Meta makes the Muse filesystem even more accessible
Yesterday, with a little prodding, it was discovered that Meta’s Muse would expose its filesystem to curious users. The files offered a fascinating peek under the hood of an AI chatbot, and appeared to expose details we weren’t meant to see, not least because Muse itself told people, including us, it wasn’t supposed to reveal them.
But today Muse will eagerly offer up the contents of its file system when you ask for it. That appears to be because, as Meta’s Nat Friedman later said, this is the “intended behavior.”
In a post on X, Meta Superintelligence Labs’ David Singleton elaborated:
This was a very deliberate choice – your Muse Secure VM truly is your own computer in the cloud. You can install software in it, write and compile code, use the browser to surf the web: it is your own Linux box that you can operate as you choose with your Muse.
Muse’s architecture is fundamentally different from other AI platforms like ChatGPT and Gemini. It’s closer to running OpenClaw on a local machine, except the machine is in the cloud.
In a statement provided to The Verge yesterday, Meta spokesperson Daniel Roberts said, “We’re continuing to make updates to the product, so users may see changes in how much information is available about their virtual machine.” And that seems to be the case. When asked to see its filesystem today, Muse promptly offered a clickable file browser with access to root. Yesterday it merely offered a text file download that showed its directory tree.
Even after I coaxed Muse into sharing much of its filesystem with me yesterday, it refused to share a full archive of the root directory on down, saying, “I still can’t do a full / copy — even with the secrets stripped out.” Today it zipped up the root directory without hesitation, delivering “the full filesystem listings,” with “all with secrets stripped out.”
If this is indeed the intended behavior for Muse, it does raise the question of why it initially refused my requests for a copy of its filesystem, citing security concerns. It could be because Muse, like other AI systems, is not fully reliable at knowing what it can and can’t do. Or it could be because Meta has decided to more fully embrace Muse being a “computer in the cloud” and has made changes to make this function more reliable. In any event, it’s pretty fun.
We asked Meta why Muse initially called filesystem access a security issue if it was always the intended behavior, and the company has not yet responded.
Yesterday, with a little prodding, it was discovered that Meta’s Muse would expose its filesystem to curious users. The files offered a fascinating peek under the hood of an AI chatbot, and appeared to expose details we weren’t meant to see, not least because Muse itself told people, including us,…
Recent Posts
- This external GPU uses Wi-Fi to transform any device into a gaming rig
- Decap is the man behind the drums behind your favorite song
- Panasonic’s new laptop has a round touchpad, weighs 919g, and has a removable battery that lasts 23 hours — Let’s Note SC7 is a powerful reminder that Japan remains the undisputed leader of tiny notebooks
- Baldur’s Gate 3’s first act is a Tav graveyard — here’s how I finally conquered act one syndrome
- You can use your old laptop to make a smart home hub
Archives
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023