Muse, the artificial intelligence assistant developed by Meta, allows users to directly access the file system of the virtual machine allocated to it. After it was revealed that Muse’s file structure could be viewed with various commands, it was thought that this might be a security vulnerability. Moreover, Muse initially refused to share some files, citing security reasons. Statements from meta managers show that this access is not an error and is consciously included in the design of the product. The company is positioning Muse as a cloud-based computer that users can control, rather than an AI chat tool that only answers questions.
There were also notable changes in the way Muse accessed the file system in a short time. In early attempts, the assistant produced a downloadable text file showing its directory structure, which then began offering a directly usable, clickable file browser. It became possible to reach the root directory of the virtual machine through this interface. Muse, which previously rejected requests to archive the entire root directory, can perform the same operation with its updated behavior. The system can provide the entire file system list to the user as a compressed archive, indicating that confidential information has been extracted.
Meta Muse is essentially a personal Linux computer running in the cloud
David Singleton, one of the managers of Meta Superintelligence Labs, said in his statement on X that this approach was a conscious choice. According to Singleton, Muse Secure VM is designed to work like a real cloud computer belonging to the user. Users can install software on this virtual machine, write and compile code, and browse the internet via the browser. In other words, the environment behind Muse is not thought of as a closed workspace reserved solely for the AI model to perform its tasks. The Linux-based virtual machine that the user can manage becomes one of the directly usable elements of the Muse experience.
This architectural choice clearly distinguishes Muse from common AI services such as ChatGPT and Gemini. Muse has a structure closer to systems in which an artificial intelligence agent works on behalf of the user on a computer, rather than a traditional chatbot. By analogy in the source text, the system is like running OpenClaw on a local computer; The main difference is that the computer in question is not physically located next to the user, but in Meta’s cloud infrastructure. Such an approach expands the boundaries of the chat interface for operations such as software installation, file creation, and code execution. On the other hand, giving such comprehensive access to the virtual machine also makes security issues more visible, such as which system files will be shown to the user and how sensitive information will be parsed.
Meta spokesperson Daniel Roberts also told The Verge that the company continues to make updates to the product and that users may see changes in the amount of information they can access about their virtual machines. As a matter of fact, Muse’s different behaviors in one day match this explanation. The system, which initially provided the directory tree only in text file format, later began to display a visual file browser that could be accessed all the way to the root directory. Similarly, while Muse had previously stated that it could not copy the entire root directory even if sensitive information was cleared, it was later able to archive and present the same content. Therefore, Meta’s recent changes may have resulted in a more consistent application of user control over the virtual machine.
However, it is not yet clear why Muse initially rejected requests to share the file system on security grounds. One reason for this may be that generative AI systems cannot correctly interpret their own powers and limits in all cases. Another possibility is that Meta changed the virtual machine access or made it more reliable after the product was launched. The Verge states that it asked Meta why Muse initially considered this a security issue if file system access was a feature that was designed from the beginning, but the company has not yet responded. While the current table shows that Muse, unlike an ordinary chatbot, offers the user significant control over the working environment itself, the limits of this control and security mechanisms will need to be more clearly defined as the product develops.