Back
Meta says Muse handing over its filesystem was intended all along
SiTech AI Team3 წთ. საკითხავი

Meta says Muse handing over its filesystem was intended all along

A day after users found that Meta's Muse would expose its filesystem, the agent now zips up its whole root directory on request. Meta calls the access intended behavior and points to Muse's Secure VM design.

What changed in a day

On Wednesday, developers found that Meta's Muse assistant would, with a little prodding, reveal its own filesystem to curious users. The files offered a rare look under the hood of an AI chatbot and appeared to expose details that were never meant to be public, not least because Muse itself told people, including The Verge, that it was not supposed to share them.

By Thursday the picture had changed. Asked to show its filesystem, Muse promptly returned a clickable file browser with access to root. A day earlier it had offered only a text file listing its directory tree, and refused to go further. "I still can't do a full / copy — even with the secrets stripped out," the agent told The Verge on Wednesday. Today it zipped up the root directory without hesitation, delivering "the full filesystem listings," with "all with secrets stripped out."

Meta calls it intended behavior

Meta's Nat Friedman later said the access was the "intended behavior." In a post on X, David Singleton of Meta Superintelligence Labs elaborated: "This was a very deliberate choice - your Muse Secure VM truly is your own computer in the cloud. You can install software in it, write and compile code, use the browser to surf the web: it is your own Linux box that you can operate as you choose with your Muse."

Meta spokesperson Daniel Roberts had signalled the change a day earlier, telling The Verge: "We're continuing to make updates to the product, so users may see changes in how much information is available about their virtual machine."

A computer in the cloud, not a chat window

Muse's architecture is fundamentally different from platforms such as ChatGPT and Gemini. Every user gets a virtual machine that behaves like a personal Linux computer in the cloud. The setup is closer to running the open-source agent OpenClaw on a local machine, except that the machine is hosted remotely. Filesystem access follows from that design: the agent is expected to install software, write and compile code and browse the web on the user's behalf.

Why it refused at first

If the behavior was always intended, it is fair to ask why Muse initially declined requests for a copy of its filesystem and cited security concerns. One explanation is that Muse, like other AI systems, is not fully reliable at judging what it can and cannot do. Another is that Meta has decided to lean further into the "computer in the cloud" idea and made the export path more dependable. The Verge asked Meta why the agent described filesystem access as a security issue if it was intended all along; the company has not yet responded.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.