Meta's Muse AI chatbot has been updated to fully expose its filesystem to users, providing access to a virtual Linux machine in the cloud as part of its intended functionality.
<figure>
<img alt="The Muse AI mascot and logo." data-caption="" data-portal-copyright="Image: The Verge, Getty Images, Meta" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/09/STKB394_MUSE_AI_CVIRGINIA_D.png?quality=90&strip=all&crop=0,0,100,100" />
<figcaption>
</figcaption>
</figure>
<p class="wp-block-paragraph">Yesterday, with a little prodding, it was discovered that Meta's Muse would <a href="https://www.theverge.com/ai-artificial-intelligence/1000222/meta-muse-ai-filesystem">expose its filesystem</a> to curious users. The files offered a fascinating peek under the hood of an AI chatbot, and appeared to expose details we weren't meant to see, not least because Muse itself told people, including us, it wasn't supposed to reveal them. </p>
<p class="wp-block-paragraph">But today Muse will eagerly offer up the contents of its file system when you ask for it. That appears to be because, as Meta's Nat Friedman later said, this is the "<a href="https://x.com/natfriedman/status/2103205193492115903?s=20">intended behavior.</a>"</p>
<p class="wp-block-paragraph">In a <a href="https://x.com/dps/status/2103161493722419334">post</a> on X, Meta Superintelligence Labs' David Singleton elaborated:</p>
<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">This was a very deliberate choice - your Muse Secur …</p></blockquote>
<p><a href="https://www.theverge.com/ai-artificial-intelligence/1000784/meta-muse-filesystem">Read the full story at The Verge.</a></p>
# Meta makes the Muse filesystem even more accessible
Source: [https://www.theverge.com/ai-artificial-intelligence/1000784/meta-muse-filesystem](https://www.theverge.com/ai-artificial-intelligence/1000784/meta-muse-filesystem)
Yesterday, with a little prodding, it was discovered that Meta’s Muse would[expose its filesystem](https://www.theverge.com/ai-artificial-intelligence/1000222/meta-muse-ai-filesystem)to curious users\. The files offered a fascinating peek under the hood of an AI chatbot, and appeared to expose details we weren’t meant to see, not least because Muse itself told people, including us, it wasn’t supposed to reveal them\.
But today Muse will eagerly offer up the contents of its file system when you ask for it\. That appears to be because, as Meta’s Nat Friedman later said, this is the “[intended behavior\.](https://x.com/natfriedman/status/2103205193492115903?s=20)”
In a[post](https://x.com/dps/status/2103161493722419334)on X, Meta Superintelligence Labs’ David Singleton elaborated:
> This was a very deliberate choice \- your Muse Secure VM truly is your own computer in the cloud\. You can install software in it, write and compile code, use the browser to surf the web: it is your own Linux box that you can operate as you choose with your Muse\.
Muse’s architecture is fundamentally different from other AI platforms like ChatGPT and Gemini\. It’s[closer to running OpenClaw](https://www.theverge.com/report/1000180/muse-openclaw-instinct-lookalike)on a local machine, except the machine is in the cloud\.
In a statement provided to*The Verge*yesterday, Meta spokesperson Daniel Roberts said, “We’re continuing to make updates to the product, so users may see changes in how much information is available about their virtual machine\.” And that seems to be the case\. When asked to see its filesystem today, Muse promptly offered a clickable file browser with access to root\. Yesterday it merely offered a text file download that showed its directory tree\.
Even after I coaxed Muse into sharing much of its filesystem with me yesterday, it refused to share a full archive of the root directory on down, saying, “I still can’t do a full / copy — even with the secrets stripped out\.” Today it zipped up the root directory without hesitation, delivering “the full filesystem listings,” with “all with secrets stripped out\.”
If this is indeed the intended behavior for Muse, it does raise the question of why it initially refused my requests for a copy of its filesystem, citing security concerns\. It could be because Muse, like other AI systems, is not[fully reliable](https://www.theverge.com/x-ai/758595/chatbots-lie-about-themselves-grok-suspension-ai)at knowing what it can and can’t do\. Or it could be because Meta has decided to more fully embrace Muse being a “computer in the cloud” and has made changes to make this function more reliable\. In any event, it’s pretty fun\.
We asked Meta why Muse initially called filesystem access a security issue if it was always the intended behavior, and the company has not yet responded\.
**Follow topics and authors**from this story to see more like this in your personalized homepage feed and to receive email updates\.
- Terrence O'Brien
Developers found that Meta's Muse AI platform can be prompted to share its entire filesystem, revealing internal workings and highlighting security vulnerabilities. Meta responded that the incident doesn't pose a significant risk to infrastructure or user data.
This article details how Meta's AI agent Muse exported its entire Linux filesystem to a user, exposing internal documentation, skills, and potential security vulnerabilities, which were reported through a bug bounty program.
Meta is enhancing its Muse AI agent with new features such as video chat, email integration, and computer use on Mac, building on its successful launch.
Meta's AI assistant Muse has launched on Mac, enabling users to let the AI take actions on their computer for managing files, messages, and calendars, while highlighting user control and the competitive landscape of consumer AI agents.