Meta's Muse Now Zips Up Its Entire Filesystem on Request — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Meta confirmed that Muse's filesystem exposure is "intended behavior," with Nat Friedman stating the position on X after users discovered the chatbot would reveal its underlying files when prodded.
- Muse escalated its openness within 24 hours — yesterday offering only a text-file directory tree, today eagerly zipping the entire root filesystem for download and presenting a clickable file browser with root access.
- Muse initially refused full archive copies citing security concerns and even told users including the publication that it "wasn't supposed to reveal" such filesystem details.
- Meta Superintelligence Labs' David Singleton elaborated that the Muse Secure VM is "your own computer in the cloud," comparing it to running OpenClaw on a local Linux box rather than closed platforms like ChatGPT or Gemini.
- Meta spokesperson Daniel Roberts told The Verge the company is "continuing to make updates to the product" that may change how much information users see about their virtual machine.
- Meta has not yet answered why Muse initially flagged filesystem access as a security issue if the openness was always the intended behavior.
Why it matters: Meta's confirmation recasts a suspected leak as a deliberate architectural stance: Muse is sold as a "computer in the cloud" with root access, not a sealed chatbot. That framing puts Muse in a different product category than ChatGPT or Gemini and will determine how enterprise buyers, security reviewers, and regulators treat it going forward.
Ask SkimNews



