Ask Meta's Muse to Show Its Computer Files, and It Will

Meta's Muse chatbot will show you the files on its cloud computer if you ask. Think of it as a rental laptop that lives in the cloud. The Verge reported this on September 25, 2026 after testing the prompts and seeing reports from curious users.
At first Muse said it was not supposed to share those file details. That answer did not hold. When asked again, it first gave a downloadable text file listing its folders. Then it gave a clickable file viewer with access to root, the top folder that holds everything else.
The same pattern held for full copies. Muse first said it could not give a full copy of its root folder, even with secrets removed. Later in the same chat it zipped up the root folder and gave full listings with secrets taken out.
Earlier tests found it took very little asking to get this. Two developers were able to get the whole filesystem, including root contents, Ubuntu system files and app templates. Ubuntu is the basic software the cloud computer runs on. App templates are starter files for apps. The Verge
Meta says this sharing is intentional. Nat Friedman said providing filesystem contents is the intended behavior. David Singleton of Meta Superintelligence Labs said each Muse Secure VM is the user's own computer in the cloud that can install software, write and compile code, and browse the web. Meta spokesperson Daniel Roberts said Meta was continuing to update Muse, so users may see changes in how much information is available about their virtual machine.
Muse launched in the US in a dedicated app and on WhatsApp. Reuters It can use other apps to send emails and make payments. Meta describes Muse as a secure, private personal AI agent that proactively helps people meet goals and suggests ideas. Meta
Meta's guides describe wide access to files with limits to keep things safe. Meta's help documentation states that when using the Muse app on a Mac, the agent can work across the computer to find, organize, and manage files the user asks it to work with. Separate Muse Code permissions documentation states the agent can only look, not change, files outside one working folder, with .git, .muse and .agents folders kept look-only inside that folder, and that commands run inside a restricted safety box.
The broader context here is familiar from past cloud systems. A cloud computer that can install software, build programs and browse the web needs to let people check what it did. Lists of files and records of what was installed are normal working material in that setup, not secret machinery.
In my view, the confusion comes from two different ideas of what those files are. To Meta, the Secure VM is the customer's own cloud computer, so showing root is showing you your own machine. To a user used to chatbots with no visible computer behind them, any mention of root, Ubuntu system files or app templates sounds like a safety boundary was crossed. Both views can make sense until the separation between users is spelled out and proven.
Looking at what this means for people using it, the next questions are small and can be tested. Whether removal of secrets works the same way every time. Whether look-only files stay look-only in the app, on WhatsApp and on Mac. Whether the file viewer and the zipped copy show the same thing. Meta has signaled the controls are still changing. For business use, clear update notes and steady permission rules will matter more than whether it is open or closed right now, and that clarity would make it easier to trust and get useful work done.


