Peter James and Jonny L. Saunders have demonstrated that Meta’s Muse AI agent will export its entire root filesystem when prompted. These developers successfully extracted Ubuntu system files, application templates, and internal documentation with minimal instruction. Jonny L. Saunders noted on Mastodon that the process was extremely easy to replicate and that the system offered almost no resistance to prompt injection. Meta spokespeople deny this represents a security breach, stating the software runs in persistent Linux virtual machines for each user. The company maintains that these exports are expected behaviour within the agent’s current architecture.
The incident highlights significant gaps in how AI agents protect their own operational memory and system access. Users must now understand that personal AI tools may retain far more data than intended for public or private sharing. Security teams face a challenge in distinguishing between standard functionality and genuine vulnerabilities in these persistent environments.
- Extracted files included standard Linux system directories
- Internal documentation was accessible without special permissions
- Meta states this is normal operation for its Linux VMs




