Meta Superintelligence Labs @meta formerly CEO & cofounder at @dreamer, CTO @stripe. ❤️ @fjsingleton. I like to make things.

San Francisco, CA
I’ve seen a couple of posts about this so wanted to demystify. Today, every Muse user gets a free computer in the cloud. It's a real computer, and we’ve designed the security architecture of the Muse Secure VM carefully so you and your Muse can do almost anything you could with a computer sitting under your desk while keeping you and the system safe from threats like prompt injection. We wrote about this at length in our security blog post – security.muse.ai. Activity in the “runtime cell”, which you share with your Muse is unfettered, but sensitive actions are all overseen by the Sentinel, which runs outside of that cell. Similarly, all sensitive secrets - like the passwords you enter into Muse’s secure credential storage - are also stored outside the runtime cell. The runtime cell gets its own root filesystem (including a full Ubuntu linux image) separate from the host filesystem where your other more sensitive data lives. Because it is isolated from the sensitive stuff that runs on the same box, this means that we can, and do, offer users full visibility and control over the files in the runtime cell. Just as you can when you install Linux on your home computer, you can poke around and see all the files that make the system work - both debian system files and the binaries and data files that implement the parts of Muse which run in the runtime cell. This was a very deliberate choice - your Muse Secure VM truly is your own computer in the cloud. You can install software in it, write and compile code, use the browser to surf the web: it is your own Linux box that you can operate as you choose with your Muse. Poking around in this computer doesn't give you any privileged access to Meta infrastructure, or to other people's data If I may geek out a little here for a second… As a kid I loved to take things apart to see how they worked. As a teenager I got into computers and soon found myself drawn to C:\WINDOWS\SYSTEM and the system registry, later Slackware’s /dev/, /proc/ etc – I could see how the system was laid out and as I explored what DLL files and .so files actually did, I gradually became able to meld the computer to my own will. We’re really proud to be able to put a real computer in millions of people’s hands with a similar level of transparency. We built a file explorer right into the Library tab of the UI. We want you to be able to see the markdown files Muse writes while it thinks about how to serve you better, and explore the internals of the system if you’d like to. So, when you ask your Muse to show you its entire filesystem, and receive gigabytes of files you’re seeing the full contents of the runtime cell. It’s yours to explore and enjoy! If you’re not a geek like me, or simply want to download the data that you personally have created directly with your Muse, we added a feature for that too in Settings > Data controls > Download your agent data.
250
319
3,818
803,494
We built a system file explorer right into the mobile app:
12
16
369
38,936
David Singleton retweeted
Excited to be the first to bring the music to @Muse 🎧
29
59
1,158
257,023
David Singleton retweeted
you gave your Muse a look. now give it a voice
115
102
2,013
339,089
I love cooking, so being able to talk to my Muse to go from recipe idea -> shopping list -> ingredients at my door has my mouth watering already!
Instacart is coming to @Muse! Soon, you can connect Instacart, say “Taco Tuesday,” and turn the idea into a cart from your favorite store. Then check out and get groceries delivered to your door. Same Instacart grocery experience, new way to get started. tr.ee/6xWsKG
10
2
90
11,844
David Singleton retweeted
Here at Expedia, we love planning trips. Soon, your personal AI agent will too. We're joining @Muse: tell it where you're headed and it can work with Expedia to sort your hotels, and everything in between.
