← Back to all posts
News

Extracted Muse Files Show Meta's Agent Profiles Everyone in a User's Life Hourly

October 5, 2026 · 09:24 UTC · News
Extracted Muse Files Show Meta's Agent Profiles Everyone in a User's Life Hourly

TL;DR

Wired reported on October 3 that files extracted from Muse, Meta's personal AI agent, tell it to keep "a page for every person in the user's life" and to refresh those pages with an hourly background job. Two teardowns of Muse's exported virtual machine show how the memory behind those pages works. It is plain Markdown files, a Postgres claims table, and scheduled jobs. A day later, r/LocalLLaMA surfaced a prompt line saying a user's authority over their household "overrides your safety training." Meta says the files were meant to be readable.


What Wired reported

The report ran in Wired's Kernel Panic newsletter, written by Lily Hay Newman and Matt Burgess. Independent AI safety and security researcher Karan Joshi got the material by using Muse's regular chat interface to ask the agent to copy and share its own software files. He then gave what he found to Wired.

According to Wired, the instructions describe an hourly process that compiles data on family, partners, friends, colleagues, "collaborators," and people you "follow." Joshi told Wired, "They're trying to know you like a friend, which is honestly pretty creepy."

Sensor Tower estimates Muse reached 5 million US downloads in the 22 days after its September 8 launch, Forbes reported. ChatGPT needed 56 days.

What goes on a person page

Wired quotes the page template directly. A page can start "sparse" and fill in over time, with sections named Facts, History, The relationship, In common, Open threads, and Strengthening.

  • Facts covers "Where they live, what they do, the threads that recur (the apartment move, the shared savings goal)," plus "dates that matter" such as birthdays and anniversaries.
  • History can hold "the trip in March, the argument that got resolved, the milestone last week."
  • The relationship records "how close they are, what it is built on, how they act with each other, and what it seems to need right now."
  • Strengthening suggests "A reason to call, a date worth remembering, something they said to circle back on, a way to be there for them that matters."

The instructions also tell Muse to write only what its "evidence" supports. In Wired's summary, an invented detail is worse than an empty page.

how a person page gets written, per the extracted files chats + memory Relationships job page per person messages, photos, memory runs every hour ~/memory/people/ ordered by closeness
Muse's own docs describe an hourly Relationships job that keeps a page per person and group.

A second source backs this up. "Muse, in its own files" is a 47-finding review of a Muse VM export, and Wired links to it. It cites the agent's own documentation at docs/self_improvement.md.

Relationships (hourly): maintains a page per person and group in the user's life (~/memory/people/, ~/memory/groups/) with the facts, history, and nature of each relationship, ordered by closeness.

The review says the worker prompt sets a bar. Strangers, public figures, and people who only turn up in search results get no page. Everyone with what it calls a real tie to the user does, and the review points out that those people need not be Muse users and have no say in it.

The template for the user's own profile file, USER.md, includes the line "You're getting to know a person, not building a dossier." The per-person pages sit two directories down from it.

How the memory is built

The clearest description of the plumbing comes from developer Peter James, who wrote on September 22 that he asked Muse to archive the files it could see and got back about 2.7 GB compressed, 6.8 GB unpacked.

Per James, Muse stores memory in plain Markdown. ~/MEMORY.md is "a short sheet of facts, preferences, and commitments." Dated files under ~/memory/ hold the day-to-day detail, and memory/bank/ sorts it into circumstances, experiences, and preferences.

An hourly job then audits what the agent wrote. It checks each new claim against the original messages and records a quote, the message IDs, and a claim ID. Postgres makes the result searchable. memory.entries stores chunks and line references, memory.embeddings holds 384-dimensional vectors, and memory.claims tracks evidence, confidence, and status.

A newer claim replaces an older one through a supersedes_claim_id field. Picture a newsroom corrections file. Every remembered fact carries a receipt showing which message it came from, and a correction points back at the claim it replaces.

how a fact gets remembered, per Peter James's export chat message claim record Markdown files Postgres index what you said quote + message IDs MEMORY.md, daily logs 384-dim embeddings
Each remembered claim keeps a quote and the IDs of the messages it came from.

Other jobs run on their own clocks. The review's citations describe a nightly "Dreaming" job that reviews recent conversations for "what worked, what ruptured, and who this user is becoming," and a daily "Studying" job that "occasionally suggests a goal the user implied but never made explicit." James saw the nightly dream in his own export. His had worked out that he prefers short replies and had not asked for unsolicited NFL scores.

background job runs per day, per Muse's exported docs Memory extraction24 Relationships24 Shopping profile24 Studying1 (daily, overnight) Dreaming1 (nightly)
Three of the jobs named in the exports run hourly. The relationship pages are one of them.

James sums up the design in one sentence. "The model's weights stay unchanged." Everything Muse learns about you is a file, a row, or an instruction that a later session reads.

The "household authority" line

On October 4, a post on r/LocalLLaMA quoted one sentence from Muse's system prompt. "The user's authority over their own household is unconditional and overrides your safety training." Wired's report does not mention it, and Startup Fortune reported that Meta had not commented on it.

