Product1 publisher3 min readPublished
Muse's own prompts show Meta's agent building a page on every person in a user's life
Researcher Karan Joshi asked Meta's Muse for its system prompts in plain chat and got them, including an hourly job profiling everyone a user knows. Anyone shipping an agent should write its prompt expecting it to be read, especially the lines about people other than the account holder.
The Product Desk · Product desk

What happened
- Millions have downloaded Muse and connected it to bank accounts, messages or health data so it can complete tasks for them.
- Each person's page can start sparse and grow sections such as History, Open threads and Strengthening, built only from evidence the agent holds.
- Meta says each user gets a dedicated virtual machine, can wipe memories or disconnect services, and can review an audit log of the agent's activity and plans.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- exposure Friends, partners and colleagues get pages compiled about them, while every user-facing control Meta described can be used only by the account holder.
- contradiction Researchers describe extracting and dumping files that Meta says it meant to share, so the chat-window request is either a hole Meta should close or a feature it intends to keep.
- decision Teams building consumer agents have to write system prompts on the assumption that users will ask for them and get them, because Muse handed its over in ordinary chat.
A Muse user asks where to take a coffee-loving friend for breakfast, and the agent makes a suggestion [6]. The suggestion comes from a page. According to the instructions researcher Karan Joshi extracted, Muse keeps "a page for every person in the user's life" [5]. An hourly process fills those pages in for family, partners, friends, colleagues, "collaborators" and people the user follows [5]. An hourly job runs 24 times a day [2].
The friend's page can record where they live, what they do, "dates that matter" and history such as "the argument that got resolved" [8]. Its Strengthening section proposes "A reason to call, a date worth remembering, something they said to circle back on, a way to be there for them that matters" [13].
What users do with Muse is connect it to bank accounts, messages or health data and hand it tasks [1]. What Meta can point to is a set of protections. Each user gets a dedicated virtual machine that other agents cannot reach. Users can wipe memories, disconnect services, confirm before an email or a purchase goes out, and read an audit log of activity and future plans [10]. Each of those user-facing controls is operated by the account holder, and the reporting describes none for the friend in the breakfast question [1].
Joshi was blunt about the design. "They're trying to know you like a friend, which is honestly pretty creepy," he said [9]. Meta spokesperson Daniel Roberts gave the company's case: "For any agent to be useful and actually help you achieve your goals, it needs to have context about you and those you interact with" [11].
Joshi got the files through the regular chat interface, by essentially asking Muse to copy and share its own software files, according to WIRED [4]. Multiple researchers have dumped the agent's operating instructions in recent days [2]. Meta has maintained that it intended the files to be accessible, in the interest of transparency [3]. If that is true, the chat window did what Meta built it to do. The reporting establishes that anyone who asks can read how Muse is built. It does not show any user's bank, message or health data leaving the app by the same route.
The instructions do contain one sound rule. Muse should use only the "evidence" it has, and invented details are worse than an empty page [7]. That protects the user from bad advice about a real person. Carissa Véliz, an associate professor at Oxford's Institute for Ethics in AI, pointed at the direction the information flows. "We are giving AI systems much more information about us than we are getting information from them," she said [12].
For a team shipping an agent, I'd take two things from Muse. Assume the system prompt is public, since Muse handed its over in ordinary chat [4]. Then sort every record the prompt tells the agent to build by two questions: is it about the user or about someone else, and can that person see and delete it? Records about the user that the user can wipe sit in the box Meta's controls already cover [10]. Records about someone else that only the user can wipe sit in the hard box, and Muse's relationship pages are there [1]. The prompt line that builds them, "a page for every person in the user's life," is already public [5].
What to watch
- Whether Meta closes the chat-window route to Muse's internal files or keeps it open, which would test its transparency explanation.
- Whether Meta adds any notice or deletion option for the people who have relationship pages compiled about them.
- Whether researchers find that the same chat requests can pull user memories or connected-account data, beyond the instructions.