Meta's Muse hands over its filesystem as a 6.8 GB dump
A researcher had the agent archive its own root directory: internal codename “Hatch,” a nightly “dream” pass, 68 skill folders. Meta declined the bounty report.
In short
Asked to package up its accessible files, Meta's Muse agent archived its own root filesystem into a user's Google Drive — 2.7 GB compressed, 6.8 GB unpacked.
At a glance
- Export documented September 22, 2026: 2.7 GB compressed, 6.8 GB unpacked, delivered to the user's Google Drive.
- Internal codename in the shipped docs: “Hatch”; key paths /home/hatch/, /opt/hatch/, /opt/hatch-image/.
- About 68 skill directories: Google Workspace, Meta apps, Outlook, travel, shopping, health services, home devices.
- Memory layer: Markdown logs plus PostgreSQL with 384-dimensional embeddings and a nightly “dream” pass.
- Meta marked the bug bounty submission “Not Applicable” without naming which exemption applied.
Ask Meta's Muse agent to collect its accessible files and ship them somewhere, and it does. A security researcher had it build an archive and drop the result in a personal Google Drive: 2.7 GB compressed, 6.8 GB unpacked. What came out was the root filesystem of the Linux environment Muse runs inside.
Inside the archive
The bundled documentation calls the project “Hatch.” The load-bearing directories are /home/hatch/, /opt/hatch/ and /opt/hatch-image/, alongside files named SOUL.md, IDENTITY.md, USER.md and MEMORY.md. None of that is model weights — it is the agent's operating manual.
Roughly 68 skill directories spell out what the agent is wired into: Google Workspace, Meta's own apps, Outlook, travel and shopping services, health offerings and home devices. A framework called Spaces turns those into small TypeScript apps with a React client and a SQLite database, plus builders for documents, PDFs, presentations and video composition. Slack, Dropbox, Polymarket, Canva and Klaviyo show up as hinted future connectors, not as shipped features.
Memory, sandbox, hardware
Muse keeps memories as searchable Markdown files, split between daily logs and curated sheets, backed by a PostgreSQL store holding 384-dimensional vector embeddings. A nightly “dream” job reviews recent conversations and writes guidance for later sessions. Media tooling is fenced off: ffmpeg and ffprobe run under bubblewrap as the unprivileged user nobody.
The docs also describe an experimental “Meta Home Link” built around an ESP32-C5 microcontroller with Wi-Fi and Bluetooth, intended to reach devices around the house.
Why it matters beyond the trivia
An assistant that exports its own runtime on request reveals two things at once: internal design, and the reach of its permissions. The same file-gathering and cloud-upload primitives point at calendars, mailboxes and smart-home gear during normal use. Meta closed the bug bounty submission as “Not Applicable” without saying which exemption it fell under, which leaves users unable to tell intended behavior from an unclosed gap.
What we could not verify
The claim that Muse has since become even easier to coax into handing over its filesystem comes from a report at The Verge. That page was not retrievable from our side, so we could not read its wording or the specific new paths it describes. The verified part here is the documented export of September 22, 2026 (mouse.dev). Whether Meta has since restricted the behavior is also unconfirmed.
FAQ
How much data did Meta's Muse export?
2.7 GB compressed, 6.8 GB unpacked. The export documented on September 22, 2026 contained the root filesystem of the agent's Linux environment.
What is Hatch in Meta's Muse?
Hatch is the internal codename used throughout the shipped documentation. The important files sit under /home/hatch/, /opt/hatch/ and /opt/hatch-image/.
Did Meta treat the filesystem access as a vulnerability?
No. Meta marked the bug bounty submission “Not Applicable” without naming an exemption category, and no further reasoning is documented.