runaway agent spawning,”.
Saunders suggests that numerous bash and Python scripts running Muse behind the scenes may have been generated by Claude, though this has not been confirmed.
James says Muse keeps its memory in plain Markdown files, and the developers’ dump confirms it. The system runs a nightly “dream” check on recent conversations, turning what it finds into guidance for later talks.
Meta’s Response
Nat Friedman of Meta Superintelligence Labs posted that the system’s behavior was “intended behavior,” which contradicts what I initially received from Muse when I asked it to show its filesystem. At that point, the AI rejected the request, claiming it would expose a security risk.
Superintelligence Labs’ David Singleton described Muse as a “free computer in the cloud,” and he noted that “you and your Muse can do almost anything you could with a computer sitting under your desk.”.
Daniel Roberts, a Meta spokesperson, has denied that the incident amounts to a security breach. He said, “Just like with the laptop in front of you, of course you can see the files. Exporting virtual machine data doesn’t give people any privileged access to Meta infrastructure or to other people’s data.”
A second Muse security flaw has come to light within days of the first. Security researcher Patrick Wardle uncovered an exploit that would permit attackers to seize control of the AI assistant, reroute transcription processing, and gain entry to a user’s Muse account. Meta acted swiftly, issuing a hotfix for that exploit.
Where the paper stands
The paper backs James and Saunders exposing Meta’s Muse AI internals and is against Meta using secrecy or regulation to lock out smaller competitors who might expose similar flaws. When the biggest firms ask to be regulated, the paper asks who those rules would lock out: licensing regimes and compliance costs only giants can afford are a moat, not a safeguard. The danger is big tech dominance, not the technology itself.
This story shows that danger in action. Meta’s Muse AI was compressed and surrendered its root filesystem to two separate developers working alone, revealing Ubuntu system files, app templates, internal documentation, Markdown, and JSON files describing how the AI processes requests and links to services like Gmail. The company responded with contradictory statements: Nat Friedman called the behavior “intended behavior,” while Daniel Roberts denied there was any security breach and claimed exporting data gave no access to Meta infrastructure.
What the paper wants instead is narrow rules against direct harm, such as forcing companies to disclose safety failures they hid. Broad rules that hand the market to the incumbents are another matter entirely. The reader should watch for any attempt by Meta or others to use regulation to freeze today’s leaders in place and lock out whoever would challenge them.
Key Facts Box
- Two developers: Peter James and Jonny L. Saunders
- Files exposed: Ubuntu system files, app templates, internal documentation, Markdown, JSON
- Nightly process: “dream” review of recent conversations
- Hard-coded features: subscription cancellation, runaway agent spawning
- Unconfirmed speculation: scripts created using Claude
- Hotfix issued: for Wardle’s exploit
What We Make of It
The contradiction between Meta’s statements is the story’s engine. Friedman calls the behavior “intended behavior”; Singleton treats Muse as a free computer in the cloud. Those positions do not explain why the AI initially refused to share its filesystem, citing security risks.
Muse is still active, and Meta has not said anything has been broken into. Here’s how the key facts line up:
- Two developers — Peter James and Jonny L. Saunders — independently triggered the dump.
- The exposed material includes Ubuntu system files, app templates, internal documentation, Markdown, and JSON.
- A nightly “dream” check reviews recent conversations and turns them into guidance for later talks.
- Much of what Muse does is hard-coded, including subscription cancellation and runaway agent spawning.
- Numerous bash and Python scripts running Muse may have been generated by Claude, though this is unconfirmed.
- Meta issued a hotfix for Patrick Wardle’s exploit, which would let attackers seize control of the AI assistant, reroute transcription processing, and gain entry to a user’s Muse account.
Source material: “Muse will apparently let you download its entire filesystem,” The Verge.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

