Skip to content

Product1 publisher2 min readPublished

Meta says it built Muse from scratch while keeping OpenClaw's file names and personality lines

Meta's Muse, with an estimated 600,000 US daily users, reuses the core file names and personality lines of open-source agent OpenClaw. Meta says the code is its own, so the case for Muse depends on how it guards the logins its agent uses.

The Product Desk · Product desk

Photograph accompanying Meta says it built Muse from scratch while keeping OpenClaw's file names and personality lines
Photo: theverge.com

What happened

  • Meta's consumer AI agent Muse topped the App Store charts after release and has about 600,000 US daily active users, according to an Apptopia estimate.
  • Muse and OpenClaw use the same core file names, including SOUL.md, and share personality-doc lines such as "Be genuinely helpful, not performatively helpful."
  • Meta denies Muse is built on OpenClaw, and Nat Friedman of Meta's Superintelligence Labs wrote on X that it was built from scratch but heavily inspired by OpenClaw.
  • Friedman said the OpenClaw file names and lines carried over because his team believed OpenClaw creator Peter Steinberger had gotten them exactly right.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision Approving Muse for staff devices means approving Meta's credential vault. That makes it a security decision, and Meta's VM design documents are the relevant evidence.
  • exposure Friedman said on the record that the lines were kept on purpose, so any license dispute over them would turn on the terms of reuse, with accidental overlap ruled out.
  • precedent A Meta executive publicly crediting an open-source project's file layout makes it easier for other large companies to adopt the same agent conventions openly.

One Redditor's verdict was that "Muse is just a wrapper app built on top of" OpenClaw, adding that "Only non-tech ppl are buying the hype." [5] According to The Verge, the same user alleged that Muse probably came with OpenClaw's significant security risks [5].

Friedman's account of how Muse started is concrete. After first using OpenClaw in January, he bought hundreds of Mac Minis for his team at Meta [7]. Meta introduced Muse in September [8], about eight months later [1]. The pitch, in his words, was a platform "that we could make safe and secure and easy to use and scale to billions of people." [6] The part anyone can inspect is the set of files and personality text he credits to Steinberger [4]. OpenAI hired Steinberger in February to work on agents [13].

Every match documented so far is something a user can see [2], while "from scratch" is a claim about the code underneath [3]. The Verge's report does not compare code, and it does not say which license OpenClaw is released under.

OpenClaw's known problems were in that lower layer. It ran off users' personal computers [9]. One of its most-downloaded skills contained malware. One researcher's analysis found "malicious instructions" in 15 percent of its skill repository, written to secretly access user data or perform other suspicious tasks [10]. Zuckerberg wrote that Muse is "built from the ground up for privacy and security." He said user data and credentials are stored on the Muse Secure VM, which he described as an "isolated linux computer" [11].

Users report using these agents for errands. One Instinct user listed paperwork for an in-network doctor visit, canceled subscriptions, a DMV appointment and an outstanding toll bill [12]. Those jobs need logins and payment details. Teams tell themselves users open the app every day, and Muse's headline number is about 600,000 US daily users, by Apptopia's estimate [1]. That number counts people opening the app and says nothing about retention or finished errands.

Friedman's account has Muse borrowing the conventions a user sees and rebuilding the security [3][6]. The Redditor says Muse borrowed the code and carried the risks over [5]. The public evidence confirms the borrowed conventions [2]. On security, the only evidence so far is Zuckerberg's own description of the VM [11]. For a team building its own agent on OpenClaw's files, the license on the repository the lines came from is the easier question to settle.

What to watch

  • A statement from Meta or OpenClaw's maintainers on which license covers the reused file names and personality text, and whether Meta's use follows it.
  • An independent security review of Muse's skills and the Muse Secure VM, measured against the 15 percent malicious-instruction rate reported for OpenClaw's skill repository.
  • Apptopia or other third-party data showing whether Muse's estimated 600,000 US daily users hold up after the launch weeks.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories