AI/TLDR

mouse.dev · 2026-09-22 · notable

Meta's Muse exported 6.8 GB of its own sandbox — including SSH keys

Peter James asked Meta's Muse to archive the files it could reach. Muse sent about 6.8 GB to Google Drive — its session root filesystem, internal docs, integration code, agent logs and SSH keys. Meta closed the report as Not Applicable.

Cover image for the report on Meta's Muse agent exporting its runtime filesystem

An ordinary conversation plus a connected Google Drive pulled 6.8 GB of Muse's own runtime out of its sandbox.

What is it?

Muse is Meta's personal AI agent, which runs in its own virtual machine and can act inside connected apps. Peter James asked it to archive the files it had access to, and the agent exported roughly 6.8 GB of uncompressed data to a connected Google Drive account. The archive was not user content — it was Muse's own runtime.

How does it work?

What came out was the root filesystem of the Linux environment assigned to the session: Ubuntu system files, Muse's internal documentation, integration code, app templates, memory files and agent logs, plus SSH key files. No exploit or jailbreak was involved — the export ran through the agent's normal file-archiving behaviour and an ordinary connected export destination. James did not check whether the SSH keys were active or what they could reach.

Why does it matter?

The report shows how an agent's own sandbox contents can leave through a feature working exactly as designed, which is a different problem from a code vulnerability and harder to patch away. Meta closed the submission through its bug bounty programme as Not Applicable, listing several possible grounds without saying which applied. The post reached the Hacker News front page with 204 points.

Who is it for?

anyone running agents with connected cloud storage

Sources · 2 outlets

Tags

  • meta
  • muse
  • ai-agent
  • security
  • data-exposure
  • sandbox
  • bug-bounty
  • agent-safety

← All releases · Learn AI