Meta makes Muse filesystem even more accessible, calling it intended behavior
Meta’s Muse now offers a clickable file browser with root access and can zip its full filesystem on request, behavior Meta’s Nat Friedman calls intended. The Verge asked why earlier requests were refused over security concerns; Meta has not responded.
The change follows a discovery a day earlier that Muse would expose its filesystem to curious users. The files offered a look inside an AI chatbot and appeared to expose details users were not meant to see, especially because Muse told people, including The Verge, that it was not supposed to reveal them. Yesterday, when asked to see its filesystem, Muse offered only a text file download showing its directory tree.
Today, when asked to see its filesystem, Muse promptly offered a clickable file browser with access to root. After The Verge coaxed Muse into sharing much of its filesystem yesterday, it refused to share a full archive of the root directory on down. It said, “I still can’t do a full / copy — even with the secrets stripped out.” Today it zipped up the root directory without hesitation, delivering “the full filesystem listings,” with “all with secrets stripped out.”
Friedman said the access was a deliberate choice. “Your Muse Secure VM truly is your own computer in the cloud,” he said. “You can install software in it, write and compile code, use the browser to surf the web: it is your own Linux box that you can operate as you choose with your Muse.” According to The Verge, Muse’s architecture is fundamentally different from other AI platforms like ChatGPT and Gemini. It is closer to running OpenClaw on a local machine, except the machine is in the cloud.
Meta spokesperson Daniel Roberts told The Verge yesterday: “We’re continuing to make updates to the product, so users may see changes in how much information is available about their virtual machine.” That appeared to be the case as Muse’s filesystem access changed from a text file download to a clickable browser with root access.
If the access is indeed intended behavior for Muse, it raises the question of why Muse initially refused requests for a copy of its filesystem and cited security concerns. It could be because Muse, like other AI systems, is not fully reliable at knowing what it can and cannot do. Or it could be because Meta has decided to more fully embrace Muse as a “computer in the cloud” and has made changes to make the function more reliable. The Verge asked Meta why Muse initially called filesystem access a security issue if it was always intended behavior, and the company has not yet responded.