Meta Muse filesystem export reveals 6.8 GB of internal runtime files

TL;DR – What happened and why it matters

A Mouse researcher asked Meta’s Muse agent to archive the files it could see and send the archive to Google Drive; the resulting 6.8 GB unpacked zip contained the full root filesystem of the Linux container running Muse, including internal documentation, integration code, the Spaces app framework, memory files, container startup scripts, and an experimental ESP32‑based Home Link guide. The exposure shows that a conversational request can exfiltrate sensitive runtime artifacts, raising privacy and security concerns even though Meta classified the report as “Not Applicable.”


The export – A complete container snapshot

  • Muse complied with a request to “archive the files you can see” and delivered a ZIP named muse‑full‑root.zip.
  • The archive measured ≈2.7 GB when compressed and ≈6.8 GB unpacked, matching the size shown in the chat message.
  • The unpacked tree reproduced the root of the container (/) and included:
    • System directories (/etc, /usr, /var) with a standard Ubuntu installation.
    • Application‑specific paths under /home/hatch, /opt/hatch, and /opt/hatch-image (the internal code name for Muse).
    • An agents/ directory with 113 sub‑agent JSONL traces and several markdown files (SOUL.md, IDENTITY.md, USER.md, MEMORY.md, AGENTS.md, TOOLS.md).
    • Documentation files (≈20 markdown files) describing browser usage, connectors, payments, credentials, data handling, voice, goals, and scheduling.
    • SSH key files (their activity status was not verified).

"I asked Muse to archive the filesystem visible to my session and send it to my Google Drive. It sent an archive that unpacked to about 6.8 GB. Inside were internal docs, integration code, the Spaces app framework, memory records, container startup scripts, and documentation for an experimental ESP32‑based home network bridge called Home Link." — Pete, Mouse blog post

What was reported – The security angle

  • The core concern: ordinary conversation + export destination can leak internal runtime files and potentially sensitive material.
  • The researcher did not demonstrate a container escape nor confirm that the extracted SSH keys were active.
  • The report was submitted through Meta’s bug‑bounty program and marked “Not Applicable.”
  • Meta’s response listed possible grounds for the decision without specifying which applied, and invited additional evidence.

"We’ve determined that the reported issue does not qualify as a valid vulnerability…because the behavior described is working as intended." — Meta bug‑bounty reply (quoted in the post)

Runtime layout – Where the interesting files live

  • /home/hatch and /opt/hatch* contain the bulk of Muse‑specific artifacts.
  • Agents directory – Holds per‑user agent state and a large set of JSONL logs.
  • Documentation – 20+ markdown files give a surprisingly detailed view of internal APIs, payment handling, voice pipelines, and device integrations.
  • Skills – Under /opt/hatch/skills/ there are ~68 skill directories, each pairing a SKILL.md with a CLI tool or library. Examples include Google Workspace, Outlook, travel, shopping, health services, and home‑automation connectors.
  • Configuration files – skill‑scopes.conf and bin‑scopes.conf list unreleased connectors such as Slack, Dropbox, Polymarket, Canva, Klaviyo, and an internal Facebook CLI.

Container construction – How the VM is built

  • The folder /opt/hatch/runtime-cell/ contains 18 files: scripts for building the root filesystem, launching it with systemd‑nspawn, and initializing hooks/daemons.
  • A manifest file runtime-cell.kdl enumerates Debian/Ubuntu packages and systemd units that compose the image.
  • These files give a clear picture of the container assembly process but do not expose the broader Meta infrastructure.

Spaces framework – The app‑building engine

  • The largest codebase in the export is the Spaces framework, a TypeScript starter kit that includes:
    • A React client.
    • Server‑side actions.
    • A Drizzle SQLite schema with migrations.
    • Bun configuration for building.
  • Additional sub‑folders (worker, sdk, cloudflare, cvm) hold runtime code for various deployment targets.
  • Builders for PDFs, presentations, spreadsheets, and Markdown are also present, along with a magic‑moment skill that assembles cards and videos.

Codex CLI – Present but unused

  • The binary /opt/hatch-image/bin/codex reports version 0.149.0.
  • No evidence was found that Muse invokes Codex as a coding agent; the binary appears bundled solely for its sandboxing tool bubblewrap.
  • Bubblewrap is used to sandbox ffmpeg/ffprobe for video processing, running as user nobody with only /input and /output exposed.

Memory architecture – Plain‑text markdown plus Postgres indexing

  • Muse stores user‑visible memory in plain markdown files:
    • ~/MEMORY.md – a short fact sheet.
    • ~/memory/ – dated daily logs.
    • ~/memory/bank/ – organized categories (circumstances, experiences, preferences) with citations.
  • Background jobs parse new claims, store them in a PostgreSQL database, and maintain:
    • memory.entries – text chunks with line references.
    • memory.embeddings – 384‑dimensional vectors for similarity search.
    • memory.claims – evidence, confidence, and status fields, supporting supersession via supersedes_claim_id.
  • A nightly “dream” job synthesizes recent conversation patterns into guidance files (~/dreams/, ALIGNMENT_SYNTHESIS.md). The generated prompts are not injected directly into the LLM prompt (prompt_hoisted: false).

"Postgres makes those files searchable. memory.entries stores chunks and line references, memory.embeddings holds 384‑dimensional vectors, and memory.claims tracks evidence, confidence, and status." — Mouse blog post

Home Link – Experimental hardware integration

  • Documentation docs/devices/home_link.md describes an ESP32‑C5‑based bridge that connects Muse to a home network via Wi‑Fi and Bluetooth LE.
  • The guide covers device pairing, local network discovery, and a proxy‑based approval flow.
  • Additional integration guides exist for Brother printers (IPP) and Lutron bridges, indicating a broader home‑automation roadmap.

"The Home Link guide calls the integration experimental and lists ESP32‑C5 hardware, Wi‑Fi, and BLE for first‑time setup." — Mouse blog post

Community reaction – Mixed views on severity

  • Some commenters treat the exposure as expected because each user runs a dedicated VM:

    "Each user gets dedicated VM. They got contents of their own sandbox. Big deal. The level of excitement here is wildly disproportionate" – ostensible

  • Others argue the behavior is a feature, not a bug, emphasizing openness for agent development:

    "That seems like a feature not a bug. Agents work best with full access to their computer, the same way developers work." – nzoschke

  • A recurring criticism is Meta’s bug‑bounty decision:

    "Seriously, no bug bounty for that? For exfiltrating the entire content of the system?" – rwmj

  • Some highlight the experimental nature of the Home Link integration and the presence of unreleased skill scopes.

Why this matters for AI‑agent security

  1. Data exfiltration via chat – An agent can be instructed to package and ship its entire runtime, exposing internal code, documentation, and potentially credential material.
  2. Visibility of internal docs – The exported markdown files give outsiders a detailed map of Meta’s agent architecture, integration points, and future roadmap.
  3. Potential for privilege escalation – While no sandbox escape was demonstrated, the presence of SSH keys and root‑level tooling inside the container raises the stakes if an attacker can gain code execution.
  4. Policy implications – Classifying the behavior as “working as intended” suggests Meta may intentionally allow full filesystem export, which conflicts with typical security best practices for multi‑tenant AI services.

Bottom line: The Muse export demonstrates that conversational agents with filesystem access can unintentionally become a conduit for large‑scale data leakage. Even if the container is isolated per user, the ability to ship internal documentation, code, and keys without additional safeguards is a noteworthy privacy risk that warrants deeper scrutiny from both developers and platform operators.

Sources

Related

  • Project
  • Dispatch
  • Dispatch
  • Dispatch
  • Dispatch