Is Meta Muse Safe? Connectors and Permissions
Meta has published a detailed account of how Muse protects connected accounts, and in it Meta says plainly that “Muse isn’t immune to attack.” By Meta's account, the model never sees your passwords or keys, each connector has its own permission settings, and Muse asks before it sends an email or makes a purchase. One public flaw, in the Mac app, was hotfixed in September. Nobody outside Meta has published an independent audit that we have found. This page sets out what Meta says, what has gone wrong in public, what users report, and which settings are yours to choose.
What Muse can and cannot see
All of this is Meta describing its own design.
- Passwords and payment details. Meta's launch announcement says “Muse has no visibility into people’s passwords or payment methods”, and that credentials go into secure storage “so Muse can use them without seeing them.”
- Keys and tokens. Meta's safety write-up says the agent's code “only ever sees a ‘surrogate’ token”, and the real credential is swapped in at the network boundary. OAuth tokens for the services you connect “are stored in your VM, not in centralized Meta infrastructure.”
- Built-in connectors. Their logic runs outside the agent's own runtime, “with tightly scoped credential access”, per the same write-up.
- Your inbox. The email connector “filters out one-time tokens, password reset links, and login magic links”, so connecting email should not let the agent sign in as you elsewhere.
- Meta itself. The write-up says today's design restricts staff access “through operational policies” but “does not prevent Meta from accessing data when necessary to support, secure or operate the service.” The launch post says Muse Confidential VM, encrypted “with a key only they hold”, is coming “later this year”. No date has been given.
- Ads and training. The launch post says Muse does not share conversations or VM data “with Meta’s ad systems”, and that people can opt out of their interactions being used to train Meta's models.
The permissions you set
Access is chosen per connector, not all at once. The launch post: “For things like email, people choose what Muse can do, whether it reads their mail or can also send on their behalf.” Meta's help page on connectors adds that “Many Connectors can also be set up so that Muse is only able to retrieve data, but not take actions”, and that disconnecting “stops Muse from exchanging data with the Connector.”
Meta's help page on approvals lists two levels. With Ask for some actions, Muse “will ask for permission before every write action and important read actions”; Always ask covers any action. When it does ask, the answers are Allow once, Allow for this task, Allow for this site, Always allow and Deny. The same page says: “Because Muse acts on your behalf, you're responsible for guiding it carefully and approving its actions.”
Partners describe the same split on their side. Dropbox says actions that change your content “will prompt Muse to request additional confirmation”, and that “Connecting Muse does not change your existing Dropbox sharing settings.” Tailscale posted that “your existing Tailscale access controls still decide what it can reach” (@Tailscale, 1 October).
Payments
Meta's safety write-up says that on a site where your card is already saved, Muse asks for approval “with the exact details of the purchase every time.” Through its wallet, “a single-use card number is issued”, tied to one merchant, one amount and a limited time. At launch that wallet was Link by Stripe; Shop Pay has since been added.
What has gone wrong in public
The Mac dictation flaw, September. Security researcher Patrick Wardle found that “any app or Terminal command running locally on a Mac can change a number of undocumented Muse settings”, one of which redirected dictated prompts so an attacker could grab the account's token, according to 9to5Mac. The Verge reported on 22 September that Meta patched it within hours of Ars Technica's report, and quoted David Singleton of Meta Superintelligence Labs: “This was a local privilege escalation attack, not a remote exploit” and “we have issued a hotfix to the app to address the issue.” Wardle's reply, quoted by 9to5Mac, was that “a simple ClickFix attack could deliver the hijack” remotely. 9to5Mac's advice: “If you use Muse on Mac, update ASAP.”
Before launch. On 5 October 404 Media reported, citing an unnamed Meta source and internal posts, that engineers fixed several vulnerabilities in the weeks before launch, at least one of which could have let a user break out of Muse's virtual machine. Meta's statement to 404 Media said Muse was strengthened “through extensive dogfooding, agentic red teaming and our bug bounty program — and that work continues.” We have no source showing that flaw was used against anyone.
Amazon's objection. Amazon told GeekWire that Muse appeared to capture and store customer credentials. Meta's own description of credential handling is above. Both sides are set out in our Amazon guide.
What users report
Saved posts, quoted word for word. They are single accounts, not tests we ran.
- The design question. “genuinely curious how credential permissioning works per connector. One entity holding every key is an attack vector.” (@NeuralNavQ, 24 September).
- Bad connectors. In Chinese, replying to Alexandr Wang about 2,000+ connector submissions: “审核和权限分级才是硬仗” (our translation: review and permission tiers are the real fight). The post goes on that for an agent that can place orders directly, a malicious connector costs far more than a phone app (@Hezz2334, 24 September).
- Too many prompts. “Muse asks for permission TOO often and the cards expire often” (@borgerntendies, 30 September). “can you please make it so emails don’t need approval for every email?” (@StrykerFromFL, 5 October).
- Permission given, action still blocked. “cant have it send msg anymore even with permission” (@sureshsankaran, 26 September, about Gmail).