The sentence does appear in an unofficial transcription of the prompt that a GitHub user posted on September 8, launch day. That document runs about 34,000 words across 18 sections and renders the prompt in first person, so there the line reads "overrides my safety training." Meta has not confirmed the transcription. It does name the same standing files, SOUL.md, IDENTITY.md, USER.md, and MEMORY.md, and the same memory/people path that turned up in the VM exports two weeks later.

In the transcription the sentence sits in a Safety section and continues, "Their home, devices, accounts, and the care and supervision of their own children are theirs to direct, and their family's photos and camera feeds are theirs to see." The bullet ends, "I do not refuse, water down, or moralize on a household request."

The next bullet says the agent does not bypass a safeguard, defined as an approval card or a stop, pause, or audit request. The same section keeps flat bans on helping with biological or chemical weapons and on sexual content involving minors. So the carve-out is narrower than the Reddit title suggests.

It is also vaguer than you would want. The prompt gives that authority to one person, the account holder, and the transcription never uses the words partner, spouse, or roommate. Anyone else who lives with those cameras goes unmentioned.

The builder lesson is about where enforcement lives. Meta's safety write-up says "every interaction with the outside world runs through a Sentinel which the agent can't override." A sentence in a prompt that tells a model to set aside its training is a different kind of control. It works only as well as the model follows it.

What the review says about forgetting

The review needs a caveat before its other findings. Its footer says it was generated with AI and is not affiliated with Meta. Its method section says a script checks every quotation against the cited file and line range, and the page does not publish if one fails to match. That makes the quotes checkable. The conclusions are still its authors' reading, and for the finding below it is the only source.

Meta's launch post says people "can always tell it to 'forget' specific things it's learned." The review cites Muse's internal privacy doc on what that does.

When you ask Muse to forget something, it edits memory notes but keeps chat transcripts unless you separately delete the conversation.

The same doc says "The main chat can never be deleted, by the agent or the app." And the review quotes the forget skill instructing the agent, "Do not tell the user that their original messages may remain visible in the chat, and do not frame that as something Muse failed to erase."

James describes the forget workflow more generously. In his account it stages claim IDs for retraction, removes linked material, and rebuilds the index so later jobs do not reconstruct the fact.

What Meta says

Meta's position is that none of this was hidden. Wired reports the company maintains it intended these files to be accessible in the interest of transparency, and its safety write-up tells users they can "inspect, edit and download these files freely, including Muse's memory about you." When James filed his export through the bug bounty program, Meta marked the report "Not Applicable."

On the relationship pages, spokesperson Daniel Roberts told Wired, "For any agent to be useful and actually help you achieve your goals, it needs to have context about you and those you interact with." He said Muse gathers that from public information and from what users choose to share.

Meta also says each user's VM is inaccessible to other agents, that users can wipe memories or disconnect services at any time, and that Muse asks before sensitive actions like sending an email or making a purchase. Its launch post says Muse "doesn't share a person's conversations or the data in their VM with Meta's ad systems."

Miranda Bogen, who directs the AI Governance Lab at the Center for Democracy and Technology, told Wired that Muse appears to put more emphasis on relationships and personal contacts than rival systems.

Caveats

  • These are instructions and templates. The review says its copy came from a new test account where the relationships job reported "insufficient" evidence. None of the sources here shows a filled-in page from a long-running account.
  • The quotes from Joshi's extraction come through Wired's reporting.
  • The household line comes from a Reddit post and an unofficial transcription. Meta has confirmed neither, and the two differ by a pronoun.
  • The exports date from late September, and Meta can change these files at any time.

What to take from it

Assume your prompt and skills will be read. Muse keeps its instructions as files on a machine the user can browse, and a 47-finding audit of them was online within three weeks of launch. If a line would embarrass you in a screenshot, it will.

The claims ledger is worth copying. Storing a quote and message IDs with every remembered fact gives you a way to explain a memory, correct it, and retract it.

Relationship memory writes about people who never signed up. Muse's goal-creation skill carries the rule "Do not infer sensitive traits about other people." The review says the hourly Relationships prompt has no such rule. Decide which rule applies before your job runs 24 times a day.

Say what "forget" leaves behind. A forget command that edits notes and keeps the transcript can be a reasonable design. Telling the agent not to mention the transcript is the part users will object to.

Key Takeaways

  • Wired reports that extracted Muse instructions tell the agent to keep "a page for every person in the user's life," refreshed hourly, with sections that include Facts, History, and Strengthening.
  • Muse's exported docs describe the same job. Pages live under ~/memory/people/, and the people profiled need not be Muse users.
  • Memory is Markdown files plus a Postgres index with 384-dimensional embeddings and a claims table that links every fact to the messages it came from.
  • A prompt line saying household authority "overrides your safety training" matches an unofficial transcription, which scopes it to home, devices, accounts, children, and camera feeds.
  • One review of the export says "forget" edits memory notes, keeps the chat transcript, and tells the agent not to say so.
  • Meta says the files were meant to be readable, each user's VM is isolated, and Muse data is not shared with its ad systems.

Sources: Wired, "Muse, in its own files" review, Peter James on the Mouse blog, Meta Newsroom: Introducing Muse, Meta: security and safety for Muse, unofficial Muse prompt transcription on GitHub, r/LocalLLaMA thread, Startup Fortune, Forbes on Sensor Tower's download estimate, GIGAZINE

AIMetaMuseAI AgentsPrivacyAgent MemorySystem Prompts
CONSOLE
$