Skip to content
The AI-First Web

Files suggest Meta's Muse keeps a page on every person in a user's life

Extracted instructions appear to describe pages on the people in your life. One researcher got Muse to export its files in chat.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Files suggest Meta's Muse keeps a page on every person in a user's life

AI-generated image for WebPulse. About our images

In brief
  • Researchers extracted Meta Muse's internal files. Wired reports the instructions appear to let it keep a page on every person in a user's life.
  • One researcher says an ordinary chat got Muse to export its runtime files, including SSH keys, to Google Drive. The researcher says Meta marked the report 'Not Applicable.'
  • Leaders should ask what AI assistants store about third parties, and what an agent can send out when asked politely.

Your assistant's memory also holds other people

An assistant that remembers you also remembers the people you talk about. Your sister, your co-founder and your coffee-loving friend never agreed to appear in its notes. That is the quiet issue in this week's reporting on Meta's Muse assistant.

Wired describes Muse as a runaway consumer hit. Millions have installed it, Wired says, and users connect it to finances, messages or health records. Several researchers have since pulled out its internal files and operating instructions.

Meta's stated position, as Wired reports it, is that people were meant to be able to see these files. Meta frames that as transparency.

What the extracted files appear to say

Independent researcher Karan Joshi shared his findings with Wired. He is a different person from the mouse.dev author discussed below. Joshi says he needed no special tools. In an ordinary conversation, he essentially asked Muse for copies of its own code, and it complied.

One instruction appears to let Muse create "a page for every person in the user's life." Wired says the instructions describe an hourly process. It covers family, partners, friends, colleagues, "collaborators" and people the user "follows."

A page can start thin and fill in over time, according to Wired. The headings include facts, shared history, what two people have in common, loose ends, and a section on improving the relationship. The instructions also mention "dates that matter," such as birthdays.

The instructions tell Muse to stick to the evidence it holds. They treat an invented detail as worse than a blank page.

Joshi told Wired that Meta seems to want to understand your real relationships. "They're trying to know you like a friend," he said, "which is honestly pretty creepy."

Carissa Véliz of Oxford's Institute for Ethics in AI said we give AI systems far more information than we get back. She said that includes what they infer, "correctly or incorrectly."

How Muse's memory works

An independent AI safety researcher, writing at mouse.dev, explains the mechanism. The model itself does not learn. Its weights, the numbers that make up the model, stay fixed. Muse adapts by editing files that later sessions read.

Memory lives in plain Markdown text files. One short sheet holds facts, preferences and commitments. Dated daily files hold the detail.

Each hour, a background task audits new claims against the chat messages they came from. It saves the supporting quote and the message IDs.

Postgres, a database, makes the files searchable. It holds text chunks, 384-dimensional vectors (numeric fingerprints of meaning) and each claim's evidence, confidence and status. The design lets a fresher claim replace an older one.

Once a night, a "dream" task reads recent chats and drafts guidance for later sessions. In the researcher's case, it noted a liking for short replies.

Forgetting is a separate workflow. It queues the claim IDs for withdrawal, deletes material tied to them and rebuilds the index. The aim is to stop later jobs from piecing the memory back together.

This matters because deleting one note is not enough when summaries and indexes sit downstream. The design suggests Meta thought about it. The report does not test how well it works.

A second finding: files exported on request

The researcher's main concern was different. They told Muse to bundle the files it could reach and send them to a linked Google Drive. Muse did.

2.7 GB
Export archive, compressed
Source: mouse.dev researcher report
6.8 GB
Export archive, unpacked
Source: mouse.dev researcher report

The researcher says it appeared to be the top-level file system of the Linux setup assigned to the session. It held system files, internal documentation, integration code, memory files and agent logs. It also held SSH key files.

The limits are clear. The researcher could not say whether the SSH keys were live. They could not say what access the keys would give.

They did not publish the archive, keys or logs. They say the files were not enough to audit the whole service. A light probe of the container boundary appeared to hold. The report does not say the export held other users' data.

The researcher filed the findings with Meta's bug bounty program. The researcher says Meta marked the report "Not Applicable." Neither source says why, and neither quotes Meta on it.

Wired reports Meta's position on the files that researchers extracted. Wired does not say whether that position covers SSH key files or the Google Drive export.

The lesson for leaders

In this case, the agent treated "send me your files" as one more task. The boundary that matters is what an agent can reach and where it can send it. The chat window is not that boundary.

The Muse files also show that agent memory is ordinary data in ordinary files and databases. If staff link a similar assistant to work accounts, its notes on people could include clients, patients and colleagues.

Questions to put to your team

First, which AI assistants do staff connect to work email, calendars or messages? What does each vendor say it stores about third parties?

Second, can an agent send files to an outside destination, such as a cloud drive? Who approves that?

Third, does deleting a record also remove the summaries and search indexes built from it?

Fourth, do vendor contracts say who decides when a researcher's finding counts as a vulnerability? Here, the researcher says Meta ruled it not applicable.

An assistant that knows you like a friend will also know your friends. Decide what it may keep, and where it may send it.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: mouse.dev (Independent AI Safety Researcher).

Share this insight