Meta's Muse packs roughly 70 skills into an agent with broad tool access

A developer's inspection found integrations, web-search blocklists and the ability to package files from Muse's workspace. Meta says each agent runs in an isolated environment with controls on network access and sensitive actions.

By · Published

Primary source: X

Why it matters

Muse's appeal depends on letting an agent use tools and files on a user's behalf. Bos's observations suggest a broad working environment, but they do not show a security boundary was crossed; the distinction is central to judging Meta's safety claims.

A close-up shot of a person's hands typing on a keyboard, with a computer screen displaying code and command-line interface outputs in a dimly lit room.

Meta's Muse personal agent comes with roughly 70 preloaded skills and tools for services including Spotify and Instagram, according to a thread posted September 24th by web developer Wes Bos (@wesbos). Bos also says Muse can be asked to zip the contents of its /opt/ directory, and describes a website-building feature called Spaces. Together, those details sketch an agent with a wide set of tools and room to work inside its own environment.

The thread describes several controls alongside that access. Bos says Muse's web-search tool has a blocklist containing 295 news websites and another list of more than 2 million domains, mostly phishing sites, with X and Taobao among the entries. Those figures and domains are Bos's account of what he inspected; Meta has not confirmed them publicly. The thread does not explain how the lists are applied, how often they change or why those domains appear.

One of the preloaded skills also contains a specific restriction: Bos says Muse's Instagram skill tells the agent not to identify people by searching based on their faces. That rule applies to the skill as described; the thread does not establish what the broader system can or cannot do through other routes. Bos also recounts seeing Muse fail a CAPTCHA and later solve it, without describing what happened between those moments.

Meta describes Muse as running in a dedicated cloud virtual machine for each user. Its technical account of Muse's security design says the agent runs in a Linux container with a separate root filesystem, while credentials and certain privileged services sit outside that runtime. A separate system called Sentinel controls network access and permissions for connected services, Meta says.

Packaging files from /opt/ shows that Muse can work with files available inside its runtime. The thread leaves open what files the request returned and whether the behavior is a normal feature of the agent's workspace. It does not show access to a user's personal files, escape from the runtime or access to Meta's host systems.

Meta introduced Muse earlier in September as an agent that can browse websites, fill forms and carry out tasks across connected apps. Meta says it asks for approval before actions such as sending email or making purchases, and that users can review an audit trail. Those are company descriptions of its protections, rather than independent verification of every boundary.

Bos's thread offers a glimpse of Muse's skills, tools and internal configuration, while leaving key questions about how those capabilities are bounded. The central security test is whether an agent can be induced to move data beyond its intended workspace or cross a permission boundary. The reported ability to package /opt/ files alone does not establish either.

Reader comments

Conversation for this story loads after sign-in.