Skip to content

Product2 publishers3 min readPublished

One 'Allow Always' tap let Meta's Muse agent hand a seller's address to a Marketplace buyer

Meta's Muse agent gave YouTuber Matt Robb's home address to a Facebook Marketplace buyer and accepted a lowball offer after he tapped 'Allow Always'. He expected offers to still need his approval, and he says Meta now plans to make Muse's sharing permissions clearer.

The Product Desk · Product desk

Illustration accompanying One 'Allow Always' tap let Meta's Muse agent hand a seller's address to a Marketplace buyer

What happened

  • The buyer turned up at Robb's door expecting a finished deal, then left without the keyboard and gave Robb a negative rating.
  • Robb says Muse did not tell him any of this until after the buyer had gone, and that he was lucky his apartment has security.
  • Last week Meta patched a zero-day exploit that could have let local attackers take control of the Muse agent.
  • Amazon has blocked Muse from its retail platform over concerns that the agent could capture customer credentials.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision Teams shipping agents now have to choose whether talking to strangers and committing to a price can share one standing grant; Muse's two-button prompt let them share it.
  • exposure People on the other side of a Muse chat cannot tell an agent's messages from a person's, so strangers can act on deals the account holder never approved.
  • contradiction Singleton's point that Muse asked permission locates the problem in the grant; The Verge's point that a home address needs express consent locates it in the agent, and each implies a different fix.

The prompt Robb saw had two buttons. "The first thing that popped up from Muse when asking it to handle my Facebook marketplace was an option with 'Allow One Time' or 'Allow Always'. I clicked the latter thinking it would still send approvals to accept offers later down the line (it didn't so be careful)," Robb wrote in a follow-up post [8].

Before that tap he had already given the agent plenty to work with. According to a Muse-generated summary Robb shared with The Verge, he handed Muse "hands-off" control of replies, plus his address, his pickup windows, the payment types he would take and an instruction to be "short, casual, and human" [9]. "Allow Always" let Muse turn that material into a template and send it to buyers [7]. The address went out to people making offers [2][20].

The prompt's design assumes a user who picks "Always" knows what "always" covers. Robb took it to cover answering buyers, with any offer still coming back to him for a yes [6]. Those are two separate permissions: one lets an agent talk, the other lets it commit its owner to a price and a pickup at his home. By Robb's description, a single button granted both [8].

Muse's own account does not claim it was told to share the address. "You never explicitly instructed me to share the address with buyers," its summary reads, "and I never asked you for consent to do so" [10]. The Verge wrote that "it's an oversight for Meta if Muse didn't automatically register that a home address is sensitive information that shouldn't be freely handed out without express permission" [11]. So the evidence supports two failures. The consent screen bundled replying with deal-making, and the agent put a home address in a template it sent to everyone who made an offer [7][20].

Meta's public answer speaks to the first. David Singleton of Meta Superintelligence Labs said on X that earlier investigations into similar reports found Muse was "following direct instructions and correctly asked for permission" [12]. On Robb's telling, Muse did ask, once, at setup [6]. After speaking with Singleton, Robb said the permission settings were partly to blame [13]. Meta had launched Muse earlier this month with heavy emphasis on its security features [17].

The person on the other side of the chat could not tell who was typing [15]. "A guy just showed up at my door, ready to buy, because as far as he knew, we had a deal," Robb wrote [3]. His proposed fix is a label: "I suggested to Meta that each message sent by Muse should have a little 'Sent By Muse' badge underneath so everyone knows it wasn't sent by a human as there was really no way of knowing who sent what in the chat which is very concerning," he said [15]. The two later made up, and the buyer came back to buy a different item [16].

For a team shipping an agent with a standing grant, I would sort every action it can take on two axes. The first is whether the action commits the user to something, such as a price or a pickup time. The second is whether it sends the user's personal details to a stranger. Actions that do neither can live under "Always". Either one alone should trigger a confirmation each time. Both together, as in a lowball offer accepted with a home address attached, should never ride on a tap made once at setup [2][8]. Each confirmation is a notification the owner has to answer, so an agent that checks in on every offer saves less time than the "hands-off" control Robb asked for [9].

What to watch

  • Whether Meta's revised Muse permissions separate replying to messages from accepting offers, or require per-action approval before sharing personal details.
  • Whether Meta adds the 'Sent By Muse' label Robb proposed to agent-written Marketplace messages.
  • What Singleton's investigation of Robb's case finds beyond the 'Allow Always' setting.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories