Overview
- Researchers published Muse system prompts and an exported virtual machine on Monday that show the agent runs an hourly process to create or refresh a dedicated page for every person and group tied to a user.
- Those pages store granular details such as names, locations, important dates, interaction history, relationship notes and guidance on how to communicate, and they appear to include people who do not use Muse themselves.
- Meta says each Muse agent runs in a private per‑user virtual machine and that collecting this context is necessary for the agent to act on a user’s behalf, but the company has not provided independent validation of those isolation claims.
- Security and commercial partners have already pushed back: Amazon blocked Muse shopping access in September and Meta patched a macOS zero‑day that could let local malware misuse granted Muse permissions.
- The disclosures sharpen the near‑term issues for Muse’s rollout by raising questions about third‑party cooperation, independent audits, regulatory scrutiny and the risks of giving a single agent broad access to a user’s accounts.