Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • This isn't a bug and doesn't deserves any bounty. Each user gets isolated VM and that is the design and agent is able to access everything.
  • Seriously, no bug bounty for that? For exfiltrating the entire content of the system?
    by rwmj
  • Ah, glad to hear Muse has a Polymarket integration in the pipeline. I mean, what could possibly go wrong?
  • Am I missing something? This isn't a vulnerability. Your agent can see the files in its virtual environment. SSH keys are also not necessarily confidential. Please don't use AI to write blog posts.
  • Each user gets dedicated VM. They got contents of their own sandbox. Big deal. The level of excitement here is wildly disproportionate
  • These files are visible in the muse app by browsing system files.
  • That seems like a feature not a bug. Agents work best with full access to their computer, the same way developers work.

    It gives me a glimmer of hope that openness will win. I don't trust Meta as a corp, but they've been doing the a lot of good things with open source, open models, and developer friendly agents.

    More thoughts on agent computer architecture here, as I've been building our own open core system for this: https://housecat.com/blog/agent-computer-101

  • I asked it for it's harness and then asked agy to do a teardown. It's a monolithic 332MB binary written in Rust from scratch.

    Full teardown is here:

    https://gist.github.com/simonpure/d6f960045334453360eff1e2a0...

Explore Birbla archives