101
135
1,784
722,369
We appreciate this report and have issued a hotfix to the Muse Mac app. This was a local privilege escalation attack, not a remote exploit. Using it to do harm therefore requires malicious code already running on the user’s machine under their user account and the practical risk to users of the Muse Mac app was therefore quite low. Nonetheless, we have issued a hotfix to the app to address the issue. We take every report of a possible security problem very seriously, including those that arrive as published exploit code (like this one). We strive to be extremely transparent about privacy and security in Muse as we know this is important to maintain your trust. Therefore, here’s a little more detail on this issue: - Muse's dictation is powered by a server-side speech model. The app shipped with an internal setting that allows the endpoint used by this feature to be redirected to a different URL, which is useful during debugging and development. - The setting lives in the app's local preferences, which macOS allows any program running under your user account to modify. Changing this requires malicious code already running on your Mac. This is not remotely exploitable, and it does not involve Muse's servers or the Secure VM that isolates agent tasks. - Overriding this setting would let an attacker proxy audio dictation requests and capture the access tokens the Muse app uses to drive the Muse agent – expanding malware already present on your computer into the Muse agent. Our hotfix removes the endpoint setting from production builds entirely, which closes this vulnerability. - We are grateful for the work of the security research community and potential security issues can be responsibly disclosed via our bug bounty program, which pays up to $300,000 for exactly this class of finding. bugbounty.meta.com/
Please don't install - it's trivial to turn Muse into the ultimate backdoor 💀👀 Ya, as an AI assistant built to manage your Mac, Muse needs broad access to your digital life. But serious 0-day flaw(s) can let local malware/attackers invisibly hijack it. Let me show you. 🧵
18
15
365
78,174
David Singleton retweeted
We are excited to announce we are partnering deeply with Muse to enable agentic checkout with Shop Pay on all Shopify stores, offering people an easy and delightful way to shop and check out with Muse.
404
347
8,002
2,100,655
David Singleton retweeted
Your @Muse can now use Notion. Connect Notion and give Muse something to do. It'll find the context, make updates, and keep work moving for you.
26
22
359
69,124
David Singleton retweeted
Opening access for developers to build Muse connectors. You bring the API -- Muse brings the agent, the browser, and the context of what the person actually wants. People reach your service just by asking for it, and their agent takes it from there. New connectors are live today. Come build with us. muse.ai/platform
1,034
885
11,700
5,993,624
David Singleton retweeted
Here’s how to add Muse to your iPhone’s action button and instantly upgrade your life
The action button integration is absolutely the fastest way to ask your @Muse to do stuff for you on iOS - including directly from the lock screen. It's sick!
14
16
270
78,934
The action button integration is absolutely the fastest way to ask your @Muse to do stuff for you on iOS - including directly from the lock screen. It's sick!
Oh shit. Muse has an iPhone action button shortcut that automatically opens voice transcription to your agent. You hold once, talk, hold again to send. You can get into a really good flow just using the action button to keep conversing with your Muse. Seriously try this. Add it to your action button, and then try having a multi message convo with your Muse by just using the action button. They nailed this.
12
12
263
194,572
David Singleton retweeted
Oh shit. Muse has an iPhone action button shortcut that automatically opens voice transcription to your agent. You hold once, talk, hold again to send. You can get into a really good flow just using the action button to keep conversing with your Muse. Seriously try this. Add it to your action button, and then try having a multi message convo with your Muse by just using the action button. They nailed this.
14
6
121
48,850
David Singleton retweeted
Replying to @Muse
3
3
35
2,128
I've been using the @Muse app on my Mac all day, every day for a while. There are four things it does that I really love: 1/ Quick access to my Muse when I'm working in any other app: ⌥–Space and Octavian appears, ready to help. 2/ Fast SOTA dictation into any app on my computer by holding fn (these shortcuts are configurable, ofc). 3/ The Muse app works with the messaging apps on my computer and helps me keep up. Sorry if I ghosted you before; I can never keep on top of my messages. Muse is already making me a better texter. 4/ My Muse has a little bot status pill that hangs out in the corner and tells me what Octavian is up to on my behalf all day long. What are you using the Mac app for?
muse for mac is HERE!! your agent can now get stuff done right on your computer — files, messages, calendar, notes, all of it. you're in control of what it can access, and it always asks before doing anything sensitive. Add it to the dock - ai.meta.com/muse/download/
20
6
207
36,747
Power user @Muse feature - custom connectors 🔧. Muse has tons of connectors for popular services built in. Even better, Muse can write its own software and run it in the VM you and your Muse share in the cloud. So you can connect Muse to any service with an API.
51
24
560
153,122
@Muse secure VM's Sentinel and human-in-the-loop system gives you visibility and control over all sensitive actions your agent can take. Custom connectors fit right into this system. You’ll get a human-in-the-loop approval for custom connector requests.
2
28
3,163
The power and flexibility of being able to integrate with *any* API service you care about means the ceiling of @Muse capabilities is very very high. Which services have you built custom connectors for in Muse and what are you using them for?
3
17
2,598