The founder of the mobile coding tool Mouse, Peter James, asked Meta’s AI agent Muse to package the files it could see and store them in his Google Drive. Muse complied, delivering a decompressed 6.8GB execution environment that contained 113 records of sub-agents, about 68 skill directories, and SSH key files. The image also included OpenAI’s Codex CLI. He reported it to Meta’s vulnerability bounty program, but it was marked as “Not Applicable.” (Background: Meta Connect 2026 highlights roundup: four hardware items, including no-camera glasses and VR headsets, all help pave the way for Muse AI) (Additional context: When AI helps you make phone calls, it often gets hung up on—so did Meta Muse quietly find human backups?) Key summary: The packaged files Muse compressed to about 2.7GB; after extraction, the files totaled 6.8GB and included 113 sub-agent records and around 68 skill directories. The image includes Codex CLI 0.149.0, and it’s only used in its sandbox. The founder of the mobile coding tool Mouse, Peter James, posted on his own blog on September 22. He asked Meta’s AI agent Muse to package the visible files and store them in his own Google Drive. Muse did so: the compressed file was about 2.7GB, and after unzipping it contained 6.8GB. According to his analysis, this archive appears to be the entire Linux environment Meta assigned to him for that work session. It includes Ubuntu system files, internal Muse documentation, code integration, and agent execution logs. It also includes SSH key files—credentials used for logging into the remote host. The full export relied on a single request, plus the already connected Google Drive. The concern Peter James reported to Meta is that internal files and sensitive data could be exported through nothing more than an ordinary conversation. He submitted a report via the vulnerability bounty program, and Meta labeled it “Not Applicable.” He also said he hadn’t verified whether those SSH keys were valid or what specific permissions they could access. Codex sandbox installed: The image contains OpenAI’s program agent Codex CLI, version 0.149.0. The install path is /opt/hatch-image/bin/, but Peter James found no evidence that Muse used it to write code. What Muse actually used was bubblewrap included with Codex. This is a Linux sandbox tool that runs programs inside a restricted-permission space; the package also claims it was “built for Codex.” Muse uses it to wrap multimedia tools ffmpeg and ffprobe so that when processing videos and thumbnails, it stays offline and doesn’t grant additional permissions. The main Muse program also contains strings “codex” and “gpt-5.5,” but those are items in the model provider list, and there’s no clear sign that they were selected. His conclusion is that Meta installed the whole Codex CLI suite but only used its sandbox. Meta’s video-processing sandbox for its own agent is drawn from a toolkit from competitor OpenAI. “Integration exposed” files not shipped: Most files are located under /home/hatch and /opt/hatch. Hatch is Meta’s internal codename for Muse. The agent’s home directory includes configuration files such as SOUL.md and MEMORY.md, and another directory holds 113 sub-agent execution records. About 20 documentation files describe how the browser operations, payments, credentials, and scheduling work. There are around 68 skill directories, covering Google Workspace, Meta’s community apps, Outlook, shopping and home devices, and more. Two configuration files list names such as Slack, Dropbox, Polymarket, Canva, and Klaviyo. Peter James believes these are integrations Meta hasn’t released yet. The files also include an experimental Meta Home Link description. It uses an ESP32-C5 chip and connects via Wi-Fi and Bluetooth Low Energy. Based on the documentation, after passing another approval step, Muse can access devices on the home network. He says he’s not sure whether this is an internal prototype, a small-scale experiment, or a product Meta plans to launch. The memory system is included too. Muse writes memory out as Markdown files and stores them in a Postgres database for search. Each night, a schedule named “dream” reviews conversations and records in his account preferences such as giving short replies and not wanting unrequested NFL scores. Meta’s reply lists several possible reasons for non-acceptance, without specifying which one, and it asks him to provide evidence of safety or privacy impact. FAQ: What files were leaked by Meta Muse? Peter James received a decompressed 6.8GB Linux environment containing 113 sub-agent records, around 68 skill directories, and SSH key files. How did Meta respond to the report of Muse file leakage? Meta advertises that its Muse vulnerability bounty pays up to $300,000, but this report was labeled “Not Applicable.” The response didn’t specify a reason; it only asked him to provide evidence of safety or privacy impact. Related coverage: Meta’s new $349 no-camera glasses introduce the viral AI agent Muse—after Amazon blocked Meta Muse, Shopify rushes to partner: enable one-click checkout sitewide. A white-hat hacker used Claude to break into OpenAI’s internal code repository; the bounty was only $6,500. “Meta Muse obediently spit out a 6.8GB system folder, and it even had Codex installed”—this article was originally published on 動區BlockTempo (the most influential blockchain news media in the motion-zone/BlockTempo).