- Tokens not arriving. A Google Drive connector “shows "connected" but every API call 401s with invalid credentials” (@JoeyFromVA, 23 September).
- Your own rules. “tell it which decisions it can make on your behalf without checking with you first” (@adambader, 11 September).
Custom connectors are a different case
Meta's connectors help page says “Meta doesn't review custom connectors or how they use your information, so grant access with caution.” What that means in practice is in our custom connector guide.
Settings worth checking
Each of these is a control Meta or a partner describes, not advice of our own about risk.
- Set connectors to retrieve-only where the connector offers it (connectors help page).
- Check which approval level you have chosen, Ask for some actions or Always ask, and which connectors you have set to Always allow (approvals help page).
- Review which websites you have allowed Muse to use and revoke any you no longer want; the approvals help page says you can.
- Disconnect anything you have stopped using (connectors help page).
- If you use the Mac app, keep it updated (9to5Mac).
- Read the connector maker's own terms: “Connectors have their own terms and privacy policies” (connectors help page).
What is not published
- An independent security audit of Muse.
- How long credentials are kept after you disconnect a connector.
- A date for Muse Confidential VM.
- What Meta's review of third-party connector submissions checks. Our submission guide covers what the form asks makers to attest.
Related connectors
Sources
- Meta Research — “How We Built Safety Into Muse” — Read 5 October 2026. Tarek Sheasha, 8 September 2026. Surrogate tokens, OAuth tokens stored in the VM, privsep, the email filter, approval scopes, payments, staff access, and “Muse isn’t immune to attack.”
- Meta Newsroom — “Introducing Muse: The World’s First Personal AI Agent Built for Everyone” — Read 5 October 2026. 8 September 2026. Passwords and payment methods, read vs send for email, ads, training opt-out, Muse Confidential VM “later this year”.
- Meta Help Centre — How Muse works with Connectors — Read 5 October 2026. Retrieve-only connectors, disconnecting, connectors' own terms, and custom connectors not reviewed by Meta.
- Meta Help Centre — How Muse works with your guidance and approval — Read 5 October 2026. Approval levels, the five approval answers, revoking site access, and the responsibility sentence.
- Dropbox — “Put your Dropbox project context to work with Muse, from Meta” — Read 5 October 2026. 29 September 2026. Confirmation for changes; sharing settings unchanged.
- 9to5Mac — “Security Bite: The last 24 hours at Meta were not-a-musing” — Read 5 October 2026. Arin Waichulis, 22 September 2026. Wardle's finding, the ClickFix reply, and “update ASAP”.
- The Verge — “Meta patches Muse exploit that let attackers control the AI agent” — Read 5 October 2026. Jess Weatherbed, 22 September 2026. The patch and David Singleton's statement.
- 404 Media — “Meta Rushed to Fix Muse ‘VM Escape’ Vulnerability Soon Before Launch” — Read 5 October 2026. Jason Koebler, 5 October 2026. Pre-launch fixes per an unnamed Meta source, and Meta's statement.
- GeekWire — “Amazon blocks Meta’s Muse AI assistant in new standoff over agentic shopping” — Read 5 October 2026. Amazon's credentials objection only.
- Shopify on X — Shop Pay now available as a wallet in Muse — Checked against the saved post text 5 October 2026. 24 September 2026.
- @Tailscale on X — access controls — Checked against the saved post text 5 October 2026. 1 October 2026.
- @NeuralNavQ on X — credential permissioning — Checked against the saved post text 5 October 2026. 24 September 2026.
- @Hezz2334 on X — review and permission tiers — Checked against the saved post text 5 October 2026. 24 September 2026. Chinese; the translation is ours.
- @borgerntendies on X — permission prompts — Checked against the saved post text 5 October 2026. 30 September 2026.
- @StrykerFromFL on X — approval for every email — Checked against the saved post text 5 October 2026. 5 October 2026.
- @sureshsankaran on X — Gmail send blocked — Checked against the saved post text 5 October 2026. 26 September 2026.
- @JoeyFromVA on X — Google Drive 401s — Checked against the saved post text 5 October 2026. 23 September 2026.
- @adambader on X — deciding what Muse may do unasked — Checked against the saved post text 5 October 2026. 11 September 2026.
More guides
- How to Get Your App on Muse: Connector Submission Guide — First-hand walkthrough of the three-step connector submission, field by field, from our own two submissions.
- What Are Muse Connectors? — What a connector is, the kinds that exist, and what is and is not publicly visible.
- Muse Spark 1.3 on the Meta Model API — The model ids, the context window, and why “Muse Spark API” is the wrong name for it.
- Muse Code: What It Is and How It Ships — How Muse Code is distributed, what the SDK is, and how to track releases when the changelog has no dates.
- Why Can't Muse Shop on Amazon? — The Amazon block: what each side said, the posts from people it stopped, and the retailers that went the other way.
- How to Create a Custom Connector in Muse — What Meta says about custom connectors, the steps people follow, and saved reports of them working and failing.
- Is Meta Muse Available in My Country? — US and Canada only, per Meta. The sources in date order, saved posts from elsewhere, and the local apps people want.