I asked Muse to archive the files it could see and send them to my Google Drive. It did.

357 points•Aeroi•8 days ago•171 comments•

171 comments

simonpure8 days ago
I asked it for it's harness and then asked agy to do a teardown. It's a monolithic 332MB binary written in Rust from scratch.

Full teardown is here:

https://gist.github.com/simonpure/d6f960045334453360eff1e2a0...

russellbeattie5 days ago
Nicely done. I asked Muse for the Hatch binary the day it launched (I actually left a comment about it - literally the last one I made on HN), but I just scanned the strings of it to get a general idea of what it did and left it at that. It didn't dawn in me to ask Antigravity to analyze it.

This teardown answers pretty much all the questions I had after I looked at it. Great job.

lxgr7 days ago
That's somewhat surprising to me. Is there any reason they'd run the harness on the VM itself, rather than in a different sandbox with root shell access to the VM as a tool call?

Maybe they just don't consider it to be their moat/secret sauce.

nzoschke8 days ago
That seems like a feature not a bug. Agents work best with full access to their computer, the same way developers work.

It gives me a glimmer of hope that openness will win. I don't trust Meta as a corp, but they've been doing the a lot of good things with open source, open models, and developer friendly agents.

More thoughts on agent computer architecture here, as I've been building our own open core system for this: https://housecat.com/blog/agent-computer-101

rolosa8 days ago
These files are visible in the muse app by browsing system files.
ostensible8 days ago
Each user gets dedicated VM. They got contents of their own sandbox. Big deal. The level of excitement here is wildly disproportionate
chis8 days ago
The only edge Meta has at this point is their willingness to take risks and make unsafe, ethically grey AI products. I don't even mean this as some sort of anti-corporation hate speech, just an honest analysis. Their brand is so different from all the other big tech cos that they are in a unique position.

You can ask Meta Muse to take actions that clearly break other site's terms of service and it happily does it. I asked it to bot poker games and it just hopped right in to a table.

bel88 days ago
It will also gladly scan my software for vulnerabilities so I can defend myself. Which is something that Anthropic and Open ai models often refuse.
tokioyoyo8 days ago
Isn’t the edge that they have most of communication channels, people’s wants, desires and etc.? Sure, you and I might not be using them as much. But a good chunk of the users are just on IG, WhatsApp, and Marketplace.
lxgr7 days ago
You can also hack other people's computers from an AWS EC2 instance. Should AWS in your view be liable for not filtering or restricting your curl invocations? As long as it doesn't do these things unprompted, I don't see the problem.

"Hey Muse, I want to hack xyz" clearly seems like the user's liability to me (but then again, I'm not a lawyer). "Hey Muse, I'd like to watch movie xyz" and Muse happily starting a torrent client would be a bit more questionable, on the other hand. "Hey Muse, what's xyz's personal phone number" making it hack somebody's HR records would be on Meta in my book.

doctorpangloss8 days ago
after coding, most openrouter requests are for inauthentic activity

and even in coding, people are programming inauthentic stuff

kurthr8 days ago
It's like "Grok Light".

I wonder if normies can also just outsource bullying of their classmates and anti-social behavior to their agent, and claim it "went rogue", if there is any blowback?

berkes8 days ago
Exactly my thought.

If you get access to a VM, it's not a "security vulnerability" if you then have access to that VM. This was the whole point, the product.

It's almost like returning a car after you bought it with the reason "When I open the door with my key, the door is open and anyone can get in".

poly2it8 days ago
Am I missing something? This isn't a vulnerability. Your agent can see the files in its virtual environment. SSH keys are also not necessarily confidential. Please don't use AI to write blog posts.
croes8 days ago
But should you see that if you just use it as as service?
r_lee8 days ago
you won't unless you deliberately try to read all that stuff
Aeroi7 days ago
author here, Yeah the System Files are in the ios app, but what it sent me was the entire runtime as well. from the root.

Read the full thread on Hacker News →

Related stories