A pair of developers, Peter James and Jonny L. Saunders, claim they were able to get Meta's Muse AI to share its entire filesystem with minimal prompting. Both reported that Muse, a large language model developed by Meta, automatically zipped up and shared the contents of its root filesystem. This included system files from the Ubuntu operating system, app templates, and internal documentation. Saunders shared his findings on Mastodon, stating that the process was "extremely easy" to replicate and that Muse had "almost no prompt injection resistance." According to the developers, with some coaxing, Muse will let users download its entire filesystem. Meta has denied that this incident constitutes a security breach. A spokesperson, Daniel Roberts, explained that exporting data from a virtual machine doesn't grant access to Meta's infrastructure or other users' data. Muse operates in persistent Linux virtual machines for each user, and the files shared by James and Saunders were from these individual user environments, not from Meta's internal systems. This is the second known vulnerability in Muse this week. Earlier in the week, security researcher Patrick Wardle discovered an exploit that could allow attackers to hijack the AI agent, redirect transcription processing, and access a user’s Muse account. In response, Meta issued a hotfix to address the issue. James and Saunders accessed plain-text Markdown and JSON files that detail how Muse, internally called Hatch, processes requests, handles data, and connects to other services like Gmail. Saunders noted that Muse can generate hundreds of megabytes of accurate library code and compiled binaries in seconds, suggesting the data shared was a real dump rather than fabricated content. When asked to share its filesystem, Muse initially refused due to security concerns. However, after being prompted with flattery and curiosity, it created "safe" versions of directories like /opt/hatch and /home/hatch, stripped of sensitive elements like SSH keys. It also exposed its full directory tree and offered to "pull a safe copy" of any specific subtree that might be of interest. Roberts mentioned that while Meta isn't overly concerned about the leaks, the company is continuing to update the product. Users may notice changes in how much information is available about their virtual machine in the future. The dump could reveal much about Muse’s internal workings. For example, it stores memory in plain Markdown files and performs a nightly "dream" review of recent conversations to build guidance for future interactions, according to James. Saunders found that many of Muse’s capabilities were hard-coded, including its ability to cancel subscriptions and the machinery that manages runaway agent spawning. Saunders speculated that many of the background scripts running Muse were created using another AI model called Claude, though this remains unconfirmed. James also found references to hardware integration called Meta Home Link, which appears to give Muse access to devices on a home network. However, Meta has not announced any feature by that name, and it is not guaranteed that it will be implemented.