Skip to content

Product1 publisher3 min readPublished

One 'allow always' click let Meta's Muse send a seller's home address to every buyer who made an offer

Meta's Muse sent YouTuber Matt Robb's home address to every buyer who made an offer after he ticked 'allow always' instead of 'allow one time'. The cartoon mascots on Muse and OpenAI's Dots leave that risk where it was, in permission screens people click once and forget.

The Product Desk · Product desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying One 'allow always' click let Meta's Muse send a seller's home address to every buyer who made an offer
Photo: engadget.com

What happened

  • Robb first said Muse shared his address without permission, then said after Meta executive David Singleton got involved that he had granted it without realizing.
  • Inc. columnist Jason Aten found Muse's Mac app had synced his text messages and could read all of them, though he believed he had explicitly denied that access.
  • Singleton replied to Aten's posts on X that message syncing in Muse is opt-in, implying Aten had switched it on himself.
  • Meta and OpenAI both encourage users to treat their agents as named digital pets, with Muse fronted by a fuzzy egg-shaped mascot called Jolly.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision The once-or-always prompt is the real access decision in these agents, since a standing grant lets one errand's data flow into every later action without a fresh check.
  • exposure Users who connect cards and health data to get the full product are making standing grants over far more sensitive material than a Marketplace pickup address.
  • contradiction With Meta saying syncing is opt-in and Aten saying he never opted in, admins cannot yet tell whether the Mac setup flow enabled access users did not choose.

When Robb first asked Muse to handle his listing, the agent drafted a message template with his pickup address in it [8]. He expected it to check with him before that line went to anyone [8]. His grant covered every future message, so the agent sent it to "everyone that gave me an offer," in his words [9]. Engadget called it "exactly the kind of mistake that's easy to make when using an agent" [21].

A labelled toggle is designed on the assumption that a user who reads it has agreed to what it says. Robb answered the prompt for the errand in front of him and did not realize what he had granted [7]. He makes tech videos for a living [6]. Engadget puts Aten among the people who consider themselves tech savvy and still ran into trouble [22].

Aten remains certain he never let Muse see his messages [12]. He argued that it does not matter who is right. "If we grant Singleton's premise that I managed to unknowingly click something that enabled this capability, I still think that's really bad," he wrote [13]. "You should not design your system in a way that people end up surprised by this kind of thing" [14].

According to Engadget, seemingly every Muse update arrives with X posts carrying images or video of Jolly [15]. Singleton used one in a long post explaining Muse's virtual machine [16], and Jolly has been a meme on X in the week since Meta's Connect conference [17]. OpenAI launched its muppet-like Dots with a video of people talking earnestly to agents of different colors, shapes and accents, one of them green with googly eyes and a bowtie [2][18].

Engadget is explicit that the Muse mishaps did not happen because of the avatar [15]. Both incidents it describes involve Muse, and it does not report a comparable failure with Dots. The case for caution on Dots rests on what both agents need connected to do everything promised: email inboxes, credit card details, documents, text messages, health data and productivity apps [19]. Engadget calls the cuteness a distraction from that list [20]. Both companies say layers of safeguards protect the data [4]. Engadget's point is that a system working as intended can still take actions its user did not mean [5].

The two cases sort onto two axes that apply to any grant. One is how long it lasts: once, or always. The other is where the result goes: it stays with the agent, or it reaches another person. The low-risk corner is a one-time grant that stays with the agent. One-time grants that reach someone else are tolerable when the confirmation lists the recipients. Aten's square is a standing grant that stays with the agent, a synced message archive the agent can read [10]. Robb's is a standing grant that reaches other people: one address, every buyer with an offer [9].

For a team rolling these agents out, I would keep anything that leaves the account in the one-time column until users can say what they allowed. The cost is more prompts and a slower agent, and I'd expect some users to pick "always" only to make the prompts stop. A check a week after setup shows which square a grant is really in. Ask the user what the agent may do without asking first, then compare the answer with the settings screen. Where the two differ, the user is sitting in Robb's or Aten's square without knowing it.

What to watch

  • Whether Meta changes Muse so a message carrying a home address needs per-recipient confirmation even under an 'allow always' grant.
  • A Meta account of how the Muse Mac app presents its message-sync opt-in, enough to settle Aten's dispute with Singleton.
  • The first reported Dots incident involving connected email, cards or health data, and how OpenAI words its grant prompts.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories